Document commit signing: rationale, setup, and org-wide enforcement
@Ethan-Arrowood がすでに取り組んでいます。
2026年7月10日 から。
評価
この issue はまだ評価されていません。
説明
Summary
Write a commit signing guideline doc. We want to enforce commit signing across the org — all commits to all HarperFast repos, with public-facing OSS repos as the highest priority, should be signed.
Doc outline
The doc should be structured in this order:
1. Why commit signing matters
Open with the rationale: signed commits cryptographically verify that a commit actually came from the person it claims to be from. Cover the threat model briefly — author spoofing (anyone can set user.name/user.email to anything), supply chain integrity for our OSS consumers, and the "Verified" badge as a trust signal on public repos.
2. How to set it up
Link out to setup resources rather than duplicating them:
- GitHub: About commit signature verification
- GitHub: Signing commits
- SSH key signing (the lowest-friction option for most people): Telling Git about your SSH key
- GPG setup for those who prefer it
- Note on signing via the GitHub web UI (web-created commits are automatically signed by GitHub)
3. How we enforce it
Link to the enforcement mechanisms and document which ones we use:
- Org-level: rulesets at the organization level with the "Require signed commits" rule
- Repo-level: branch protection / repo rulesets requiring signed commits on default branches
- Document the actual settings we apply so repo admins can verify their repo is compliant
4. AI agent workflows
Platform enforcement (rulesets, CI, hooks) is the backstop, but AI agents are a major producer of commits and a major reviewer of PRs — the guideline should be embedded in agent workflows too, especially in the window before hard enforcement is rolled out:
- Producing commits: skills / agent instructions (e.g. in the
skillsrepo,CLAUDE.md/AGENTS.mdconventions) should instruct agents that commits they author must be signed — verify the environment's signing config (git config commit.gpgsign, signing key present) before committing, and surface a warning rather than silently producing unsigned commits. - Reviewing PRs: PR-review skills should include a commit check step — flag unsigned/unverified commits in review output. This gives us soft enforcement via agent review before org rulesets are turned on.
The doc should note this pattern; actually updating the individual skills can be follow-up work.
5. Effective date
Short closing section: this policy was adopted in July 2026. Enforcement applies to commits from this point onward — historical unsigned commits are grandfathered in and do not need to be rewritten. Only new commits are required to pass signature verification.
Acceptance criteria
- Doc added to this repo following the sections above
- Enforcement settings (org ruleset and/or repo-level guidance) documented
- AI agent workflow guidance included (agents sign their commits; review skills check for signatures)
- Effective date (July 2026, forward-looking only) stated
- 主要言語
- JavaScript
- スター
- 3
- フォーク
- 0
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
- Dockerfile・Docker Compose ファイルなし
- プルリクエストのテンプレートなし
- コントリビューションガイドを読む
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
HarperFast/code-guidelines のほかの issue
-
Define commit standards: authorship, AI attribution, and trailers再び着手できるかも @Ethan-Arrowood が 84 日前に担当しましたが、オープン中のプルリクエストはありません。 オープン
HarperFast/code-guidelines#13 · 担当者 1 名 ·
HarperFast/code-guidelines の issue をすべて見る
似ている issue
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
CircuitVerse/CircuitVerse#7967 · コメント 1 件 · リアクション 1 件 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
CopilotKit/aimock#491 ·
メンテナーはふだん 1 日以内に返信
-
cvss-severity:high devguard l3montree-cybersecurity/.../devguard-documentation pkg:devguard/l3montree-c.../devguard-documentation risk:low state:open
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
l3montree-dev/devguard-documentation#338 · コメント 1 件 ·
-
bug runtime spec compliance
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
frostney/GocciaScript#1413 ·
メンテナーはふだん 1 日以内に返信
-
bug
難易度 2/5 1〜3時間 初心者へのやさしさ 75/100
keyxmakerx/Chronicle#967 ·
メンテナーはふだん 1 日以内に返信