Re: Commit sigining and message policy

Christoph Cullmann <[email protected]> Tue, 21 Jul 2026 18:01:41 +0000
Newsgroups gmane.comp.kde.devel.general
Message-ID <16u9qN6WHWCx66hFKBL8Tiiwbbe1cbDSp7CP0-SXWIqAgrNEBij6A33nt_rZ2WZxljVDViBb_wbku7NxIsVlnx1vgjAjPn58loeq4xZQwGw=@cullmann.io>
This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--------30409a374768f246722c243116ad9e72ac133eb97bba0e097a93d9953182f673
Content-Type: multipart/mixed;boundary=---------------------28f72b3abb61e2f31dbe4ea9c327c9ce

-----------------------28f72b3abb61e2f31dbe4ea9c327c9ce
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;charset=utf-8

Hi,

On Tuesday, July 21st, 2026 at 19:43, Benson Muite <benson_muite@emailplus=
.org> wrote:

> =


> We are trying to come up with contribution guidelines for Mankala, a
> project we would like to bring to KDE. There is a commit policy
> available at:
> =


> https://community.kde.org/Policies/Commit_Policy
> =


> a) Is it ok to ask for signed commits for a project?

I think requiring that is as for KDevelop a no-go.


> b) If someone has used a coding agent, what is the best way to
> acknowledge this?  Should the commit message be co-authored, or contain
> an acknowledgement?  A number of KDE projects do not accept AI generated
> code (primarily due to licensing and ethical concerns), but others do.
> Of those that do, a few indicate co-authored and the name of the AI
> tool/agent - the commit policy was written before the use of AI agents.

There is an explicit statement for that in our policy:

Do not indicate code manipulation tools have authorship: Authorship is for=
 humans, not tools. Code assistants and such must not be described in comm=
its using tags like "Co-authored-by" or similar. Nor must they be listed a=
s primary author.

Greetings
Christoph

-----------------------28f72b3abb61e2f31dbe4ea9c327c9ce--

--------30409a374768f246722c243116ad9e72ac133eb97bba0e097a93d9953182f673
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: ProtonMail

wrsEARYKAG0Fgmpfs/YJEM1fs5FLcYVCRRQAAAAAABwAIHNhbHRAbm90YXRp
b25zLm9wZW5wZ3Bqcy5vcmfsyw5xwevCr9gJLqmy4AodEB/K/6PTF+qFtuhq
ismDfBYhBO1uxDUBKKYjabTl981fs5FLcYVCAADi6AD+LsPeujvV2rrWY0FS
KdCpUHKyqjR5QpePA83SUmKma0kA/2g1IOY1MW6kibLYGxx4Sbtup0H+9DzP
qqciw85bBSUH
=AbMk
-----END PGP SIGNATURE-----


--------30409a374768f246722c243116ad9e72ac133eb97bba0e097a93d9953182f673--