Policy guides¶
Two rules are off by default because they encode a decision only your project can make: whether contributors must certify the origin of their work, and whether AI assistance is welcome, disclosed, or refused.
Commit Check does not take a side on either. It gives you a way to enforce the position you have already taken, so it stops being relitigated in every review.
Require signoff (DCO)¶
Projects that use the Developer Certificate of Origin
require every commit to carry a Signed-off-by trailer. The Linux kernel and
much of the CNCF work this way.
A DCO bot rejecting a pull request after the fact is a poor experience: the contributor has to rewrite history for every commit in the branch. Checking locally fixes it before it becomes a problem.
Turn it on¶
This enables CC012, which is off by default.
Signing off¶
The trailer is appended automatically from your user.name and user.email:
Forgot it? Fix the last commit in place:
Fix a whole branch:
Make it automatic
Signing off is easy to forget. Combine this rule with the pre-commit hook so a missing trailer is caught at commit time, not at review time.
Identity matters¶
The DCO is a statement about who wrote the code, so it only means something if the identity is real. CC101 and CC102 check the committer name and email, and are enabled by default when their check runs:
To require a company address:
Bots¶
Automation cannot meaningfully sign the DCO, and forcing it to produces meaningless trailers. Exempt bots instead:
[commit]
require_signed_off_by = true
ignore_authors = ["dependabot[bot]", "renovate[bot]"]
ignore_authors matches the commit author and any Co-authored-by: trailers.
AI attribution¶
AI coding tools add trailers to commit messages identifying themselves. Whether that is welcome, required, or unacceptable is a decision each project makes for itself — and the industry has landed in different places:
- The Linux kernel added an
Assisted-by:trailer, treating AI assistance as something to disclose. - Some projects disallow AI-assisted contributions outright, usually over provenance and licensing.
- Most projects have no stated position, which means the question resurfaces in every code review.
The default: no opinion¶
CC013 is off. Commits carrying AI trailers pass, and so do commits without them.
Forbidding AI-attributed commits¶
Commits carrying a recognised AI signature now fail:
CC013 ai-attribution check failed ==> feat: add caching layer
AI attribution policy violation
Suggest: This project forbids AI-assisted commits. Remove AI trailers and re-commit.
Docs: https://commit-check.com/rules/#cc013
Recognised signatures are trailers and co-author lines naming Claude Code, GitHub Copilot, Codex, Gemini, Cursor, Devin, Aider, Windsurf and Tabby, plus generic AI model patterns.
This checks disclosure, not authorship
CC013 reads commit metadata. It detects a commit that says it was AI-assisted; it cannot detect one that was AI-assisted and did not say so.
Set against a policy of "no AI contributions", it is an honesty check on contributors who are already following the rules — not an enforcement mechanism against those who aren't. Be clear with yourself about which of those you are buying.
Exempting automation¶
Bots that legitimately carry AI trailers can be excluded:
Documenting the decision¶
Whichever way you go, the config file is not where contributors look. State the
policy where they will see it — CONTRIBUTING.md, the pull request template —
and let Commit Check be the mechanism rather than the announcement.
Enforcing an undocumented policy produces a confusing failure for somebody acting in good faith.