Commit metadata governance¶
Git commit metadata is immutable engineering evidence. It is part of the repository governance record. Agents and automation must not mutate it without an explicit, per-commit decision by the human operator.
Authority: GOV-COMMIT-META-001. Enforcement: lefthook commit-msg,
gitlab_components CI component commit-metadata-governance, Cursor shell
policy hook.
Forbidden without explicit operator request¶
Any automated process that mutates Git commit metadata, including:
git commit --trailer …Co-authored-bySigned-off-byReviewed-byTested-byGenerated-byMade-with- AI / IDE attribution (
Cursor,cursoragent,Copilot,openstandardagents, …) - automatic
git commit --amend - automatic commit message rewriting
prepare-commit-msginjection that adds attributioncommit-msgmutation that adds attribution- post-commit rewriting of messages or authors
If tooling attempts to inject commit metadata automatically, agents must treat that as a governance violation: stop, report, fix the tooling. Do not normalize the behavior or repeatedly clean history as routine work.
Agent binding rules¶
Agents are never permitted to:
- append trailers
- modify authors or committers
- amend commits
- rewrite messages
- inject attribution
- add
Co-authored-byor AI metadata
unless the operator explicitly requests it for that specific commit.
When a violation is detected on an unmerged feature branch, the operator may
approve a metadata-only history rewrite (git commit-tree or equivalent) followed
by git push --force-with-lease. Never rewrite shared or merged branches.
Authored-artifact surfaces (beyond commits)¶
The same prohibition applies to every authored history surface, not only commit
metadata. AI attribution, session links (for example claude.ai/code/session…),
and tool-generated footers ("Generated with …") are prohibited in:
- commit messages
- merge request descriptions
- issue descriptions
- release notes
- changelogs
Agent identity is provided by the platform, not embedded in authored artifacts.
Human operators¶
Humans may add trailers when they explicitly choose to (for example DCO
Signed-off-by on a human-authored commit). Automation must not add trailers
on their behalf.
Enforcement (platform-wide)¶
| Layer | Mechanism | Activation |
|---|---|---|
| Local | commit-msg hook via shared script (see .lefthook-example.yml) |
After vendoring script from gitlab_components |
| IDE | .cursor/hooks/cursor-before-shell-policy.sh |
OBSERVED active on Mac workspace |
| CI | commit-metadata-governance GitLab component on MR pipelines |
Only after authority merge + dogfood pass (see execution-constitution CI gate law) |
Do not enable the CI component in consumer repos until gitlab_components has merged the script and its own pipeline passes with the gate. Local lefthook + IDE deny are sufficient until then.
Related standards¶
git-discipline.md— Git discipline, forbidden commands, and remote authority.cursorrules— workspace binding (no Cursor co-author trailers)