Check commit author/committer identity for AI attribution, not just message text - #2455
Merged
Merged
Conversation
…essage check_no_ai_attribution.sh only ever scanned commit message text. A recent PR carried a commit with a clean message but an AI-tool author identity, so it went undetected. Give the script an --identity mode for checking a "Name <email>" string, and wire it into commit-msg (via `git var GIT_AUTHOR_IDENT`/`GIT_COMMITTER_IDENT`, available before the commit exists) and into pre-push (scanning each pushed commit's author AND committer, since a bad identity can slip in via either field).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
check_no_ai_attribution.shonly ever scanned commit message text forclaude|anthropic. PR #2448 carried a commit with a completely clean message, but its author identity wasClaude <noreply@anthropic.com>— nothing checked that field, so it landed undetected.This closes that gap:
check_no_ai_attribution.shgains an--identitymode that checks an author/committerName <email>string against the same pattern, alongside the existing message-only check.commit-msgnow also checksgit var GIT_AUTHOR_IDENT/GIT_COMMITTER_IDENT(available before the commit exists), so a bad identity is rejected at commit time.pre-pushnow also checks each pushed commit's author and committer (git log --format='%an <%ae>|%cn <%ce>'), since a bad identity can slip in via either field, not just author.The existing message-only caveat is preserved as-is (a patch can legitimately carry a real contributor byline, and there's no way to tell that apart from an AI-tool trailer from the message text alone). Identity strings don't have that ambiguity: this repo's commit identity is always
Ludovic Henry <git@ludovic.dev>, so any author/committer identity matching the pattern is an AI-tool identity, full stop.Tested locally in an isolated sandbox repo (a fresh
git initseeded with the updated scripts, so the hooks resolve to the patched checker rather than the not-yet-merged main checkout): confirmedcommit-msgrejects an author-only bad identity, a committer-only bad identity, and allows a fully clean commit; confirmedpre-pushrejects a push whose commit has a clean message but a bad author/committer identity, and allows a fully clean push.