Skip to content

Check commit author/committer identity for AI attribution, not just message text - #2455

Merged
luhenry merged 1 commit into
mainfrom
fix-ai-attribution-author-check
Sep 29, 2026
Merged

luhenry merged 1 commit into
mainfrom
fix-ai-attribution-author-check

Conversation

@luhenry

@luhenry luhenry commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

check_no_ai_attribution.sh only ever scanned commit message text for claude|anthropic. PR #2448 carried a commit with a completely clean message, but its author identity was Claude <noreply@anthropic.com> — nothing checked that field, so it landed undetected.

This closes that gap:

  • check_no_ai_attribution.sh gains an --identity mode that checks an author/committer Name <email> string against the same pattern, alongside the existing message-only check.
  • commit-msg now also checks git var GIT_AUTHOR_IDENT / GIT_COMMITTER_IDENT (available before the commit exists), so a bad identity is rejected at commit time.
  • pre-push now also checks each pushed commit's author and committer (git log --format='%an <%ae>|%cn <%ce>'), since a bad identity can slip in via either field, not just author.

The existing message-only caveat is preserved as-is (a patch can legitimately carry a real contributor byline, and there's no way to tell that apart from an AI-tool trailer from the message text alone). Identity strings don't have that ambiguity: this repo's commit identity is always Ludovic Henry <git@ludovic.dev>, so any author/committer identity matching the pattern is an AI-tool identity, full stop.

Tested locally in an isolated sandbox repo (a fresh git init seeded with the updated scripts, so the hooks resolve to the patched checker rather than the not-yet-merged main checkout): confirmed commit-msg rejects an author-only bad identity, a committer-only bad identity, and allows a fully clean commit; confirmed pre-push rejects a push whose commit has a clean message but a bad author/committer identity, and allows a fully clean push.

…essage

check_no_ai_attribution.sh only ever scanned commit message text. A recent
PR carried a commit with a clean message but an AI-tool author identity, so
it went undetected.

Give the script an --identity mode for checking a "Name <email>" string, and
wire it into commit-msg (via `git var GIT_AUTHOR_IDENT`/`GIT_COMMITTER_IDENT`,
available before the commit exists) and into pre-push (scanning each pushed
commit's author AND committer, since a bad identity can slip in via either
field).
@luhenry
luhenry merged commit 2a934e1 into main Sep 29, 2026
4 of 6 checks passed
@luhenry
luhenry deleted the fix-ai-attribution-author-check branch September 29, 2026 13:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant