For everyone

REWORK Proof for GitHub

A check on every pull request showing who actually wrote the commits — signature state, author attribution and disclosed AI assistance. Counts only; no code leaves your repository.

REWORK Proof answers one question on a pull request: who actually wrote these commits? It reads the signals GitHub already records about every commit — the cryptographic signature state, the account GitHub resolved the author to, and any co-author trailer the author chose to write — and puts them in one place with a verdict attached.

It does not read your code. It cannot see a keystroke, and it makes no claim about quality. What it does is turn "trust me, I wrote this" into something a buyer can check for themselves.

What it reports

For every commit on the pull request:

  • Signature state — whether GitHub could cryptographically verify it. Signing is not required, and unsigned commits are not a fault.
  • Author attribution — whether the account GitHub resolved the commit to is the pull request's author.
  • Disclosed AI assistance — a Co-Authored-By: Claude trailer, or Copilot, GPT, Gemini and the rest.

Two of those come with a deliberate promise. Disclosing AI assistance never lowers the result. Writing the trailer is the behaviour we want; penalising it would teach people to delete it, which destroys the signal for the buyer who actually needed it. And a commit whose email never matched a GitHub account is ordinary — it reads as "no matching account", not as an impostor. Most local git configs have never been linked, and flagging those would make the check noise nobody reads.

The check concludes "success" or "neutral" — never "failure". A red mark on an honest pull request is not a finding, and the rational response to one is to uninstall.

Two ways to run it

Both report the same thing. Pick on how much access you want to grant.

The GitHub App needs no workflow file. Install it, choose repositories, and a check named REWORK Proof appears on every pull request from then on. It holds read access to contents and pull requests, and nothing else.

The Action grants REWORK no access to your repository at all. You add one workflow file, it reads the pull request with the token your workflow already has, and writes the report into the workflow run's summary. Nothing is sent anywhere unless you explicitly turn on attestation.

Install the App from github.com/apps/rework-proof, or find the Action at REWORK Proof Check.

Reading the result

With the App, open the pull request, go to Checks, and select REWORK Proof. The title states the verdict — "4 commits verified", or "9/12 commits cryptographically signed". Below it sits a summary in plain language and a per-commit table: commit, signature, author, AI disclosed.

With the Action, the same report appears in the workflow run's summary panel. The Action also sets step outputs, so a later step in your own workflow can act on the numbers.

Automation is not a co-author

GitHub's machine accounts all end in [bot] — dependabot, github-actions and friends. A dependency bump is not a person who helped write your feature, so those commits are listed separately as automation rather than beside human co-authors. They are never hidden, and they still have to be signed for a clean result.

If your repository has a release or CI account that does not carry the [bot] suffix, name it in a .github/rework-proof.yml file with an automation_authors list. That file only relabels: the commits stay listed, signing is still required, and the summary says when this file did the classing. It is read from your default branch, so a pull request cannot write its own exemptions and be verified under them.

What leaves your repository

Counts. Nothing else.

  • Stored: how many commits were examined, signed, human co-authored, automation, AI-disclosed; the repository name, pull request number and head commit.
  • Never stored: your code, commit messages, diffs, or file paths.

If you have linked your installation to a REWORK account, those counts appear as verified activity on your own proofs dashboard, visible only to you. You can also switch on a public README badge per repository — off by default, showing how many pull requests have been checked, and nothing more.

Limits, stated plainly

The commit read stops at 300 commits. A pull request larger than that is reported as inconclusive rather than clean, because reporting success on a pull request we only partly read is the one failure mode that actively misleads whoever relies on it.

The per-commit table lists the first 50 commits and says so when it truncates. The totals in the summary always cover every commit read.

REWORK Proof also cannot tell you whether code is *good*. It tells you who committed it, whether that is provable, and what the author disclosed. Those are different questions, and conflating them would be its own kind of dishonesty.

Ready to automate your business?

Hire verified AI & automation experts and deploy intelligent workflows today.

The AI & automation platform. Hire verified experts, build proof-of-work portfolios, and deploy intelligent workflows with escrow-protected delivery.

The REWORK Pulse

AI & automation insights, platform updates - weekly

No spam. Unsubscribe anytime.

Platform

Products

Legal

Company

Get an AI summary of REWORK

© 2026 REWORK Digital. All rights reserved.

Oh Canada Tech Directory badgeListed in the
Oh Canada Tech