Skip to content

Clean commits. Clear standards.

Commit Check enforces the rules your Git history already depends on — commit messages, branch names, committer identity, signoff — from one config, in every place your team writes code.

Get started Browse the rules


One config, enforced everywhere

Write the policy once. The same rules run on a developer's laptop, in CI, and in whatever your AI agent is committing on your behalf.

$ commit-check --message --branch
CC003 subject_imperative check failed ==> docs: revamped the profile
Commit message should use imperative mood (e.g., 'fix bug' not 'fixed bug')
Suggest: Change the first verb to imperative form
Docs: https://docs.commit-check.com/rules/#cc003
.pre-commit-config.yaml
repos:
  - repo: https://github.com/commit-check/commit-check
    rev: v2.11.0
    hooks:
      - id: check-message
      - id: check-branch
      - id: check-author-email
.github/workflows/commit-check.yml
- uses: commit-check/commit-check-action@v1
  with:
    message: true
    branch: true
    pr-comments: ${{ github.event_name == 'pull_request' }}
MCP server
{
  "mcpServers": {
    "commit-check": { "command": "commit-check-mcp" }
  }
}

What it checks

  • Commit messages


    Conventional Commits by default, or your own pattern. Subject length, mood, capitalisation, required body, forbidden merge/fixup/WIP commits.

    CC001–CC013

  • Branch names


    Conventional Branch naming, plus rebase checks that catch a branch drifting behind its target before CI wastes a run on stale code.

    CC201–CC202

  • Committer identity


    Catch commits authored by ec2-user on a build box, or require everyone to contribute from a company address.

    CC101–CC102

  • Signoff and DCO


    Require the Signed-off-by trailer locally, so contributors find out before CI rejects the pull request.

    Signoff guide

  • AI attribution


    Whatever your project has decided about AI-assisted commits, enforce it mechanically instead of relitigating it in review.

    AI attribution guide

  • Org-wide policy


    Inherit a base config from a shared repository, then let each project override only what it needs.

    Organization guide

Built to be trusted

  • SLSA Level 3


    Build provenance with artifact attestation you can verify before installing.

  • Stable rule IDs


    Every diagnostic carries an ID like CC003 that never changes, so you can cite it in review, suppress it, or feed it to tooling.

  • Used in production


    Running at Apache, Texas Instruments, Mila, and many more.

Ready in two minutes

$ pip install commit-check
$ commit-check --message --branch

No configuration file needed to start — sensible defaults apply immediately, and you tighten them when you are ready.

Install Why Commit Check?