Skip to content

Address false positives with dojo.js and YUI

817d733
Select commit
Loading
Failed to load commit list.
Merged

Address false positives with dojo.js and YUI #1018

Address false positives with dojo.js and YUI
817d733
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Jun 27, 2025 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 319037304283181542884484126567951916881029343520 (0x37e220a4375425acffddd4c609fc4cf272afa920)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Jun 27 01:57:40 2025 UTC
            Not After : Jun 27 02:07:40 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    0b:86:82:fd:f2:64:0f:cb:56:38:20:a1:ca:71:76:
                    a1:d0:d2:b3:15:5b:c8:25:05:99:65:70:fc:45:56:
                    29:7c
                Y:
                    10:9e:ee:49:f5:6d:65:24:67:38:8c:ce:73:a7:89:
                    65:0b:33:e2:d9:ca:23:03:0b:32:cc:fc:bd:55:b8:
                    0b:1d
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                71:5A:DC:48:4F:B1:E0:06:72:A6:1C:56:27:F7:16:5D:D3:F3:49:2A
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:evan.gibler@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABl68a0lcAAAQDAEcwRQIhAORvWDnXJR8B2BnJj2kVM9pPHWXlyujsjfDiwp4EHVLnAiAn3GotUpi76cUcZP4MAqQ0ShzNeuo/MezRZTUWcaCd6g==

    Signature Algorithm: ECDSA-SHA384
         30:64:02:30:64:5e:92:48:b7:77:a8:da:e6:37:45:db:55:f1:
         5c:f6:12:ca:50:b2:76:56:1a:1c:d4:1e:17:1e:56:65:ec:77:
         95:55:d2:ae:92:88:c2:ca:f3:07:6d:ba:88:36:cd:d8:02:30:
         20:a4:7a:50:7f:24:18:0c:a9:10:b7:00:fc:9a:79:45:f3:c1:
         e7:10:8f:c8:d4:da:bd:ee:9c:1f:42:54:36:d3:2f:cb:ff:db:
         77:a8:6c:94:8b:42:e3:aa:06:f0:59:a6

Rekor Entry

{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJhZmQ1OTYyYzEyYzkyOTJjYzUyZTQ1ODdjOWFlNTE0YWJjNWZmYzViN2I4NDc4YmZhOTAzNGVjMGE1NTA2M2VkIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURFbmVYblgrSC9XR0pWM3MrUG93Q0NFbUZDcVpVNmMzRlYwKzZkNmQrWlhnSWhBTFlTamE1M0hnMEZxUE9rMU5tMkJKRStKTWlQUURiZG9WOGdaSTVHVDh0VCIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdha05EUVd4dFowRjNTVUpCWjBsVlRpdEpaM0JFWkZWS1lYb3ZNMlJVUjBObWVFMDRia3QyY1ZOQmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVxU1ROTlJFVXhUbnBSZDFkb1kwNU5hbFYzVG1wSk0wMUVTWGRPZWxGM1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZETkdGREwyWkthMFE0ZEZkUFEwTm9lVzVHTW05a1JGTnplRlppZVVOVlJtMVhWbmNLTDBWV1YwdFlkMUZ1ZFRWS09WY3hiRXBIWXpScVRUVjZjRFJzYkVONlVHa3lZMjlxUVhkemVYcFFlVGxXWW1kTVNHRlBRMEZZWjNkblowWXdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZqVm5KakNsTkZLM2cwUVZwNWNHaDRWMG92WTFkWVpGQjZVMU52ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHRDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJZDBWbFowSTBRVWhaUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdBcHllSEpUVm5kQlFVSkJUVUZTZWtKR1FXbEZRVFZIT1ZsUFpHTnNTSGRJV1VkamJWQmhVbFY2TW1zNFpGcGxXRXMyVDNsT09FOU1RMjVuVVdSVmRXTkRDa2xEWm1OaGFURlRiVXgyY0hoU2VHc3ZaM2REY0VSU1MwaE5NVFkyYWpoNE4wNUdiRTVTV25odlNqTnhUVUZ2UjBORGNVZFRUVFE1UWtGTlJFRXlZMEVLVFVkUlEwMUhVbVZyYTJrelpEWnFZVFZxWkVZeU1WaDRXRkJaVTNsc1EzbGtiRmxoU0U1UlpVWjROVmRhWlhnemJGWllVM0p3UzBsM2MzSjZRakl5TmdwcFJHSk9Na0ZKZDBsTFVqWlZTRGhyUjBGNWNFVk1ZMEV2U25BMVVtWlFRalY0UTFCNVRsUmhkbVUyWTBnd1NsVk9kRTEyZVM4dlltUTJhSE5zU1hSRENqUTJiMGM0Um0xdENpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
  "integratedTime": 1750989460,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 252467817,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n130575101\nrr5OGeFIsMbKyZsNaFBzY06NnhrgMKtCGAJSqcdGvHQ=\n\n— rekor.sigstore.dev wNI9ajBFAiAdhefORQVkrkBK2sj+AVY9BerjXTX7MUhwp9Uv8TxrzQIhAMhezJ91Bx99p6I6FtlnIyaslI9KHwKplEa8a/Xw1AKg\n",
      "hashes": [
        "d8b11d4cc679ef1594bf70bee7a260fb70c5baeda7e952643600279d68bde1ce",
        "5f4cdb9f1c5c8732a107c2a05d5c8e79f98d19c85e341a485f808ec025fdd941",
        "0884f32e4a2ac6fb45f8584f50e06353a5c472f8bdf8114e6a563682710232b5",
        "7e328b0aebda55be90d4d51f2a86eaafba00a7296880480d64fe59b2474dc6b8",
        "564292d28c956881bdd6e49993d12f628bfd754d02b81f750975a94299e5ca59",
        "a9a86bfa45981b7ee01fe614d9bd921f06f64af98ebbdd568e289bf86125156e",
        "eddc9b9e1c6c7b8959386c7a9bb7951c9660e5fcba5d2844eebb7032f5736969",
        "c1bccef048cc8eedb0a9af0784c8fa16b90161b981f241748494684e471ec351",
        "29f59bd715800749797d0348c06c44615dce6b1bea1d13a25ad830d809620e73",
        "dec5dea0dbb3d5aa3e5d7d2b3033edba4a91533950314e0681785945eedab698",
        "dae9e006e178033ba8408669edcd39c09ecfabc0032b4f80c7de626be0bff58e",
        "437a656644e7f829942a80e4b525982bb27a7aa8c4318a67da6cf61b6bbcd49c",
        "68e25718b46b25a594efc09a52676c34dc1c97b936a7f82f68b67472f94eff77",
        "2afe4484e8af12fcb9b9e892e329f16d5489769465179e19a9c96c18a1acea3e",
        "9ab315823f18114a158a5b8b96397d446e421faa63c12783da1137ff1bdd689c",
        "75a41dda97e025a122f0e3267bfa318aa845df7a432929c251f0287998e8f4e9",
        "91f52ae36873f27251076d2278acf171d3bdcc2300122970e1d9136368c90fe1",
        "8d5f018fd493bfbd56d2ddb24629f5ebd1216566a0edd049e2f06e2c7dd42c14",
        "eb71b7e59580d8980e1376d7bb4a0a86ba37b624782033c7d4880ca76d7fa639",
        "9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
        "eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
      ],
      "logIndex": 130563555,
      "rootHash": "aebe4e19e148b0c6cac99b0d685073634e8d9e1ae030ab42180252a9c746bc74",
      "treeSize": 130575101
    },
    "signedEntryTimestamp": "MEYCIQCVaEjo3gaxqg7zM5nimNVa7etl40GJFREAtCi/MogFyAIhAI/5B8kIAmdxmJ8rXLHDwMiYK4n4O8j01WUNzg8gd9MG"
  }
}