Add nil checks for slice pointers; filter invalid overrides from reports #1031
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jul 2, 2025 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 559636006598660453208430197323528464353559172355 (0x6206f24aaf0549d18f542d3aed2e3dc448a5d503)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jul 2 22:57:31 2025 UTC
Not After : Jul 2 23:07:31 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
71:28:4b:62:5b:98:63:1d:0e:2b:27:99:3c:ba:0f:
e2:2f:08:b4:7b:99:06:6f:01:51:ea:fd:4c:04:32:
e5:7f
Y:
08:26:54:c1:b7:5d:37:18:99:c2:0b:7f:c5:bb:55:
05:b9:3b:2d:0f:f8:5f:bf:e5:85:af:e2:20:ed:55:
66:ab
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
20:FB:F3:4D:0F:20:B7:82:17:B5:BC:1C:AB:CE:BB:47:BF:1F:5B:6E
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABl81cDoEAAAQDAEYwRAIgQqPkyKrMr7UvGbQOFAJQl2l8/lFGslPe5vskBFddCIICIGfutYaWMl1LctDgIksF2A2TNMd0Qs/6m7xvjRGsZlvf
Signature Algorithm: ECDSA-SHA384
30:64:02:30:5e:64:10:4b:8c:af:d2:13:27:89:59:98:e2:bd:
5e:c5:5e:d4:7c:2c:60:e8:83:79:cd:d5:47:e9:a2:26:81:b7:
41:82:05:7a:17:20:0f:5f:c5:58:88:cc:ab:82:6b:be:02:30:
29:09:85:cc:ae:56:0d:fe:a1:3b:77:c2:9d:97:06:c6:69:12:
9c:d3:56:29:5d:ad:24:c7:57:84:e3:4d:e9:31:04:42:3e:2a:
6b:2d:4d:3f:bb:0d:63:ac:c0:ef:d6:27
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI5YzA0MjVjZTdkM2EyZmY5MmJiODRlODU4YTBkNmE4MGVlNzUyZTAwOWUzZjMyNzQ2NjMzOWEwNTdhOTE2MmQ1In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURvRW9UaGt0bnJPYzVRSy9vSTdqUGF4UFJjMnNDc1AvZWNkRDFpa2VDQ3pBSWhBT2FudUtBYUNtTC9JSzRXTzBBaVp5MEVvdysxTnBDT2ZDOEVTUUZldEowYyIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdWRU5EUVd4cFowRjNTVUpCWjBsVldXZGllVk54T0VaVFpFZFFWa013TmpkVE5EbDRSV2xzTVZGTmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDU2UVhsTmFra3hUbnBOZUZkb1kwNU5hbFYzVG5wQmVVMXFUWGRPZWsxNFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZqVTJoTVdXeDFXVmw0TUU5TGVXVmFVRXh2VURScE9FbDBTSFZhUW0wNFFsVmxjamtLVkVGUmVUVllPRWxLYkZSQ2RERXdNMGRLYmtORE15OUdkVEZWUm5WVWMzUkVMMmhtZGl0WFJuSXJTV2MzVmxadGNUWlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZKVUhaNkNsUlJPR2QwTkVsWWRHSjNZM0U0TmpkU056aG1WekkwZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdBcDZWbmRQWjFGQlFVSkJUVUZTYWtKRlFXbENRMjhyVkVseGMzbDJkRk00V25SQk5GVkJiRU5ZWVZoNksxVlZZWGxWT1RkdEszbFJSVll4TUVsblowbG5DbG9yTmpGb2NGbDVXRlYwZVRCUFFXbFRkMWhaUkZwTk1IZ3pVa042TDNGaWRrY3JUa1ZoZUcxWE9UaDNRMmRaU1V0dldrbDZhakJGUVhkTlJGcDNRWGNLV2tGSmQxaHRVVkZUTkhsMk1HaE5ibWxXYlZrMGNqRmxlRlkzVldaRGVHYzJTVTQxZW1SV1NEWmhTVzFuWW1SQ1oyZFdOa1o1UVZCWU9GWlphVTE1Y2dwbmJYVXJRV3BCY0VOWldFMXliRmxPTDNGRk4yUTRTMlJzZDJKSFlWSkxZekF4V1hCWVlUQnJlREZsUlRRd00zQk5VVkpEVUdsd2NreFZNQzkxZHpGcUNuSk5SSFl4YVdNOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1751497052,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 260655843,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n138758746\njKprrIXAB+9iyV6cVBDMUAR8lhASTbrU7IUicJseinE=\n\n— rekor.sigstore.dev wNI9ajBEAiAcENc5gbRedqiV33mLgkO0sq+U6BLxyAtE7w6dE6t+FgIgHVgBzf4/uXg+7RWKI3C19KcYMX3J6ZiZDtb7hjh/mFg=\n",
"hashes": [
"07b982d687eef459dc29e35af0b691266601996befa648761f7ea3a25c56d124",
"b5101c6bf5119bc6ee6bbb737f3d95f4c94f579ea74bd335699d0d83a1fbe0f8",
"2fd1d678111fceff2831acf1d11e7136a530546e0bb850c9372889cb25830ef5",
"4590d6cc338db59535cc968f61bd7414a658543195b52ade06ec126c08fd47d0",
"c41a4f77cac769e6608fc6b06f0715c81200671839206f86075ba17ddae6db88",
"6432f5e9bd0fcd91353c068aaea779e365c16beae66d4566542d834f2f727bf5",
"1ba8e16ff9fdd8d9e53ca67c789a27fa8a5c4aa1d598ade9608a0436c0a8a24c",
"cce872159570605fb42f3b356e7dc63cd40f5ae778d511555e31f69cac96f083",
"4dbf1354b657d87a14cc6592ea9bff01347595781871063e92e65b31a6cc3fc1",
"e9b242a7bd23ba3b9d4638c6a1b68b3b0b6f7205f1f919c1d20d37ffd38542eb",
"f450d3f6f1cd4e937580744432032fb63624c4907ebb1816ce650fa84042b0d5",
"f93ea432d1c55e56453e05d6e90843ec56c4e5fbb4417d247f18b4413e3de8f7",
"8f1e1cd9828eaee68dd8ed7256085cdb27d7d3421c618d8c9b34f29039913b64",
"52ab92e3a937ec0d8477400195340c855db8de33c0c100ce57d3400d8461992d",
"c1d3ce7bdfe1fb1aa6f29bfa895604f1488029afd636684ff5e6876dde77a864",
"eaf894f52b244af547a3c137bf19a8c48d861cf959a90260aa4d1db1ec6363f8",
"8864e8a0a4cc071191458cb169f7dbc4d539d182cbb468ada6de60e15246e826",
"da01c99a549b7c6152d97b519e06af690d0a518a5f8e0ce072974ac2b3c82d7b",
"c0b00d4f434cc48461fe9e6b45c6a6e0ca694886d45c87d3d47b7d1500365e72"
],
"logIndex": 138751581,
"rootHash": "8caa6bac85c007ef62c95e9c5410cc50047c9610124dbad4ec8522709b1e8a71",
"treeSize": 138758746
},
"signedEntryTimestamp": "MEUCIQDYpQpJHgjyZXfdricHLGLKro8tfZxSev6hJfeflyjmXQIge5pzK0Sx9CSXJMZHbmUDr7RrpG78LHS2CrjkQUpuakk="
}
}
Loading