Skip to content

Use Workflow URIs for source.yaml#1189

Merged
egibs merged 1 commit into
chainguard-dev:mainfrom
egibs:fix-trust-policy
Oct 31, 2025
Merged

Use Workflow URIs for source.yaml#1189
egibs merged 1 commit into
chainguard-dev:mainfrom
egibs:fix-trust-policy

Use Workflow URIs for source.yaml

2bcdcbc
Select commit
Loading
Failed to load commit list.
Chainguard Guardener / Enforce - Commit Signing succeeded Oct 31, 2025 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 691476041680970331661886922529812220035291575064 (0x791edbabcff5b797bdb2e845b99514254ae67318)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Oct 31 17:30:24 2025 UTC
            Not After : Oct 31 17:40:24 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    d5:b8:f7:81:a1:93:36:c8:ba:08:94:b2:65:74:8a:
                    d6:23:0a:8e:d8:99:9c:9c:79:bb:03:57:97:b7:91:
                    30:c9
                Y:
                    80:33:e4:6b:cd:b6:29:7b:fe:b6:34:8b:35:9c:6c:
                    ad:f1:7b:b6:d6:e8:f6:30:a8:9e:0e:94:93:ae:cf:
                    b1:99
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                09:DB:F9:75:C7:97:6A:2F:B5:10:E1:DA:30:1F:8C:A8:1D:45:8F:1A
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:evan.gibler@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmjtSDzsAAAQDAEgwRgIhALlzq5z9Kqe9DTf/ue4wNdtPQ6+MlUi0jEN2qgOEZj2FAiEArQUFXup7p3X2BPBA1WDyZanfJ+SBz9Bb/DI/fa9zmKo=

    Signature Algorithm: ECDSA-SHA384
         30:66:02:31:00:b1:51:ad:c3:ec:e5:a7:06:76:c7:3c:a2:36:
         02:cb:1f:35:cb:90:ab:ed:e5:b1:e0:1d:9a:82:70:84:1b:35:
         56:41:ff:64:35:01:d5:f5:e4:cc:e6:a4:18:42:71:d0:c6:02:
         31:00:ba:a7:52:c5:5b:ad:02:51:e6:47:8f:41:43:cb:18:f0:
         70:15:44:84:c3:30:2b:9a:2b:71:b1:4b:be:eb:2d:3a:e2:62:
         e6:07:38:99:a7:e8:9e:69:21:ec:d9:2c:30:3d

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIwM2YxMmMzMDE3ZTdjNjUyMTgwYmI2N2VlZDJlZjBkNjU0YTQ1MzI5NzhiMzc0ZjVlNmQzODBjZmIyZjYzNjBiIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURVajhET0FCZDA4eDQzV2lYK1Mvd01PVWlLQjVLVTJrMjBuWC9qWWdTQ3hBSWhBTFZZdXF4SkQ3Ym42U3dOYmZoTUFwbWdId2I3N0ppdkdpYyttVDVBME5USiIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhWRU5EUVd4eFowRjNTVUpCWjBsVlpWSTNZbkU0THpGME5XVTVjM1ZvUm5WYVZWVktWWEp0WTNobmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFFVFhoTlZHTjZUVVJKTUZkb1kwNU5hbFY0VFVSTmVFMVVZekJOUkVrd1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVV4WW1veloyRkhWRTV6YVRaRFNsTjVXbGhUU3pGcFRVdHFkR2xhYmtwNE5YVjNUbGdLYkRkbFVrMU5iVUZOSzFKeWVtSlpjR1V2TmpKT1NYTXhia2Q1ZERoWWRUSXhkV295VFV0cFpVUndVMVJ5Y3l0NGJXRlBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZEWkhZMUNtUmpaVmhoYVNzeFJVOUlZVTFDSzAxeFFqRkdhbmh2ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHhDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJTUVWbGQwSTFRVWhqUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFlRcFBNVWxRVDNkQlFVSkJUVUZUUkVKSFFXbEZRWFZZVDNKdVVEQnhjRGN3VGs0dkt6VTNha0V4TWpBNVJISTBlVlpUVEZOTlVUTmhjVUUwVW0xUVdWVkRDa2xSUTNSQ1VWWmxObTUxYm1SbVdVVTRSVVJXV1ZCS2JIRmtPRzQxU1VoUU1FWjJPRTFxT1RseU0wOVpjV3BCUzBKblozRm9hMnBQVUZGUlJFRjNUbkFLUVVSQ2JVRnFSVUZ6VmtkMGR5dDZiSEIzV2pKNGVubHBUbWRNVEVoNldFeHJTM1owTldKSVowaGFjVU5qU1ZGaVRsWmFRaTh5VVRGQlpGZ3hOVTE2YlFwd1FtaERZMlJFUjBGcVJVRjFjV1JUZUZaMWRFRnNTRzFTTkRsQ1VUaHpXVGhJUVZaU1NWUkVUVU4xWVVzelIzaFROemR5VEZSeWFWbDFXVWhQU20xdUNqWktOWEJKWlhwYVRFUkJPUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
  "integratedTime": 1761931825,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 659561786,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n537666659\nWot5e3gv0fQlYPUWF37xkEIGaFvJMr2AZNp9Mpjus4I=\n\n— rekor.sigstore.dev wNI9ajBGAiEA4jIjZxe3tWtQMAB6f+dJ6B/EHzL02MvlUNHY9o9rdNQCIQCBcIyuW+rVIkwcUDW50EyH3hEI9RWiq8Qvxrm7L+yrNQ==\n",
      "hashes": [
        "b8845e18d6652ca9ee1fffc537a58e13dcbbcf3d0552a9ab59cede57731cf9fc",
        "746f1005ed42a81b766ee08d6eff6de62038e4b865f7a748e9b1082b39240b20",
        "20101720371ed12ec5db6c332dbf1bcd6e0fc57bfdbe6333f67c65286d3b77d0",
        "aa7cea4fb9bdf83a71524edd80a5d79d4d02df46ac726dfdfc51371120153a4c",
        "932d105ebc04da8838e8c314567649eacbc0c2097c95d76c0a854758e9d8473c",
        "e34d06ccb1f0cd0785fcbfa709af5ca4e7904ca0e302afc3fcb03a40bf4908ab",
        "5c05ed3de4b70afffa22d2552c6bddcb0cb760060228334a7d5acc9f2b34f8ec",
        "d3a761a4504cd461d99de71a83867851c349d36b7786df00f265774032a5a71f",
        "1eb3c94b650e66b2e2be1e181b63dd3c0f7fee62abed7cbbdb2f57f1668358b5",
        "d7bd8002bc1f7e565e0d454056ee443386d937cb9386e2a9b702453706567c38",
        "20058d30392024d6db505cf06d1cde7573f39ca2e5fe246c7bdbb9970eb99f8a",
        "b704a12df49487abd1c32da9186334f8b94247788ca03d357718755636014d56",
        "1c4b8a856ccdc36f93d57f06f87daf816d05d23265293514c81eb8246e6bf8d2",
        "df028b11762172fef919e7a57e0fef22c267f8c687e4dad011ad25fafb84a4a5",
        "cc1282ced903e7cad505db2b8c8c1bd0ea51f564378c5de03147f8e40b22fe27",
        "239cdfc25e34b63614eaf37cac1fb582b486d47b3d777b62db0183fb71f5d65c",
        "4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
      ],
      "logIndex": 537657524,
      "rootHash": "5a8b797b782fd1f42560f516177ef1904206685bc932bd8064da7d3298eeb382",
      "treeSize": 537666659
    },
    "signedEntryTimestamp": "MEUCIHvvAZjnlsiXQskLN0WQ5mHd1Q/dY14eBM8CU8zumi38AiEA1CLRoG3HEMyoERjGwuk/q/MyprAE1eAzj+ajdhLXSxA="
  }
}