Add fuzzing for extraction, file type determination, and report generation #1204
Chainguard Enforce / Enforce - Commit Signing
succeeded
Nov 7, 2025 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 441820366320807952104383196828319803814870521225 (0x4d63e911b88a2ee41a98d9050f17ff56081c1589)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Nov 7 16:26:33 2025 UTC
Not After : Nov 7 16:36:33 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
39:5a:cd:4f:a5:3d:9e:18:cf:52:bc:2a:a8:81:a1:
cf:09:91:78:81:b0:c1:9c:85:2f:a0:0d:46:71:88:
21:30
Y:
12:0c:1e:47:d8:50:b2:25:1e:b3:d7:03:91:f2:98:
ca:60:8e:df:f8:47:fe:c3:76:ee:58:43:48:d0:b5:
41:7d
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
60:00:EC:75:8F:E7:DC:65:A0:96:57:9B:CF:02:0E:50:48:AB:35:6A
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABml8kHocAAAQDAEYwRAIgWEhIpx6kZFX9Zvqi+yDI5uxz60A1Dot3V08dJJI5Ge0CIH9C7iLrj9cXaybuPhA7E2TYic5w80eUPUYYQ9rxjacy
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:d6:db:33:2f:aa:f3:21:40:f8:a2:c1:8e:45:
17:46:d2:81:ff:c1:0b:35:6b:c4:ca:9b:c5:8c:47:58:fc:69:
11:28:c2:d1:75:c5:dd:0a:29:a3:23:d9:46:d1:f2:ae:db:02:
31:00:90:3c:ec:ac:cd:97:3e:86:19:45:81:0d:0e:c2:3d:af:
a0:55:7d:2d:6c:54:8a:b0:1e:89:f4:d1:82:fe:52:c9:d2:61:
49:be:e4:68:ca:94:b6:b3:0c:23:f8:a3:7d:0e
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI0NTk5YjgyZjZhYjFiYzAxODFlMDE4YjRjZTQxMmVhOGY1YTJhZjMxOTU0ZmFjMWQ2ZDdlMWFjMTAyNTgyMTYyIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUUQ1YlowazQ1eUNUSDVzbkFMUVU3cm1lMDVQZVJhRFJoRVlJMldsWTZUREh3SWhBSVRGRlpaZW42WG5WS3p6SXZSL1lsd3p4bkgxSWM0V0VaZFVQWEhzdEZnRiIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4cFowRjNTVUpCWjBsVlZGZFFjRVZpYVV0TWRWRmhiVTVyUmtSNFppOVdaMmRqUmxscmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFVUVROTlZGbDVUbXBOZWxkb1kwNU5hbFY0VFZSQk0wMVVXWHBPYWsxNlYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZQVm5KT1ZEWlZPVzVvYWxCVmNuZHhjVWxIYUhwM2JWSmxTVWQzZDFwNVJrdzJRVTRLVW01SFNVbFVRVk5FUWpWSU1rWkRlVXBTTm5veGQwOVNPSEJxUzFsSk4yWXJSV1lyZHpOaWRWZEZUa2t3VEZaQ1ptRlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZaUVVSekNtUlpMMjR6UjFkbmJHeGxZbnAzU1U5VlJXbHlUbGR2ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFlRcFllVkZsYUhkQlFVSkJUVUZTYWtKRlFXbENXVk5GYVc1SWNWSnJWbVl4YlN0eFREZEpUV3B0TjBoUWNsRkVWVTlwTTJSWVZIZ3dhMnRxYTFvM1VVbG5DbVl3VEhWSmRYVlFNWGhrY2twMU5DdEZSSE5VV2s1cFNucHVSSHBTTlZFNVVtaG9SREoyUjA1d2VrbDNRMmRaU1V0dldrbDZhakJGUVhkTlJHRlJRWGNLV21kSmVFRk9ZbUpOZVN0eE9IbEdRU3RMVEVKcWExVllVblJMUWk4NFJVeE9WM1pGZVhCMlJtcEZaRmt2UjJ0U1MwMU1VbVJqV0dSRGFXMXFTVGxzUndvd1prdDFNbmRKZUVGS1FUZzNTM3BPYkhvMlIwZFZWMEpFVVRkRFVHRXJaMVpZTUhSaVJsTkxjMEkyU2psT1IwTXZiRXhLTUcxR1NuWjFVbTk1Y0ZNeUNuTjNkMm9yUzA0NVJHYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1762532794,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 682479014,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n560584601\nQXkajwPWG0kTJ4pbafM0+lWjBv6ZFBxpsDJUOY8SnqY=\n\n— rekor.sigstore.dev wNI9ajBGAiEAsp4FagZFP1y/9hRqZ4E1zIO/ECRE/hKzWywz81F6wpUCIQDM8He6LsIO8FWR8wQa9S5x7p5kC4QEb65kUI5AIyPg+g==\n",
"hashes": [
"fee9d54b54c4d9fd831e33370deff21d6ebcf55a0e9a2e80d06625487d20cbde",
"082fe3b3be8b6c347c3b1096bc7a6e5fb6f39ece1e0824fc598861f86535ee45",
"57186c80301bb517708a756a4d9afa9997fca5e714713e7c0cc56653ac124b47",
"8755331fc5612edfcb66046ccefd2d974e46e4e1d5dd0a55be4303ae5084d931",
"cb6165342bdbffba1455a8aedd50dbde2f5d23f103b68c5da7f2249c6d434d76",
"46b2dd25994841d7f4141bbad876ec1595f1a84cf2a15386c6865e0feef0703a",
"29a572be6518be96df329bd4ebad4b54a7ce8dad0afa77929ff47c2b0d778627",
"c3c6fdcb71bf49725c4f15da2935e6766b27551ad026e845771bccdb41511f5d",
"2669878c0ca12fe7e37e6179ffd1286185aa973b61a6fd9e894b1a4cbdb4272a",
"a8907d4cb8c11fa5f352bb692bd1267750922ea70d6d73aba34a17c2f49bd283",
"a5025abe8c4993cfe822d10b93e0ceeb18a22573f768188467d2d1aaae518721",
"74b3bacb0eb96a062677a8b010762ff0a54877f7c115969c8857069756c68806",
"9db92b1dbfe4a3fafcf8f1ddf0efd960bc8f3cd41ff54bd8c3003134327e56ea",
"263bf678080809298be4b0bc27e040bcc6dc83287708f250b614ace1db02a55c",
"e2637f41abf545fa40b03c6681635542ad4ea23a5a5f16d8a5dbbeb6cfbe04c2",
"7677dccd7bfde199d8f11ae51e22d43f14f2af3fd67c5223fa5a781530a13352",
"216cb88befcaabba7d2b2b0421413035bca7c9811067db1f2c0d33bc1994e2da",
"afc816d0af4e2458ee5028985fd8eaaf0599e699153a09f986f62bd398f429cf",
"8b7160f4108afcecb3533411359637637aa2aca2ef78be565a3e53a7fcdeafd7",
"edb3ee79838b1e3e816821737ff73504f4a2df7b69620fdfc342899fb89dce98",
"94979e354cec08966b9a35599340ed49afced24de4fd92d4b1596377784c9ea0",
"4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
],
"logIndex": 560574752,
"rootHash": "41791a8f03d61b4913278a5b69f334fa55a306fe99141c69b03254398f129ea6",
"treeSize": 560584601
},
"signedEntryTimestamp": "MEQCIDmpXiTky+LJUpW+7WGIjk/oB9GS/qI7DDyY0LcR6hc4AiByx46lA8fPQ5j3/FGLlYDjEMI34cnW4si8+1/rC063Hg=="
}
}
Loading