chore(rules): 2026/04/15 FPR #1470
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Apr 15, 2026 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 485922389244096471388335606454318993455184797622 (0x551d8376bc7b8c8dd10238568a07609c670edfb6)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Apr 15 17:30:40 2026 UTC
Not After : Apr 15 17:40:40 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
7e:3b:50:7b:79:2b:2b:4f:10:9e:e0:96:78:88:5e:
70:39:38:f1:d9:95:53:ad:da:5a:88:eb:a7:cc:28:
b6:f3
Y:
df:52:c1:d0:51:c8:77:ae:97:72:d3:39:7c:9f:db:
d7:e2:55:10:14:4d:15:c7:5f:40:cc:42:ea:17:19:
14:f6
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
BD:9E:B6:B9:A8:F5:01:6D:36:8E:DA:E8:40:AE:7D:8F:D4:87:97:10
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnZIx9ZcAAAQDAEcwRQIhANTfg7j+7pHNPKpBhrZ4bOC/WsSOnIeYk7jlvI9dXUiFAiAww+3LIYpeGARxDhiFlXikeuhkO+ksaoF8bghhIb/RpQ==
Signature Algorithm: ECDSA-SHA384
30:65:02:30:66:31:a0:d0:52:3b:1a:7c:6e:e8:af:ec:d5:90:
81:fb:7f:70:c9:0f:eb:9e:ed:53:c6:7f:27:ef:b5:9d:ba:55:
ee:83:4e:85:2b:f6:22:9e:14:70:e2:c0:73:5a:6c:6b:02:31:
00:b5:97:ca:b6:6d:84:3c:37:1c:ff:9c:ef:3d:54:a3:83:c2:
3d:d6:7d:37:c5:40:27:dd:31:5e:87:41:fa:53:aa:c8:58:6b:
32:52:35:78:fa:96:66:49:05:71:60:74:45
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIzNzBlMmJjZTBhYjIwNTNmMTdjNjA1OTM4YjZmNzQ0YjkyMDdlOTU3MDExNTE1YjA2M2RiMDc4ZWFhZGIzYTI1In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJUURyeTNPYUV0YUE0TENpVU5mYVBuVk5qUnBIemNjUkFseitiU29iSTNlYzhRSWdFVTZQK0FTb2dOdXlIL1dCUVkxQkVUaUpEOG5UYzFBTFdMZjFyd2g5V0VnPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4dFowRjNTVUpCWjBsVlZsSXlSR1J5ZURkcVNUTlNRV3BvVjJsblpHZHVSMk5QTXpkWmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVFUlRGTlZHTjZUVVJSZDFkb1kwNU5hbGwzVGtSRk1VMVVZekJOUkZGM1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZtYW5SUlpUTnJja3N3T0ZGdWRVTlhaVWxvWldORWF6UTRaRzFXVlRZellWZHZhbklLY0RoM2IzUjJVR1pWYzBoUlZXTm9NM0p3Wkhrd2VtdzRiamwyV0RSc1ZWRkdSVEJXZURFNVFYcEZUSEZHZUd0Vk9YRlBRMEZZWjNkblowWXdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlYyV2pZeUNuVmhhakZCVnpBeWFuUnliMUZMTlRscU9WTkliSGhCZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHRDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJZDBWbFowSTBRVWhaUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFpBcHJha2d4YkhkQlFVSkJUVUZTZWtKR1FXbEZRVEZPSzBSMVVEZDFhMk13T0hGclIwZDBibWh6TkV3NVlYaEpObU5vTldsVWRVOVhPR294TVdSVFNWVkRDa2xFUkVRM1kzTm9hV3cwV1VKSVJVOUhTVmRXWlV0U05qWkhVVGMyVTNoeFoxaDRkVU5IUldoMk9VZHNUVUZ2UjBORGNVZFRUVFE1UWtGTlJFRXlaMEVLVFVkVlEwMUhXWGh2VGtKVFQzaHdPR0oxYVhZM1RsZFJaMlowTDJOTmExQTJOVGQwVlRoYUwwb3JLekZ1WW5CV04yOU9UMmhUZGpKSmNEUlZZMDlNUVFwak1YQnpZWGRKZUVGTVYxaDVjbHAwYUVSM00waFFLMk0zZWpGVmJ6UlFRMUJrV2psT09GWkJTamt3ZUZodlpFSXJiRTl4ZVVab2NrMXNTVEZsVUhGWENscHJhMFpqVjBJd1VsRTlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1776274241,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 1310312520,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1188480064\nVAZCGhG+CNn1NfgR2zsUx/cFbbZGEr49NGjR1S+IDyg=\n\n— rekor.sigstore.dev wNI9ajBEAiBuKA/OsNl67rxttuaZWtnqXiWywCuUjzGFmSw5cQzZjQIgTjyAPFmVZo5JjJ/LPS8L5vqxExP9TcdIEZ6vrmqsndo=\n",
"hashes": [
"a67ea7a94c5a75c6e7ad15d1055083ad3c985e067afcfa4fa1e5d39a7775bae8",
"b5c6d1602322a9158453ce1deccf7c8a4651c248ae69964763a497bbe767ae08",
"dc15e9de4aa7ed4f8afb7f1001af04af783d32ac2435d4006156f1de6ea2a8d7",
"59d8d6453da1d64ffe92a9c69aa453f9790c37ae9abef0871dd69a3fac405c78",
"c309d82559de9aa5cbf4cb5eb5c64fda2f794125b5bd7455f63d2188deea7442",
"f614a9121c810230d8e764d195d77e49d766f1fd9e435ef7175070ca14549a1a",
"c8f61f664094917e5c2c6e1fdd8a094ca5a5c4263accd75a8c315c06d249da6f",
"e2caf1ac566f186525a61ba0daeb85076b75bfe66adc503f47578ffd8bc3a446",
"985ddc3cef32ac82f96a40cad947fab4b2019270559141621acec10480743676",
"b2d7198c41b7aa77dde23603cf9e8cac20c5b43a65610a067b323d5156e96fdc",
"8aa608136d41e4960ec0d7992d973fd9cc4ecc1397d99c643b80d27f3063aeb1",
"08c664193d4233c8228e1ac1833f348951afe3a5dfafdec5adb250d07f77601b",
"4ae21974202755e04b2f6c7009c548ec4eaba1da26d8aec113edc16bc76fd0bb",
"60c08f8b78144d3bfa3d957f638a6c3399eee6204ce2ee391e2ac1220a0c592e",
"3624f8e135aa5ef65558289144934dde307f80f43af1094be26a8b10955e3b41",
"127b4941326e7a8e082cb54aa6a1220bdd7b753dd09bde6ff9f2bc3e3b4517ef",
"99054dfb7f4b53320ce286512b971e686f25dd0ec82558c8a08e3ff769bfe5ec",
"b75b8833b4eabd13da174514967cf06755cfaef583870cf80716d867f77f0153",
"4bb275dcdc97eee963e6518c57ace81414340cc2b2426060c8e87e4c3d4a7a51",
"f3c7b1ba057f7abd9ccc419eb70e894797c22c775eef59aa0ba9c1d7a99bb2ac",
"f85f5e3b847d1e39dddfbd191a6a7b093bfb89c0a82085818006f89d872930e6",
"a1fc9c4914a97ef34683d6213281bbbc86d5c97b9f21f8c90eaec8ffaa35b1df",
"17641e8522e017e9ac3596c1b3c6871001cb6029b08e194b830be95c57ef1f87",
"41b2f63bc6f44111243c481a2d998cae486164e3bf2ef76fcd80e6302479e1c6",
"0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
],
"logIndex": 1188408258,
"rootHash": "5406421a11be08d9f535f811db3b14c7f7056db64612be3d3468d1d52f880f28",
"treeSize": 1188480064
},
"signedEntryTimestamp": "MEQCIAVYaoA2QpqbYE+SKhnMSM59FheuPB+UdslvdygUy5SkAiAeI+3P3O3MbUSTxlnKnjwf4YiUT0JRig7lgaKC4/4jtg=="
}
}
Loading