chore(rules): 2026/04/16 FPR #1473
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Apr 16, 2026 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 441511359053571968788461868350745385048176403244 (0x4d560dd6fa75e0d5af5d5eb98a56888b47a9232c)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Apr 16 19:11:10 2026 UTC
Not After : Apr 16 19:21:10 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
7c:a7:5a:0f:7b:0e:b8:3d:ee:a6:9f:ad:7a:cb:bb:
be:7f:67:0a:b7:bd:fe:92:aa:66:11:72:44:0c:b4:
07:38
Y:
d8:b7:ae:af:f1:b2:2d:d5:ba:a6:49:76:89:09:89:
38:7e:ed:dd:be:41:63:a0:2c:f1:ad:8e:85:4e:d4:
0a:92
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
61:04:EF:E5:DD:EE:24:9E:81:EF:62:AA:EF:6F:07:4D:53:AE:12:4A
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnZe0UtAAAAQDAEYwRAIgUHVg1/Sux2MOYCGZYuroH+iZ3TWJ1oFYvEJQ2+Qf0qgCIHBJXyfEBfJG9q8R5sTp0oYtP+oMlTKTEQYrXtx2OHxP
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:eb:4b:c4:9d:b8:db:3f:a3:ee:54:58:d7:c1:
3d:e4:e7:0c:c5:0d:cc:7e:a4:9b:e6:09:ac:94:05:74:2d:b4:
68:3e:58:e4:30:83:93:54:04:fa:5a:19:17:f1:1d:2b:ac:02:
31:00:be:b3:31:74:25:3b:af:d6:41:02:7e:85:51:c6:70:22:
47:0f:4b:c9:60:05:20:e4:3d:f2:90:96:56:ec:7a:eb:93:49:
8c:c9:40:c5:9a:e7:09:d7:a5:87:ee:21:81:e5
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI5M2U3NmFmN2IzZGUxNGIwZmFhNmM4Y2Q3MzVlNWUzZDBhN2M2NDllODUyNmJiZjdiZjMyMjY4NWYwMDEyZjE4In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJRllDVWNPRFcranZRMXR6ZVBTV0VLc1k3aWdRUnZwUjFzbWZNUUNtdzZiQkFpQkVJNHRvc3NBZ3pybHJHWldCbjdud2NrRmhaYnJ4cGoyekNnTjBCS05UbUE9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4cFowRjNTVUpCWjBsVlZGWlpUakYyY0RFMFRsZDJXRlkyTldsc1lVbHBNR1Z3U1hsM2QwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVFUlRKTlZHdDRUVlJGZDFkb1kwNU5hbGwzVGtSRk1rMVVhM2xOVkVWM1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZtUzJSaFJETnpUM1ZFTTNWd2NDdDBaWE4xTjNadU9XNURjbVU1TDNCTGNWcG9SbmtLVWtGNU1FSjZhbGwwTmpaMk9HSkpkREZpY1cxVFdHRktRMWxyTkdaMU0yUjJhMFpxYjBONmVISlpOa1pVZEZGTGEzRlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZaVVZSMkNqVmtNM1ZLU2paQ056SkxjVGN5T0VoVVZrOTFSV3R2ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFpBcHNOMUpUTUVGQlFVSkJUVUZTYWtKRlFXbENVV1JYUkZnNVN6ZElXWGMxWjBsYWJHazJkV2RtTmtwdVpFNVpibGRuVm1rNFVXeEVZalZDTDFOeFFVbG5DbU5GYkdaS09GRkdPR3RpTW5KNFNHMTRUMjVUYUdrd0x6Wm5lVlpOY0UxU1FtbDBaVE5JV1RSbVJUaDNRMmRaU1V0dldrbDZhakJGUVhkTlJHRlJRWGNLV21kSmVFRlBkRXg0U2pJME1ub3JhamRzVWxreE9FVTVOVTlqVFhoUk0wMW1jVk5pTldkdGMyeEJWakJNWWxKdlVHeHFhMDFKVDFSV1FWUTJWMmhyV0FvNFVqQnlja0ZKZUVGTU5ucE5XRkZzVHpZdlYxRlJTaXRvVmtoSFkwTktTRVF3ZGtwWlFWVm5OVVF6ZVd0S1dsYzNTSEp5YXpCdFRYbFZSRVp0ZFdOS0NqRTJWMGczYVVkQ05WRTlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1776366670,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 1320351440,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1198500901\n2E/FjeTUL6hVCckNB6L4Z/TMSm65s19xaVLjr4jx0Fg=\n\n— rekor.sigstore.dev wNI9ajBGAiEAsHt6rjulDSzzKAraAEB5rXRRZbhLP/6ARSawYk8sGiYCIQDsUzn0sxvWnnDQYUwNUb7MlH/5qJ0+eZdJcDr9pPGpHw==\n",
"hashes": [
"97020fc22d8b458e15df63ce3463c3018c175fca5079b415a3d19ab9e36bd683",
"8b699ede720a2fd82b6c594fe416bf4f8cec3c40784afcecea5204983f4a9a8a",
"63dfdf721beadc4b601df9f4047eb2280440827571591579c87a45fcc20fdc21",
"28b8bbca7418b9de229f155c90965362ae8f65d8857abc2241555c305b939ac7",
"b6833a117dddc441d392c48ea0a9971d781a8be64c5a3e60f4e4151c24e1dd68",
"9abbc4c27a1d43b376b45d58d9c71bb43d804bb53d2c68983e6f3ef3af564dc8",
"a32879afcc4ecfe39b39cdcfe237a338bab3eaa806ebd349bdcdd30e08d7583b",
"107d1802cce9cfe7e3154d14127f479d40540d6c256208dbb96cbb3c953e3bb0",
"0c4c102b102d9799146e63ff64ba7c55332cc1b440751d58dc2475c3109e939d",
"ebd1fd0fad0c4cfbdd26285c7f8a35e05431a78d4f3fa4f62eccca325a23f60c",
"263d0c93507bed2add0956d353af18d254305fa732b0d203458849521362c049",
"a201c79ba3853710e14898860e284b8aaacb5a3a9eb369850e16c81865ea6dd3",
"e079f48b30c41679eb3fc346aa80ff2ecf6b33cd8c9a8fe83efb09904439bae4",
"3fc145fc78da01fcbc17ccc5457a84febc8835d92df26259f87d2340716c67ac",
"a45528091ab1e3088d2ad22a36c7c85401f5632959021e24ba79eaf5ca7c1a88",
"38dff6d4c0386e418450e81fe69b1fb00fce49731bd849a959ac01f60caa0012",
"cda6a362475c57816834bb8218cc397933f35ec3546040aad8bff8eeff5f2aa5",
"464d866a9ed4bc6891584b31fa3cbf5b250eed0e85decd93b33cd5b1fcf1c961",
"b83426ba2889308025a128a834de3acf3fcc25a7c7a2ce4986f9aa5aafaad75e",
"21d26828619144fa4b0d8957aa495977f3c68d4a59d0d69e7be51a55a1e36b84",
"c09a87de7a9b409b708fe6a3389016f2b2fa90eaff70b0c6161b9b5d47ff5a57",
"c106a9c91b50f706d2d12e4f92cc41b83767355fc95c10dc423c98d0d8591ead",
"619d91bac71afa81718f062701fe147fb1830c7ed6b472d517d32f17b25542dd",
"17641e8522e017e9ac3596c1b3c6871001cb6029b08e194b830be95c57ef1f87",
"41b2f63bc6f44111243c481a2d998cae486164e3bf2ef76fcd80e6302479e1c6",
"0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
],
"logIndex": 1198447178,
"rootHash": "d84fc58de4d42fa85509c90d07a2f867f4cc4a6eb9b35f716952e3af88f1d058",
"treeSize": 1198500901
},
"signedEntryTimestamp": "MEUCIQCLNSHnaHCc5KIhswPfnJlQI/WfALpSQWFKYCP2HmOfbAIgUaQ/sfGRz0hxI6Bg1jB9IDPwbjWJWmxwbCsooM0KFA8="
}
}
Loading