Skip to content

chore(rules): 2026/05/04 FPR#1499

Merged
egibs merged 1 commit into
chainguard-dev:mainfrom
egibs:20260504-fpr
May 4, 2026
Merged

chore(rules): 2026/05/04 FPR#1499
egibs merged 1 commit into
chainguard-dev:mainfrom
egibs:20260504-fpr

chore(rules): 2026/05/04 FPR

7af56d2
Select commit
Loading
Failed to load commit list.
Chainguard Guardener / Enforce - Commit Signing succeeded May 4, 2026 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 581347935054184843408789139706900183515182168925 (0x65d48b01cbc60fc4eb4ceb1c5865cfea76c07b5d)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: May 4 13:08:10 2026 UTC
            Not After : May 4 13:18:10 2026 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    53:1f:2c:79:0b:2b:8f:86:a1:be:31:25:b7:84:1e:
                    5c:21:75:ad:34:cc:7b:74:88:e6:fd:41:39:1a:a0:
                    94:fb
                Y:
                    49:f1:62:78:32:45:93:e1:74:3e:60:4b:b9:f3:eb:
                    c1:fe:db:8c:9d:e6:0a:6d:06:64:77:89:62:03:2e:
                    db:8a
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                00:82:18:A8:D8:81:B8:8B:5F:57:BA:0B:0F:36:86:52:BD:5E:F9:14
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:evan.gibler@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnfMadAUAAAQDAEYwRAIgMBLPFBgUjGtdnM0w5sQCAssG0rTNJdGS4hFxjXcgTWsCIEKfKdLzjAYC1ecOf3ZjYQ+OV1VdKcTEMOP29sPpITwj

    Signature Algorithm: ECDSA-SHA384
         30:65:02:30:68:31:cb:b8:d2:46:f5:0a:57:4c:13:4a:6d:54:
         13:30:96:ff:58:a3:21:b1:ac:4d:f3:e8:e5:65:37:c4:ac:11:
         5c:c4:50:ff:fc:eb:14:d3:7d:76:56:bb:7e:b7:20:9e:02:31:
         00:b5:d1:f3:5e:ae:89:8a:66:54:f9:5f:e7:63:dc:ce:f4:e3:
         e0:61:ec:6c:31:c6:05:d3:fd:76:bd:2f:96:fd:6e:43:b7:0a:
         c5:20:e4:37:69:1a:c6:7f:da:8f:78:81:b3

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIzMzAzZDNhOGIyOTk5ZWIzNWRhN2NjYmJmZTdiM2Q1MzIzZGU2OGZiODc3YWFjZTMzMjA4ODMyZWRiZGI0YzI2In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQkdicDdTZ08wbGRqaHJHR2paRkNpeVlzNVExUzRBMWgvc29OcFRHVUVsQkFpRUEycHBMSFoxVEtwVThFektDbERxK2pBVTFCQSt6bDJQbjdzWXF6SVJPZWRJPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdha05EUVd4cFowRjNTVUpCWjBsVldtUlRURUZqZGtkRU9GUnlWRTl6WTFkSFdGQTJibUpCWlRFd2QwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVVUVRCTlZFMTNUMFJGZDFkb1kwNU5hbGwzVGxSQk1FMVVUWGhQUkVWM1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZWZURoelpWRnpjbW8wWVdoMmFrVnNkRFJSWlZoRFJqRnlWRlJOWlROVFNUVjJNVUlLVDFKeFoyeFFkRW80VjBvMFRXdFhWRFJZVVN0WlJYVTFPQ3QyUWk5MGRVMXVaVmxMWWxGYWEyUTBiR2xCZVRkaWFYRlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZCU1VsWkNuRk9hVUoxU1hSbVZqZHZURVI2WVVkVmNqRmxLMUpSZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFpBbzRlSEF3UWxGQlFVSkJUVUZTYWtKRlFXbEJkMFZ6T0ZWSFFsTk5ZVEV5WTNwVVJHMTRRVWxEZVhkaVUzUk5NR3d3V2t4cFJWaEhUbVI1UWs1aGQwbG5DbEZ3T0hBd2RrOU5RbWRNVmpWM05TOWtiVTVvUkRRMVdGWldNSEI0VFZGM05DOWlNbmNyYTJoUVEwMTNRMmRaU1V0dldrbDZhakJGUVhkTlJHRkJRWGNLV2xGSmQyRkVTRXgxVGtwSE9WRndXRlJDVGt0aVZsRlVUVXBpTDFkTFRXaHpZWGhPT0N0cWJGcFVaa1Z5UWtaamVFWkVMeTlQYzFVd016RXlWbkowS3dwMGVVTmxRV3BGUVhSa1NIcFljVFpLYVcxYVZTdFdMMjVaT1hwUE9VOVFaMWxsZUhOTlkxbEdNQzh4TW5aVEsxY3ZWelZFZEhkeVJrbFBVVE5oVW5KSENtWTVjVkJsU1VkNkNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
  "integratedTime": 1777900090,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 1437396350,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1315499833\nM8uBHUFN3DLCdelPcoxkP8BehEa/DzDP36Pcehjxup8=\n\n— rekor.sigstore.dev wNI9ajBFAiEAp/vdn1v5ToZIu7xY3GlbOE8PIqN9d6SESqMVFqLI9PwCIAaROR9qEyFFtoyqHt1FuQ2ZnrPwEWsb49Y+aAlRxOrA\n",
      "hashes": [
        "aeb18a9e6ad4c6466b0487b9b94764d86353da64fb8dbb6193ecf76c3d044702",
        "dfb6ebb0ff2da41f904f362424508d7cde0a79de459b1d6e4ab7e892d6b7a583",
        "2e85e480c4390b0acb71ea657d4d994b0d293f9e8e77f4aee11e798067359e39",
        "6c0d22d98760782e0cbacd909552a05adcc9d70f806a7f0dde208cdb11bfd448",
        "7e33eb9708e9dad8bfaab7ea3588e8d0e4452a67611fda2523fff077f4778043",
        "4c704a45157dbc14daa5a9c5519a133200a0430e7b8c19e197586cd92a8b87fe",
        "a7b3986e6a554faede0ad633d998d47e697824e811da540037b2e3572efee289",
        "1ffc1c95fd2cc5de851f6772b4764bb4a750603ff679538d4f354a8195aaf08d",
        "a885b69adfb8d258247afe6ffd1790c07779599c8e2b5c444d0eb99bf16e6037",
        "b70c9677cc5a78d6c26d7ae7d855b2df061c1d20fb57228b8bdd4fc13a1bf036",
        "ec53b77ceef46bf408f34182228ce210d724961526ea1da8d3790183375da84b",
        "2f146a11efd0da0d2131c3c7ee74d125c7c9b3aea4fff1316f5ad3ba18e22672",
        "d092236b6c92b94fa50364f5b39dc6086cb0b12148fe7bd0f2aa6db66b212d71",
        "a691d11e0eea162fa4a79deeea4f6ee1d8667247575724f6c52baa5fcf3db3ba",
        "afd47b048dcf11658d8252d92ad2467b5771d51ca49f6dea414ff63bceaec974",
        "80082ef3b1ffb55c182a25d0c142310a7aadaacdb4dc84737d4a2e9f8ab0876f",
        "c398167a874c885d9b2558d32b1816b8f40c8f944107fe497fe31e1fb9d05e67",
        "3b1e8f23d885dcb2af7347f5be1f1e28432efb9e686ba72273c1a3d6810a7579",
        "69aeec50757ee8b3d8fb9782e25705d51966a5dcfc1fd1c973f7c5139d94fc47",
        "31186bb55a2bfd47fe84a97284558e93ff7f4360b779d0b511a27efd55d27741",
        "c1ae56efdcca7323677155455f1f0f33cefce49fa7d14d2ac622b61972b3d879",
        "ef2db6fce76f9cd4c9de0cf3e7b5845ba0ff9a69ab2d75747554320f07a7c790",
        "0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
      ],
      "logIndex": 1315492088,
      "rootHash": "33cb811d414ddc32c275e94f728c643fc05e8446bf0f30cfdfa3dc7a18f1ba9f",
      "treeSize": 1315499833
    },
    "signedEntryTimestamp": "MEYCIQD9uK2Byhtv/tM+gnlZa5t1JzAv24U21zUnQ0SQWS/ZNgIhANiETX0T7ZKEuljRAHet28/229fBjVeMqIEaLyBcktKl"
  }
}