fix(ci): resolve template injection and ref-version-mismatch findings #1502
Chainguard Enforce / Enforce - Commit Signing
succeeded
May 4, 2026 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 307773178767774166248280604315518039592828612538 (0x35e906d270ba35b84ddf0cfb269a2f2667af2fba)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: May 4 21:19:15 2026 UTC
Not After : May 4 21:29:15 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
36:45:48:a3:6c:4f:1d:11:8a:7b:e8:16:52:46:69:
39:7c:4a:86:16:a3:2d:9c:f3:7a:ef:b9:8e:f0:37:
b4:db
Y:
a0:8c:93:d8:e4:07:9e:0e:89:1a:50:a8:a6:f3:d2:
81:4c:24:11:00:31:bb:6e:ad:43:3d:03:ed:94:d8:
88:10
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
5F:51:E6:6D:D0:D9:A0:97:F4:18:3B:65:BF:D7:4B:37:C0:56:5E:8C
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:steve.beattie@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnfTcDmYAAAQDAEgwRgIhAL6G1P58eI40FJrbAeOoAa80VUzoljJ+rG+3hkoz2TMSAiEAnBOU+OToMqTNDbZsWe46pYddB7f5IQr3m4hELNLcjEg=
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:99:ba:1d:72:fb:25:ef:43:45:2b:32:c9:0d:
ac:8e:bb:5f:2e:e6:f6:36:76:6a:67:20:29:39:8a:e3:65:9a:
ce:0a:d3:e8:cc:46:63:3e:3e:13:b9:55:24:2c:d8:1e:bc:02:
31:00:c9:bc:17:21:34:f5:1b:83:9e:fe:67:2c:f5:64:e1:65:
36:fd:c2:80:f8:73:f6:66:83:d4:0e:04:e4:19:c4:c6:e5:16:
e8:c0:a5:37:a2:8a:2a:f0:a2:34:21:e4:de:6a
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI4MzYxNDkwMzM0MzU4ZWFkNTcwNGE3YjkyMGZhMTBmNWY3ZWRhOWZlNDBjYjA5NTg0YmVmMDRkOWIyOWQyNjgwIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJRHJnR0VNdzVFRjl2bndsM0JiR3l2OXBSVmlpRnBWNWRCN3lWS3dVVHZObkFpQnpwUGQvWEd2b1l6WXpyWVRrWklNQUExcHY5SDhrbkkzSnFWcDF5QTl3UlE9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhla05EUVd4NVowRjNTVUpCWjBsVlRtVnJSekJ1UXpaT1ltaE9NM2Q2TjBwd2IzWktiV1YyVERkdmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVVUVRCTmFrVjRUMVJGTVZkb1kwNU5hbGwzVGxSQk1FMXFSWGxQVkVVeFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZPYTFaSmJ6SjRVRWhTUjB0bEsyZFhWV3RhY0U5WWVFdG9hR0ZxVEZwNmVtVjFLelVLYW5aQk0zUk9kV2RxU2xCWk5VRmxaVVJ2YTJGVlMybHRPRGxMUWxSRFVWSkJSRWMzWW5FeFJGQlJVSFJzVG1sSlJVdFBRMEZZYzNkblowWXpUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZZTVVodENtSmtSRnB2U21Zd1IwUjBiSFk1WkV4T09FSlhXRzkzZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0bldVUldVakJTUVZGSUwwSkRRWGRJYjBWall6TlNiR1J0VlhWWmJWWm9aRWhTY0ZwVlFtcGhSMFp3WW0xa01WbFlTbXRNYlZKc1pHcEJjQXBDWjI5eVFtZEZSVUZaVHk5TlFVVkNRa0owYjJSSVVuZGplbTkyVERKR2Fsa3lPVEZpYmxKNlRHMWtkbUl5WkhOYVV6VnFZakl3ZDB0M1dVdExkMWxDQ2tKQlIwUjJla0ZDUTBGUlpFUkNkRzlrU0ZKM1kzcHZka3d5Um1wWk1qa3hZbTVTZWt4dFpIWmlNbVJ6V2xNMWFtSXlNSGRuV1hOSFEybHpSMEZSVVVJS01XNXJRMEpCU1VWbVVWSTNRVWhyUVdSM1JHUlFWRUp4ZUhOalVrMXRUVnBJYUhsYVducGpRMjlyY0dWMVRqUTRjbVlyU0dsdVMwRk1lVzUxYW1kQlFRcEJXak13TTBFMWJVRkJRVVZCZDBKSlRVVlpRMGxSUXl0b2RGUXJaa2hwVDA1Q1UyRXlkMGhxY1VGSGRrNUdWazAyU2xsNVpuRjRkblEwV2t0Tk9XdDZDa1ZuU1doQlNuZFViRkJxYXpaRVMydDZVVEl5WWtadWRVOXhWMGhZVVdVeksxTkZTemsxZFVsU1EzcFRNMGw0U1UxQmIwZERRM0ZIVTAwME9VSkJUVVFLUVRKclFVMUhXVU5OVVVOYWRXZ3hlU3Q1V0haUk1GVnlUWE5yVG5KSk5qZFllVGR0T1dwYU1tRnRZMmRMVkcxTE5ESlhZWHBuY2xRMlRYaEhXWG8wS3dwRk4yeFdTa042V1VoeWQwTk5VVVJLZGtKamFFNVFWV0puTlRjcldubDZNVnBQUm14T2RqTkRaMUJvZWpsdFlVUXhRVFJGTlVKdVJYaDFWVmMyVFVOc0NrNDJTMHRMZGtOcFRrTklhek50YnowS0xTMHRMUzFGVGtRZ1EwVlNWRWxHU1VOQlZFVXRMUzB0TFFvPSJ9fX19",
"integratedTime": 1777929556,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 1438337689,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1316657998\n/IP19MmlWZwcaHSyoKJvoObL3PcRdRZLpeRxur5YaN0=\n\n— rekor.sigstore.dev wNI9ajBEAiBUnDRYtW/t9sVHD3a8XIzgyz4ps5Tf68JRdeaZJGW07gIgY4wZSKyh27ho8pz03MDMC1YmVjUpkCFyyfraMBQWgVU=\n",
"hashes": [
"6cf5915c78bb471d7b2dd939363967d5dd79f189563d17c80299c1f1a776ad44",
"c47c3b09059d3855693465bed4e824325d247993fa093fb3f7a3c9f86361b80d",
"0cca67076345af9bdbf54f163e5d77717bcb726a4ccaba968dbe886df8bdc576",
"e586189be2f1e28befcf28408ee2d4109a3f7c5f2d9b6e21a5aa3b5cddf08b4d",
"7f34524e4e83b7be2691d0c045e5971294d6446727e38e8f170307527333ac70",
"03542101c440443b5da0ebca23d4fd99201824067b692afedf048ded1e20db06",
"00c71cdc103134d623c4f998ce1d0cb605bdbf624a5e779d652c165b0def6db9",
"04ea8210195f4ed1d87a2080c9a923e52d1a613be3e03c9f80a516b5f0307c30",
"5f2b64d4adf8e96d98cfddeaa9c26695633492cfb1714f9d282c4a21686b3c46",
"45546dcd999305aa35cb2e5ed88716351d766adeb6049b0d303fe982459cfbde",
"1ff7834f011367e18bb8449ac606bb14e01c54c10d29a3c1eac90dc7814c5680",
"253edf8198b9bdbadefc539f731a5a49cd7f166b1c3b866b0f3326b41ef3d7f3",
"71c13fd728ad46c74752c7a4ee04cb2c7ec0d4f9efa86680ccc0d728a9e5e3c1",
"edb74190bad684523f2a736bf5658229f067dfa15e4ba186c425649b0a9be6ba",
"032dfdfe13acf25e10f14b896539e9726210360b26d43bb6764e05d6fb3d2763",
"67ab98b11ca24375ee43a54cadb144b17847c38273629f15870888c41ad88f3d",
"5688031220641dd4580ecba400c65fd3b5a7f639e874e2cddac36c25092de9e4",
"af4e8ebdec4976747e183302286073bb52616321680942cfca27050fc72d1c6a",
"9b0b4a7f44352f03f72aa51be236c0a456ffb7969135fca21198c4cdc50b10d5",
"76d95d097c5e848ddabf6f46ad2e9a39299dc22d77b05e56a24d60cb5b7b67a2",
"06538db9ca99f0ae1155e6a00e4a537637508699dc7f0239f1ed2b8707d2167f",
"3b1e8f23d885dcb2af7347f5be1f1e28432efb9e686ba72273c1a3d6810a7579",
"69aeec50757ee8b3d8fb9782e25705d51966a5dcfc1fd1c973f7c5139d94fc47",
"31186bb55a2bfd47fe84a97284558e93ff7f4360b779d0b511a27efd55d27741",
"c1ae56efdcca7323677155455f1f0f33cefce49fa7d14d2ac622b61972b3d879",
"ef2db6fce76f9cd4c9de0cf3e7b5845ba0ff9a69ab2d75747554320f07a7c790",
"0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
],
"logIndex": 1316433427,
"rootHash": "fc83f5f4c9a5599c1c6874b2a0a26fa0e6cbdcf71175164ba5e471babe5868dd",
"treeSize": 1316657998
},
"signedEntryTimestamp": "MEUCIDLfB3tUtxxMeYH5MePneNIWEntjoHU/vZIIdXb7xTbdAiEAqfjjSPIJJxf75SITHdX3HxqUPFef0C7mSaLVGTNklsI="
}
}
Loading