fix(js): Reducing severity of javascript issues to reduce false posit… #907
Chainguard Enforce / Enforce - Commit Signing
succeeded
May 8, 2025 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 89936496064321645351854089564887604953546426673 (0xfc0e457a4122f2bb1e704fb7f41fc8e40f30931)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: May 7 18:36:27 2025 UTC
Not After : May 7 18:46:27 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
01:f2:96:20:bd:92:fb:ea:2a:f7:19:46:86:39:b2:
8b:d6:54:9d:a2:29:19:a7:f6:0f:19:97:9d:70:d2:
cd:65
Y:
f8:3a:0f:56:52:fd:9b:6c:c6:d2:c4:06:c6:6a:44:
c6:87:70:cb:1b:7e:1b:36:fd:e1:30:a5:44:d2:82:
e1:8b
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
97:DC:99:B4:A3:C8:93:AD:B8:1E:5D:DE:7F:78:2C:73:69:3A:E8:2E
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:mark.manning@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlqwI6MYAAAQDAEYwRAIgJQUuW5V8bUNc7wqgwcKV9jUG39UN8v5+qwsN9jhH13wCIDxi4daSI9eA/G/dzNSFbImCe8VXvskkSPZMTc4ArdKd
Signature Algorithm: ECDSA-SHA384
30:65:02:31:00:d1:da:ed:ec:7a:88:a3:cb:44:a5:bf:de:2f:
a2:18:9d:f0:bf:39:5b:1c:3b:bc:55:74:f7:93:a4:c6:96:a2:
38:be:cb:42:14:32:95:d8:44:43:ea:f5:63:33:9e:36:db:02:
30:70:27:fc:82:ed:37:d8:c4:6c:f5:ab:37:e2:3f:6b:b1:5c:
1d:f2:91:4a:82:1d:e3:ef:11:d8:b4:9c:eb:1f:1a:78:02:5c:
49:4f:3d:29:19:14:bb:90:7e:ec:ab:6a:e7
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI2MmZlYTJlZjNlNmFiNGUzNWQ3OTJhZTcxNjIxNzBiOWZmNDMxZTFmNjFlYjRiMDhhNDE4YjZmYjUwODA1YzdkIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRCt2MDVBOHZnbkdhc21DVWhqU000UGtTM2NLMnYzc2wzekx6bFZDZHhtc0FpRUFvMjRYUFVkUGhTTS9XUmpSSjNrcWcyVWRTbTI0OXhWYzBxTWVQcjJsS2RNPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4dFowRjNTVUpCWjBsVlJEaEVhMVkyVVZOTWVYVjROWGRVTjJZd1NEaHFhMFI2UTFSRmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVVUVROTlZHZDZUbXBKTTFkb1kwNU5hbFYzVGxSQk0wMVVaekJPYWtrelYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZCWmt0WFNVd3lVeXNyYjNFNWVHeEhhR3B0ZVdrNVdsVnVZVWx3UjJGbU1rUjRiVmdLYmxoRVUzcFhXRFJQWnpsWFZYWXlZbUpOWWxONFFXSkhZV3RVUjJnelJFeEhNelJpVG5ZemFFMUxWa1V3YjB4b2FUWlBRMEZZWjNkblowWXdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZzT1hsYUNuUkxVRWxyTmpJMFNHd3paV1l6WjNOak1tczJOa00wZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0UldVUldVakJTUVZGSUwwSkNPSGRJV1VWaVlsZEdlV0Y1TlhSWlZ6VjFZVmMxYmxGSFRtOVpWMngxV2pOV2FHTnRVWFZhUjFZeVRVTnJSd3BEYVhOSFFWRlJRbWMzT0hkQlVVVkZSekpvTUdSSVFucFBhVGgyV1ZkT2FtSXpWblZrU0UxMVdqSTVkbG95ZUd4TWJVNTJZbFJCY2tKbmIzSkNaMFZGQ2tGWlR5OU5RVVZKUWtJd1RVY3lhREJrU0VKNlQyazRkbGxYVG1waU0xWjFaRWhOZFZveU9YWmFNbmhzVEcxT2RtSlVRMEpwVVZsTFMzZFpRa0pCU0ZjS1pWRkpSVUZuVWpkQ1NHdEJaSGRDTVVGT01EbE5SM0pIZUhoRmVWbDRhMlZJU214dVRuZExhVk5zTmpRemFubDBMelJsUzJOdlFYWkxaVFpQUVVGQlFncHNjWGRKTmsxWlFVRkJVVVJCUlZsM1VrRkpaMHBSVlhWWE5WWTRZbFZPWXpkM2NXZDNZMHRXT1dwVlJ6TTVWVTQ0ZGpVcmNYZHpUamxxYUVneE0zZERDa2xFZUdrMFpHRlRTVGxsUVM5SEwyUjZUbE5HWWtsdFEyVTRWbGgyYzJ0clUxQmFUVlJqTkVGeVpFdGtUVUZ2UjBORGNVZFRUVFE1UWtGTlJFRXlaMEVLVFVkVlEwMVJSRkl5ZFROelpXOXBhbmt3VTJ4Mk9UUjJiMmhwWkRoTU9EVlhlSGMzZGtaV01EazFUMnQ0Y0dGcFQwdzNURkZvVVhsc1pHaEZVU3R5TVFwWmVrOWxUblJ6UTAxSVFXNHZTVXgwVGpscVJXSlFWM0pPSzBrdllUZEdZMGhtUzFKVGIwbGtOQ3M0VWpKTVUyTTJlRGhoWlVGS1kxTlZPRGxMVW10VkNuVTFRaXMzUzNSeE5YYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1746642987,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 208075746,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n86607271\nwGBn7ITdnXpBnpQRpFMnRcFntn0vwuc6Jp2RkOypEmg=\n\n— rekor.sigstore.dev wNI9ajBGAiEA8k4iAcRoa8B2pig9YJ0PE7aMlo85qw4Ah1gggCBdjfgCIQDji/oO46zXbKu5T35v/C558vPH95b0ETwC0N3/GJLpxA==\n",
"hashes": [
"4edc5fe0a971ebbfd1974631c4a9f65aa2fc7ef392a05fdad25a25d64a7b36c5",
"9a60a7f990eb58891425819e9041b3a27f3c52eab88ac83a04acda155b95c4bf",
"033610fe82ac92e3d1cc5afe8e6c0d9b6976ea6ec0123c8bf587539c93a23d37",
"855401fd22e5587cb11af790c6987131dcbf390ab30113e9c923581db8d2152a",
"0ec3cb34a385b0f56887d6d90ae0dcfbed6cffa7a49f631cf334b64bad0c0cb1",
"077d5876210ae60121bde5e3f91ab2be959ec99ed145cbfbbbf12b1758576bb3",
"9adad6bea7fa694701f167b685114ef1d0cf74471e5487efe7c4d9a42a4e9a10",
"fa1f32d11b61bce03b0870ddfe78dfa3eac0dad0f1322c9a56f1ca533ba21f3f",
"accd7a4b6a2793422976a4949b64fafeb0bda1eec3301e68ad9eecd2959ed72f",
"6d7a3e9c4da0d20fe781368e2dd2bf228354d30c292b7131509d4495664f8b1f",
"9cbc7ec2aa10ffd759f7e1c0a5bf608520c6686d47de77b10902a69a7a124d76",
"3e93654865c36a7fa4ca9459fc983708ec13d7d08d31e93e6c0fd2df61fea334",
"8404493359f49d08b2f971abc33b0063fffec122f7c3611fcdaedbc9207daf10",
"b437a7fefe542fd132740c8b98d5ce9ead3022190ac670847fc1bf5fd7800d3a",
"8aaaf86bbff021a3832d90189be3250e466076bc1d13bdd9af25995c88dfaf50",
"e7869512015c3f60cb771b329a48078cb1041a21e8a57c951dbeefd74c1bae52",
"3df0091c7712af08b3074e72e92297d864799ecf6159482012bc3b4e68b58590",
"882f0bf595728cdce356014e629da58334f4f8941a2e084912450854380793a9",
"a6732c79aec9aad1c2e2fa81ad6b696639bf2956b460fedcc7c7c133ad790530",
"f8fc36f5169d14f4dfdb5b3ba4bca7e89daa3427f6f82e5336279a5760ff1196",
"6456090d7f2b75287408ff28655cbf224d81fa13246d9105e3a120a001710d9e",
"fbed4b32ecf7b48756d7fa5f11f84f7d70b8a2dd40c030170dc3f27e26f31b27",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 86171484,
"rootHash": "c06067ec84dd9d7a419e9411a4532745c167b67d2fc2e73a269d9190eca91268",
"treeSize": 86607271
},
"signedEntryTimestamp": "MEUCIEOqG/KlhzsuY19fzwN1A51MqwWBXITR/Ee/jFPF68zuAiEA5ffhvRs419hkizXbWB+nCfJxZSmbRiD3MAvtCMFbs4M="
}
}
Loading