Skip to content

fix(js): Reducing severity of javascript issues to reduce false posit…

06f2843
Select commit
Loading
Failed to load commit list.
Closed

fix(js): Reducing severity of javascript issues to reduce false posit… #907

fix(js): Reducing severity of javascript issues to reduce false posit…
06f2843
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded May 8, 2025 in 1s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 89936496064321645351854089564887604953546426673 (0xfc0e457a4122f2bb1e704fb7f41fc8e40f30931)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: May 7 18:36:27 2025 UTC
            Not After : May 7 18:46:27 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    01:f2:96:20:bd:92:fb:ea:2a:f7:19:46:86:39:b2:
                    8b:d6:54:9d:a2:29:19:a7:f6:0f:19:97:9d:70:d2:
                    cd:65
                Y:
                    f8:3a:0f:56:52:fd:9b:6c:c6:d2:c4:06:c6:6a:44:
                    c6:87:70:cb:1b:7e:1b:36:fd:e1:30:a5:44:d2:82:
                    e1:8b
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                97:DC:99:B4:A3:C8:93:AD:B8:1E:5D:DE:7F:78:2C:73:69:3A:E8:2E
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:mark.manning@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlqwI6MYAAAQDAEYwRAIgJQUuW5V8bUNc7wqgwcKV9jUG39UN8v5+qwsN9jhH13wCIDxi4daSI9eA/G/dzNSFbImCe8VXvskkSPZMTc4ArdKd

    Signature Algorithm: ECDSA-SHA384
         30:65:02:31:00:d1:da:ed:ec:7a:88:a3:cb:44:a5:bf:de:2f:
         a2:18:9d:f0:bf:39:5b:1c:3b:bc:55:74:f7:93:a4:c6:96:a2:
         38:be:cb:42:14:32:95:d8:44:43:ea:f5:63:33:9e:36:db:02:
         30:70:27:fc:82:ed:37:d8:c4:6c:f5:ab:37:e2:3f:6b:b1:5c:
         1d:f2:91:4a:82:1d:e3:ef:11:d8:b4:9c:eb:1f:1a:78:02:5c:
         49:4f:3d:29:19:14:bb:90:7e:ec:ab:6a:e7

Rekor Entry

{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI2MmZlYTJlZjNlNmFiNGUzNWQ3OTJhZTcxNjIxNzBiOWZmNDMxZTFmNjFlYjRiMDhhNDE4YjZmYjUwODA1YzdkIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRCt2MDVBOHZnbkdhc21DVWhqU000UGtTM2NLMnYzc2wzekx6bFZDZHhtc0FpRUFvMjRYUFVkUGhTTS9XUmpSSjNrcWcyVWRTbTI0OXhWYzBxTWVQcjJsS2RNPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4dFowRjNTVUpCWjBsVlJEaEVhMVkyVVZOTWVYVjROWGRVTjJZd1NEaHFhMFI2UTFSRmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVVUVROTlZHZDZUbXBKTTFkb1kwNU5hbFYzVGxSQk0wMVVaekJPYWtrelYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZCWmt0WFNVd3lVeXNyYjNFNWVHeEhhR3B0ZVdrNVdsVnVZVWx3UjJGbU1rUjRiVmdLYmxoRVUzcFhXRFJQWnpsWFZYWXlZbUpOWWxONFFXSkhZV3RVUjJnelJFeEhNelJpVG5ZemFFMUxWa1V3YjB4b2FUWlBRMEZZWjNkblowWXdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZzT1hsYUNuUkxVRWxyTmpJMFNHd3paV1l6WjNOak1tczJOa00wZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0UldVUldVakJTUVZGSUwwSkNPSGRJV1VWaVlsZEdlV0Y1TlhSWlZ6VjFZVmMxYmxGSFRtOVpWMngxV2pOV2FHTnRVWFZhUjFZeVRVTnJSd3BEYVhOSFFWRlJRbWMzT0hkQlVVVkZSekpvTUdSSVFucFBhVGgyV1ZkT2FtSXpWblZrU0UxMVdqSTVkbG95ZUd4TWJVNTJZbFJCY2tKbmIzSkNaMFZGQ2tGWlR5OU5RVVZKUWtJd1RVY3lhREJrU0VKNlQyazRkbGxYVG1waU0xWjFaRWhOZFZveU9YWmFNbmhzVEcxT2RtSlVRMEpwVVZsTFMzZFpRa0pCU0ZjS1pWRkpSVUZuVWpkQ1NHdEJaSGRDTVVGT01EbE5SM0pIZUhoRmVWbDRhMlZJU214dVRuZExhVk5zTmpRemFubDBMelJsUzJOdlFYWkxaVFpQUVVGQlFncHNjWGRKTmsxWlFVRkJVVVJCUlZsM1VrRkpaMHBSVlhWWE5WWTRZbFZPWXpkM2NXZDNZMHRXT1dwVlJ6TTVWVTQ0ZGpVcmNYZHpUamxxYUVneE0zZERDa2xFZUdrMFpHRlRTVGxsUVM5SEwyUjZUbE5HWWtsdFEyVTRWbGgyYzJ0clUxQmFUVlJqTkVGeVpFdGtUVUZ2UjBORGNVZFRUVFE1UWtGTlJFRXlaMEVLVFVkVlEwMVJSRkl5ZFROelpXOXBhbmt3VTJ4Mk9UUjJiMmhwWkRoTU9EVlhlSGMzZGtaV01EazFUMnQ0Y0dGcFQwdzNURkZvVVhsc1pHaEZVU3R5TVFwWmVrOWxUblJ6UTAxSVFXNHZTVXgwVGpscVJXSlFWM0pPSzBrdllUZEdZMGhtUzFKVGIwbGtOQ3M0VWpKTVUyTTJlRGhoWlVGS1kxTlZPRGxMVW10VkNuVTFRaXMzUzNSeE5YYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
  "integratedTime": 1746642987,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 208075746,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n86607271\nwGBn7ITdnXpBnpQRpFMnRcFntn0vwuc6Jp2RkOypEmg=\n\n— rekor.sigstore.dev wNI9ajBGAiEA8k4iAcRoa8B2pig9YJ0PE7aMlo85qw4Ah1gggCBdjfgCIQDji/oO46zXbKu5T35v/C558vPH95b0ETwC0N3/GJLpxA==\n",
      "hashes": [
        "4edc5fe0a971ebbfd1974631c4a9f65aa2fc7ef392a05fdad25a25d64a7b36c5",
        "9a60a7f990eb58891425819e9041b3a27f3c52eab88ac83a04acda155b95c4bf",
        "033610fe82ac92e3d1cc5afe8e6c0d9b6976ea6ec0123c8bf587539c93a23d37",
        "855401fd22e5587cb11af790c6987131dcbf390ab30113e9c923581db8d2152a",
        "0ec3cb34a385b0f56887d6d90ae0dcfbed6cffa7a49f631cf334b64bad0c0cb1",
        "077d5876210ae60121bde5e3f91ab2be959ec99ed145cbfbbbf12b1758576bb3",
        "9adad6bea7fa694701f167b685114ef1d0cf74471e5487efe7c4d9a42a4e9a10",
        "fa1f32d11b61bce03b0870ddfe78dfa3eac0dad0f1322c9a56f1ca533ba21f3f",
        "accd7a4b6a2793422976a4949b64fafeb0bda1eec3301e68ad9eecd2959ed72f",
        "6d7a3e9c4da0d20fe781368e2dd2bf228354d30c292b7131509d4495664f8b1f",
        "9cbc7ec2aa10ffd759f7e1c0a5bf608520c6686d47de77b10902a69a7a124d76",
        "3e93654865c36a7fa4ca9459fc983708ec13d7d08d31e93e6c0fd2df61fea334",
        "8404493359f49d08b2f971abc33b0063fffec122f7c3611fcdaedbc9207daf10",
        "b437a7fefe542fd132740c8b98d5ce9ead3022190ac670847fc1bf5fd7800d3a",
        "8aaaf86bbff021a3832d90189be3250e466076bc1d13bdd9af25995c88dfaf50",
        "e7869512015c3f60cb771b329a48078cb1041a21e8a57c951dbeefd74c1bae52",
        "3df0091c7712af08b3074e72e92297d864799ecf6159482012bc3b4e68b58590",
        "882f0bf595728cdce356014e629da58334f4f8941a2e084912450854380793a9",
        "a6732c79aec9aad1c2e2fa81ad6b696639bf2956b460fedcc7c7c133ad790530",
        "f8fc36f5169d14f4dfdb5b3ba4bca7e89daa3427f6f82e5336279a5760ff1196",
        "6456090d7f2b75287408ff28655cbf224d81fa13246d9105e3a120a001710d9e",
        "fbed4b32ecf7b48756d7fa5f11f84f7d70b8a2dd40c030170dc3f27e26f31b27",
        "eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
      ],
      "logIndex": 86171484,
      "rootHash": "c06067ec84dd9d7a419e9411a4532745c167b67d2fc2e73a269d9190eca91268",
      "treeSize": 86607271
    },
    "signedEntryTimestamp": "MEUCIEOqG/KlhzsuY19fzwN1A51MqwWBXITR/Ee/jFPF68zuAiEA5ffhvRs419hkizXbWB+nCfJxZSmbRiD3MAvtCMFbs4M="
  }
}