Remove overly-aggressive filetype guards when extracting archives #966
Chainguard Enforce / Enforce - Commit Signing
succeeded
May 28, 2025 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 112168742928414618384683455541780495438835971562 (0x13a5d20520c2c5a75a4ad08d989c70d1dc5575ea)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: May 28 22:42:34 2025 UTC
Not After : May 28 22:52:34 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
3d:5f:f9:65:bd:f8:41:6b:c5:b8:4b:37:af:5c:76:
65:87:d3:71:83:33:42:25:6c:07:02:3f:b5:1e:b3:
6e:fc
Y:
d5:ee:8d:02:8c:6a:74:62:50:6e:76:b7:14:55:b4:
82:bd:c5:91:1d:43:aa:83:1c:ef:07:f9:96:73:d1:
a9:2d
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
0A:39:2F:C3:63:48:11:01:79:07:75:27:FD:1D:F5:26:33:A9:30:FE
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlxkPyrsAAAQDAEgwRgIhALDTnZksX8WWWQtxujTBxNMnD3RzP/5XxIuYpfPrBSt+AiEAs1RBVCuLmdV6wl+QPxP/+D+narV7MIw9HJ8u/lGvS38=
Signature Algorithm: ECDSA-SHA384
30:64:02:30:14:09:c0:5a:6d:cb:72:c3:0f:e7:32:9e:74:e1:
da:8a:70:3e:00:9f:f9:ee:b6:ab:d5:ec:c6:ca:86:0c:76:76:
3b:18:a5:72:60:98:1a:58:75:2f:3f:b3:63:e2:74:28:02:30:
36:58:ef:c0:7c:c0:73:ee:37:f5:2f:26:37:8a:81:82:f8:0b:
fc:9b:13:98:82:58:64:60:b9:f7:85:1e:bf:ba:e9:06:08:7d:
83:a9:73:f1:22:7e:7a:a5:5e:2f:da:13
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJkZjNhMTA4MDRkNTBhMjVmMzU1MzM4MTFlYmZkNWU0NTVkYzNiYmUyMDkxNDQwZDlkMzg5ZWEyM2M3ZmU3ODA2In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJQ1ErOFh3RGZMUjlLU0U1dmw2RFZENzBpVER6eDdML3NTemQwQkVSRzZtTUFpQXliR1l0MDNhSER3TWR2ckdWVzRJc3NDL3hXakFJUHVTbUlUQ2xJOEw1MFE9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4eFowRjNTVUpCWjBsVlJUWllVMEpUUkVONFlXUmhVM1JEVG0xS2VIY3daSGhXWkdWdmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVVU1RSTmFra3dUV3BOTUZkb1kwNU5hbFYzVGxSSk5FMXFTVEZOYWswd1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZRVmk4MVdtSXpORkZYZGtaMVJYTXpjakY0TWxwWlpsUmpXVTE2VVdsV2MwSjNTUzhLZEZJMmVtSjJlbFkzYnpCRGFrZHdNRmxzUW5Wa2NtTlZWbUpUUTNaalYxSklWVTl4WjNoNmRrSXZiVmRqT1Vkd1RHRlBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZEYW10MkNuY3lUa2xGVVVZMVFqTlZiaTlTTXpGS2FrOXdUVkEwZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHhDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJTUVWbGQwSTFRVWhqUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdBcEhVUzlMZFhkQlFVSkJUVUZUUkVKSFFXbEZRWE5PVDJSdFUzaG1lRnBhV2tNelJ6Wk9UVWhGTUhsalVHUklUUzh2YkdaRmFUVnBiRGdyYzBaTE16UkRDa2xSUTNwV1JVWlZTelIxV2pGWWNrTllOVUV2UlM4dk5GQTJaSEYwV0hOM2FrUXdZMjU1Tnl0VllUbE1abnBCUzBKblozRm9hMnBQVUZGUlJFRjNUbTRLUVVSQ2EwRnFRVlZEWTBKaFltTjBlWGQzTDI1TmNEVXdOR1J4UzJORU5FRnVMMjUxZEhGMlZqZE5Za3RvWjNneVpHcHpXWEJZU21kdFFuQlpaRk00THdwek1sQnBaRU5uUTAxRVdsazNPRUk0ZDBoUWRVNHZWWFpLYW1WTFoxbE1ORU12ZVdKRk5XbERWMGRTWjNWbVpVWkljaXMyTmxGWlNXWlpUM0JqTDBWcENtWnVjV3hZYVM5aFJYYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1748472155,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 223018607,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n101115400\nscZ7Xrn9yu5FxuNve5f79OiOvMbKhwHHr2yMYAUdx7Q=\n\n— rekor.sigstore.dev wNI9ajBFAiBq3maP5WKI0FljdyV0R2N6SzCP5IS6ahLUL5hKuHM/hAIhAOq4XFQ/06zFme+sWplqOaNgY3hsA06aUE8qOUQ+lzm9\n",
"hashes": [
"a8ee879b86a155b72a282f1f2a14e0180e1bb4efc25869488bedd79d94c595bf",
"4f01bcf791ab73c28cfb2e30287591564f95338c461e74de374b94511315c93f",
"169f9880bba16af7dbea828abc699b7f599008d1f64805f3d625d94f40738a6b",
"494f54f842f86362808da315fa7de37bc1da3c7b2500572ac69badfd622bbea8",
"7bf4b9c8b652ab51b039cca02a2f73489273d09e1f2c93aec0f992626a66b2ea",
"f65700db22e92afaf13a4d5416aafdd9f9a6e3c7fb1d65100a5f74ab2721a232",
"a42b3da7ba842d5dc61e96e973642f6b665baa67daf7d600111dfa8cb8867393",
"5a740146d75cef8c044bb67aa1f258b271e3c5505a292b317515d0b1e94dd1f6",
"37ad85df49d9cb2581a1a4b5017659b94f43626c4b771d46c2e905c7b2e66451",
"a7d237e9c9b0bcb1cf7db04bf41050c780782a77329c652a898f179a0d4a5a82",
"e1ee9092cc18535c241707b62385fd503797a701f165a712f02dab10163e31e1",
"4dd618151e13604d9fe9521fa5a3d91b78f166e324189ac5ee3a8c055365399d",
"03bafc27f91f3408b419ce2687f08cacc1d454b435979b46f447185224405866",
"a1238a3460588d0591a290c894fdd11a027db1b2621f946f2e555baae64835f2",
"40b66f06e9b159ad3dfb43b113a2f443c1b79a3c862af61f32fcfcc1bedc3f47",
"5590b9cd9ab17a3474abbab04b429eb809837ff10d31a4cc4bd2351f756540ce",
"9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 101114345,
"rootHash": "b1c67b5eb9fdcaee45c6e36f7b97fbf4e88ebcc6ca8701c7af6c8c60051dc7b4",
"treeSize": 101115400
},
"signedEntryTimestamp": "MEYCIQDHdDJ23O0eydSdqJMiI1DMm6htd9XnvFQvX0bxMSDtUgIhAKQAKBjCOxP2ImJB7BwJZbPHZHgHcQiRY3dFqD3ZdyNe"
}
}
Loading