Address extraction edge cases re: duplicate file names #967
Chainguard Enforce / Enforce - Commit Signing
succeeded
May 29, 2025 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 225910894012307405203116726188585448720074273095 (0x279231e1406f64b5ac51afac6366a5e4c56bf147)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: May 29 02:06:23 2025 UTC
Not After : May 29 02:16:23 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
46:a5:1f:37:19:64:91:e5:4f:d6:d6:0b:f0:50:46:
84:eb:c8:f5:91:a0:9f:f6:d1:ad:d5:a7:ff:90:36:
85:ec
Y:
c0:5b:72:bb:b6:7a:c9:80:e0:4a:84:af:0a:24:d0:
e4:4e:98:a6:9b:d6:6c:7e:80:96:92:b6:a4:01:11:
68:42
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
50:9E:76:51:D2:83:F3:01:53:F1:00:EB:9B:67:9F:63:A3:F9:A6:09
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlxnKZFIAAAQDAEgwRgIhAMtKAy76iqcryafsdfThg0/tUBYbJV/BQFCufXDRwwTUAiEAsQOEvuUMA+AJC2jdfoOFQoMreB/vfqN8mQ34RAi3m9k=
Signature Algorithm: ECDSA-SHA384
30:65:02:30:0e:14:6a:5c:f7:14:c7:c9:6f:f2:a0:6a:b6:5c:
ec:d5:ec:a2:a6:80:a4:6f:cc:f3:d4:07:c5:99:65:6c:33:d6:
e5:31:47:d2:20:fd:87:10:a1:d9:33:2e:5d:f2:6d:8b:02:31:
00:9f:07:85:0f:74:62:b4:ad:97:3e:59:c5:9b:fe:90:65:54:
1b:5e:f1:76:45:1a:55:85:f4:bb:e1:ed:71:57:f8:c8:9d:5d:
b9:04:07:e3:05:41:38:e5:72:97:87:2b:6e
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJlMzQzYTkwYjEyOGU2MWRkMjQ2NjMxZmNkNWMxYzg3YzBjMTkwMzc4ODI0MTI5YTI2NWJlMzRjOGNmYTk3MzI0In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FTUNJQXIwMHB0dkFINGYzSXo2VlgvcEZPS2djSTRNR2hSRmhac3RqZHlQK0hoakFoOWxFdzltSjhGQ1ovVlNHZjBxaDNyZG9yT1VQWjlvRDB3U1JGY0FEc3pRIiwicHVibGljS2V5Ijp7ImNvbnRlbnQiOiJMUzB0TFMxQ1JVZEpUaUJEUlZKVVNVWkpRMEZVUlMwdExTMHRDazFKU1VNeFJFTkRRV3h4WjBGM1NVSkJaMGxWU2pWSmVEUlZRblphVEZkelZXRXJjMWt5WVd3MVRWWnlPRlZqZDBObldVbExiMXBKZW1vd1JVRjNUWGNLVG5wRlZrMUNUVWRCTVZWRlEyaE5UV015Ykc1ak0xSjJZMjFWZFZwSFZqSk5ValIzU0VGWlJGWlJVVVJGZUZaNllWZGtlbVJIT1hsYVV6RndZbTVTYkFwamJURnNXa2RzYUdSSFZYZElhR05PVFdwVmQwNVVTVFZOUkVsM1RtcEplbGRvWTA1TmFsVjNUbFJKTlUxRVNYaE9ha2w2VjJwQlFVMUdhM2RGZDFsSUNrdHZXa2w2YWpCRFFWRlpTVXR2V2tsNmFqQkVRVkZqUkZGblFVVlNjVlZtVG5oc2EydGxWbEF4ZEZsTU9FWkNSMmhQZGtrNVdrZG5iaTlpVW5Ka1YyNEtMelZCTW1obGVrRlhNMHMzZEc1eVNtZFBRa3RvU3poTFNrNUVhMVJ3YVcxdE9WcHpabTlEVjJ0eVlXdEJVa1p2VVhGUFEwRllhM2RuWjBZeFRVRTBSd3BCTVZWa1JIZEZRaTkzVVVWQmQwbElaMFJCVkVKblRsWklVMVZGUkVSQlMwSm5aM0pDWjBWR1FsRmpSRUY2UVdSQ1owNVdTRkUwUlVablVWVlZTalV5Q2xWa1MwUTRkMFpVT0ZGRWNtMHlaV1paTmxBMWNHZHJkMGgzV1VSV1VqQnFRa0puZDBadlFWVXpPVkJ3ZWpGWmEwVmFZalZ4VG1wd1MwWlhhWGhwTkZrS1drUTRkMHRCV1VSV1VqQlNRVkZJTDBKQ05IZElTVVZoV2xoYWFHSnBOVzVoVjBweldsaEtRVmt5YUdoaFZ6VnVaRmRHZVZwRE5XdGFXRmwzUzFGWlN3cExkMWxDUWtGSFJIWjZRVUpCVVZGaVlVaFNNR05JVFRaTWVUbG9XVEpPZG1SWE5UQmplVFZ1WWpJNWJtSkhWWFZaTWpsMFRVTnpSME5wYzBkQlVWRkNDbWMzT0hkQlVXZEZTRkYzWW1GSVVqQmpTRTAyVEhrNWFGa3lUblprVnpVd1kzazFibUl5T1c1aVIxVjFXVEk1ZEUxSlIweENaMjl5UW1kRlJVRmtXalVLUVdkUlEwSklNRVZsZDBJMVFVaGpRVE5VTUhkaGMySklSVlJLYWtkU05HTnRWMk16UVhGS1MxaHlhbVZRU3pNdmFEUndlV2RET0hBM2J6UkJRVUZIV0FwSFkzQnJWV2RCUVVKQlRVRlRSRUpIUVdsRlFYa3diMFJNZG5GTGNIbDJTbkFyZURFNVQwZEVWQ3N4VVVab2MyeFlPRVpCVlVzMU9XTk9TRVJDVGxGRENrbFJRM2hCTkZNck5WRjNSRFJCYTB4aFRqRXJaelJXUTJkNWREUklLemtyYnpONVdrUm1hRVZEVEdWaU1sUkJTMEpuWjNGb2EycFBVRkZSUkVGM1RtOEtRVVJDYkVGcVFVOUdSM0JqT1hoVVNIbFhMM2x2UjNFeVdFOTZWamRMUzIxblMxSjJlbEJRVlVJNFYxcGFWM2Q2TVhWVmVGSTVTV2N2V1dOUmIyUnJlZ3BNYkRONVlsbHpRMDFSUTJaQ05GVlFaRWRMTUhKYVl5dFhZMWRpTDNCQ2JGWkNkR1U0V0ZwR1IyeFhSamxNZG1nM1dFWllLMDFwWkZoaWEwVkNLMDFHQ2xGVWFteGpjR1ZJU3pJMFBRb3RMUzB0TFVWT1JDQkRSVkpVU1VaSlEwRlVSUzB0TFMwdENnPT0ifX19fQ==",
"integratedTime": 1748484384,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 223417602,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n101520489\n6FKgTX4bPeOW1H6wRCLXulLa/17DyLxXqB57AZU5suY=\n\n— rekor.sigstore.dev wNI9ajBFAiA0RMhgY7fhKEaR88jZnz1dkseQT+yfUZZvz04N1oNZlgIhAIIXOmcavpWEzFG0svxEqj1Wiw26I9Iu+U292bad/oik\n",
"hashes": [
"334d4119893d1eaecb3d20ec7adbf4d665646c5a6f0689226b76c10cb4d86574",
"aed7fbf323d7a9522cb7bd1575ba9b9f36fb8f3f3721da9fe8191a96dc45a48e",
"9e298fc2ffc5ee6e47fe35347e021d81df69916f945c791266f0c2ae709eb5f3",
"f95740a3a90457156071a0978a336f9a11dc44587c47c13adc95342a16cbcc11",
"247e4f1745bcc912a943e87d87576791aace7e1a3dbb58039f32d09e319ebf93",
"316b69c272ef62e059dc6353f18637251412aa7a87f65645365f472914c58363",
"adfdc7cc2068ae46ab796441431d0c8da61afe42b9eb9081092d3e50acbd2682",
"3fe6339676d253bd76aec74878e6a5d7a685d65565adb0ce468641155c572bae",
"e45544c13393113999fa2c098c81616f3d681fa6fe848544146f33f59bdaa4db",
"c909de143ef4dd5da858ab3082c6d1d577539edd50ab4b485a2a400bc37053db",
"ce09038098b4eab182d7828592a9ee704041e257c8a8deb93212159ae678ab45",
"839758f605be817c3adff238903f288882681f322fa8c6cc66a99e87c61b7726",
"6f9b9bee0b6d0dcf71980ec60af5c511a515f4513b31528233494c6938bd1371",
"461ed054e1aedc8ba1fa8421e8425080904ecccbea1a3b5112ba072ffc42ddb3",
"0fb451857eb091510d4eba7eb1bfbb3ff4b0e8ef87c26df1a4fd9ce7408a1a06",
"b689097bc84091510fd0d0fbe493c1f8d80e70be4d158c673da78009db121321",
"8b0dc49b09c56abcfacc5dc4a653f695804cd90752019b0a3986befc8dd07fb4",
"f6fd5f031c834d1fbf461f36380182d7ccc824b9ed71755abc0741926e3f8d0f",
"70c3541d10060d2a59583ba1739361899366fad419628ef2441f12e04092c9ca",
"9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 101513340,
"rootHash": "e852a04d7e1b3de396d47eb04422d7ba52daff5ec3c8bc57a81e7b019539b2e6",
"treeSize": 101520489
},
"signedEntryTimestamp": "MEQCIDPaYZZgllFyEu9+2zSNKIxzlGPUMo5hVmnbmUJvmEgiAiBNqPMEIRnbpU0yuHI2OB5TwBMp44uQmkwG1BlGBtxNtg=="
}
}
Loading