Fix third-party rule breaking automated updates #986
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jun 5, 2025 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 420843947963041599753614950490984816014315538951 (0x49b74b9885508c7ab91f45a81db2ee95578cca07)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jun 5 14:15:49 2025 UTC
Not After : Jun 5 14:25:49 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
99:a7:fa:fa:a0:1e:ee:e7:97:db:1d:c3:67:e6:70:
80:74:f2:2f:d1:ef:b7:de:a8:2c:b0:a0:98:36:36:
b4:02
Y:
0c:38:9d:f3:08:69:8d:b6:2a:ed:b3:a3:5e:e3:70:
9c:7b:1b:b0:e5:68:c8:90:b1:18:76:bb:2e:c8:72:
ed:8d
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
51:12:ED:07:7F:3A:6E:3D:B3:C0:09:01:92:55:28:00:16:6F:98:92
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABl0ByuEAAAAQDAEgwRgIhAJtXG7382WHt47FgwKaLimaKidDUY9R71l2mJAbspXLYAiEAhnNaF0NsN2wXpVtxmoa3qAl1mOHx908KV4QiwqUASBA=
Signature Algorithm: ECDSA-SHA384
30:64:02:30:0e:99:82:ec:eb:e3:a1:96:a5:e6:cd:5b:9b:e9:
e1:d8:f6:ec:1a:2b:b3:24:25:7f:03:f8:dd:6c:86:42:f1:81:
d6:b1:86:05:a6:e9:ad:e4:cb:0d:fe:16:be:a9:bc:01:02:30:
6c:fb:cd:11:f6:fd:83:6a:91:30:7b:cb:eb:7a:b9:f3:93:3a:
72:01:87:02:f7:30:d9:04:bb:61:cd:34:bc:fd:d6:ce:76:e2:
5b:05:2d:fb:2e:e3:c9:96:da:6e:6a:80
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJmYmNlNDE4NzA1YzlhNDNmZWExN2NlYjQ1NmJiZGQ1Nzc0YWI3MTYwMTJlOTU4MTA4YjMyOGU4MmQ1NzM4ZGU2In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRm5uVWNFMFRReDVwNXpjWnJhMC9WZ21BVUk4M2RJM0h4WVp5VGFKQmd2OEFpRUEwT3krNzdlSTBMbWlJV3FkNFBMWUlyTlRvekFnckl6RzU1L0MzU244ZTgwPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4eFowRjNTVUpCWjBsVlUySmtURzFKVmxGcVNIRTFTREJYYjBoaVRIVnNWbVZOZVdkamQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVxUVRGTlZGRjRUbFJSTlZkb1kwNU5hbFYzVG1wQk1VMVVVWGxPVkZFMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZ0WVdZMkszRkJaVGQxWlZneWVETkVXaXRhZDJkSVZIbE1PVWgyZERrMmIweE1RMmNLYlVSWk1uUkJTVTFQU2pONlEwZHRUblJwY25Sek5rNWxORE5EWTJWNGRYYzFWMnBKYTB4RldXUnljM1Y1U0V4MGFtRlBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZWVWt4MENrSXpPRFppYWpKNmQwRnJRbXRzVlc5QlFscDJiVXBKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHhDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJTUVWbGQwSTFRVWhqUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdBcFJTRXMwVVVGQlFVSkJUVUZUUkVKSFFXbEZRVzB4WTJKMlpucGFXV1V6YW5OWFJFRndiM1ZMV205eFNqQk9VbW94U0haWFdHRlphMEoxZVd4amRHZERDa2xSUTBkak1XOVlVVEozTTJKQ1pXeFhNMGRoYUhKbGIwTllWMWswWmtnelZIZHdXR2hEVEVOd1VVSkpSVVJCUzBKblozRm9hMnBQVUZGUlJFRjNUbTRLUVVSQ2EwRnFRVTl0V1V4ek5pdFBhR3h4V0cxNlZuVmlObVZJV1RsMWQyRkxOMDFyU2xnNFJDdE9NWE5vYTB4NFoyUmhlR2huVjIwMllUTnJlWGN6S3dwR2NqWndka0ZGUTAxSGVqZDZVa2d5TDFsT2NXdFVRamQ1SzNRMmRXWlBWRTl1U1VKb2Qwd3pUVTVyUlhVeVNFNU9USG81TVhNMU1qUnNjMFpNWm5OMUNqUTRiVmN5YlRWeFowRTlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1749132949,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 230240305,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n108358077\njeeY5QHSm8Slt+D4GrtJ64LGvISCUkrtV3i0e9KELfQ=\n\n— rekor.sigstore.dev wNI9ajBGAiEAkSRJWdhvPCXL/0DegFpe/aMJjhSBT0LB2ht1Vdf+Bz0CIQD/RSr6Sb4zzatkTuJjcwZ3EzEsRXV4knF0mQlvlcJBFw==\n",
"hashes": [
"0733b700ee53e85c7be8cc4092d23362de084dfbe2f70c74d5747c1942fe4c5f",
"c851dcb03378eb5324a28f4c4f2c1caa1ef36575a1e492f0c4142a48df98111b",
"709378d066116fc4e9b2a00c52e8a90f2d27788cc7a4948fdf80baca3b77723c",
"c33dfc8f9f306d3c6ebac9df2cc57bffbff25f523d304e8fd201aa85d6119ce1",
"99d43a29771a9f04aaed6addfe9fd02744f41746a3b61696e2597570fb49ada2",
"4be1194f120fa2e7cb1ecbc3f4e136645e2c6c3bfbd258033108cb4d64fae71b",
"14ca97dfc417e052684bf8fb1ff09af949f0c9eb4b57e6074d42f5e42bcd8d8a",
"229688d31a72c6f700e0aa3a6774bf5baf717d4f0c4caf351189aeb7df850146",
"ae3ba1af2900a2fac4c4f2f090b252db345190529234fca455c246ebfe8d1a9d",
"f3c45b42b37850554bf74f793b113e869b6e27f741c2bb9eba940b7e5a78fea9",
"fe6a27699d7c939cf3e728ef6b740800fb38f09d579e87bab5b16c130b11dd3f",
"a0f8cdb7fa777e9fbd1b1aea4e25b8bf956efff65c5057c5c9355739a477b8d5",
"d7e996e8ba5572ad2ad4f6d76ca194589076b5e35b69667ccef1565bb710b2be",
"51426c6e30341542a27f75907b2aa192476da1a8ac96221ae65127945493decb",
"b7c06756eb10b5b7d0d197949db1690532845930c5bfde7b66f9877a9d6cdc3a",
"ad0ecaac1258a67c49e9007862c65d441fa20b406931922cfa3ae22e5bbaaf4b",
"8decae9d74aa19cc1263a55ee369f7820ed8796435ec59961f822323a3691bc6",
"32830b27abd97a75dba75edd805ec828fb5587c2a3625861f702321a7d6ba737",
"b84245b7070640931df648d08645dbee0976583dd6304942735e6e0c5bc51b1b",
"55d38ace9421265a578228f35c035ffe13658ded46fcdd6452e56728db2492ca",
"9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 108336043,
"rootHash": "8de798e501d29bc4a5b7e0f81abb49eb82c6bc8482524aed5778b47bd2842df4",
"treeSize": 108358077
},
"signedEntryTimestamp": "MEYCIQCyfFYeKYW/Hk5BdoaJNYrfQcVyND53vSrreNf132LjPgIhAJ+b3ex5xjk2uQft9+oZ39ZqBGteJlCbHdvNBNe6K147"
}
}
Loading