fix(maven): skip dependencies using ${project.version} instead of failing #96
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jun 3, 2026 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 695236380392334013128643644007549964248849759189 (0x79c77a3e17e31984701a322087183c004d16bbd5)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jun 3 09:26:46 2026 UTC
Not After : Jun 3 09:36:46 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
3f:5c:c7:c1:84:8b:39:e5:6e:f9:d3:51:f7:ab:e7:
4b:61:66:10:b9:10:77:39:7e:6d:24:2f:9c:1e:8e:
37:f3
Y:
97:73:5f:1f:9d:ec:08:dd:3c:e0:47:22:bf:a4:7a:
9f:8e:b7:8a:3e:b2:aa:19:be:4e:53:07:93:f7:3d:
b7:44
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
D1:1B:71:A4:C7:3B:49:01:05:B5:AA:8F:12:B3:56:C6:07:E7:74:37
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:david.negreira@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Unknown extension 1.3.6.1.4.1.57264.1.24
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnozOiQ0AAAQDAEgwRgIhAKdbBwJYegM5On8ITy2Zf7he0Kfw8zYkqNxOSwk/72aiAiEAhOZMGjHOr9tyFmHMS3TQxxyc3HEBns6jEI2CJYp5hRM=
Signature Algorithm: ECDSA-SHA384
30:64:02:30:47:9a:a5:7b:c9:41:cd:8e:b6:5a:05:6e:b1:56:
51:60:f3:25:af:8e:e3:ac:9c:8a:8d:ae:94:10:42:f2:ed:c7:
b5:dd:4c:ef:4d:16:0c:63:1b:5b:db:99:9c:17:3c:a6:02:30:
07:70:1a:7d:34:92:9f:86:ea:bf:97:10:e3:a3:aa:8c:b6:54:
2b:2a:95:da:3d:fd:ab:f9:66:2e:ba:9c:1b:80:9c:be:22:d8:
a6:f2:40:40:67:00:fd:83:f0:e0:32:dc
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI4MjZiZDhhNTJhYjNlMmE4YjQxMGUyZTA1YTI2OTJhZTE5YzQzMWI5YWY0YjlkNjM0MDU0YjU1NTczZDNiMThmIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURhVnJFaGQvUmdrZWRwQmMzZ1pyU2FsU2NNVm5zd3pKbTlUWGRnVUo3bERRSWhBTGhsZithS3VOMzNmSzhyUEx1SGJTckJlNGozNmNBUlR1YnpQVi90eEFmZSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVUk5la05EUVhKeFowRjNTVUpCWjBsVlpXTmtObEJvWm1wSFdWSjNSMnBKWjJoNFp6aEJSVEJYZFRsVmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVxUVhwTlJHdDVUbXBSTWxkb1kwNU5hbGwzVG1wQmVrMUVhM3BPYWxFeVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZRTVhwSWQxbFRURTlsVm5VclpFNVNPVFoyYmxNeVJtMUZUR3RSWkhwc0sySlRVWFlLYmtJMlQwNHZUMWhqTVRobWJtVjNTVE5VZW1kU2VVc3ZjRWh4Wm1weVpVdFFja3R4UjJJMVQxVjNaVlE1ZWpJelVrdFBRMEZrYTNkblowaFdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlV3VW5SNENuQk5ZemRUVVVWR2RHRnhVRVZ5VGxkNFoyWnVaRVJqZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0M1dVUldVakJTUVZGSUwwSkRSWGRJTkVWa1drZEdNbUZYVVhWaWJWWnVZMjFXY0dOdFJrRlpNbWhvWVZjMWJtUlhSbmxhUXpWcldsaFpkd3BMVVZsTFMzZFpRa0pCUjBSMmVrRkNRVkZSWW1GSVVqQmpTRTAyVEhrNWFGa3lUblprVnpVd1kzazFibUl5T1c1aVIxVjFXVEk1ZEUxRGMwZERhWE5IQ2tGUlVVSm5OemgzUVZGblJVaFJkMkpoU0ZJd1kwaE5Oa3g1T1doWk1rNTJaRmMxTUdONU5XNWlNamx1WWtkVmRWa3lPWFJOUm5OSFEybHpSMEZSVVVJS1p6YzRkMEZTWjBWVVVYaE1VVEpvVm1WRk1WVldXR3hPVWtkTk1WUlhjSEpOUlRGRlUxaHdVRlpGTUhoVVdIQk9UVVU1UlZOV1RrbE5iV2QzV2tWb1F3cGxhemx3Vmxoc1UyRldWalZWYlRGSFlXeHJlVTlVUm1saWJFbzJWRWN4YTJSdFNYbGFTRTVoVlhwV2NWbHFTWGROU1VkTVFtZHZja0puUlVWQlpGbzFDa0ZuVVVOQ1NEQkZaWGRDTlVGSVkwRXpWREIzWVhOaVNFVlVTbXBIVWpSamJWZGpNMEZ4U2t0WWNtcGxVRXN6TDJnMGNIbG5Remh3TjI4MFFVRkJSMlVLYWswMlNrUlJRVUZDUVUxQlUwUkNSMEZwUlVGd01YTklRV3hvTmtGNmF6Wm1kMmhRVEZwc0wzVkdOMUZ3TDBSNlRtbFRiek5GTlV4RFZDOTJXbkZKUXdwSlVVTkZOV3QzWVUxak5uWXlNMGxYV1dONFRHUk9SRWhJU25walkxRkhaWHB4VFZGcVdVbHNhVzV0UmtWNlFVdENaMmR4YUd0cVQxQlJVVVJCZDA1dUNrRkVRbXRCYWtKSWJYRldOM2xWU0U1cWNscGhRbGMyZUZac1JtYzRlVmQyYW5WUGMyNUpjVTV5Y0ZGUlVYWk1kSGczV0dSVVR6bE9SbWQ0YWtjeGRtSUtiVnAzV0ZCTFdVTk5RV1IzUjI0d01HdHdLMGMyY2l0WVJVOVBhbkZ2ZVRKV1EzTnhiR1J2T1M5aGRqVmFhVFkyYmtKMVFXNU1OR2t5UzJKNVVVVkNiZ3BCVURKRU9FOUJlVE5CUFQwS0xTMHRMUzFGVGtRZ1EwVlNWRWxHU1VOQlZFVXRMUzB0TFFvPSJ9fX19",
"integratedTime": 1780478806,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 1708539116,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1588094134\nWQwgP8b3hU7iuJ1H1KVZfcoCI1t4iqKIGakU5PnsjT8=\n\n— rekor.sigstore.dev wNI9ajBEAiACy6zkRzTyZ6B/jMbWJF5NOfm7OAnBVnc5eXrgttQjSgIgDG/3wGCbveVhwUYINyUVfHZsq8Ov9AJanvpPT8hSKUs=\n",
"hashes": [
"9be706e1a90bb1b24b7c714ec7c9f8f4653900c3777e20848c4d7c9650ed526a",
"b2e873a2ee1f9f16bc935aed1dfebb13ac937b242200ca7159354cc61231f652",
"4c88d7a4334b88f72c0258fcde14e1215c360d5c4282a023ae832dcc6b6ac389",
"2be9a480278eea9276452becf292bb1d4598605465ff9d1c85d99a4c857b0143",
"fc5b06566b2e8e8f534e12fdda06e6ab2231726ee7f1c5ad2c558447c4d442c6",
"dba03f9b0cd0b243f8ebef979642c2b9afbaebe85e5a1e6d5fb2bb8fce9103bc",
"c8ecdf23c93c1a50b1f7557bac9698c9136bdd8c8232a3143529b43edd40704d",
"48f0106cd83157c980d96d953f86199a30b281b09486b2d4889d6eb6eadcd49a",
"81fffab4f2f73bbb2d8dc0a4278fbefe03a1b2dd8047a2bdeb5b7515d55b0c8f",
"0881e100d6cc1c0d2554045659395c026a21dc96169e75c6b3747cbafd5ae57c",
"f618332cc70986e40787a622bde032e7dc1d51e323263ac0d6e6d35f7ba2fa4b",
"905e24187ffbfe7e1dda9dde7be460be0b4a78eaecd3621fe6b94c075256dd57",
"3647c2918572f67e52ec8b6099c8fcea8eb06f2e649ea0fa25c0c7b80e78b7e6",
"32feb8aa3483ae21120ab9f2ae46a55a6cc5b3a03e889d5ac7c0faf2148a0638",
"2399eaa2ca2ed2ffef39ba59625758dbcc33a53caef08b5eac245ca2600d3f07",
"c12d36866dcd639d6c166957eee2049df595b52b1c079311b7e6b39b5e2060fa",
"37d04be1ad8dde04688659b613fdb731ff20e608a9491e690b240947a8306ae1",
"7dee879022822e6aff73f5f6f37fa56db179533ea278c7e93a0d546fd5164f7f",
"5846bbf93f610aaf5a2f96a91fc814849cfbe39d8020c8d6dab8814b9ed51b54",
"a083e71cb028f1c5291b3546482b5eee4b2980e7a5e351e56992bb47741d15d1",
"f8c79c12a4eb700e48aef8687764e420976d5abec688d905764adb1f46edb89b",
"2718377d4e427aca60e4b375b15a4d4bc3c8e3c4b5a81e59c43e9bf066471de0",
"fc7f60ddc412d16333b75c4de8a62d598042f776fd0be06e97200127a933bdec",
"35291f8eaa2c8dc6e3b884d147793efb708a2c3aa5fe16a8e0c53272f76b3177",
"867fa9a6eeefc254828bb5b52f967be746e901dafe5940092d25276fca8bcb79",
"af99e7f7e99b81440be26f2779383f5e362475fda10ff72f64cb0d47fbf47015",
"793f85e3bd60d8725f778dd4e23e0bd4f20192de2b2db1d077fa4e47fae594ed",
"0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
],
"logIndex": 1586634854,
"rootHash": "590c203fc6f7854ee2b89d47d4a5597dca02235b788aa28819a914e4f9ec8d3f",
"treeSize": 1588094134
},
"signedEntryTimestamp": "MEUCIQCYfRm5wGvhPukm0iK3gQYcbc4KG5iMZ+CCJhauUx0ywwIgOgJNuY04DRc7FlrYs7L3XW99sSMaGCsfnjwsX4AMqAU="
}
}
Loading