feat: build config can specify package CPE #1768
+92
−0
Draft
Chainguard Enforce / Enforce - Commit Signing
succeeded
Feb 16, 2025 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 426428843847666565771318564076481104339371784270 (0x4ab1bb0e6d30f99defab981a7a71912d2057784e)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Feb 16 01:26:39 2025 UTC
Not After : Feb 16 01:36:39 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
5f:37:03:a3:db:83:51:d0:70:9f:33:fb:43:73:75:
d5:76:23:cc:ea:31:bc:18:8c:d1:ba:7c:c2:98:18:
a4:d9
Y:
c0:74:9b:fa:e6:e6:a4:76:72:96:38:b4:1e:22:b2:
09:15:8b:6e:43:3e:24:9b:11:d9:d7:81:91:0e:ea:
d5:5c
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
40:4F:11:5D:4E:6F:57:69:70:56:89:89:6A:D2:BC:CB:AC:11:F1:75
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlQxdXAgAAAQDAEYwRAIge2V6TcHFnqQBF30/kX9GlUoc0bqjgZsYPLBnPCorUy0CIARohhce+cEL9sgfF9f0tATPaGPUiZT9kBxpPuXROqTL
Signature Algorithm: ECDSA-SHA384
30:65:02:30:43:d6:fc:a6:23:63:a6:20:f7:9e:9a:98:ca:2d:
f4:0d:d7:f4:5c:8e:16:b5:9a:38:a1:1e:ce:da:11:50:a8:ab:
a3:7f:34:e7:ba:a3:e1:d3:e9:20:ad:55:d8:e3:2e:98:02:31:
00:c8:98:64:05:b2:14:54:ca:6b:28:81:4a:87:33:e3:eb:ea:
ff:bc:54:77:23:9e:07:c0:89:6c:38:ce:14:0e:0b:ab:02:19:
3b:df:52:30:2b:94:ae:b2:ae:e7:13:7f:75
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIwNDJjY2NiODE0YTdhYTNkYTZkZTdmZWY5MGIwMzNhNDI3MGMwNGJlMGY3YjIwOWU5YWMzZWIyM2NhZjEzZDhjIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQ25WNUR6UXU5TUVaZzNBSWZLakw5WnEyMlNOem5mU0ZHNzJiQ1RzaGMvYUFpRUFwQ3pWUG4zdWFlRG5jZE9zUGNDNU5oVjREU2x5OU45Z3RvN0dPeFFBaW1zPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjZla05EUVd4WFowRjNTVUpCWjBsVlUzSkhOMFJ0TUhjcldqTjJjVFZuWVdWdVIxSk1VMEpZWlVVMGQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDFxUlRKTlJFVjVUbXBOTlZkb1kwNU5hbFYzVFdwRk1rMUVSWHBPYWswMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZZZW1ORWJ6bDFSRlZrUW5kdWVsQTNVVE5PTVRGWVdXcDZUMjk0ZGtKcFRUQmljRGdLZDNCbldYQk9ia0ZrU25ZMk5YVmhhMlJ1UzFkUFRGRmxTWEpKU2taWmRIVlJlalJyYlhoSVdqRTBSMUpFZFhKV1dFdFBRMEZZVVhkblowWjNUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZSUlRoU0NsaFZOWFpXTW14M1ZtOXRTbUYwU3poNU5uZFNPRmhWZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwUldVUldVakJTUVZGSUwwSkNjM2RIV1VWWVdrZDRNV0ZJU25CaWJXUkJXVEpvYUdGWE5XNWtWMFo1V2tNMWExcFlXWGRMVVZsTFMzZFpRZ3BDUVVkRWRucEJRa0ZSVVdKaFNGSXdZMGhOTmt4NU9XaFpNazUyWkZjMU1HTjVOVzVpTWpsdVlrZFZkVmt5T1hSTlEzTkhRMmx6UjBGUlVVSm5OemgzQ2tGUlowVklVWGRpWVVoU01HTklUVFpNZVRsb1dUSk9kbVJYTlRCamVUVnVZakk1Ym1KSFZYVlpNamwwVFVsSFNrSm5iM0pDWjBWRlFXUmFOVUZuVVVNS1FraHpSV1ZSUWpOQlNGVkJNMVF3ZDJGellraEZWRXBxUjFJMFkyMVhZek5CY1VwTFdISnFaVkJMTXk5b05IQjVaME00Y0Rkdk5FRkJRVWRXUkVZeFl3cERRVUZCUWtGTlFWSnFRa1ZCYVVJM1dsaHdUbmRqVjJWd1FVVllabFFyVW1Zd1lWWlRhSHBTZFhGUFFtMTRaemh6UjJNNFMybDBWRXhSU1dkQ1IybEhDa1o0TnpWM1VYWXllVUk0V0RFdlV6QkNUVGx2V1RsVFNteFFNbEZJUjJzck5XUkZObkJOYzNkRFoxbEpTMjlhU1hwcU1FVkJkMDFFWVVGQmQxcFJTWGNLVVRsaU9IQnBUbXB3YVVRemJuQnhXWGxwTXpCRVpHWXdXRWswVjNSYWJ6UnZVamRQTW1oR1VYRkxkV3BtZWxSdWRYRlFhREFyYTJkeVZsaFpOSGsyV1FwQmFrVkJlVXBvYTBKaVNWVldUWEJ5UzBsR1MyaDZVR28ySzNJdmRrWlNNMGsxTkVoM1NXeHpUMDAwVlVSbmRYSkJhR3MzTXpGSmQwczFVM1Z6Y1RkdUNrVXpPVEVLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
"integratedTime": 1739669200,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 171593607,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n49689362\nW4bZaKrcSb/dUW+bJzryrFyPjwwUxRMncmTx32O3kJU=\n\n— rekor.sigstore.dev wNI9ajBFAiBEewme7ihEBdobSRYHiLqziqbZxSB9Ubeuy9vonHlJ4wIhAMsDw0Tv9QtHpIGuSd+ecHhWvZGVWcEWIGPT0VfqjqqQ\n",
"hashes": [
"a89990b6aa8b5eb6374b4433c83e2352e643a25ffb92f45c3a03239f486dd947",
"c54aa29ecd6e8607fe6987fc556051aaa587ddfb4db90971f4f10ff5a1c3cc6a",
"d531360b35749cce4aa4f9e72088f64a09d29cd012a332b94ae5a3b33bb4de26",
"58fd344ba5c555341d92331c9c394a5cb22fe87267fc0a4cb23b268720ebdc78",
"bb449c65608bae0c44fe0a20be4b70048a6cd96cd7b6378d27b0c32be064d7ab",
"4dbed846a8d2a0721bdaee5d12ce31031a09fa6e8327f0448125358eb86ae53d",
"be280ad43abd6223607bb1eba72c6b007ed7b9e7344a822b18b7f1ea1d3ebc59",
"98216c547118a5c10b3edd4eb644846f2219244001ccee2a2f1c0f2555d2d9c7",
"9b7ddd657ecc1846af8a9c356e79803ec900bddbfec6ef159f4f1b70cb37d6aa",
"93aec4dcddce9fbaf4897fbc5534275d6ca6773d5ee6c6d8d0cd509480219dd5",
"ab67674d89c5857c38d19a51af5e970160badb93feb544617ca724d314975b54",
"8d85b43b15246bdc4b08508f0585ab8801a61325dd770768fa6d5f9da545da9b",
"dc6d427c42d1824ae919cec1241b1e716fc7bcea23b131e9978d16b281ffdc0d",
"66c7b704f911fdc26feb62ef56e8831fe129808139bf7577a97746f074057f50",
"8d4f7eb608d320a51819e53b4fb463ab22fe17e80557db427705f6199d54b50b",
"bde9b268c8f435ad4b3236c1ffd0e692af13fa301bde8fb20844a001ac940015"
],
"logIndex": 49689345,
"rootHash": "5b86d968aadc49bfdd516f9b273af2ac5c8f8f0c14c513277264f1df63b79095",
"treeSize": 49689362
},
"signedEntryTimestamp": "MEUCIQCnsJu3ZUeg8zQ9hnbfiw0W1ap7kD9wKP0MQXAieFNRhgIgMqhsuGJC721PsVqITJiRiBtgmQJajuHp6U+7R5TTg/Q="
}
}
Loading