Bump apko, handle pointers #436
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Dec 30, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 343833507328621304996998407412573010352551933062 (0x3c3a0717b873fcf47284b39f22809d5dcfcab486)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Dec 30 21:21:32 2024 UTC
Not After : Dec 30 21:31:32 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
ff:63:90:1b:47:68:bb:fc:4d:c2:4e:7b:f7:93:7c:
9f:60:18:32:bb:9b:e5:f6:b1:fe:b1:0e:7b:bc:c1:
4f:61
Y:
ff:9d:4f:82:17:a6:48:95:8e:5a:75:3b:93:85:17:
09:17:bc:f4:1c:ff:4c:91:81:81:ed:5f:e6:1f:29:
57:4d
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
95:C6:0F:A1:53:3A:08:41:28:3D:B1:49:8A:A2:25:E3:F7:F6:79:A2
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:jon.johnson@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlBlyDZcAAAQDAEcwRQIhAPU/hu7+q4GJXf7BAHAKoWbXT9Mlb2s/tnvTm8sdHIuUAiBOkJTe1Ax+1gsh/S/Y7Y5Lw6M9DKLzi1dIlR2tszRmwg==
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:c3:2a:fe:9f:86:6a:00:f3:2f:1c:a8:fe:d8:
9c:18:a3:bb:04:8e:fb:1e:92:ae:f7:0b:20:4d:36:54:52:4f:
e0:31:a4:bc:76:38:6f:bc:e4:84:d2:4d:69:e3:3b:db:05:02:
31:00:d7:df:55:86:cb:3a:2d:06:69:67:c1:13:66:e0:5a:0e:
c9:bd:51:7b:cc:7c:ed:7a:6b:79:64:b9:9c:84:c1:1f:6b:83:
eb:73:c9:6f:ee:7e:8b:d8:67:8f:08:10:2e:e2
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI3NWFiNGQ3ZDBkZmE0YzlhNzIxYWU3NmEyYjkyZjI5MWI0OTgzMGNhZThiMTVjNWIzOWI4NjI2ZmYwNzg5YTQzIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQzFNZEVObTVRSWhtQ1Brc2hqZjVScDRiVnkwckdVRXNGcFVjUnovV1ZDVEFpRUF1WER4Tlp0SFJHR0dlTEJIcENPa3l2U0pDT0NOc292RUZsQ2ZUNW5ENHkwPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhSRU5EUVd4dFowRjNTVUpCWjBsVlVFUnZTRVkzYUhvdlVGSjVhRXhQWmtsdlEyUllZeTlMZEVsWmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJlRTFxVFhkTmFrVjVUVlJOZVZkb1kwNU5hbEY0VFdwTmQwMXFSWHBOVkUxNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVV2TWs5UlJ6QmtiM1V2ZUU1M2F6VTNPVFZPT0c0eVFWbE5jblZpTldaaGVDOXlSVThLWlRkNlFsUXlTQzl1VlN0RFJqWmFTV3haTldGa1ZIVlVhRkpqU2tZM2VqQklVRGxOYTFsSFFqZFdMMjFJZVd4WVZHRlBRMEZZWjNkblowWXdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZzWTFsUUNtOVdUVFpEUlVWdlVHSkdTbWx4U1d3MEwyWXlaV0ZKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFlXMDVkVXh0Y0haaFJ6VjZZakkxUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHRDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJZDBWbFowSTBRVWhaUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFZRcEhXRWxPYkhkQlFVSkJUVUZTZWtKR1FXbEZRVGxVSzBjM2RqWnlaMWxzWkM5elJVRmpRWEZvV25Sa1VEQjVWblpoZWlzeVpUbFBZbmw0TUdOcE5WRkRDa2xGTmxGc1RqZFZSRWczVjBONVNEbE1PV3AwYW10MlJHOTZNRTF2ZGs5TVZqQnBWa2hoTW5wT1IySkRUVUZ2UjBORGNVZFRUVFE1UWtGTlJFRXlhMEVLVFVkWlEwMVJSRVJMZGpabWFHMXZRVGg1T0dOeFVEZFpia0pwYW5WM1UwOHJlRFpUY25aalRFbEZNREpXUmtwUU5FUkhhM1pJV1RSaU4zcHJhRTVLVGdwaFpVMDNNbmRWUTAxUlJGZ3pNVmRIZVhwdmRFSnRiRzUzVWs1dE5FWnZUM2xpTVZKbE9IZzROMWh3Y21WWFV6VnVTVlJDU0RKMVJEWXpVRXBpS3pVckNtazVhRzVxZDJkUlRIVkpQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1735593692,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 158381455,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n36478392\nk1uMRDolY8Dn5eWYpef28U5iF7W6ooLYYOZLfNqoAA0=\n\n— rekor.sigstore.dev wNI9ajBEAiBtfnzbPvER2UkMzbaCA2e3OXiu/Qr9ayjDEhNKq/Bp6wIgDktoagAogDEwXca4S4rZyOl6hXl23skYaMdfLaaGGE8=\n",
"hashes": [
"d9600ef9995ee0a8f944d35fbbcdee3c27e7a49792e5c676b69aee10a449a404",
"815cc1a7f33aa24426e7432dcc37c69594c5c4800b1e1d5e34a87513328f17c1",
"f94241b9071d05c69b9592d6ef5ee1da50172558b93edc53dca17af546bdd2a6",
"5bb9330ebe2f514989d9b5cd05265e2c0e5e03096c5cebcad9ebc6ad39ab289f",
"5e11c2e3d8238120102cbf26da537eaa8aafcc86fc1a734c8d5aa0d5959e971c",
"0e66393a8ed195d41e0c935e1c6fdfb75c3e0ae80c6f38869f8fbb5e7039ab8a",
"5ec39a3822633bc847bead06819c5948588223a604d5bfa6d05c1644a0311bcd",
"89aba7e87aba97b5717913cfc5259d5b0745886964259ec0bea488f216806f02",
"b47563ba4a91bc9f981a12e23cb0d5bf5387bf78567bcb618ae4ac92926bf43d",
"fa874c659854c509764e699678c59aea6408104040ce9c1cbf583934201be449",
"e8e1c1dea52efd6a1474b0a2c2d69755d7ed651fb6fc870a23bf28e1f4c2a0fd",
"9b1c05918ed738a633fdd539fddc778c0e07806d6913a0578e83264166f62655",
"550f0b9399caa6fa7ff44bd4a5fa1cfedbec4264ba7694a9f517b206f23c1aeb",
"2cb77459695531ba238af548a508e8c6b806b043f35136c7894b4c5cfb6ebbb9",
"fe7f0c59fccebbf7635e8e886aef7dfb9635e5c98457e82bdccd6beca6516909",
"27430520088f9f87a8db67b05119fd33d2f8982a35f81c06b1a485d56a98fd11",
"b600b0c24a703d9e8d741f89861c6d37727f31d04a96e3edcd9b8a826e1e4568",
"bde9b268c8f435ad4b3236c1ffd0e692af13fa301bde8fb20844a001ac940015"
],
"logIndex": 36477193,
"rootHash": "935b8c443a2563c0e7e5e598a5e7f6f14e6217b5baa282d860e64b7cdaa8000d",
"treeSize": 36478392
},
"signedEntryTimestamp": "MEQCIF62w41XSyF64QmRxvRbmYyJV8cHsbt3I5zFYcGzbxUaAiAl4FIyUWV3vAmsRuwLKfmJtwWKTUYE4/F3rcJzHPXAbw=="
}
}
Loading