Address false positives for SQLPad and Lerna #375
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jul 22, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 380399120757200966820138272229247934965312712825 (0x42a1afbfc506f28687f4bd5a7b78c7b83f50f079)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jul 22 14:55:52 2024 UTC
Not After : Jul 22 15:05:52 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
03:34:6e:9f:73:dc:67:6c:d7:5f:31:ce:82:38:d9:
7f:b6:4e:d6:36:ad:8a:18:8e:45:d9:0b:09:26:92:
da:be
Y:
3c:39:00:7a:46:93:33:2c:b1:2e:f9:60:79:21:bc:
d4:77:d8:26:e5:9a:da:6c:82:df:ca:c3:63:75:ed:
7a:89
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
63:9A:49:DB:01:AD:16:B7:3A:4C:65:2C:7D:1D:61:07:0A:95:AA:9F
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkNrxHBMAAAQDAEYwRAIgL82C1e/RNED2fedsdNRosIg7fABqYKrX26UZY++FthYCIE2VpVgr901n39rzHw6oIjXcCDMTqjF5K1aD3rYlv/hx
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:8c:c7:ce:58:1d:33:b4:26:aa:34:44:29:d4:
0f:c6:14:60:cd:94:b2:bd:a6:18:a1:21:a7:97:43:b0:67:e8:
02:ab:d0:61:5c:87:73:4c:4e:91:fc:cf:03:3a:35:e7:23:02:
31:00:d3:dc:b8:d2:4e:b2:4e:ea:8b:5d:80:fe:e3:39:8a:3d:
07:c8:0c:26:1f:9d:84:1e:95:9f:b8:0c:06:b1:d1:bf:a1:89:
3a:5e:f5:9c:f7:01:11:e5:71:52:c7:3e:e5:ef
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJkOGNlYzI0NjcyNjEzYTliOGM0ZTZhOGEwZGI1YjExZjIwZDJhMzhiMDU0ZDNlYjg0ZTJjODJmYWIxN2UzMGExIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJR1RuWjVabUtEcDNqeG1YbWZ4MEJnRjJaUTNzSnVsV2R2VnZSeVpPN0NzVUFpRUE4dzJlWko2aENIWFJDT0w2NFdFVEcyMVNCT2s3WkRtSXJxUmtQbzRPTklnPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4cFowRjNTVUpCWjBsVlVYRkhkblk0VlVjNGIyRklPVXd4WVdVemFraDFSRGxST0VocmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDU2U1hsTlZGRXhUbFJWZVZkb1kwNU5hbEYzVG5wSmVVMVVWWGRPVkZWNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZCZWxKMWJqTlFZMW95ZWxoWWVraFBaMnBxV21ZM1drOHhhbUYwYVdocFQxSmthMHdLUTFOaFV6SnlORGhQVVVJMlVuQk5la3hNUlhVclYwSTFTV0o2VldRNVoyMDFXbkpoWWtsTVpubHpUbXBrWlRFMmFXRlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZaTlhCS0NqSjNSM1JHY21NMlZFZFZjMlpTTVdoQ2QzRldjWEE0ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFVRb3lka1ZqUlhkQlFVSkJUVUZTYWtKRlFXbEJkbnBaVEZZM09VVXdVVkJhT1RVeWVEQXhSMmwzYVVSME9FRkhjR2R4ZEdaaWNGSnNhamMwVnpKR1owbG5DbFJhVjJ4WFEzWXpWRmRtWmpKMlRXWkVjV2RwVG1SM1NVMTRUM0ZOV0d0eVZtOVFaWFJwVnk4clNFVjNRMmRaU1V0dldrbDZhakJGUVhkTlJHRlJRWGNLV21kSmVFRkpla2g2Ykdka1RUZFJiWEZxVWtWTFpGRlFlR2hTWjNwYVUzbDJZVmxaYjFOSGJtd3dUM2RhSzJkRGNUbENhRmhKWkhwVVJUWlNMMDA0UkFwUGFsaHVTWGRKZUVGT1VHTjFUa3BQYzJzM2NXa3hNa0V2ZFUwMWFXb3dTSGxCZDIxSU5USkZTSEJYWm5WQmQwZHpaRWN2YjFsck5saDJWMk01ZDBWU0NqVllSbE40ZWpkc04zYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1721660153,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 114127995,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n109965630\n5RMBGzWabcimlv5KG90yzjbd9vZkc20CG1mOdc1YJWM=\n\n— rekor.sigstore.dev wNI9ajBFAiEA0OUI6nlsk0BJVN81+A3VNwQOhb1wI5Pf1EPY0JskQZoCID4NRW1KKHhGE000rlTb7p59987UPGNo4iIfR7iEXR1E\n",
"hashes": [
"780c6f3c3c00b810cafb96498bad4b929d64b665b410ca56be349a02a8a7cac3",
"3915f4d8294abdd8f50c3bee5aebc37695fe31e77de5b17cd91a20d52e63348c",
"4d8a2cea334b3d08d3b4b6d85d3442cc2c1f25c238003a7d2d04c4a45f9a485a",
"98d64512a238fe86ac9fd6e043d26cc990a7b9c4a859c2771db96930bb72c42a",
"e36b363af06b7197b2fb8cef1719f57e8b3c881d27f000d581e680e34cb1f953",
"e1af9a66c5e4baa628f613ceac47acd5c1f6de93e232503730a25924f4ff3214",
"ecc6f1f5d7859b0c8793cb99a9190b5c977aa1c3fcf78ca96cab127718330c3e",
"b5bb950bb0d513d7416ea64ba21008ea7156124322f684a6f22de961e4a87dc9",
"5cc6190eb30f9b829b33842606ac6f55bdbcc11d6eb1187fed69f327488a8e13",
"ec94976796b58783f32bbc97c4ed0d13b1437fc7f0214a91256fd0dbbbbe7845",
"b91aa947b8006415eb5c459ee8db9bcfd599417473e370fc3d3042fbbf3ac226",
"dc0c18094365498dd4c1a47cf6d9287651fb53ea7f5fc4d8e0edada5af95a6a0",
"7329b7c7f720b5b0691e9fe5415ad4a372143df8374620e73d70f38c909f5350",
"8d3a20c5d85d5215b65ba342effa6b039a143474b23f22127a5847380f6ccae6",
"520dd60bffc8c376c6ccf195d854a23730b8f97f42df6ff302fbe329d4f92d11",
"22cecf1deef96797cdcc94483f5573d320cad8f22042be871a931e1e506ce4a6",
"492e475e4eb3593d88486a9393ce86790b6a9c345ed6808180c13ece3895d842",
"349976c68643ff99046f830350f9f44ad36a729eb9e833faf0c4307b53568557",
"2ff2525f1324923f60819305c550f96db0f91b646d075ac37c711d8183fc00a5",
"9dd9a31717bcf68269e33f9f5dc2d03350660beed2a7c9bc54c90d21a7cd8589",
"6ba90b9f03789cf95da96ab83a83ba333db9650c754da2cc17421b31231576e4",
"f7c7a7ccc682fb1e6808cbc8650039cfcbeed9aa4330216f13ff77e4d7ee3f0f"
],
"logIndex": 109964564,
"rootHash": "e513011b359a6dc8a696fe4a1bdd32ce36ddf6f664736d021b598e75cd582563",
"treeSize": 109965630
},
"signedEntryTimestamp": "MEUCIEmSFXE8YxK1IiySK45QXbf//86pm8XEvK9FcheUT0xzAiEAn236uOGvtVwfChfsdVx0yib2wvN5BfpEdIkQno6ANQg="
}
}
Loading