Address false positives seen with argocd, grafana, jupyterhub, and reflex #475
Chainguard Enforce / Enforce - Commit Signing
succeeded
Oct 1, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 421806916057454382788900305099381295372799556227 (0x49e279ed688475474c1a48296513dd12ae83ba83)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Oct 1 21:05:14 2024 UTC
Not After : Oct 1 21:15:14 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
92:7e:bd:bd:03:06:1d:50:11:cf:e6:87:54:36:4f:
73:6f:c7:e2:89:cd:d3:d4:28:34:31:4a:d2:41:9a:
70:ac
Y:
bd:14:05:b5:97:01:48:0b:80:26:36:79:57:4c:08:
a1:ed:fa:e3:db:b1:bb:3b:c0:11:f3:de:ad:90:9d:
f8:c0
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
8D:17:07:8F:86:E3:B8:2D:15:21:51:CB:AD:3F:C2:0F:CD:20:14:39
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:evan.gibler@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkknmyR8AAAQDAEgwRgIhAOojDFqknDhSlK6d3pT8607VhwAo7yQsW3KlZ//zXN6VAiEA57ZbwGHupgPq5OcASWlPgamWLnQUmfWwpH15cXIU3f4=
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:b7:3e:b0:04:82:79:ba:b9:23:70:0c:a5:b4:
4c:ba:62:b9:3b:4b:f4:f4:fe:85:32:d7:64:df:87:05:77:b3:
20:72:16:7a:51:e8:e0:fb:ee:7f:71:c0:54:30:b6:f7:25:02:
31:00:c7:73:6e:f4:20:22:ac:b4:28:5d:99:d2:66:73:5a:03:
42:82:ec:ed:9e:d3:af:7e:30:be:a6:7e:2d:7e:cb:81:ba:83:
c3:10:84:3f:e1:b0:77:34:5c:e5:92:c7:32:38
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIxOGI2ZmNkZTIyZWM2ODAxYzI2MmU2Zjg3NTA0YTYyYzBiOTk2ODU2YjAzMmI3OWUzMDYwYzE5ODQ5MTQyNjFmIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJR2w1dHRyTk5uNkVnNzFOU3FJbDg5K3l3aU1UOERqMnFyTmhmUVh0WnlYTUFpQUZhdmM0c3loeWMralZQOTFIOENRSzFpSFVDM3A2Z2FVTEU3SzlabHM3cnc9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhWRU5EUVd4eFowRjNTVUpCWjBsVlUyVktOVGRYYVVWa1ZXUk5SMnRuY0ZwU1VHUkZjVFpFZFc5TmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJlRTFFUVhoTmFrVjNUbFJGTUZkb1kwNU5hbEY0VFVSQmVFMXFSWGhPVkVVd1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZyYmpZNWRsRk5SMGhXUVZKNksyRklWa1JhVUdNeUwwZzBiMjVPTURsUmIwNUVSa3NLTUd0SFlXTkxlVGxHUVZjeGJIZEdTVU0wUVcxT2JteFlWRUZwYURkbWNtb3lOMGMzVHpoQlVqZzVOblJyU2pNMGQwdFBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZxVW1OSUNtbzBZbXAxUXpCV1NWWklUSEpVTDBORU9EQm5Sa1JyZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHhDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJTUVWbGQwSTFRVWhqUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFV3cFRaV0pLU0hkQlFVSkJUVUZUUkVKSFFXbEZRVFpwVFUxWGNWTmpUMFpMVlhKd00yVnNVSHB5VkhSWFNFRkRhblpLUTNoaVkzRldiaTh2VG1NemNGVkRDa2xSUkc1MGJIWkJXV1UyYlVFcmNtczFkMEpLWVZVclFuRmFXWFZrUWxOYU9XSkRhMlpZYkhoamFGUmtMMnBCUzBKblozRm9hMnBQVUZGUlJFRjNUbkFLUVVSQ2JVRnFSVUYwZWpaM1FrbEtOWFZ5YTJwalFYbHNkRVY1TmxseWF6ZFRMMVF3TDI5VmVURXlWR1pvZDFZemMzbENlVVp1Y0ZJMlQwUTNOMjQ1ZUFwM1JsRjNkSFpqYkVGcVJVRjRNMDUxT1VOQmFYSk1VVzlZV201VFdtNU9ZVUV3UzBNM1R6SmxNRFk1SzAxTU5tMW1hVEVyZVRSSE5tYzRUVkZvUkM5b0NuTklZekJZVDFkVGVIcEpOQW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1727816714,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 135920685,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n14036955\nUu8tmLc85o8izESTgI30U00hhQdLO8SlubBIdiGOqGw=\n\n— rekor.sigstore.dev wNI9ajBEAiBbLBH95f5SkdA2CcVEJ+4LFuDYakH2irtol7Mg6tWMAQIgF1d6sgGJ4X5kJVbmTW1iAQQQ8rVdbrp9O9JRUKxGc5Y=\n",
"hashes": [
"baa989861e1f964e38b252ec62b816a8e66e4c925627ca743ac6da32c2f8635b",
"f5096ec0b3ac44d9916fa5180a7a49e2569639e7d57a99518958d4c5a6af1680",
"c2370c105a010be5d3daeb819eaaac5d381c80733715102b2ab18dcbd846766d",
"ca2be5a5591d76175edbc0d3e6c5a8beeb3cb5aba3b5ee5434c9eb8b23b5e08d",
"441dbd637874eb95ee5bd38b1990512d1a7dace6c6dd3596c3fc1f72b7169ce9",
"0d22e381302922c0fcda6c3f32fad88c45e0e5e0fa785e525b6ad69a14b8fceb",
"84edadc39a339cd334a887d1a258d69d425256e8c31055fe9309a95ecdebe4f0",
"6082d334eae1df2e7c2f92eb084b168b0ac85bdceff1318cf1455aa65f4320c9",
"65a874273b833a0f8f3f64a69af987e4bf40107295dce1ee70f8440f1a628867",
"0f1e6ea710a14bb420ffd3a7688e8920088aa89cf8b9c12a14cf0b0ddc8c0595",
"2d3ea79c783a22ed003a61e19c9796aa23dffa5367d5b629b5879531b1b11d71",
"f34cac339aa68b7542c539d77731bd3186de6b2cefb75fcce66a59f384892047",
"09a10edc66a744cb4cc24b0b552251b9745ce4d2aa2759b712fd2540f2f3a032",
"0ea2dbe7464447aa28a734c7a77be72fe7b505e2c4d16c2ace12e412fb494d9f",
"12fbbbae8db4eb4b3391a9f5275e1f09794a5c8dc2e4f890225f290b4b6ddc96",
"ac218b62c28056c38832a72ecab9399149e501c3f76e6cec97d6f2ded992d1dd",
"3db6d224630a39578f577c5578098e9f52c87d3b4391222e8d36b5968e1285b7",
"3c39a115ed13ac0f70d3acfa5ccb3f42513deb6b4657019e811001dd8426bd8d",
"d5277e2b5a51701139db23aeabb526a03ecaea30f42566aaff7f22980b3b23f2",
"ec4910e5cdfe2cfa26691de3b486ac5f2ed70a3fdbcd6256e91e478bdd1c8137",
"50e20a44dacee1263cbd058f33d5eccd8077ed27ae3bc5b333c4ff2991be9f00",
"9bc8e601d7371c40caaafbc82a61a1aa88a502fa81c5986c92d5e65e1e7c5a20"
],
"logIndex": 14016423,
"rootHash": "52ef2d98b73ce68f22cc4493808df4534d2185074b3bc4a5b9b04876218ea86c",
"treeSize": 14036955
},
"signedEntryTimestamp": "MEYCIQDoXprvjbkX/6olLaKEkfCoFfnbQt504uNsncZmECwu+gIhAJXOi5OZkrrHofA1AkeRpd9JhqgNVDn0uvQS20wmQ6wm"
}
}
Loading