Add .BUILD.apko.json to APK control section #802
Chainguard Enforce / Enforce - Commit Signing
succeeded
Sep 13, 2024 in 1s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 289769074170502611136134882583277090304707665151 (0x32c1b1d65379b105c51be5573fd019157cca1cff)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Sep 12 22:49:16 2024 UTC
Not After : Sep 12 22:59:16 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
8e:29:ae:e2:ba:8d:91:e1:00:ec:6b:0a:3a:cb:e5:
08:90:b6:fc:ae:42:15:02:4c:3a:7e:bb:c3:26:2f:
17:17
Y:
d6:bf:4f:85:de:19:79:dd:60:f5:4b:57:13:4c:fa:
15:de:cd:35:1e:d9:bd:20:3e:df:ee:4d:8a:ba:aa:
ad:b0
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
F0:EC:58:8C:CE:18:75:C2:F0:22:77:93:29:19:31:86:68:CD:73:E6
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:jon.johnson@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkehtM+UAAAQDAEcwRQIgYI3y44+0fC1CN9rM6plSUHl6t/+NyGOCwFQ7UvDDB6gCIQClaP4IgrJirYq0K5juIWFQxTjTH8ES3fupEMMPYNhrDA==
Signature Algorithm: ECDSA-SHA384
30:65:02:31:00:aa:ad:3f:14:fc:9a:71:a4:93:e1:1e:03:55:
63:c6:4f:83:64:e5:22:5b:65:c5:4d:f7:dc:22:73:5c:02:d3:
dd:ec:08:5f:7d:d1:e0:ee:05:c1:4f:1a:d3:e2:9f:db:b0:02:
30:11:ed:d4:58:24:7e:39:6f:a6:d2:0b:db:7f:72:5d:0a:9e:
b4:82:55:6a:1a:5a:a1:8a:2d:b7:dd:05:28:8a:dd:f6:a2:2d:
03:be:8a:a9:e8:33:92:73:54:86:36:c0:18
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJkZTE4NjY1MDRmMjc4MjBmY2E5MzUxYzBlMTFkY2Q5ZDYyZjIxMWI1ZjlmNmQxYzU1MjE3MzU0NDU0N2YyMjk2In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRnFQZEhtVTQweit3UW11S1J4Wk1Ub1F6YnN0YUJmUTlaZWh5TUdtWGM2NUFpRUF5dzE5bndCa0M4SWV1bkp6MTJJSHJYSkVKRWdoNzArMmZkNWtLL3hCL2FZPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4dFowRjNTVUpCWjBsVlRYTkhlREZzVGpWelVWaEdSeXRXV0ZBNVFWcEdXSHBMU0ZBNGQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDlVUlhsTmFra3dUMVJGTWxkb1kwNU5hbEYzVDFSRmVVMXFTVEZQVkVVeVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZxYVcxMU5ISnhUbXRsUlVFM1IzTkxUM04yYkVOS1F6SXZTelZEUmxGS1RVOXVOamNLZDNsWmRrWjRabGQyTUN0R00yaHNOVE5YUkRGVE1XTlVWRkJ2VmpOek1ERklkRzA1U1VRM1pqZHJNa3QxY1hGMGMwdFBRMEZZWjNkblowWXdUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlU0VDNoWkNtcE5ORmxrWTB4M1NXNWxWRXRTYTNob2JXcE9ZeXRaZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFlXMDVkVXh0Y0haaFJ6VjZZakkxUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHRDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJZDBWbFowSTBRVWhaUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFVnbzJSekI2TlZGQlFVSkJUVUZTZWtKR1FXbENaMnBtVEdwcU4xSTRURlZKTXpKemVuRnRWa3BSWlZoeE15ODBNMGxaTkV4QlZrUjBVemhOVFVoeFFVbG9Da0ZMVm04dloybERjMjFMZEdseVVYSnRUelJvV1ZaRVJrOU9UV1ozVWt4a0t6WnJVWGQzT1djeVIzTk5UVUZ2UjBORGNVZFRUVFE1UWtGTlJFRXlaMEVLVFVkVlEwMVJRM0Z5VkRoVkwwcHdlSEJLVUdoSVowNVdXVGhhVUdjeVZHeEpiSFJzZUZVek16TkRTbnBZUVV4VU0yVjNTVmd6TTFJMFR6UkdkMVU0WVFvd0swdG1NamRCUTAxQ1NIUXhSbWRyWm1wc2RuQjBTVXd5TXpsNVdGRnhaWFJKU2xaaGFIQmhiMWx2ZEhRNU1FWkxTWEprT1hGSmRFRTNOa3R4WldkNkNtdHVUbFZvYW1KQlIwRTlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1726181356,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 130008841,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n8453475\nX31Zgr9EwRqUxvMkvPhwwL+b4SPmj1dC+zeIt5/33/s=\n\n— rekor.sigstore.dev wNI9ajBGAiEAhOPoVBEH4Y35d7z22Q1TwNQfW5pjDNJYUJoVQGN8VBoCIQD2BBwxrK+LFxZwxMpdO0bQhcWxDpw+WzfANVyVec7KlA==\n",
"hashes": [
"0d598287b04cf077a744f90ade2c6a86b0ca6849fba1e13515dd44dfc81a0b33",
"1061e5e5dabc001ebdf1ca82723f0eb5b85a6491e5be4136e0ccced40fe66a75",
"03744e54a77fa4821b46127c168f21fda665589434848807d8927d39e0d1b0cb",
"8247f1132fd9ac01c4cf90baf2ae0399ffe6512608c1c22d6c6dca9a76fec888",
"5223d01faeedfd19e89c77b327416820f35d31428de0644d34d1fdbb0a375e0b",
"51cbcf3f3e488b12ea9f29698b3375d93e4038def0ec3bf0c03a50ee79af817a",
"5da6f25071bb47d8c37335527d97cffd4118a41678237fe13b87234d5c3d0eae",
"eb7ee4367aa8047b55b0cbada43c1a9b5bdc7c2b6468fb187efd23057651f826",
"0cd5de5c84981d83b42b38effbb9875e05668cc3861df9be0636e9f62311233a",
"3d2125327f79f18df63849088443b28e9319a849230bd69f02714038ef624921",
"db2fad937ae09eadf82182e0b3963c3ecc51535524176f8542330f9f3be16642",
"caf7d2df0552b1ca7561ed72b6cd8b1b95a11a2f9d83c3b1c6245e5e714e8fda",
"6631ac7d3c13c731ff0e22b1aee1e014ae432a70f690da88f4444f3e48aaa50f",
"e4fa75c7d3e2888439b5c157e24cf776534838894602d7e1756d292f27e3c9d8",
"c781514d807e375220dbc9984017acf1fec8090a76eb2e519cd7c660bf304c34",
"23d50feced13200702cd91b286ccbcf85cc933c7ef64610fdaec6ab04ccf2014",
"2372c07247cdc814aa5009d4d44ca59873d01dba58bb5e61d18dd88232865d90",
"99cb81991a9938b1ac6c9df311aa65ef91594e502103c400ca341bda5ceff1a7",
"5797d5357dd900c3c0050a9d05af5bc25aae8d757fc7728bb5c17cf4eaf86f8c",
"ad489b7f2a3c3fa1c3e30e19e5175668a1a6d08631a6361308e04faeb348667d",
"e7b6671b8713923fdd7c2bfc573ee432751b718dcd2f53e47f3300d9c81d8347",
"b91b2679aede557b2104d37a86e87fa3099f680cbd471e02ab6336bc56f636d9",
"35e1ca19597a2955dfc77fb09d0ac8af1adae0fafd15aed80e94e57fcea69537",
"99e6d6fd94954ca14ba0b9e2a14226e2b4f7ac0e553e6dcf38eb5928fc17880a"
],
"logIndex": 8104579,
"rootHash": "5f7d5982bf44c11a94c6f324bcf870c0bf9be123e68f5742fb3788b79ff7dffb",
"treeSize": 8453475
},
"signedEntryTimestamp": "MEYCIQDJ7PKvbA1DpolrjHqweL4xlDK1OIh+skbhaevEzviZNgIhAJyMNhTppt3TyETrlMC9F6cXh2z9KB/BhpDYjiyb7Kf+"
}
}
Loading