Add tag.gpgsign true to gitsign Action #442
Closed
Chainguard Enforce / Enforce - Commit Signing
succeeded
Aug 12, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 646563543213687801311236250576564044024965635943 (0x7140e9793d0330f54330253e4b811727ef021f67)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jun 9 22:59:29 2024 UTC
Not After : Jun 9 23:09:29 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
ee:71:76:8b:37:2a:0a:59:3e:20:be:3c:c6:21:1f:
d6:49:a9:68:ca:2e:5c:b6:6a:c2:59:f0:a7:31:92:
62:f1
Y:
4c:9b:49:ff:38:51:d8:32:bb:6e:3b:c3:02:31:87:
b1:fa:5e:f9:33:4b:95:14:8f:8c:7c:11:53:7b:11:
37:d1
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
01:33:1D:B0:0E:9C:23:A7:04:1E:B3:20:05:25:74:C2:2D:77:A1:FC
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://github.com/login/oauth
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABj/86apAAAAQDAEgwRgIhAILj7ltjGI1xT9pDM8IinG8RcOws216MsbccrmV0bpZXAiEA5hxwKnb16ND3opJXEFKzHjb9ynsxmoFCBDXbbuPNWf0=
Signature Algorithm: ECDSA-SHA384
30:65:02:30:70:83:7d:fe:c7:e2:fb:75:55:dc:99:8c:31:ea:
e5:83:ff:b7:45:b7:06:8f:c9:0e:ad:a9:75:31:6f:22:06:66:
3e:3a:89:bd:10:94:2d:42:8f:e2:6d:0e:5c:9c:54:76:02:31:
00:c6:65:50:1b:92:2c:e9:95:aa:4d:56:0f:b1:97:d8:c5:a4:
a8:49:06:ff:15:d1:74:59:c6:27:d3:79:92:c1:b7:08:1c:f2:
26:46:d9:a4:a0:77:17:19:04:2d:8a:6e:9a
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIwNTJhYjA5YWUxNjVkYjc3NmU4MjNjOTFmZmZkZjkwOTgxMDZmZDhhNDY3ZjQ3ODk2MmQ4ZDAyMTAxN2ZhZGZlIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJUURqeDB0K3ZPNXFRdVpYZjRuNE5Pdk5vbEVEMmhCRUhIcUZuV3MvL21WV0pRSWdOTnFWWVZZTG12eS94ei9BcWhNdlVPMkZIWUpNZ3IzQ1d2SHBEV1Y3VGlnPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhla05EUVd3eVowRjNTVUpCWjBsVlkxVkVjR1ZVTUVSTlVGWkVUVU5WSzFNMFJWaEtLemhEU0RKamQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDVxUVRWTmFra3hUMVJKTlZkb1kwNU5hbEYzVG1wQk5VMXFUWGRQVkVrMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVUzYmtZeWFYcGpjVU5zYXl0SlREUTRlR2xGWmpGcmJYQmhUVzkxV0V4YWNYZHNibmNLY0hwSFUxbDJSazF0TUc0dlQwWklXVTF5ZEhWUE9FMURUVmxsZUN0c056Vk5NSFZXUmtrclRXWkNSbFJsZUVVek1HRlBRMEZZZDNkblowWTBUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZCVkUxa0NuTkJObU5KTm1ORlNISk5aMEpUVmpCM2FURXpiMlozZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwUldVUldVakJTUVZGSUwwSkNjM2RIV1VWWVdsaGFhR0pwTlc1aFYwcHpXbGhLUVdOSFJuVmtSMmhzWTJrMWFtSXlNSGRNUVZsTFMzZFpRZ3BDUVVkRWRucEJRa0ZSVVdWaFNGSXdZMGhOTmt4NU9XNWhXRkp2WkZkSmRWa3lPWFJNTW5oMldqSnNkVXd5T1doa1dGSnZUVU0wUjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU1VGM1pXRklVakJqU0UwMlRIazVibUZZVW05a1YwbDFXVEk1ZEV3eWVIWmFNbXgxVERJNWFHUllVbTlOU1VkTVFtZHZja0puUlVVS1FXUmFOVUZuVVVOQ1NEQkZaWGRDTlVGSVkwRXpWREIzWVhOaVNFVlVTbXBIVWpSamJWZGpNMEZ4U2t0WWNtcGxVRXN6TDJnMGNIbG5Remh3TjI4MFFRcEJRVWRRTDNwd2NXdEJRVUZDUVUxQlUwUkNSMEZwUlVGbmRWQjFWekpOV1dwWVJsQXlhMDE2ZDJsTFkySjRSbmMzUTNwaVdHOTVlSFI0ZVhWYVdGSjFDbXhzWTBOSlVVUnRTRWhCY1dSMldHOHdVR1ZwYTJ4alVWVnlUV1ZPZGpOTFpYcEhZV2RWU1VWT1pIUjFORGd4V2k5VVFVdENaMmR4YUd0cVQxQlJVVVFLUVhkT2IwRkVRbXhCYWtKM1p6TXpLM2dyVERka1ZsaGpiVmwzZURaMVYwUXZOMlJHZEhkaFVIbFJOblJ4V0ZWNFlubEpSMXBxTkRacFlqQlJiRU14UXdwcUswcDBSR3g1WTFaSVdVTk5VVVJIV2xaQlltdHBlbkJzWVhCT1ZtY3JlR3c1YWtad1MyaEtRblk0VmpCWVVscDRhV1pVWlZwTVFuUjNaMk00YVZwSENqSmhVMmRrZUdOYVFrTXlTMkp3YnowS0xTMHRMUzFGVGtRZ1EwVlNWRWxHU1VOQlZFVXRMUzB0TFFvPSJ9fX19",
"integratedTime": 1717973969,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 101204803,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n116588665\neOKrpQVkhSdTM0J6uzGUiap+fz/SV/z++bYPeK836dc=\n\n— rekor.sigstore.dev wNI9ajBFAiEA2qBnonXPt1jp3LTl5hM4EhTK37c2WdXIJkbWvQhG+BYCIG6Hh+eT2Gj/8GTluXzdSShy+MqyX6hgCsyZ8VC5Odgn\n",
"hashes": [
"226314658ba1ca9a07c04b49896b2509712ee1d662c446694695bfa0d28dc280",
"6cbce2b73bd720db292601025797e770b8c680f1dceba706672786b759c00143",
"c50a7a48fb0619a865472ade242a8b07c1e109f179bef9e9fbcffefa5c598de4",
"03fe86f2f095b9a248c0847a7bf2e23f3cdc2445b8482be97956f41602b058e9",
"3a35a27951070188d4348b002e63b76cebaeeaa280a0d4690812393878d522dd",
"67adf1c328094e1a8762eea8b3702bba7f5ba75caa42f94adf02b1e086af179b",
"7e3baf8124709d51dc80e2d6cf249d7697e954f0228b7fbc6c1ba05c607663ab",
"bbe5358c7fd4b358eeb9339a0fe87a2d3ddd47a13d5972299560a44845e7c4f3",
"900426340e9eb1e13a697a6cdd6b1c94624e652dcb1237f381355da2d64d7c47",
"fc7e691718e3947a600e36da444a768a476bf243532125704788cd23a136ed51",
"648d96d2858b6fe5986f38fd2d90525db31c039bd75bf66c9289e015f7c40861",
"3ab8d513c70f791cb0e0e7a76a3a9cf09f8f53b3b8cba268b0d1a29d27cd26e9",
"82ee65ece1f7155839431e64b00c4c0476991f3c73c525d467d71c28f76a2345",
"878eb7ad26772864e0826dbdda62136f362e8e56e0bf439f43094773d9a95a9a",
"2330ac85f3b9f7d31247d96f647b696550fb0a30ebc7172bb76b951c18630f7e",
"8b9d001903a10c944637c1aec33d74b15eac31b0cc82f70837a2df2974f082c2",
"dab03bab4edb309785f9185fcdd31e4e7319044b98695dce921adbce48069537",
"11d3a36598f715ab7ccf37f890b9d76c3d9f1c190b88995d4ac8964d4fada041",
"9ad24480bf17c08ddab563805c2b48c8d855918613f1154f8a5e285dfda0d39d",
"ad7f33b699ebba98ad34d1d3aabca458a5ed9b62b58fed711e9398aea7574aed",
"34e83e10edb6be133d3de55b2e1b903614b94ddc6f5c1dca2df7e48964ac3e86",
"b4d08ed069441e3267f7506ac5c40696c3c04458c0f67e2335416de68a192dc8",
"b75debb2b9a3e6c6cc958f10304053a157546467897fb001cc6a83732d24b708",
"717dc0831fa13faeadd592db5ffc876df8d4e3aff79bf540996c86fdf8710157",
"b23a2193fdc34087d74e07ffe57a70b5d17bc8d6eb7fc63290e307af50b20584",
"2e752fadd0a71f22fe37622f4cc0176f25f9848a22eea9a4719d488f4bc87729",
"f7c7a7ccc682fb1e6808cbc8650039cfcbeed9aa4330216f13ff77e4d7ee3f0f"
],
"logIndex": 97041372,
"rootHash": "78e2aba5056485275333427abb319489aa7e7f3fd257fcfef9b60f78af37e9d7",
"treeSize": 116588665
},
"signedEntryTimestamp": "MEUCIQDbrG++uSDid2zryugmV8KTUUu8jmUdcfPFx8MQnvYEgAIgT0NZeQpp3UkbBIrfBH+ppOuZtpkq6J6+pU26vx/g2V0="
}
}
Loading