New false positive rules #502
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Oct 8, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 703769978421151855727493733948730961402363592839 (0x7b462324c7ed84593b9b0d39b3cc7383bfd74087)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Oct 7 23:39:09 2024 UTC
Not After : Oct 7 23:49:09 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
76:81:07:ec:73:8c:c1:9b:b9:2a:71:ae:c0:f4:b3:
cd:a4:78:f3:90:20:4c:67:74:fa:e1:d2:70:5e:93:
53:31
Y:
c0:e8:82:c4:9e:3a:95:57:3f:14:81:76:51:d2:5f:
89:8c:30:4f:56:5f:56:ef:2c:a6:9a:11:94:c1:80:
bd:ff
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
75:8D:80:76:02:80:6C:D9:84:29:86:03:DE:5E:4E:F8:55:56:65:AC
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkmlZ29wAAAQDAEgwRgIhAN9gKkxA6qxaYrnMl3qLImf5KhISW89RWNdkbGh939PxAiEA8X5VILkgHet+HLu99CyK36/t5+9jq8IwX0T0djBIaSI=
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:dd:52:c7:8a:f6:e2:d2:43:bf:f2:53:e9:79:
60:f3:4e:55:fb:d6:c1:85:de:70:37:50:a3:ad:67:d3:a7:9f:
a4:2a:31:b8:cd:bf:89:8d:a9:14:6f:26:e3:0b:bf:0b:12:02:
31:00:8b:96:9a:99:be:b2:a4:b4:8f:1f:5d:3d:37:cd:93:9a:
1d:18:80:ae:ff:d6:ec:40:ed:8c:d8:dd:9f:68:5a:f3:40:38:
80:0c:31:00:a4:7f:b1:2a:34:11:ba:c1:f9:79
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJhNmU1NDRjZjcwNmFhYzNiYmNhOGQ3YzZjZGYxMzQxMGU5MzdkMTE5MTNhYjEyZDkwMzcwYTE5MzZhNGJkNDc4In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURwM0M2QjEzWWx5a1pWWTlPaWRxbFE4V2lEUmlTRUdXbXhMS1JyWWtMR1hRSWhBSlhIVGZ2MGxsa1FzU1Z4SzQ5UVhNZU5KdElKR3kxSDVsRU5uaEF3ckx6aCIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhWRU5EUVd4eFowRjNTVUpCWjBsVlpUQlpha3BOWm5Sb1JtczNiWGN3TlhNNGVIcG5OeTlZVVVsamQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJlRTFFUVROTmFrMTZUMVJCTlZkb1kwNU5hbEY0VFVSQk0wMXFUVEJQVkVFMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZrYjBWSU4waFBUWGRhZFRWTGJrZDFkMUJUZW5waFVqUTROVUZuVkVka01DdDFTRk1LWTBZMlZGVjZTRUUyU1V4RmJtcHhWbFo2T0ZWbldGcFNNR3dyU21wRVFsQldiRGxYTjNsNWJXMW9SMVYzV1VNNUx6WlBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZrV1RKQkNtUm5TMEZpVG0xRlMxbFpSRE5zTlU4clJsWlhXbUYzZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFdsaGFhR0pwTlc1aFYwcHpXbGhLUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHhDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJTUVWbGQwSTFRVWhqUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFV3cGhWbTVpTTBGQlFVSkJUVUZUUkVKSFFXbEZRVE15UVhGVVJVUnhja1p3YVhWamVWaGxiM05wV2k5cmNVVm9TbUo2TVVaWk1USlNjMkZJTTJZd0wwVkRDa2xSUkhobWJGVm5kVk5CWkRZek5HTjFOek13VEVseVpuSXJNMjQzTWs5eWQycENabEpRVWpKTlJXaHdTV3BCUzBKblozRm9hMnBQVUZGUlJFRjNUbkFLUVVSQ2JVRnFSVUV6Vmt4SWFYWmlhVEJyVHk4NGJGQndaVmRFZWxSc1dEY3hjMGRHTTI1Qk0xVkxUM1JhT1U5dWJqWlJjVTFpYWs1Mk5HMU9jVkpTZGdwS2RVMU1kbmR6VTBGcVJVRnBOV0ZoYldJMmVYQk1VMUJJTVRBNVRqZ3lWRzFvTUZsblN6Y3ZNWFY0UVRkWmVsa3pXamx2VjNaT1FVOUpRVTFOVVVOckNtWTNSWEZPUWtjMmQyWnNOUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1728344349,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 137854212,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n15951893\nTJb/BdvriKGJI7h3KXHwpg6OqbIZsXCbZh/DYTySq6c=\n\n— rekor.sigstore.dev wNI9ajBGAiEAm//5/PO5jL8fva0pZLcfwYRv4i8Fd1TZp0aMPdyTnAoCIQD3fUwsurvxVyejfw/DUuSO0FVPjta4sZXKNoYOCzhwOw==\n",
"hashes": [
"fad1b17d65bcbeda8d9ac2e1a15e27341cf37e9ffb2f9845624553ebef0296e0",
"101ebba9da561d5603e2843204f85fb3bfb89841b407bdd0b941eaa77901076c",
"aa357e0246f892abc12458f9aa3232789b16562c220221523415c463a22bfbc6",
"5a1a35255f3391473d3f8ab84fa461dce399244c1694942ed91ef952430c03e8",
"6a4d4799ec8d86e8ecbca83d41d87d6c78adc7847f730ac8f8e5fef8d5049f58",
"5d9d67a014528cee55a024f4a27f5fc3f920365fa94f03f791f5e2f243123eea",
"91e634a4a3ec2f1865c9e0ca9aeb9b84219202a7b0de40e0fdf5dd8529e7308f",
"623d98f5a852c704bc5be4468d9a90f0800ed351bb6f7506e40d12a1060b63ab",
"5cd95cedc90ad4ea6e89d175f71d81435eac9f0e72b59808a4a4a815da6f97d9",
"04a7deb33d1c97e0681be5a413eea0b57f4110059a48fb1cc87e6202c2ac8bd4",
"764bdb7f56990b5be27f43821d2a3d6d70db58e46f60708ac79db9f6a87888be",
"239bf304d793aaa17ac4462c3e27d70b88e0f1a6e5da99fb3c7c500e91e73ab4",
"9cec671be00a98f0b09ed604c579930eb6ca256a4121e457a98d940f6cd64d6a",
"99d4212943d1f761a4c587d4bdbff7cb02c3e7361d0a6adc0f1faba5a88e6f28",
"63398dd64ad2517b3fe6010b911a2cd2f13c01f8fda7da5c00b49ad2f3185d19",
"6ecec58a83858c60f54b66b64ec1bf7bcf9e937e77e3f72c5ba5f26512b10466",
"eba0392acb1391b45a3e13faab4ab0329ce08e8af4330cbfb365d367ae9c3297",
"572e2031e8a0af397687b135bf4fe131a3b315749d210374d64f6dc2d840b76e",
"50e20a44dacee1263cbd058f33d5eccd8077ed27ae3bc5b333c4ff2991be9f00",
"9bc8e601d7371c40caaafbc82a61a1aa88a502fa81c5986c92d5e65e1e7c5a20"
],
"logIndex": 15949950,
"rootHash": "4c96ff05dbeb88a18923b8772971f0a60e8ea9b219b1709b661fc3613c92aba7",
"treeSize": 15951893
},
"signedEntryTimestamp": "MEUCIGxnaTXvbDAFdbllDmdq5Sh8uWVKzURbx1zoXBLrIN5IAiEAn1147g992D4jxZ5MmNuTzhatFiQvJ24U/tDLw1I4CGE="
}
}
Loading