feat: Pass libraries token to build environment #1896
Draft
Chainguard Enforce / Enforce - Commit Signing
succeeded
Apr 7, 2025 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 372963239003625945695269599032579150140637479050 (0x415440034869aac9b6789d731084c5491e30808a)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Apr 7 16:39:07 2025 UTC
Not After : Apr 7 16:49:07 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
2a:8f:f8:98:14:8e:1b:c2:de:cf:e1:26:71:00:1d:
fb:6b:25:88:c1:57:ad:e6:f0:29:88:a5:c8:42:37:
c1:0e
Y:
ac:14:90:52:18:d1:dc:58:b2:94:d7:6e:97:bd:d8:
af:62:b2:7a:87:de:d8:de:47:59:70:16:30:aa:6f:
b9:29
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
12:B5:35:79:D6:F5:10:29:F2:74:FE:C6:46:36:F3:D6:04:A4:F4:0A
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:rj.sampson@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlhEetcsAAAQDAEcwRQIhALDxtIFUUFYXb7KRBMDckOztXP2985B7TFkb9RggH08AAiAEQb1D0MSy/6TmBks0+qK2aAdmB/rxKelmSYAV7IfMqA==
Signature Algorithm: ECDSA-SHA384
30:65:02:31:00:ce:4a:17:8e:e8:1c:f8:86:95:1a:2a:fd:8e:
d9:e7:01:80:bb:d9:c4:81:cf:cd:55:16:46:20:2c:2e:b3:96:
d0:4a:7d:c5:84:85:51:9e:77:17:e6:bc:5a:9b:ba:0e:f4:02:
30:1c:37:24:6e:d1:71:7a:f7:7c:c0:7a:49:6a:6d:42:bc:10:
77:06:ee:f6:10:04:0f:56:84:24:f7:41:0a:fe:e1:fc:a4:6e:
75:6c:2e:64:db:0e:6c:e0:e1:b9:4c:b8:28
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI0ZmE2ZmVlMTdlY2RjMzIxZWFlM2E1MWE4ZDkyZmRmYmU0YTc2NjRlODNmZGY1MDA0OTRlNWRjNTA1ZjY3NmYyIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRHkzQUt5b1JNVE9VY0xQUVR3aTloRVJsR1ZXSHA2bjRKVjdJRzhhaXdqRUFpRUFvc0JNaFA3alFubWJhVGVwY2pjSUNHc1JFcStJZzJQLzUrMXVpNEZ3TTB3PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdha05EUVd4cFowRjNTVUpCWjBsVlVWWlNRVUV3YUhCeGMyMHlaVW94ZWtWSlZFWlRValIzWjBsdmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVFUVROTlZGbDZUMVJCTTFkb1kwNU5hbFYzVGtSQk0wMVVXVEJQVkVFelYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZMYnk4MGJVSlRUMGM0VEdWNkswVnRZMUZCWkNzeWMyeHBUVVpZY21WaWQwdFphV3dLZVVWSk0zZFJObk5HU2tKVFIwNUlZMWRNUzFVeE1qWllkbVJwZGxseVNqWm9PVGRaTTJ0a1dtTkNXWGR4YlNzMVMyRlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZGY2xVeENtVmtZakZGUTI1NVpGQTNSMUpxWW5veFoxTnJPVUZ2ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwM1dVUldVakJTUVZGSUwwSkNNSGRITkVWYVkyMXZkV015Um5SalNFNTJZbXRDYW1GSFJuQmliV1F4V1ZoS2EweHRVbXhrYWtGd1FtZHZjZ3BDWjBWRlFWbFBMMDFCUlVKQ1FuUnZaRWhTZDJONmIzWk1Na1pxV1RJNU1XSnVVbnBNYldSMllqSmtjMXBUTldwaU1qQjNTM2RaUzB0M1dVSkNRVWRFQ25aNlFVSkRRVkZrUkVKMGIyUklVbmRqZW05MlRESkdhbGt5T1RGaWJsSjZURzFrZG1JeVpITmFVelZxWWpJd2QyZFpiMGREYVhOSFFWRlJRakZ1YTBNS1FrRkpSV1pCVWpaQlNHZEJaR2RFWkZCVVFuRjRjMk5TVFcxTldraG9lVnBhZW1ORGIydHdaWFZPTkRoeVppdElhVzVMUVV4NWJuVnFaMEZCUVZwWlVncEljbGhNUVVGQlJVRjNRa2hOUlZWRFNWRkRkemhpVTBKV1JrSlhSaklyZVd0UlZFRXpTa1J6TjFaNk9YWm1UMUZsTUhoYVJ5OVZXVWxDT1ZCQlFVbG5Da0pGUnpsUk9VUkZjM1lyYXpWbldreE9VSEZwZEcxblNGcG5aalk0VTI1d1dtdHRRVVpsZVVoNlMyZDNRMmRaU1V0dldrbDZhakJGUVhkTlJHRkJRWGNLV2xGSmVFRk5OVXRHTkRkdlNGQnBSMnhTYjNFdldUZGFOWGRIUVhVNWJrVm5ZeTlPVmxKYVIwbERkM1Z6TldKUlUyNHpSbWhKVmxKdWJtTllOWEo0WVFwdE4yOVBPVUZKZDBoRVkydGlkRVo0Wlhaa09IZEljRXBoYlRGRGRrSkNNMEoxTnpKRlFWRlFWbTlSYXprd1JVc3ZkVWc0Y0VjMU1XSkROV3N5ZHpWekNqUlBSelZVVEdkdkNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1744043947,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 193371148,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n71467306\nbuEtx5YXz9ryqB7D6nNx1CHDVDAjiG6S24+uk7VP9k4=\n\n— rekor.sigstore.dev wNI9ajBFAiEAtLzIrjturwGP6JfrB0mf1Mq5Vi8yvwqh10zchPZ4cK0CIDoEXXjVEyavy1b8rOB9K/1wHTw2IbYOht17y6XPYHWJ\n",
"hashes": [
"404cd292633e2f5f895068ef0b9cdb1c186d94628ec8afb29d193955726734bd",
"bf7774b35fdcd36943497894dc9eabffe82025afd82a5203591217f6feea6af9",
"d1650bf25fea2d4819ad1287ac2f5dbfabbecdc9a1ec304b9e174f8fe0d727b8",
"2b1a3362a0e99410a90894efe1545122ddf3453af04d436b2182d930945f18a3",
"0e34ae01eb7a93fef5853f269fb090432b1686637e2d23ce62d79f4874324d49",
"cdab4b22ba21c376be91371300c28bc10e146c7e2bf92c277829976d3ef1070c",
"06440a5ae936ff38cf2c0d95b0c7c6bef2ef3ab532d40c9fab4e8239cb0ba242",
"9972881071c822072f86d59e62dd993f06f3df2688ceec63813255ba0277427b",
"25c5753a71b25afe2e735b89eb67c20989175bda3172e26dcc609abb87b2938a",
"7e5ab4d49d2b08da9cc35e37a80fbe1ff2f82c04701d28d00b118d6d09030896",
"f2e8f4d84b0879c6a280afa695e11d7bcf93d3f92a834eeabbfb8e1bb0555750",
"9414b042a351cce040d50005425e438c96465a1e2c3e7607756e006e4260fc94",
"02001561ccd95023f324b9a5df845d7975ed1496427ab240a2510acc9aa7beab",
"eb56f46148dc34c090bc1bd0c53e829c3f2ec2d25c0b45538d52030e6a904999",
"a5b460a781b76c70566e77a873f5971f4deaa79a3640745a405e2833a94f13d8",
"eb142c8395603ab021f3260a728dec898561cfce66ef6d62b843315252ca6aa8",
"db01efbb544cc2adc9f78874a1a5dc79e40ff498026bf2ae98198779f066b6b7",
"5849b93a03f32696113affb809cae279ec4263240aacb507de16f199c410f833",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 71466886,
"rootHash": "6ee12dc79617cfdaf2a81ec3ea7371d421c3543023886e92db8fae93b54ff64e",
"treeSize": 71467306
},
"signedEntryTimestamp": "MEYCIQDe9JDrLhD+tJIL6xz/Ir8TlCOS1yWMUdvf6H677XWOUAIhAP2TuiSr+QUOFzcKxHifdX9usM6ILpDuvWCOVJbf731p"
}
}
Loading