Skip to content

feat(melange/maven): enhance pombump pipeline with analyze mode and B…

8b8c1c3
Select commit
Loading
Failed to load commit list.
Draft

feat(melange/maven): enhance pombump pipeline with analyze mode and BOM detection #2156

feat(melange/maven): enhance pombump pipeline with analyze mode and B…
8b8c1c3
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Sep 10, 2025 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 50682531686433360210195360883553623776595252520 (0x8e0aeee34f9b1296a56959ee77d927ba1179528)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Sep 10 21:39:42 2025 UTC
            Not After : Sep 10 21:49:42 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    03:59:01:c8:b1:4c:81:dd:8d:d3:2a:ea:cc:91:a3:
                    99:92:f1:85:f6:09:41:b9:da:7c:eb:66:db:5e:1a:
                    a2:b7
                Y:
                    ed:e9:55:81:ad:df:68:50:81:78:8a:cf:ad:3f:30:
                    28:18:85:6d:18:8a:fb:02:5c:80:23:02:75:c5:69:
                    aa:e3
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                64:28:F5:E5:D8:CD:79:18:8C:34:28:AD:C9:89:20:A7:E2:E1:FE:12
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:kyle.steere@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmTWR9XQAAAQDAEYwRAIgYeQCGPKCp7EuUv1EZxa77jI3S81klbPlgyFzuDxCUZMCICsfkiJnQzjpeg4jJzVJi+vPX9u9Pd/CGSGY2Pc+nJ4F

    Signature Algorithm: ECDSA-SHA384
         30:66:02:31:00:a0:31:80:7b:a4:ba:c1:56:5b:d3:e1:88:b4:
         db:7b:b8:53:7d:9a:82:4d:aa:bc:79:3b:cd:cc:f6:b7:08:1e:
         72:d0:e1:93:dd:d1:e8:16:96:31:bf:75:10:d2:02:62:ed:02:
         31:00:d5:5c:c3:03:39:57:c4:12:af:77:1e:c0:7b:36:7d:c3:
         08:9f:97:6c:de:a0:b2:c9:83:6d:93:08:8c:4f:a7:7e:34:47:
         12:c7:81:16:fd:7a:a0:17:6d:ca:6b:14:f4:a0

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJjNDY4MGFlZDI3OWIyNmY4YjJkYmY2ZGNkM2Y2YTQ0Yzk4M2M2NWQ5YjA4ZDdkNDFiMDhmYjk1ZDI4OGRmNTU3In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUUM0TExSR0dOejFzMUpPZC9Fb3lCdkR6MUxDbDc0SDRIb2pVdWtwSHJoSmRBSWhBTVFyWGxadm9UNnlWTW9XWXlySk9SRFZ0V0NkMnlHUEh2OWZlWDJSK25TcyIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4cFowRjNTVUpCWjBsVlEwOURkVGRxVkRWelUyeHhWbkJYWlRVek1sTmxOa1ZZYkZObmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDlVUlhkTmFrVjZUMVJSZVZkb1kwNU5hbFYzVDFSRmQwMXFSVEJQVkZGNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZCTVd0Q2VVeEdUV2RrTWs0d2VYSnhla3BIYW0xYVRIaG9abGxLVVdKdVlXWlBkRzBLTWpFMFlXOXlablEyVmxkQ2NtUTViMVZKUmpScGN5dDBVSHBCYjBkSlZuUkhTWEkzUVd4NVFVbDNTakY0VjIxeE5EWlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZhUTJveENqVmthazVsVW1sTlRrTnBkSGxaYTJkd0sweG9MMmhKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFlUTnNjMXBUTlhwa1IxWnNZMjFXUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdncE9Xa2d4WkVGQlFVSkJUVUZTYWtKRlFXbENhRFZCU1ZrNGIwdHVjMU0xVXk5VlVtNUdjbloxVFdwa1RIcFhVMVp6SzFkRVNWaFBORkJGU2xKcmQwbG5Da3Q0SzFOSmJXUkVUMDlzTmtScFRXNU9WVzFNTmpnNVpqSTNNRGt6T0VsYVNWcHFXVGw2Tm1OdVoxVjNRMmRaU1V0dldrbDZhakJGUVhkTlJHRlJRWGNLV21kSmVFRkxRWGhuU0hWcmRYTkdWMWM1VUdocFRGUmlaVGRvVkdaYWNVTlVZWEU0WlZSMlRucFFZVE5EUWpWNU1FOUhWRE5rU0c5R2NGbDRkak5WVVFvd1owcHBOMUZKZUVGT1ZtTjNkMDAxVmpoUlUzSXpZMlYzU0hNeVptTk5TVzQxWkhNemNVTjVlVmxPZEd0M2FVMVVObVFyVGtWalUzZzBSVmN2V0hGbkNrWXlNMHRoZUZRd2IwRTlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
  "integratedTime": 1757540382,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 496625354,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n374721635\nX++Ih4hm2Pqb2b+VVazeW4yDyCC27JTxO/PglPoBc9A=\n\n— rekor.sigstore.dev wNI9ajBFAiBXYMfLeV7EBJpHxofetvHC74J6/1Yu7TdxWn/CjTVZLwIhAJd3Ukmh5eac1oeSyn927ooqWz6bZZoiQfJAy/BNi/F8\n",
      "hashes": [
        "458c686331c2a0e6bf70db78c306cc0ca0447a678320cc73d68dee0b22a5a07d",
        "68b5858aeac866dc5f9ad0a07f8ba15210390202aa754283e13207649a0f8ef7",
        "9d53b68596099020c8fbf37a593fbcb92fba99e6f3227e5c7aeddfb91bc063a2",
        "84d0d224f9f414f007b2682993cd94b909b1166877213d20fc1e23fa42194d6e",
        "84c15834b4d99e935bb2eeaeb09a41345970e5e27e93a06b4f79c8c5e6c8c819",
        "8f2a26e0462a4241eb308285f3de9b24f2fcffaec44b296ca26a659cc144c4a3",
        "afecd9708d8e22db1b94e1b26ae8f4ae2640449daf7d840c3beb0ade97778ad8",
        "4afc60b7b67526289e7ee9b2d4e1faaa30bc73b993650cada34516ab0f9d9b5a",
        "a459cbdd7af016cda7e3a64f97b9ff7778eaacd8f810b09c5871fbfee79c22b9",
        "610f71ffc18ff5d3c9cefdea2e53e968960db5d6b5058c08249a6d18aec32a76",
        "e881206f4b81d8f080a4f654dbfe158f19a4384dbb3f284ef067e85aa354c684",
        "e51d9fbe6274f99ecee38ad66ea316d1ae70ba40d97389a9a0686714d282c3d6",
        "378f5a8d13bfcee934e9a5a89fcc18b69b4523810be09627a8596936dc3a1b53",
        "38426c7f88d0cde04c561654795fd8403a57d16e4356a169b5796f187693404d",
        "625a15b37331aa3a76f3e3a1f3757143856b919a58e623184baf668a4766a48b",
        "0811250f2ab2747d07a8e00ab7d1b4eb9e783d321748bce676c7506e6360e16a",
        "6381f4419f5a9a49159368ec42ebf65cc55b076e0fd8179e1471aae2ae5861f3",
        "5ca3280ffa363fc72a9393b729228e2aba9f0230fff6e351d2bb81ff5f062268",
        "20e8becba23a4624ec2fedeeb0af7398b3bbe64f694876dec6555dbca3308d5d",
        "5b7222296ebc60e9cffb87d5366565340b1f230ee32b914fd870b21c07150fda",
        "bd2ecee28cc72106495818a8bfe9a4a48dbb184f3302654212445c3f7343c8d1"
      ],
      "logIndex": 374721092,
      "rootHash": "5fef88878866d8fa9bd9bf9555acde5b8c83c820b6ec94f13bf3e094fa0173d0",
      "treeSize": 374721635
    },
    "signedEntryTimestamp": "MEUCICzWVS9v+yFHUDWX12zn4x6gWdiOXHNojlSjpCzEsA/BAiEAvIsPFzCCD+9Rnb5FTGcFxHXOAv6n73BO2ahZN96ky6I="
  }
}