feat(melange/maven): enhance pombump pipeline with analyze mode and BOM detection #2156
Chainguard Enforce / Enforce - Commit Signing
succeeded
Sep 10, 2025 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 50682531686433360210195360883553623776595252520 (0x8e0aeee34f9b1296a56959ee77d927ba1179528)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Sep 10 21:39:42 2025 UTC
Not After : Sep 10 21:49:42 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
03:59:01:c8:b1:4c:81:dd:8d:d3:2a:ea:cc:91:a3:
99:92:f1:85:f6:09:41:b9:da:7c:eb:66:db:5e:1a:
a2:b7
Y:
ed:e9:55:81:ad:df:68:50:81:78:8a:cf:ad:3f:30:
28:18:85:6d:18:8a:fb:02:5c:80:23:02:75:c5:69:
aa:e3
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
64:28:F5:E5:D8:CD:79:18:8C:34:28:AD:C9:89:20:A7:E2:E1:FE:12
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:kyle.steere@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmTWR9XQAAAQDAEYwRAIgYeQCGPKCp7EuUv1EZxa77jI3S81klbPlgyFzuDxCUZMCICsfkiJnQzjpeg4jJzVJi+vPX9u9Pd/CGSGY2Pc+nJ4F
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:a0:31:80:7b:a4:ba:c1:56:5b:d3:e1:88:b4:
db:7b:b8:53:7d:9a:82:4d:aa:bc:79:3b:cd:cc:f6:b7:08:1e:
72:d0:e1:93:dd:d1:e8:16:96:31:bf:75:10:d2:02:62:ed:02:
31:00:d5:5c:c3:03:39:57:c4:12:af:77:1e:c0:7b:36:7d:c3:
08:9f:97:6c:de:a0:b2:c9:83:6d:93:08:8c:4f:a7:7e:34:47:
12:c7:81:16:fd:7a:a0:17:6d:ca:6b:14:f4:a0
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJjNDY4MGFlZDI3OWIyNmY4YjJkYmY2ZGNkM2Y2YTQ0Yzk4M2M2NWQ5YjA4ZDdkNDFiMDhmYjk1ZDI4OGRmNTU3In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUUM0TExSR0dOejFzMUpPZC9Fb3lCdkR6MUxDbDc0SDRIb2pVdWtwSHJoSmRBSWhBTVFyWGxadm9UNnlWTW9XWXlySk9SRFZ0V0NkMnlHUEh2OWZlWDJSK25TcyIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4cFowRjNTVUpCWjBsVlEwOURkVGRxVkRWelUyeHhWbkJYWlRVek1sTmxOa1ZZYkZObmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDlVUlhkTmFrVjZUMVJSZVZkb1kwNU5hbFYzVDFSRmQwMXFSVEJQVkZGNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZCTVd0Q2VVeEdUV2RrTWs0d2VYSnhla3BIYW0xYVRIaG9abGxLVVdKdVlXWlBkRzBLTWpFMFlXOXlablEyVmxkQ2NtUTViMVZKUmpScGN5dDBVSHBCYjBkSlZuUkhTWEkzUVd4NVFVbDNTakY0VjIxeE5EWlBRMEZZWTNkblowWjZUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZhUTJveENqVmthazVsVW1sTlRrTnBkSGxaYTJkd0sweG9MMmhKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFlUTnNjMXBUTlhwa1IxWnNZMjFXUVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHBDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJYzBWbFVVSXpRVWhWUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdncE9Xa2d4WkVGQlFVSkJUVUZTYWtKRlFXbENhRFZCU1ZrNGIwdHVjMU0xVXk5VlVtNUdjbloxVFdwa1RIcFhVMVp6SzFkRVNWaFBORkJGU2xKcmQwbG5Da3Q0SzFOSmJXUkVUMDlzTmtScFRXNU9WVzFNTmpnNVpqSTNNRGt6T0VsYVNWcHFXVGw2Tm1OdVoxVjNRMmRaU1V0dldrbDZhakJGUVhkTlJHRlJRWGNLV21kSmVFRkxRWGhuU0hWcmRYTkdWMWM1VUdocFRGUmlaVGRvVkdaYWNVTlVZWEU0WlZSMlRucFFZVE5EUWpWNU1FOUhWRE5rU0c5R2NGbDRkak5WVVFvd1owcHBOMUZKZUVGT1ZtTjNkMDAxVmpoUlUzSXpZMlYzU0hNeVptTk5TVzQxWkhNemNVTjVlVmxPZEd0M2FVMVVObVFyVGtWalUzZzBSVmN2V0hGbkNrWXlNMHRoZUZRd2IwRTlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1757540382,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 496625354,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n374721635\nX++Ih4hm2Pqb2b+VVazeW4yDyCC27JTxO/PglPoBc9A=\n\n— rekor.sigstore.dev wNI9ajBFAiBXYMfLeV7EBJpHxofetvHC74J6/1Yu7TdxWn/CjTVZLwIhAJd3Ukmh5eac1oeSyn927ooqWz6bZZoiQfJAy/BNi/F8\n",
"hashes": [
"458c686331c2a0e6bf70db78c306cc0ca0447a678320cc73d68dee0b22a5a07d",
"68b5858aeac866dc5f9ad0a07f8ba15210390202aa754283e13207649a0f8ef7",
"9d53b68596099020c8fbf37a593fbcb92fba99e6f3227e5c7aeddfb91bc063a2",
"84d0d224f9f414f007b2682993cd94b909b1166877213d20fc1e23fa42194d6e",
"84c15834b4d99e935bb2eeaeb09a41345970e5e27e93a06b4f79c8c5e6c8c819",
"8f2a26e0462a4241eb308285f3de9b24f2fcffaec44b296ca26a659cc144c4a3",
"afecd9708d8e22db1b94e1b26ae8f4ae2640449daf7d840c3beb0ade97778ad8",
"4afc60b7b67526289e7ee9b2d4e1faaa30bc73b993650cada34516ab0f9d9b5a",
"a459cbdd7af016cda7e3a64f97b9ff7778eaacd8f810b09c5871fbfee79c22b9",
"610f71ffc18ff5d3c9cefdea2e53e968960db5d6b5058c08249a6d18aec32a76",
"e881206f4b81d8f080a4f654dbfe158f19a4384dbb3f284ef067e85aa354c684",
"e51d9fbe6274f99ecee38ad66ea316d1ae70ba40d97389a9a0686714d282c3d6",
"378f5a8d13bfcee934e9a5a89fcc18b69b4523810be09627a8596936dc3a1b53",
"38426c7f88d0cde04c561654795fd8403a57d16e4356a169b5796f187693404d",
"625a15b37331aa3a76f3e3a1f3757143856b919a58e623184baf668a4766a48b",
"0811250f2ab2747d07a8e00ab7d1b4eb9e783d321748bce676c7506e6360e16a",
"6381f4419f5a9a49159368ec42ebf65cc55b076e0fd8179e1471aae2ae5861f3",
"5ca3280ffa363fc72a9393b729228e2aba9f0230fff6e351d2bb81ff5f062268",
"20e8becba23a4624ec2fedeeb0af7398b3bbe64f694876dec6555dbca3308d5d",
"5b7222296ebc60e9cffb87d5366565340b1f230ee32b914fd870b21c07150fda",
"bd2ecee28cc72106495818a8bfe9a4a48dbb184f3302654212445c3f7343c8d1"
],
"logIndex": 374721092,
"rootHash": "5fef88878866d8fa9bd9bf9555acde5b8c83c820b6ec94f13bf3e094fa0173d0",
"treeSize": 374721635
},
"signedEntryTimestamp": "MEUCICzWVS9v+yFHUDWX12zn4x6gWdiOXHNojlSjpCzEsA/BAiEAvIsPFzCCD+9Rnb5FTGcFxHXOAv6n73BO2ahZN96ky6I="
}
}
Loading