RFC: Source fetch from melange #2170
Open
Chainguard Enforce / Enforce - Commit Signing
succeeded
Oct 30, 2025 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 521109085905488881401248455206771760855798733462 (0x5b4756ee9c3426b5790dcd37ae212789ce475a96)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Oct 30 22:37:43 2025 UTC
Not After : Oct 30 22:47:43 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
05:c7:87:96:82:a2:80:24:cb:ea:f2:47:57:d8:3a:
bb:83:c4:27:c5:ea:14:62:9e:24:f4:b1:27:5b:24:
3b:4c
Y:
95:96:0d:ce:b9:9c:91:fa:dc:00:73:a8:4d:04:00:
fe:03:1c:c6:80:49:3a:96:e8:43:6b:5b:9b:ae:3b:
a9:45
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
97:DC:F3:46:F0:82:93:55:DF:E8:15:65:D2:57:C5:89:59:C2:E0:74
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:justin.vreeland@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmjdFC34AAAQDAEcwRQIgawKk+PWlHGEaM+PLpk658iv3my/l8f+IdSuiK+W6rAICIQDM8+zhZAQIwVVWhStcxHqGj8u+niiXUJfNDKNiPNEF4w==
Signature Algorithm: ECDSA-SHA384
30:65:02:30:41:7a:f5:e8:57:a7:11:b9:20:6b:1d:9a:c6:7e:
0b:91:ae:af:3d:6f:45:e1:8f:10:4b:d6:5b:fc:26:3c:54:9c:
c2:9d:46:6e:ea:40:14:85:03:29:b6:96:ed:f1:b5:8e:02:31:
00:f4:e9:55:82:25:40:2a:82:5a:35:52:ca:c4:15:08:75:06:
c8:ca:57:03:8b:2c:d4:e8:de:e8:9f:d0:62:7d:0e:0b:39:fe:
f1:8a:30:22:10:5e:5d:09:ad:38:16:51:e9
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJiNDM3ZDFkM2QxNTE4NjRlMWI2OTEwMTU3YmM5ZTE5ZmNiMjY0NDBmZmY3MTc1Y2M4ZDgyOWMzNjVkYWU0NDEzIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUUNzK2V5cmlsbW9FVko3Y0Q5ZmJhaHJROVZtN01RMlE2WllVb2gwVEFEWDlRSWhBTFRGK25VQ0U4UVp0aTlvVDVqU2wycnJXMXZjZWVlbTlTaU1zd3RON1NWcyIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhla05EUVd3eVowRjNTVUpCWjBsVlZ6QmtWemR3ZHpCS2NsWTFSR013TTNKcFJXNXBZelZJVjNCWmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFFVFhkTmFrbDZUbnBSZWxkb1kwNU5hbFY0VFVSTmQwMXFTVEJPZWxGNlYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZDWTJWSWJHOUxhV2REVkV3MmRrcElWamxuTm5VMFVFVktPRmh4UmtkTFpVcFFVM2dLU2pGemEwOHdlVlpzWnpOUGRWcDVVaXQwZDBGak5taE9Ra0ZFSzBGNGVrZG5SV3MyYkhWb1JHRXhkV0p5YW5Wd1VtRlBRMEZZZDNkblowWTBUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZzT1hwNkNsSjJRME5yTVZobU5rSldiREJzWmtacFZtNURORWhSZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB4QldVUldVakJTUVZGSUwwSkRTWGRKU1VWbFlXNVdlbVJIYkhWTWJscDVXbGRXYzFsWE5XdFJSMDV2V1Zkc2RWb3pWbWhqYlZGMVdrZFdNZ3BOUTJ0SFEybHpSMEZSVVVKbk56aDNRVkZGUlVjeWFEQmtTRUo2VDJrNGRsbFhUbXBpTTFaMVpFaE5kVm95T1haYU1uaHNURzFPZG1KVVFYSkNaMjl5Q2tKblJVVkJXVTh2VFVGRlNVSkNNRTFITW1nd1pFaENlazlwT0haWlYwNXFZak5XZFdSSVRYVmFNamwyV2pKNGJFeHRUblppVkVOQ2FXZFpTMHQzV1VJS1FrRklWMlZSU1VWQloxSTRRa2h2UVdWQlFqSkJUakE1VFVkeVIzaDRSWGxaZUd0bFNFcHNiazUzUzJsVGJEWTBNMnA1ZEM4MFpVdGpiMEYyUzJVMlR3cEJRVUZDYldwa1JrTXpORUZCUVZGRVFVVmpkMUpSU1dkaGQwdHJLMUJYYkVoSFJXRk5LMUJNY0dzMk5UaHBkak50ZVM5c09HWXJTV1JUZFdsTEsxYzJDbkpCU1VOSlVVUk5PQ3Q2YUZwQlVVbDNWbFpYYUZOMFkzaEljVWRxT0hVcmJtbHBXRlZLWms1RVMwNXBVRTVGUmpSNlFVdENaMmR4YUd0cVQxQlJVVVFLUVhkT2IwRkVRbXhCYWtKQ1pYWlliMVkyWTFKMVUwSnlTRnB5UjJabmRWSnljVGc1WWpCWWFHcDRRa3d4YkhZNFNtcDRWVzVOUzJSU2JUZHhVVUpUUmdwQmVXMHliSFV6ZUhSWk5FTk5VVVF3TmxaWFEwcFZRWEZuYkc4eFZYTnlSVVpSYURGQ2MycExWbmRQVEV4T1ZHOHpkV2xtTUVkS09VUm5jelV2ZGtkTENrMURTVkZZYkRCS2NsUm5WMVZsYXowS0xTMHRMUzFGVGtRZ1EwVlNWRWxHU1VOQlZFVXRMUzB0TFFvPSJ9fX19",
"integratedTime": 1761863863,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 657068696,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n535164821\niNEwtHYa7JbBRH4KpVTWNCpeVPO34VKhLU8Nqya2rDI=\n\n— rekor.sigstore.dev wNI9ajBEAiAWC8dG1wUKKdZ9UpTCKr4WDYBz+vAyxfPrCxjaxpinhQIgEM5l0Ee7AeuQan6nC79ZbyjDkITm5aDfC6/OS3y1/W0=\n",
"hashes": [
"902ec08876fe093cf9a49b8bec68f5f3d7259ae0dd8e885e21298248bc32738a",
"ceb086c19c8d0e08b44be02af59ec49bce9997a14e27d7372f5c2443dffc8d7a",
"36ff332ece2835dac9b25abb5eff6e31249b2c1a88b64d5c425801676a589e01",
"0ebb7300530df5376697ca17e2569795d4f6cdcae7df738fed560a8e3944d014",
"ad3b962bc1fd4ecd6a779790b3102eb3f37228ef4488df8a072368845e677cd7",
"846a40a4354130a6b64c8c191e5872dbeaecce4d5dd049bccf4c27457116384f",
"4630a87cbbaa8f5eb0ab55ccdc4cb0959907e95fff879ac56cfa014cc0d2ab23",
"e1a781e0bdaa9ab104adac2ab03eb7af419568ad18dd39b11ca559c66bf83c15",
"aec87a64eb490d7db6d8c3f621a00c3310521736680d2f9f5e07628a713d5a87",
"94dad9393354f114a0f4bc007e2dcf0db625a91010d53085378a95ef7ff8649c",
"abc43efbe1d0497b1cd650648fcced536782b73f38f2f27a30e50514dadc918e",
"cb8c7eb5ac3e2cfb0eba15e17ae689e4e83169340afe2dfbff5307be1892843e",
"b22ac55e4cfc4afd4484ccb7def8ec70d7968d1bb520c1c6743bd7b2d7f67d2e",
"7a8f37c9f427b6c24e600ba9a4ae4706934c7eb9c0c91beb0077af2b84fce45c",
"09e781f03a1da2df9db5e451b4e881e2e676b892be54f1f4cbbcf8999a56ac5b",
"a711a87dfb4999d2d354bff6d35713d8993de731ecfb06ce284f6323978547fb",
"932e5a3e2d855b575f15ba59418984e5cfaff71cc0e793048690c4a116368d0c",
"303c2887e8392e906d4a34efa05f9b6ce1c9af3892aef83ecbe33dfeed38bdc3",
"ac89a348027a770c3bab1ab505c250df2b5503e1f4a6d5c1f9441b225a23357a",
"fd9973ac63d2d1eab6ae382d7a031b081051a10f4f231556131f99ca6383cb2c",
"a14a503ca8f09c6de3850b600c62edca3c93266aeaa0435af02ea0c7ea96225b",
"1c039383e160dc7d448f6e26c3e3fd9577e2fb898f2f910ac0077868d40e57a3",
"d96bf81a28ad87036e911295d3a7257af9d04180b35e6492ffefce26d5e0b174",
"d667f2f782a9708b6ab211fdfa0c2a57a8dc72ea5c68ca55b05dbc35ec3ccc36",
"bd2ecee28cc72106495818a8bfe9a4a48dbb184f3302654212445c3f7343c8d1"
],
"logIndex": 535164434,
"rootHash": "88d130b4761aec96c1447e0aa554d6342a5e54f3b7e152a12d4f0dab26b6ac32",
"treeSize": 535164821
},
"signedEntryTimestamp": "MEYCIQDFQFHpJf+3hgU7dwxVlxztXCy0Wb1Sdl4701l9SbddPwIhAMBzPyfAJeX+Ruo7/7yT8udRqHnTEhSJNy/N5hVxly9d"
}
}
Loading