add npm to npm/install pipeline #1527
Open
Chainguard Enforce / Enforce - Commit Signing
succeeded
Dec 13, 2024 in 1s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 97833458676845850214921293416462550423996108326 (0x11230106fd76ddd47233080f8c444b6d699e8e26)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Oct 6 08:44:16 2024 UTC
Not After : Oct 6 08:54:16 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
de:fc:27:ac:93:14:05:54:54:b7:1e:a9:73:d7:50:
e9:67:e7:71:13:43:92:82:84:1c:5b:d2:62:74:23:
8f:9e
Y:
7d:36:bc:fd:8f:b6:3f:09:4b:13:16:c6:26:f5:a8:
7b:37:a4:b3:4d:0b:45:69:8c:86:79:e2:89:01:b7:
2a:04
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
E6:E2:30:72:9A:CE:95:D2:48:A6:CF:1D:42:32:A1:BB:A7:91:FD:73
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://github.com/login/oauth
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkmEANr0AAAQDAEcwRQIgZFadLVS6mFHqqo6uJcXS+2YvLQNwtbY8hNfM47dcQDsCIQC3n/BMik+si5lXBEipp3vBLgwc9QAJRaTeYa/2Qa7Pxg==
Signature Algorithm: ECDSA-SHA384
30:64:02:30:6e:19:6a:88:a7:ec:b7:c0:c3:5d:44:93:f0:c3:
e5:25:c0:ca:6c:97:f1:53:a7:65:4c:5f:38:bc:26:19:02:8e:
a5:ec:72:43:8c:95:ec:69:8e:42:8c:d5:5c:4c:dd:ab:02:30:
51:35:f8:13:a5:d3:2b:fc:26:d6:32:0f:df:8d:ce:51:b0:22:
05:89:7b:47:f0:42:71:4f:a6:56:79:f4:7a:a8:1e:e0:b3:7b:
c5:42:d0:ed:9d:5e:19:a4:09:cc:e4:36
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJjOGFhZWM0ZGIxMThmMDYyOGRjOThlMGQ2ZGYzNDA3Yzc1NjE0N2ExNTYwMjJiYTIxMmU0OGUwZjAxN2U1YmFmIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRythcGVBelk2KzZxQkx3L1ZDVkRaV2pIRXVEa3BjckhyQnh3ZVBaeHZzTUFpRUF2d3QybHpTQnRLaklmSUhZbE9hcGZtUi9yak1ISHI5U05ZTXNBSk5oZDJRPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXlWRU5EUVcxRFowRjNTVUpCWjBsVlJWTk5Ra0oyTVRJelpGSjVUWGRuVUdwRlVreGlWMjFsYW1sWmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJlRTFFUVRKTlJHY3dUa1JGTWxkb1kwNU5hbEY0VFVSQk1rMUVaekZPUkVVeVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVV6ZG5kdWNrcE5WVUpXVWxWMGVEWndZemxrVVRaWFptNWpVazVFYTI5TFJVaEdkbE1LV1c1UmFtbzFOVGxPY25vNWFqZFpMME5WYzFSR2MxbHRPV0ZvTjA0MlUzcFVVWFJHWVZsNVIyVmxTMHBCWW1OeFFrdFBRMEZZT0hkblowWTNUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlUxZFVsM0NtTndjazlzWkVwSmNITTRaRkZxUzJoMU5tVlNMMWhOZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0UldVUldVakJTUVZGSUwwSkNPSGRJV1VWaVdWYzFNV050Um01TWJYUXhZbGRHZVZGSFRtOVpWMngxV2pOV2FHTnRVWFZhUjFZeVRVTjNSd3BEYVhOSFFWRlJRbWMzT0hkQlVVVkZTRzFvTUdSSVFucFBhVGgyV2pKc01HRklWbWxNYlU1MllsTTVjMkl5WkhCaWFUbDJXVmhXTUdGRVFYVkNaMjl5Q2tKblJVVkJXVTh2VFVGRlNVSkRRVTFJYldnd1pFaENlazlwT0haYU1td3dZVWhXYVV4dFRuWmlVemx6WWpKa2NHSnBPWFpaV0ZZd1lVUkRRbWxuV1VzS1MzZFpRa0pCU0ZkbFVVbEZRV2RTT0VKSWIwRmxRVUl5UVU0d09VMUhja2Q0ZUVWNVdYaHJaVWhLYkc1T2QwdHBVMncyTkROcWVYUXZOR1ZMWTI5QmRncExaVFpQUVVGQlFtdHRSVUZPY2pCQlFVRlJSRUZGWTNkU1VVbG5Xa1poWkV4V1V6WnRSa2h4Y1c4MmRVcGpXRk1yTWxsMlRGRk9kM1JpV1Rob1RtWk5DalEzWkdOUlJITkRTVkZETTI0dlFrMXBheXR6YVRWc1dFSkZhWEJ3TTNaQ1RHZDNZemxSUVVwU1lWUmxXV0V2TWxGaE4xQjRha0ZMUW1kbmNXaHJhazhLVUZGUlJFRjNUbTVCUkVKclFXcENkVWRYY1Vsd0sza3pkMDFPWkZKS1VIZDNLMVZzZDAxd2Myd3ZSbFJ3TWxaTldIcHBPRXBvYTBOcWNWaHpZMnRQVFFwc1pYaHdhbXRMVFRGV2VFMHpZWE5EVFVaRk1TdENUMnd3ZVhZNFNuUlplVVE1SzA1NmJFZDNTV2RYU21Vd1puZFJia1pRY0d4YU5UbEljVzlJZFVONkNtVTRWa013VHpKa1dHaHRhME5qZW10T1p6MDlDaTB0TFMwdFJVNUVJRU5GVWxSSlJrbERRVlJGTFMwdExTMEsifX19fQ==",
"integratedTime": 1728204259,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 137372288,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n33307228\nElVcKCc4oKB5vqx2yLgmfKu+oTXJ2cxM6wLtwYgKwKU=\n\n— rekor.sigstore.dev wNI9ajBGAiEAkOuuinfhs5zxb7tF13+ZV5PQo3wh3tKr+2RGrnHMb7UCIQClcKsLzKPcwSnGEy+PY6sIGyTUr51c1Vkry5iYkaHv7A==\n",
"hashes": [
"072db1a6080f427dc4494a81772cc66022e9bb8ab3760298a10b00061c863089",
"8ac804b78e7a4058191a14e6ff82dcb449198360fc642abbfcc242f121a212b1",
"79c92c94e6b9a587fa7d1ae1b04e58c677663fd941892dab4c936e45fb10b727",
"1ef903ad980d9623c0fcd502437a9cb10313b9df63c34681143610066e8c9dfa",
"3655196e9f57b6620e372b3db17aaa2d63fdd64705a0d794d67d2ed3b3e74b56",
"c5c5ac0b5de798a8e5912db74768fd05937ddcd54087fefa05274ecd031c5fbc",
"442104daefb6ebaf3bd8e2ad1c9d96543faab5ccdec401624602a7bae0d20d50",
"4111991006fcc219c4152a44ccfe14d313738dabd39a2241f1a9da40360719fc",
"a3e52a22b158a0ce5533fa890916772ebf09f6321d77bdaed2e4b591935e6752",
"139c1e6a45912566e241f793d8e4732338ee75a86f878bed22548f59cb431099",
"23deb2bbc64a88bae16a78e551e5a8d8c94244b0310bdf38bb7243adf08c497e",
"3e70667f1c5f2a0fdafd3d5f07e617c17e099ffc291215b0adf6d33c62ddb91c",
"69449c7c60c84815a3590a48d74c8600939a1aa7679c488321a98fface6ff377",
"34974fa695e3454d0eb5e4e4f33879a2f256ee79002b258671bc2055072ec23a",
"0a5d822ec04ac72c4bca78f88d69dd4e5677edef93393fc8ecfd83bce5c7b646",
"598c8b51acfd16b3887e7ef8d266b92224e3bf49d179b571855c04f268cd52d9",
"76014ff9b75b30aa590b089cc424b425f6f065e4f9ab212cb45a5011dcce942b",
"64d7e2d32dbea550e8b96c6b797ade645303098ff6c8a4e36010903471be7a70",
"e9a935943c64e990553f13025828bbfa722a14a995f8f74b41d028378f3d3b47",
"63d6c8b0bb3f65258b3a6f3c75de2c85296869b2d0f9a0154961bea8b9e87cc7",
"801014a19a9861722c51299c3090d1abd0510d04e1ff494e51c6cc3b40f3e11e",
"572e2031e8a0af397687b135bf4fe131a3b315749d210374d64f6dc2d840b76e",
"50e20a44dacee1263cbd058f33d5eccd8077ed27ae3bc5b333c4ff2991be9f00",
"9bc8e601d7371c40caaafbc82a61a1aa88a502fa81c5986c92d5e65e1e7c5a20",
"242852c552066127d34ca0763d549693d820085323b860581bd01d9425f17f9e"
],
"logIndex": 15468026,
"rootHash": "12555c282738a0a079beac76c8b8267cabbea135c9d9cc4ceb02edc1880ac0a5",
"treeSize": 33307228
},
"signedEntryTimestamp": "MEQCIF7I3iE9gotWSCHvqiLLoVw0ODMNCT12wGdK5osSanqaAiAxultSGo33f0H9Tpa3xYWtRhb3sKHlSaBO5M7sWTbK2Q=="
}
}
Loading