fix: respect go get order #30
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Mar 5, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 339296392754617762214022943748194203319343940759 (0x3b6e939257f5127295f883628a00ba8245428497)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Mar 5 22:47:52 2024 UTC
Not After : Mar 5 22:57:52 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
f4:0d:93:85:63:bb:9e:a9:53:f7:e2:dd:9a:a1:1f:
19:53:de:c0:ce:0b:4c:5c:54:62:ba:3f:c6:19:47:
6d:31
Y:
3f:5f:47:08:db:0e:e9:17:27:d8:44:00:f0:49:8e:
a4:11:42:7b:eb:26:53:90:22:8d:f5:00:9c:55:e3:
b0:48
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
98:C2:4A:F5:E6:D5:72:9F:79:B3:33:85:C0:2D:E1:DA:8E:56:AA:4F
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABjhDNRs0AAAQDAEgwRgIhAPSg0dh5c3BrINNIE35Y0j74UNt4rYup/MV367sTKVlaAiEA2vtGZ39O4NkcK2nA/4Rv0G4zZZQBn00Ptaz/EX9OHVw=
Signature Algorithm: ECDSA-SHA384
30:66:02:31:00:a0:f1:7f:2c:e7:7c:3a:50:49:eb:6e:cc:7b:
ef:32:a2:e3:39:fe:c5:8e:e5:c9:c7:87:c6:6d:86:e8:dd:06:
c6:91:e6:aa:5b:14:40:35:c8:82:98:6f:7f:83:1f:ee:ea:02:
31:00:80:8d:d4:2b:c4:ff:93:11:fb:88:0e:50:4f:73:b5:f8:
c1:34:08:12:dc:26:69:b8:58:3c:37:81:50:ad:a7:28:e2:bf:
b6:86:bf:fc:29:ce:e3:21:94:5f:79:c5:00:9e
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJiYTU2NWY3OTQzYjFhMTVhYzc3OTg1NTk4MDk5MjZiZjJkYmUxYmM2M2E3ZTRjZWY0ZDEzMTIwZmY4OTZiYzYxIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUUNuY3VLbWM4bEordU1jQkRVbjVZVmE5U3MyK2tDRHJTYmZaQUY1azR2YnBnSWhBSWdGOUs2SlVzR0Y5ZDRNd3FGMTgwbFl1bjBxL24yQlB0VXo1N2tSNjhreiIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdSRU5EUVd4WFowRjNTVUpCWjBsVlR6STJWR3RzWmpGRmJrdFdLMGxPYVdsblF6Wm5hMVpEYUVwamQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDE2UVRGTmFra3dUbnBWZVZkb1kwNU5hbEYzVFhwQk1VMXFTVEZPZWxWNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVU1UVRKVWFGZFBOMjV4YkZRNUsweGtiWEZGWmtkV1VHVjNUVFJNVkVaNFZWbHlieThLZUdoc1NHSlVSUzlZTUdOSk1uYzNjRVo1WmxsU1FVUjNVMWsyYTBWVlNqYzJlVnBVYTBOTFRqbFJRMk5XWlU5M1UwdFBRMEZZVVhkblowWjNUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZ0VFVwTENqbGxZbFpqY0RrMWMzcFBSbmRETTJneWJ6VlhjV3M0ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBsM1dVUldVakJTUVZGSUwwSkNhM2RHTkVWV1lVZFdhbVJIT1hsUlIwNXZXVmRzZFZvelZtaGpiVkYxV2tkV01rMURhMGREYVhOSFFWRlJRZ3BuTnpoM1FWRkZSVWN5YURCa1NFSjZUMms0ZGxsWFRtcGlNMVoxWkVoTmRWb3lPWFphTW5oc1RHMU9kbUpVUVhKQ1oyOXlRbWRGUlVGWlR5OU5RVVZKQ2tKQ01FMUhNbWd3WkVoQ2VrOXBPSFpaVjA1cVlqTldkV1JJVFhWYU1qbDJXako0YkV4dFRuWmlWRU5DYVhkWlMwdDNXVUpDUVVoWFpWRkpSVUZuVWprS1FraHpRV1ZSUWpOQlRqQTVUVWR5UjNoNFJYbFplR3RsU0Vwc2JrNTNTMmxUYkRZME0ycDVkQzgwWlV0amIwRjJTMlUyVDBGQlFVSnFhRVJPVW5Nd1FRcEJRVkZFUVVWbmQxSm5TV2hCVUZObk1HUm9OV016UW5KSlRrNUpSVE0xV1RCcU56UlZUblEwY2xsMWNDOU5Wak0yTjNOVVMxWnNZVUZwUlVFeWRuUkhDbG96T1U4MFRtdGpTekp1UVM4MFVuWXdSelI2V2xwUlFtNHdNRkIwWVhvdlJWZzVUMGhXZDNkRFoxbEpTMjlhU1hwcU1FVkJkMDFFWVZGQmQxcG5TWGdLUVV0RWVHWjVlbTVtUkhCUlUyVjBkWHBJZG5aTmNVeHFUMlkzUm1wMVdFcDROR1pIWWxsaWJ6TlJZa2RyWldGeFYzaFNRVTVqYVVOdFJ6a3ZaM2d2ZFFvMlowbDRRVWxEVGpGRGRrVXZOVTFTS3pSblQxVkZPWHAwWm1wQ1RrRm5Vek5EV25CMVJtYzRUalJHVVhKaFkyODBjaXN5YUhJdk9FdGpOMnBKV2xKbUNtVmpWVUZ1WnowOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1709678872,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 75930380,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n71769601\nzoNFYog06M3uVOIp+2EwsfxozF6DBjY3a5uJgrlUosg=\n\n— rekor.sigstore.dev wNI9ajBFAiBd+nLDUy49y/BybKkmZPsZaT4rPcP56Qp43c4+nQIjhgIhAK96v3+z+Po6DiyQwPOqw5dUAP7VZaD7beHyAtmsSCkk\n",
"hashes": [
"0602950203fec45d754629e5a06ff2376e6169970c0204a0b7c30294ff2071b4",
"5ad387d5382b2e3eccd6b8ec2b45707693b07d90539fd72430e0d08a0673a076",
"b289bf02e83315dddf63e74500c0e02bfd055b272dd505b6e39da1cbc6247ba1",
"0c73b9c47bd1b36105d4b6372d51ec00b7e433af067f343adabf4b41df576c7e",
"dcff42aad10c39551dc065f68747a721f44ab586e4297ad6f22903ef27f69cb6",
"b9bb7d7fd1ab07519291c4e06f305644dc0bf2cdc5f03a214f503af2bb483eed",
"7eddfb2ee52d4ba4d9ed8f07c1acaf6b4adae995e4c6b379a773a65507213921",
"f746b9f5d1fb8122d75740eac9168b50028964318b45b82a6360e0cba90d2bf3",
"2f02e7ee1cdacd03ca8c8003150192c654eff560a80d6177746a9e0c72698917",
"c34c6dacc24329d57b8ab4dfccfd6ab6dbaec8beca51edbb2c9b2c50e5a4425f",
"74184ed9c1c122e67da554ebb89cc35503d43ad4ce1c4c3596498b05f45f90b1",
"89eaeecfecd0922bf6d4eed8fab727820e58a1365cc3c0e59ea62f1a18ee5ffd",
"1df56fd68f77aa7d1ac28aaaa0ad3c8bcec95ef44cacd54f09cbcf283a2898ab",
"c0d0e8f364c095b1a1a642bbd1e544231151e62065c9c087e52774ad2e248126",
"a20f82a96565893300cfe98a74b7685c871fb333fac8f59795c6590323746b8f",
"0c4e2093721c389e9fcb5bb35bd624ae50bf3a6a6c171fff2b14b9136f4c6a9d",
"ed9d7c60b040bde8c45789c91c82a892cff19628e7851d34e6a4d6db0e10b478",
"f7c7a7ccc682fb1e6808cbc8650039cfcbeed9aa4330216f13ff77e4d7ee3f0f"
],
"logIndex": 71766949,
"rootHash": "ce8345628834e8cdee54e229fb6130b1fc68cc5e830636376b9b8982b954a2c8",
"treeSize": 71769601
},
"signedEntryTimestamp": "MEYCIQCqosfnf50JrF+Yiq/DsyYYo93iPShxw1Uctfk4o4lkLwIhALpL9c6BOmDJk+y986y7iNaPCJsQV0+eWK5siYKY3O/Q"
}
}
Loading