Add GitHub App token signer for GCP KMS. #268
Open
Chainguard Enforce / Enforce - Commit Signing
succeeded
Apr 16, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 598304904939416139194478259396726629818991953806 (0x68cceb79905a040f6c323a078a6a430accc8c78e)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Apr 16 04:31:24 2024 UTC
Not After : Apr 16 04:41:24 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
85:96:fe:a6:1d:ef:63:a5:3d:3b:f9:2f:2a:5d:75:
af:58:9e:fd:90:07:ea:91:d8:96:d2:57:89:93:06:
a1:16
Y:
43:a7:61:20:95:92:4c:4c:55:1c:ad:40:20:b3:ae:
bf:e8:0f:e9:82:aa:1e:7b:74:10:41:f9:51:d8:4c:
1c:24
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
31:1F:B7:D4:1B:FC:A9:56:D8:14:9C:52:1F:00:58:94:EF:A4:B6:00
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABjuUsiAMAAAQDAEYwRAIgYK6Fq/h4os2i3iwqIoZGsKplZtzKC6QvAG5xH2EJ3wgCIEIZoq6P/nO+plZFCxnzqEJ7ypxV9PcaXFsoDstH0/Hm
Signature Algorithm: ECDSA-SHA384
30:64:02:30:4a:f7:24:0c:f2:15:77:d6:36:36:1a:3b:88:8c:
2f:75:4d:61:ba:5d:0e:ea:3b:a4:ab:e5:1f:7a:4f:3e:54:4d:
f5:f6:c5:36:a8:73:2b:0c:21:7d:29:4d:33:43:bc:84:02:30:
56:66:4b:0d:f4:5c:40:f2:d2:c2:d8:7b:77:bc:73:4e:76:2b:
ac:a4:54:b4:4d:39:57:aa:e6:80:90:6c:e4:d0:6f:6f:91:e6:
21:56:ba:0e:b5:ed:e1:16:b1:99:b3:7f
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIwYjIxMDY5ZTQwOGUwZjIzODQ3ZmI5NjUzMmZlMjdjNWI3NjIxZjBmMDg2ZDA2ZGI3MTNiYTNkMzk5NTMzOTg1In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRzVSK3FoV01jQjZCTUx3a0xvZW05THpyOGhoM05RT3JicUZGT2J6WUxCTUFpRUE1dTcxTjJ5QzNVZlRqR2l5WWVWQUtmT2djSmkxeXFDSms3ZFdCckhSdWdFPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjVla05EUVd4TFowRjNTVUpCWjBsVllVMTZjbVZhUW1GQ1FUbHpUV3B2U0dsdGNFUkRjM3BKZURRMGQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDVFUlRKTlJGRjZUVlJKTUZkb1kwNU5hbEYzVGtSRk1rMUVVVEJOVkVrd1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZvV21JcmNHZ3pkbGsyVlRsUEwydDJTMnd4TVhJeGFXVXZXa0ZJTm5CSVdXeDBTbGdLYVZwTlIyOVNXa1J3TWtWbmJGcEtUVlJHVldOeVZVRm5jelkyTHpaQkwzQm5jVzlsWlROUlVWRm1iRkl5UlhkalNrdFBRMEZZUlhkblowWjBUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZOVWlzekNqRkNkamh4Vm1KWlJrcDRVMGgzUWxsc1R5dHJkR2RCZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBsbldVUldVakJTUVZGSUwwSkNaM2RHYjBWVldXMXNjMkpJYkVGWk1taG9ZVmMxYm1SWFJubGFRelZyV2xoWmQwdFJXVXRMZDFsQ1FrRkhSQXAyZWtGQ1FWRlJZbUZJVWpCalNFMDJUSGs1YUZreVRuWmtWelV3WTNrMWJtSXlPVzVpUjFWMVdUSTVkRTFEYzBkRGFYTkhRVkZSUW1jM09IZEJVV2RGQ2toUmQySmhTRkl3WTBoTk5reDVPV2haTWs1MlpGYzFNR041Tlc1aU1qbHVZa2RWZFZreU9YUk5TVWRLUW1kdmNrSm5SVVZCWkZvMVFXZFJRMEpJYzBVS1pWRkNNMEZJVlVFelZEQjNZWE5pU0VWVVNtcEhValJqYlZkak0wRnhTa3RZY21wbFVFc3pMMmcwY0hsblF6aHdOMjgwUVVGQlIwODFVM2xKUVhkQlFRcENRVTFCVW1wQ1JVRnBRbWR5YjFkeUswaHBhWHBoVEdWTVEyOXBhR3RoZDNGdFZtMHpUVzlNY0VNNFFXSnVSV1paVVc1bVEwRkpaMUZvYldseWJ5OHJDbU0zTm0xV2ExVk1SMlpQYjFGdWRrdHVSbGd3T1hod1kxZDVaMDk1TUdaVU9HVlpkME5uV1VsTGIxcEplbW93UlVGM1RVUmFkMEYzV2tGSmQxTjJZMnNLUkZCSlZtUTVXVEpPYUc4M2FVbDNkbVJWTVdoMWJEQlBObXAxYTNFclZXWmxhemdyVmtVek1UbHpWVEp4U0UxeVJFTkdPVXRWTUhwUk4zbEZRV3BDVndwYWEzTk9PVVo0UVRoMFRFTXlTSFF6ZGtoT1QyUnBkWE53UmxNd1ZGUnNXSEYxWVVGclIzcHJNRWM1ZG10bFdXaFdjbTlQZEdVemFFWnlSMXB6TXpnOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1713241885,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 86017893,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n81856281\nSFbV/QLzKC1wxn43vzasgSETD/oidyuPFwBfROHJr3U=\n\n— rekor.sigstore.dev wNI9ajBGAiEA5cfWEbRgJlOiDAaw+TdMUgVn3kw4zjgSK2BVDV7DJCgCIQCCII/BjYQMyjIBFNWcyBnD7/uEpeXej6iMdhX+GSON1g==\n",
"hashes": [
"7e355fcfc5658b747bf940ae67679973dddba1f818b52c9e92fa0cdd5ff075aa",
"912c5d8e90e71cf9ef1e1b70c47daebf817146329339d581bfadeab0bfa15886",
"43e1c28ad4c7ac988aed03ca0ea42476b6aba252b1779f27c9ea67d2d694fbb1",
"147c857b346b61a2d3d71ef6ef5c9a101a172066ecb3b0e40131a9e5ca47b220",
"605ae917cdfc45916aff4075e98af4ff7388f8ac7ab89bc92faa5216b2ae3391",
"5dfcbac762777fa458b1646a2d8ae61e98c80a2e27400c1da652129c731a32d3",
"178d12ffe9e73b2ff3f1d1d8802abc84852a8206321d8f44a1eab27ec43140e6",
"1ffab4598ee712f0b6e4a1c8168148b886e106dd92e2d4e414203da0f38ff539",
"8715e23bbe461318123f89ac4dd878bd3b030b57f8410b03a1284663e3d143e3",
"ea395306a3f22798d3cb4fb5451fb3f370b3128ad04dfb4a3468eac13d312ea9",
"bd8aa2c2a177b357be69e85cf1d5c17bea1dacecd3549ef40017087cbed4ca2b",
"e9f2c9ad1c0114b63395f8f797b15e4d63dce000ea8b02f01a170ef5a3211eb6",
"1ce260986769124dbc705e22bee8fd76b0981994518fc1f9d14ef942bb6bcf72",
"5601bba05915118ba3846953c215150db0d0cd74b62ad5e817a9f96d09baf1ea",
"9736145aa32bbdd1b3483083316b982920b5cdad1538c316319bcbae1507eb8c",
"f0e76f591967014927dd59271b8cb36a69e0b3a1a2fea6d107f67fb9db749227",
"62cbcf39ee2120b3791dfee4fd4c1b8ff9bb4a31e053b54e33d15d441d95180a",
"de48cf7a09019cd05ee06aa911cb8f103382632fa1b363921d4c4a19d6b1026e",
"b66caf5e8b1f7b1fcd5a06ad2371b53dc1ae6524eb4775aed563ba31d565b426",
"0c60918bcf6f554648566bcad8014e99e32a101ea7f91f7a65efaf8d601906fc",
"f7c7a7ccc682fb1e6808cbc8650039cfcbeed9aa4330216f13ff77e4d7ee3f0f"
],
"logIndex": 81854462,
"rootHash": "4856d5fd02f3282d70c67e37bf36ac8121130ffa22772b8f17005f44e1c9af75",
"treeSize": 81856281
},
"signedEntryTimestamp": "MEUCIQDLlQeXE5H5HQlIpbE0P1w6SbIGkBKn6pdLyIoHCJZKYwIgWWwuBongOD588OQ8uVi7Yjzdp1qqPGxzlOA4XnZIbEo="
}
}
Loading