Skip to content

docs: document that `mangled-package-version` will result in `git-che…

97f1399
Select commit
Loading
Failed to load commit list.
Merged

fix: make checkout expected-commit bump less greedy #2008

docs: document that `mangled-package-version` will result in `git-che…
97f1399
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Jun 16, 2025 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 356224368429289886289734784447914582519550698329 (0x3e65a733c8e00c7010b37565842fdc88cb35e359)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Jun 16 14:50:25 2025 UTC
            Not After : Jun 16 15:00:25 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    0b:e3:0a:5d:7a:a9:80:63:f7:ba:f5:36:10:46:1f:
                    be:23:8f:3b:5d:3c:65:f6:62:5c:4d:1b:c3:1d:5b:
                    16:6a
                Y:
                    eb:2f:d0:be:68:98:ed:08:06:d2:fc:b8:d3:b0:6a:
                    cb:f9:50:79:de:7a:13:7c:52:06:48:d8:89:98:0d:
                    e5:d2
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                AA:01:1B:01:92:6E:84:E1:0F:C8:B1:56:DA:02:37:25:80:F8:74:42
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:ben.tasker@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABl3k4WCMAAAQDAEYwRAIgCHFzabmyMCzVZYHUqAvX2vo3tYBccrEwn0LDjYpyE/MCIBEDCfK29k9/uusT2nSnbmUzxA0vR3TBCEzSgjMA8vcY

    Signature Algorithm: ECDSA-SHA384
         30:65:02:30:29:9e:1b:fe:31:d6:80:c5:e3:6b:b6:23:7a:a1:
         a7:59:14:f7:5a:bf:59:e4:0a:b5:fd:e1:ce:d4:65:75:17:ea:
         9a:d3:af:b7:62:7a:74:fd:db:28:7e:5a:b1:ca:ed:1d:02:31:
         00:8d:6f:b4:8e:fa:17:81:85:ef:a2:04:2e:cf:75:d9:16:38:
         51:34:e8:77:af:93:26:1b:05:08:40:e9:90:9a:64:01:d7:e5:
         e9:ce:db:ca:d7:dc:18:9a:13:4e:a0:b7:e7

Rekor Entry

{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI1OTBjNzQwOWEyNWY1NzQ1OGRiYTA2OTYyZDc4ZmI1MmNmYzg1OTNjNDgwZmU1YTdhYTNjZjBlMzgxZGQyYTA1In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQktKR2dsbTlnNDllTkhPZHozYVFqT2t3RlRXalUxM2hsRmRKZXpYRFRKR0FpRUF0aERDNG90djJrQVJZTXlVUjRyMUdoMzlOVTNZOHZsbGYxK3pxbjFsYlpJPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdWRU5EUVd4bFowRjNTVUpCWjBsVlVHMVhiazA0YW1kRVNFRlJjek5XYkdoREwyTnBUWE14TkRGcmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVxUlRKTlZGRXhUVVJKTVZkb1kwNU5hbFYzVG1wRk1rMVVWWGROUkVreFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZESzAxTFdGaHhjR2RIVUROMWRsVXlSVVZaWm5acFQxQlBNVEE0V21aYWFWaEZNR0lLZDNneFlrWnRjbkpNT1VNcllVcHFkRU5CWWxNdlRHcFVjMGR5VEN0V1FqVXpibTlVWmtaSlIxTk9hVXB0UVROc01IRlBRMEZZV1hkblowWjVUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZ4WjBWaUNrRmFTblZvVDBWUWVVeEdWekpuU1ROS1dVUTBaRVZKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwM1dVUldVakJTUVZGSUwwSkNNSGRITkVWYVdXMVdkVXh1VW1oak1uUnNZMnRDYW1GSFJuQmliV1F4V1ZoS2EweHRVbXhrYWtGd1FtZHZjZ3BDWjBWRlFWbFBMMDFCUlVKQ1FuUnZaRWhTZDJONmIzWk1Na1pxV1RJNU1XSnVVbnBNYldSMllqSmtjMXBUTldwaU1qQjNTM2RaUzB0M1dVSkNRVWRFQ25aNlFVSkRRVkZrUkVKMGIyUklVbmRqZW05MlRESkdhbGt5T1RGaWJsSjZURzFrZG1JeVpITmFVelZxWWpJd2QyZFphMGREYVhOSFFWRlJRakZ1YTBNS1FrRkpSV1YzVWpWQlNHTkJaRkZFWkZCVVFuRjRjMk5TVFcxTldraG9lVnBhZW1ORGIydHdaWFZPTkRoeVppdElhVzVMUVV4NWJuVnFaMEZCUVZwa05RcFBSbWRxUVVGQlJVRjNRa2ROUlZGRFNVRm9lR015YlRWemFrRnpNVmRYUWpGTFowd3hPWEkyVGpkWFFWaElTM2hOU2psRGR6UXlTMk5vVUhwQmFVRlNDa0YzYm5sMGRscFFaamR5Y2tVNWNEQndNalZzVFRoUlRrd3daREIzVVdoTk1HOUpla0ZRVEROSFJFRkxRbWRuY1docmFrOVFVVkZFUVhkT2IwRkVRbXdLUVdwQmNHNW9kaXROWkdGQmVHVk9jblJwVGpadllXUmFSbEJrWVhZeGJtdERjbGc1TkdNM1ZWcFlWVmcyY0hKVWNqZGthV1Z1VkRreWVXZ3JWM0pJU3dvM1VqQkRUVkZEVG1JM1UwOHJhR1ZDYUdVcmFVSkROMUJrWkd0WFQwWkZNRFpJWlhacmVWbGlRbEZvUVRaYVEyRmFRVWhZTldWdVR6STRjbGd6UW1saENrVXdObWQwSzJNOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
  "integratedTime": 1750085425,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 239747884,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n118403374\nxSc3uKgPmtIh93SFgC3bXLTn09eU2m/IYhHu9z8FoFQ=\n\n— rekor.sigstore.dev wNI9ajBGAiEAh6dyTfRF2IN89P7J0TnE9k486+3TD2xkVUbMr/9cc2kCIQCRUI3XRTN4oYXecuNreLUi7FRRTsyU215x73wY0bpZqQ==\n",
      "hashes": [
        "430c2add778ad52ff502f8a0d0be0eb53628b8109d74d4b4fdbbe69f6312f673",
        "ece76f2e3c2521f2de47656d42f6095cbafbb1e1427e4d07ede35bd2c222d3d6",
        "933817288eaa95fc6951142ad780bb313817a4e5980784e9d81b494df9a13716",
        "774f9ea57eee8713ba9abcace9549b68a4e87ae1ad901dba4dd085536e37e6c7",
        "87bc74852e730f023fe7f7de1446b78b50d4e326446fc82a74064cde3701521b",
        "04005af33ec5d2869f184cddf58195efdc2faa187e7add76729a9c5a50f51415",
        "b71bace8c186ca8a9152e5152f5e03d3d21f2cd85f4f0ef0ea926b2b713c73a7",
        "ff23dcd10eecc96ddc129e86362a3d465213b3baf9ccb404a3abeac56bcc867b",
        "4760c3b217fb6c412acbc847c937d67c4860f6f60a303e6a71fd920bb29b0de3",
        "7f2ed640a92fc08328340aa33d2faadc95eac8429737654f850f4ffffc61f0b1",
        "99d1a15ae49b0f4c67f1173e93a6e16b5cd7b40f980c0ca76c94e625a4ba95da",
        "dc398af9d5acdabba57a2a65772b6796aca830925a0ec3368287dfcad8c5d39d",
        "2597461de86ae7f0bc776e751543fb741b1fb35c88a09a913291e619fa8052ca",
        "152cb1212372f63f343daf94b9073a09063d7a90f16e0bed95f07eda1eddf4ec",
        "ad6e50472d18980d1b7e3107b9ae2e56d6664019f4154f1f4328751bba57e7d2",
        "2e93c7621cee730d2e79a5002927a27549fe92ba1a58dc92c53c7d2c3c6bf5af",
        "8b273d44b9f460b6fe2e68db5471ea25b03a7f102d687d0e8600d83a5d8a0ad6",
        "99487f4ed75bec960e128a9a42378c06c7cb9a03b29f3733716785c1b94e2c86",
        "204b7ea58bec47a08a05d2962f877965d7b5334a68b4918398a8a8c972a6dbb8",
        "361b9eaf6e716bd2f6285592c0e1b822551e684376741fdcfa552432f13f8787",
        "eb71b7e59580d8980e1376d7bb4a0a86ba37b624782033c7d4880ca76d7fa639",
        "9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
        "eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
      ],
      "logIndex": 117843622,
      "rootHash": "c52737b8a80f9ad221f77485802ddb5cb4e7d3d794da6fc86211eef73f05a054",
      "treeSize": 118403374
    },
    "signedEntryTimestamp": "MEUCIQDhIApJmeLH/4Q3MrXC+0C8Ti7+WomS4em5/Db19/AgcAIgN8rBVVN6HMlb3Z7jp9AlWChVe1Xd2rjwbXspjkL13aw="
  }
}