fix: make checkout expected-commit bump less greedy #2008
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jun 16, 2025 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 356224368429289886289734784447914582519550698329 (0x3e65a733c8e00c7010b37565842fdc88cb35e359)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jun 16 14:50:25 2025 UTC
Not After : Jun 16 15:00:25 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
0b:e3:0a:5d:7a:a9:80:63:f7:ba:f5:36:10:46:1f:
be:23:8f:3b:5d:3c:65:f6:62:5c:4d:1b:c3:1d:5b:
16:6a
Y:
eb:2f:d0:be:68:98:ed:08:06:d2:fc:b8:d3:b0:6a:
cb:f9:50:79:de:7a:13:7c:52:06:48:d8:89:98:0d:
e5:d2
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
AA:01:1B:01:92:6E:84:E1:0F:C8:B1:56:DA:02:37:25:80:F8:74:42
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:ben.tasker@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABl3k4WCMAAAQDAEYwRAIgCHFzabmyMCzVZYHUqAvX2vo3tYBccrEwn0LDjYpyE/MCIBEDCfK29k9/uusT2nSnbmUzxA0vR3TBCEzSgjMA8vcY
Signature Algorithm: ECDSA-SHA384
30:65:02:30:29:9e:1b:fe:31:d6:80:c5:e3:6b:b6:23:7a:a1:
a7:59:14:f7:5a:bf:59:e4:0a:b5:fd:e1:ce:d4:65:75:17:ea:
9a:d3:af:b7:62:7a:74:fd:db:28:7e:5a:b1:ca:ed:1d:02:31:
00:8d:6f:b4:8e:fa:17:81:85:ef:a2:04:2e:cf:75:d9:16:38:
51:34:e8:77:af:93:26:1b:05:08:40:e9:90:9a:64:01:d7:e5:
e9:ce:db:ca:d7:dc:18:9a:13:4e:a0:b7:e7
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI1OTBjNzQwOWEyNWY1NzQ1OGRiYTA2OTYyZDc4ZmI1MmNmYzg1OTNjNDgwZmU1YTdhYTNjZjBlMzgxZGQyYTA1In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQktKR2dsbTlnNDllTkhPZHozYVFqT2t3RlRXalUxM2hsRmRKZXpYRFRKR0FpRUF0aERDNG90djJrQVJZTXlVUjRyMUdoMzlOVTNZOHZsbGYxK3pxbjFsYlpJPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdWRU5EUVd4bFowRjNTVUpCWjBsVlVHMVhiazA0YW1kRVNFRlJjek5XYkdoREwyTnBUWE14TkRGcmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVxUlRKTlZGRXhUVVJKTVZkb1kwNU5hbFYzVG1wRk1rMVVWWGROUkVreFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZESzAxTFdGaHhjR2RIVUROMWRsVXlSVVZaWm5acFQxQlBNVEE0V21aYWFWaEZNR0lLZDNneFlrWnRjbkpNT1VNcllVcHFkRU5CWWxNdlRHcFVjMGR5VEN0V1FqVXpibTlVWmtaSlIxTk9hVXB0UVROc01IRlBRMEZZV1hkblowWjVUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZ4WjBWaUNrRmFTblZvVDBWUWVVeEdWekpuU1ROS1dVUTBaRVZKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwM1dVUldVakJTUVZGSUwwSkNNSGRITkVWYVdXMVdkVXh1VW1oak1uUnNZMnRDYW1GSFJuQmliV1F4V1ZoS2EweHRVbXhrYWtGd1FtZHZjZ3BDWjBWRlFWbFBMMDFCUlVKQ1FuUnZaRWhTZDJONmIzWk1Na1pxV1RJNU1XSnVVbnBNYldSMllqSmtjMXBUTldwaU1qQjNTM2RaUzB0M1dVSkNRVWRFQ25aNlFVSkRRVkZrUkVKMGIyUklVbmRqZW05MlRESkdhbGt5T1RGaWJsSjZURzFrZG1JeVpITmFVelZxWWpJd2QyZFphMGREYVhOSFFWRlJRakZ1YTBNS1FrRkpSV1YzVWpWQlNHTkJaRkZFWkZCVVFuRjRjMk5TVFcxTldraG9lVnBhZW1ORGIydHdaWFZPTkRoeVppdElhVzVMUVV4NWJuVnFaMEZCUVZwa05RcFBSbWRxUVVGQlJVRjNRa2ROUlZGRFNVRm9lR015YlRWemFrRnpNVmRYUWpGTFowd3hPWEkyVGpkWFFWaElTM2hOU2psRGR6UXlTMk5vVUhwQmFVRlNDa0YzYm5sMGRscFFaamR5Y2tVNWNEQndNalZzVFRoUlRrd3daREIzVVdoTk1HOUpla0ZRVEROSFJFRkxRbWRuY1docmFrOVFVVkZFUVhkT2IwRkVRbXdLUVdwQmNHNW9kaXROWkdGQmVHVk9jblJwVGpadllXUmFSbEJrWVhZeGJtdERjbGc1TkdNM1ZWcFlWVmcyY0hKVWNqZGthV1Z1VkRreWVXZ3JWM0pJU3dvM1VqQkRUVkZEVG1JM1UwOHJhR1ZDYUdVcmFVSkROMUJrWkd0WFQwWkZNRFpJWlhacmVWbGlRbEZvUVRaYVEyRmFRVWhZTldWdVR6STRjbGd6UW1saENrVXdObWQwSzJNOUNpMHRMUzB0UlU1RUlFTkZVbFJKUmtsRFFWUkZMUzB0TFMwSyJ9fX19",
"integratedTime": 1750085425,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 239747884,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n118403374\nxSc3uKgPmtIh93SFgC3bXLTn09eU2m/IYhHu9z8FoFQ=\n\n— rekor.sigstore.dev wNI9ajBGAiEAh6dyTfRF2IN89P7J0TnE9k486+3TD2xkVUbMr/9cc2kCIQCRUI3XRTN4oYXecuNreLUi7FRRTsyU215x73wY0bpZqQ==\n",
"hashes": [
"430c2add778ad52ff502f8a0d0be0eb53628b8109d74d4b4fdbbe69f6312f673",
"ece76f2e3c2521f2de47656d42f6095cbafbb1e1427e4d07ede35bd2c222d3d6",
"933817288eaa95fc6951142ad780bb313817a4e5980784e9d81b494df9a13716",
"774f9ea57eee8713ba9abcace9549b68a4e87ae1ad901dba4dd085536e37e6c7",
"87bc74852e730f023fe7f7de1446b78b50d4e326446fc82a74064cde3701521b",
"04005af33ec5d2869f184cddf58195efdc2faa187e7add76729a9c5a50f51415",
"b71bace8c186ca8a9152e5152f5e03d3d21f2cd85f4f0ef0ea926b2b713c73a7",
"ff23dcd10eecc96ddc129e86362a3d465213b3baf9ccb404a3abeac56bcc867b",
"4760c3b217fb6c412acbc847c937d67c4860f6f60a303e6a71fd920bb29b0de3",
"7f2ed640a92fc08328340aa33d2faadc95eac8429737654f850f4ffffc61f0b1",
"99d1a15ae49b0f4c67f1173e93a6e16b5cd7b40f980c0ca76c94e625a4ba95da",
"dc398af9d5acdabba57a2a65772b6796aca830925a0ec3368287dfcad8c5d39d",
"2597461de86ae7f0bc776e751543fb741b1fb35c88a09a913291e619fa8052ca",
"152cb1212372f63f343daf94b9073a09063d7a90f16e0bed95f07eda1eddf4ec",
"ad6e50472d18980d1b7e3107b9ae2e56d6664019f4154f1f4328751bba57e7d2",
"2e93c7621cee730d2e79a5002927a27549fe92ba1a58dc92c53c7d2c3c6bf5af",
"8b273d44b9f460b6fe2e68db5471ea25b03a7f102d687d0e8600d83a5d8a0ad6",
"99487f4ed75bec960e128a9a42378c06c7cb9a03b29f3733716785c1b94e2c86",
"204b7ea58bec47a08a05d2962f877965d7b5334a68b4918398a8a8c972a6dbb8",
"361b9eaf6e716bd2f6285592c0e1b822551e684376741fdcfa552432f13f8787",
"eb71b7e59580d8980e1376d7bb4a0a86ba37b624782033c7d4880ca76d7fa639",
"9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 117843622,
"rootHash": "c52737b8a80f9ad221f77485802ddb5cb4e7d3d794da6fc86211eef73f05a054",
"treeSize": 118403374
},
"signedEntryTimestamp": "MEUCIQDhIApJmeLH/4Q3MrXC+0C8Ti7+WomS4em5/Db19/AgcAIgN8rBVVN6HMlb3Z7jp9AlWChVe1Xd2rjwbXspjkL13aw="
}
}
Loading