[WIP] Add info about SBOM and SLSA files for JavaScript libraries #2702
Chainguard Enforce / Enforce - Commit Signing
succeeded
Oct 21, 2025 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 673513558364038013446980923207027562141787674944 (0x75f96479a5da1b23ed92aa9a84d7e936ff3cd940)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Oct 21 00:43:53 2025 UTC
Not After : Oct 21 00:53:53 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
08:fa:67:b2:73:63:b4:a2:75:56:4f:75:25:99:c3:
aa:a6:9c:47:e1:f5:b9:f3:94:33:d5:5c:23:31:23:
83:21
Y:
4c:a0:7c:66:47:5b:ad:ab:09:53:83:da:db:a6:ef:
e4:b0:c8:47:d6:24:a7:7b:10:35:82:15:36:34:48:
05:54
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
04:FC:0A:2A:55:D7:CA:B2:13:00:7C:30:B1:7C:4B:A1:65:0D:67:2E
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmgQ49jwAAAQDAEcwRQIhAPg9Jk4NuQTGHJTA23pTB9LKMShmNrU5dVdfM1WYoOT/AiBfoeLaBPmaIvHx6yVUl/mpmtTSPZEINx10hzoDb6Y41g==
Signature Algorithm: ECDSA-SHA384
30:65:02:30:49:49:a4:d6:7e:89:eb:69:d5:70:8d:01:37:26:
e6:ac:d4:cf:de:ad:03:3c:cc:66:cc:aa:ee:85:a4:4b:68:59:
8b:f2:13:c5:a9:99:3b:3d:58:48:f7:96:3c:ed:df:eb:02:31:
00:b2:73:6b:3b:5d:90:a3:4e:93:d2:29:91:f1:ee:ff:ee:0b:
f6:87:6a:43:68:68:1a:25:64:aa:84:26:5f:54:bd:c4:dd:7f:
fb:4a:25:6b:6f:06:6c:f8:87:9d:03:c4:3f
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIzOTY2ZTBjZmU0ZWM2MDBlOGUyNzdjNmFmY2U4MmI3ZDUyYTdjNzU0NzA5NTUzMTVkMTQ2NTViMTNlYTZiNTE5In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJUUQ3ODJRVjJnTkZ0NlZnOWJ1bmhZS3dUR0p1ajNYOGNRK0ozVUNXdWd3NTNBSWdRNmgrSCtMWWxhQ2praFRpOWtwWDM2d1Q1c3YvclY3RDBVb25JQVNFR0RRPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhWRU5EUVd4MVowRjNTVUpCWjBsVlpHWnNhMlZoV0dGSGVWQjBhM0Z4WVdoT1puQk9kamc0TWxWQmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFFU1hoTlJFRXdUWHBWZWxkb1kwNU5hbFY0VFVSSmVFMUVRVEZOZWxWNlYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZEVUhCdWMyNU9hblJMU2pGV2F6a3hTbHB1UkhGeFlXTlNLMGd4ZFdaUFZVMDVWbU1LU1hwRmFtZDVSazF2U0hodFVqRjFkSEYzYkZSbk9YSmljSFV2YTNOTmFFZ3hhVk51WlhoQk1XZG9WVEpPUldkR1ZrdFBRMEZZYjNkblowWXlUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZDVUhkTENrdHNXRmg1Y2tsVVFVaDNkM05ZZUV4dlYxVk9XbmswZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0bldVUldVakJTUVZGSUwwSkRRWGRJYjBWallsZEdkVnB1U214YVF6VjBZak5PYkdOclFtcGhSMFp3WW0xa01WbFlTbXRNYlZKc1pHcEJjQXBDWjI5eVFtZEZSVUZaVHk5TlFVVkNRa0owYjJSSVVuZGplbTkyVERKR2Fsa3lPVEZpYmxKNlRHMWtkbUl5WkhOYVV6VnFZakl3ZDB0M1dVdExkMWxDQ2tKQlIwUjJla0ZDUTBGUlpFUkNkRzlrU0ZKM1kzcHZka3d5Um1wWk1qa3hZbTVTZWt4dFpIWmlNbVJ6V2xNMWFtSXlNSGRuV1c5SFEybHpSMEZSVVVJS01XNXJRMEpCU1VWbVFWSTJRVWhuUVdSblJHUlFWRUp4ZUhOalVrMXRUVnBJYUhsYVducGpRMjlyY0dWMVRqUTRjbVlyU0dsdVMwRk1lVzUxYW1kQlFRcEJXbTlGVDFCWk9FRkJRVVZCZDBKSVRVVlZRMGxSUkRSUVUxcFBSR0pyUlhob2VWVjNUblEyVlhkbVUzbHFSVzlhYW1FeFQxaFdXRmg2VGxadFMwUnJDaTkzU1dkWU5raHBNbWRVTlcxcFRIZzRaWE5zVmtwbU5YRmFjbFV3YWpKU1EwUmpaR1JKWXpaQk1pdHRUMDVaZDBObldVbExiMXBKZW1vd1JVRjNUVVFLWVVGQmQxcFJTWGRUVlcxck1XNDJTall5YmxaalNUQkNUbmxpYlhKT1ZGQXpjVEJFVUUxNGJYcExjblZvWVZKTVlVWnRURGhvVUVaeFdtczNVRlpvU1FvNU5WazROMlF2Y2tGcVJVRnpiazV5VHpFeVVXOHdObFF3YVcxU09HVTNMemRuZGpKb01uQkVZVWRuWVVwWFUzRm9RMXBtVmt3elJUTllMemRUYVZaeUNtSjNXbk1yU1dWa1FUaFJMd290TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1761007433,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 625546922,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n506954531\nQAkxgRLUc9Eng7MxzpBQjtSgDZ4JZ11THbQpIOMnR+0=\n\n— rekor.sigstore.dev wNI9ajBFAiEAgjXIbEPEYAl50Pxc/A04Y4k8H3ymd5C5rFLbPzNYGjMCIB+jkokCOlK8wqEx0HBpXZVPg1H0h9fttMnPZzJnpOmD\n",
"hashes": [
"e4265aee417cfaf9ed2c756c93f226435f826c5ba47d67d8e53efe50232c73ee",
"6be5d14f0c410c7f6ff763d42b7c6a81caaf199a7cc5c7eda451f26d512d5c0d",
"9aee78be786a28f3c475af3a1fb485dd42d147df3619d7c75a4025c4c1bc6f9e",
"8dbed0e345dbd13aacbcddfd1ae8aae53f29eeb95ed78382e13add8901ec137d",
"b84b570f628471ffd87159f4aa83b709255b1c060eec33bfd208d9653c942a8a",
"d3e8ae38f83dee4e8d21680fb781e31633a1871be2d80f04a6ce889cfe90ccfa",
"895aa9b9080e8be77e755c498f156d8f6163552cbb062dbb77297c9e2f43a07d",
"c4aff00c793bd9759dcb85935d3017bd0f5a068ebfe65f0ad5964debec266227",
"f71958fcd18885f458ad87390acbe62515a19f4ec916249fe68bdc88be0e84ec",
"17534775e6bf6c4e2c31c074e043e13bc1ea82e657325c22fb52b2f8c8ed3c2a",
"3018d0dbd8cb452cf9132ac3b41eb88e49a6d45d165afc53fdd6e59598347d09",
"e8988f792a833b2116a50ae4fe7049c1cfad483ea08a04183a1c66d3aa6bd5ef",
"ce9e4972de3db26d162d2380203b214279975f0c601b975567b643fb6d079254",
"3492a4024fb609205bf167411f4ae6db2791774fc0639da09d769b14a7d126b7",
"b2ee74b3cd57a601c28dfa9ea1c4dd352374a2bc0d22f9cdddfb55d25f29f085",
"04c8a9f1d5ea8ff7ede73be2084b920487c36052f1ef35adc19622ec79329c26",
"28b0fec70a24173c258d2bc949471b6aa39f10c5964711c7561b004d1b0d8726",
"3c5dcdae2b6abe2e4f4e35edcf57a7164b9bc9362b2d1707de3148e723f4adc3",
"20d2e47066d6a9adf480394fea4b0ac00aa280f39e8c25a1d5df21de3c660894",
"7a4db9f68f6a2e03f688c6acf1ae04b8f0cbd778c456e12f1d6fb42b00b23ccd",
"ac74913b6289dc240abaeb5f8e514d69992a81c7c484561a3b41d790cc7f02a0",
"5241bb97cd2920e2fb16075cd0b1fe927f0fa7cf2ad7e2267af88363c2fbfc99",
"1c039383e160dc7d448f6e26c3e3fd9577e2fb898f2f910ac0077868d40e57a3",
"d96bf81a28ad87036e911295d3a7257af9d04180b35e6492ffefce26d5e0b174",
"d667f2f782a9708b6ab211fdfa0c2a57a8dc72ea5c68ca55b05dbc35ec3ccc36",
"bd2ecee28cc72106495818a8bfe9a4a48dbb184f3302654212445c3f7343c8d1"
],
"logIndex": 503642660,
"rootHash": "4009318112d473d12783b331ce90508ed4a00d9e09675d531db42920e32747ed",
"treeSize": 506954531
},
"signedEntryTimestamp": "MEUCIGU637Htm0600WA0CkbHesAUVxDPJXSat5wSXCbG0lw4AiEA3KW2DWYk9JGeM972zyNbJyI88y8w+ae6ACey2LwY268="
}
}
Loading