Add slack alerting on post-submit failure #45
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jan 24, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 487612023180242332965380046818023841493490163545 (0x556947829a7f2ae7c64bb28c43fbf5a1a8ad5f59)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jan 24 18:28:17 2024 UTC
Not After : Jan 24 18:38:17 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
ec:5b:ed:f3:ec:9c:1a:bf:d6:41:a5:85:fa:51:e9:
56:7d:b3:e5:58:70:76:e1:d8:84:75:b1:45:c4:ac:
e0:16
Y:
d6:b4:f8:c7:3a:1e:94:0e:de:73:90:9c:46:10:e0:
27:bb:a7:e7:4c:f7:7d:9a:0f:d7:03:35:a1:c6:c4:
64:fe
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
21:BA:8B:3D:5C:40:5E:CB:E0:C0:82:ED:49:CC:BE:7E:7C:18:A3:DA
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABjTy65WEAAAQDAEYwRAIgaI2OhiVdP6sp1TdwhDjN4Qvwh/r1uHoq7VK9GGxmRL8CIFeTLTRFZz2EXCJz9AlYNfob81j37FUxp2nslTIz8wav
Signature Algorithm: ECDSA-SHA384
30:65:02:30:68:94:2d:e9:5f:fe:18:84:0e:5c:98:5d:7b:94:
05:e1:12:a1:32:04:f5:1c:e4:79:3b:71:99:6a:3e:d4:b8:87:
5f:ee:bf:58:22:22:09:1e:d3:78:85:d3:01:a6:69:ce:02:31:
00:e3:48:06:b5:2c:85:fe:2d:94:cf:ca:52:47:e7:03:bb:a7:
40:1f:2d:f1:b7:a9:d7:b9:ce:b3:79:95:7f:d3:c8:ce:12:57:
14:33:40:4c:f6:a3:10:01:48:55:8b:ac:65
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJkNzM1OWI1M2U4NWZlMmE1MmU2ZTAyMmJhY2E0M2E1ZDVjNDA5Y2EyYjkwNGUzOWZhMzhkZGI3MDgyMDJlMzAxIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRGZ2Qk5YdXM0QXVqMXlXaURESFNkVGNhMytRbUs4NktNQXFXYSsrNFNRQkFpRUFwOSs4NkJIRU5ERkdyYTBIdGpDelNaSHFuV3FXRU9ZMEl6ZHZRc05zTURJPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjZla05EUVd4WFowRjNTVUpCWjBsVlZsZHNTR2R3Y0M5TGRXWkhVemRMVFZFdmRqRnZZV2wwV0RGcmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDFVU1RCTlZHZDVUMFJGTTFkb1kwNU5hbEYzVFZSSk1FMVVaM3BQUkVVelYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVUzUm5aME9DdDVZMGR5TDFkUllWZEdLMnhJY0ZadU1ubzFWbWgzWkhWSVdXaElWM2dLVW1OVGN6UkNZbGQwVUdwSVQyZzJWVVIwTlhwclNuaEhSVTlCYm5VMlptNVVVR1E1YldjdldFRjZWMmg0YzFKckwzRlBRMEZZVVhkblowWjNUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZKWW5GTUNsQldlRUZZYzNabmQwbE1kRk5qZVN0bWJuZFpiemx2ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwUldVUldVakJTUVZGSUwwSkNjM2RIV1VWWVlsZEdNR1JITVhaaU0wcEJXVEpvYUdGWE5XNWtWMFo1V2tNMWExcFlXWGRMVVZsTFMzZFpRZ3BDUVVkRWRucEJRa0ZSVVdKaFNGSXdZMGhOTmt4NU9XaFpNazUyWkZjMU1HTjVOVzVpTWpsdVlrZFZkVmt5T1hSTlEzTkhRMmx6UjBGUlVVSm5OemgzQ2tGUlowVklVWGRpWVVoU01HTklUVFpNZVRsb1dUSk9kbVJYTlRCamVUVnVZakk1Ym1KSFZYVlpNamwwVFVsSFNrSm5iM0pDWjBWRlFXUmFOVUZuVVVNS1FraHpSV1ZSUWpOQlNGVkJNMVF3ZDJGellraEZWRXBxUjFJMFkyMVhZek5CY1VwTFdISnFaVkJMTXk5b05IQjVaME00Y0Rkdk5FRkJRVWRPVUV4eWJBcFpVVUZCUWtGTlFWSnFRa1ZCYVVKdmFsazJSMHBXTUM5eGVXNVdUak5EUlU5Tk0yaERMME5JSzNaWE5HVnBjblJWY2pCWllrZGFSWFozU1dkV05VMTBDazVGVm01UVdWSmpTVzVRTUVOV1p6RXJhSFo2VjFCbWMxWlVSMjVoWlhsV1RXcFFla0p4T0hkRFoxbEpTMjlhU1hwcU1FVkJkMDFFWVVGQmQxcFJTWGNLWVVwUmREWldMeXRIU1ZGUFdFcG9aR1UxVVVZMFVrdG9UV2RVTVVoUFVqVlBNMGRhWVdvM1ZYVkpaR1kzY2psWlNXbEpTa2gwVGpSb1pFMUNjRzF1VHdwQmFrVkJOREJuUjNSVGVVWXZhVEpWZWpod1UxSXJZMFIxTm1SQlNIa3plSFEyYmxoMVl6WjZaVnBXTHpBNGFrOUZiR05WVFRCQ1RUbHhUVkZCVldoV0NtazJlR3dLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
"integratedTime": 1706120898,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 66181660,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 2605736670972794746\n62018555\nDVOqEWGdREHcqPT9YQI1tIFC78DgHRIU4CAOc/auFmw=\nTimestamp: 1706121022736410415\n\n— rekor.sigstore.dev wNI9ajBEAiBPgaIKmgCrTq1SAbUCF1KRKcYM1BUgPwaq3WsiRStp7gIgS/31qGq9V09OnXRcc+ncxV+7I1YbvmOQPO0xdcrO7LE=\n",
"hashes": [
"82b0344e0defd441bff0a55c2cd1beb6ad9dbcd7e63e783bf00ed62a3b0f867a",
"d7f30a578547cc5f8b484fe92a0d87190323291a2eaf79a8723ec326f92593cc",
"22a13c06eeef6179ad9de03a64dd656a72b01e655a445758f330c724f50ae33d",
"6a8da85869d4b083539d14b46c53da60757b9d68c1b50a16078954748df0cc43",
"7fdb237c79d693738fef1c7977c895b5b16b52862b4a2ac329076bb49534005d",
"7904190812c010122d0126b7fd13c68616e1595ff8602cc69ea0560f37abc87c",
"2d4b01d09a67c4ae444a44439b0ec216c4b4778ec468dffe1e1c622f9c86b5c0",
"b7acc7581438a6068e700cb1626d9ee541bdd06761da627973e6d2cc62094d39",
"c73fb5906b92879962182fd4a482496ec9c6f9007118940d31d77a25806223f7",
"18194d9de0224245f8421bc5c529798b68ba27e8f7638be3b14d41fe6c36098f",
"e51825d4428f2ac1ed50e245c29430ce6190c6bc93de82f2d20588453cd52f0b",
"26421fd67d1be7e16e0c062ad0b6f07015640b97e497a1429be1a7bc2408032e",
"392a1be5a079a8feeba4b99764d2a4c5b3402db872334ec805775204c9ef8d08",
"1e3a13cd8bbb9c5ab101af654d20d9c680386b5c09e0ff014f6fd0c8b33c3c7e",
"22c2db32aae375e1e1c99e97383800b3de5a535d8c2486def5707a91768c0d8c",
"51e5d80682cc50abdb392ed3a0cb1aa1b946e1f4bff103d04d314620155e13bd",
"98c486feb5d87092a78a46c4b5be04868654900affc2e86ffb20074dc73a883a",
"6969c49bd73f19bf28a5eaeabd331ddd60502defb2cd3d96e17b741c80adec6c"
],
"logIndex": 62018229,
"rootHash": "0d53aa11619d4441dca8f4fd610235b48142efc0e01d1214e0200e73f6ae166c",
"treeSize": 62018555
},
"signedEntryTimestamp": "MEUCIQDdr5qUWWnTRIWHXKESPF9cDgGARlg0ZLyDpianG4PMPgIgPodeNuVBrOoPTBXdaOBmiA5VRtqj0Z9RE/yQ9W58tfE="
}
}
Loading