Improve JS/Python malware detection based on NPM/PyPI samples #456
Chainguard Enforce / Enforce - Commit Signing
succeeded
Sep 16, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 389356465968428371360303480203228367433565583125 (0x44335907814a981f38d7d04c87d5ab8a433db715)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Sep 16 19:28:49 2024 UTC
Not After : Sep 16 19:38:49 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
f7:af:50:2b:34:02:46:d2:65:c6:78:5b:5c:1f:ff:
58:77:9b:92:f8:ba:51:8d:86:db:cb:09:10:b8:f3:
40:77
Y:
06:21:22:2f:f7:5e:4b:1f:78:35:23:40:2c:9a:07:
07:48:82:41:0d:97:2e:9c:12:54:3b:01:95:36:58:
df:90
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
BE:08:43:19:7D:22:D9:D2:C0:0A:D5:67:5F:38:66:E1:5A:6E:D6:B2
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkfxPIMkAAAQDAEYwRAIgeyQYbPMUaC/AhOzNMbkfvCszNTulEYWaP4zJERItdswCIG/1JFzH0qC2S7IKUaA/6buRLO7ZEufn0NkUQrRrE2sP
Signature Algorithm: ECDSA-SHA384
30:65:02:30:35:5c:a6:a0:f9:b6:94:14:ba:9f:18:a4:0f:78:
a7:13:1b:e1:53:7d:c4:20:34:70:c5:8f:ba:31:03:f5:0f:fa:
db:60:d5:09:09:fa:a3:5b:ac:3d:20:16:0a:db:9b:5e:02:31:
00:e9:38:59:ff:d9:95:8f:09:34:0c:45:78:4c:cd:58:ba:b3:
4e:9a:66:6e:60:f7:a2:c2:16:ff:ef:6f:21:b3:10:fd:7d:47:
04:63:db:96:0c:ad:a6:98:a4:7c:48:48:f9
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJmZTVlMjM3MjYxZjk1MzU3OTBmMWY0ZWJmMDIyMDliYmMyNDg1ZWUzMDZkODFmYTZmMjlmNDg3MzliMTYzNDRkIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJR0t1TldPWENicldZMmlrb2NhNVM0TlA2V0ROZm9pZ3lWVzJRZ1NRREdtc0FpQldmdGtzNHRQd3JocEdISHBXRm1OYUdQWVMwZUhRek15eTg5S1ppSXlXSEE9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjVSRU5EUVdzMlowRjNTVUpCWjBsVlVrUk9Xa0kwUmt0dFFqZzBNVGxDVFdnNVYzSnBhMDA1ZEhoVmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJkMDlVUlRKTlZHdDVUMFJSTlZkb1kwNU5hbEYzVDFSRk1rMVVhM3BQUkZFMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVU1TmpsUlMzcFJRMUowU214NGJtaGlXRUl2TDFkSVpXSnJkbWsyVlZreVJ6STRjMG9LUlV4cWVsRklZMGRKVTBsMk9URTFURWd6WnpGSk1FRnpiV2RqU0ZOSlNrSkVXbU4xYmtKS1ZVOTNSMVpPYkdwbWEwdFBRMEZYTUhkblowWndUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlYyWjJoRUNrZFlNR2t5WkV4QlEzUldibGg2YUcwMFZuQjFNWEpKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBobldVUldVakJTUVZGSUwwSkNVWGRGYjBWUlpFVkNhbUZIUm5CaWJXUXhXVmhLYTB4dFVteGtha0Z3UW1kdmNrSm5SVVZCV1U4dlRVRkZRZ3BDUW5SdlpFaFNkMk42YjNaTU1rWnFXVEk1TVdKdVVucE1iV1IyWWpKa2MxcFROV3BpTWpCM1MzZFpTMHQzV1VKQ1FVZEVkbnBCUWtOQlVXUkVRblJ2Q21SSVVuZGplbTkyVERKR2Fsa3lPVEZpYmxKNlRHMWtkbUl5WkhOYVV6VnFZakl3ZDJkWmEwZERhWE5IUVZGUlFqRnVhME5DUVVsRlpYZFNOVUZJWTBFS1pGRkVaRkJVUW5GNGMyTlNUVzFOV2tob2VWcGFlbU5EYjJ0d1pYVk9ORGh5Wml0SWFXNUxRVXg1Ym5WcVowRkJRVnBJT0ZSNVJFcEJRVUZGUVhkQ1J3cE5SVkZEU1VoemEwZEhlbnBHUjJkMmQwbFVjM3BVUnpWSU4zZHlUWHBWTjNCU1IwWnRhaXROZVZKRlUweFlZazFCYVVKMk9WTlNZM2c1UzJkMGEzVjVDa05zUjJkUUsyMDNhMU42ZFRKU1RHNDFPVVJhUmtWTE1HRjRUbkpFZWtGTFFtZG5jV2hyYWs5UVVWRkVRWGRPYjBGRVFteEJha0V4V0V0aFp5dGlZVlVLUmt4eFprZExVVkJsUzJOVVJ5dEdWR1pqVVdkT1NFUkdhamR2ZUVFdlZWQXJkSFJuTVZGclNpdHhUbUp5UkRCblJtZHlZbTB4TkVOTlVVUndUMFp1THdveVdsZFFRMVJSVFZKWWFFMTZWbWsyY3pBMllWcHROV2M1Tmt4RFJuWXZkbUo1UjNwRlVERTVVbmRTYWpJMVdVMXlZV0ZaY0VoNFNWTlFhejBLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
"integratedTime": 1726514930,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 131133447,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n9283153\nt4lt+EU2SV0iyFg93ec4mPZER/NKSnaBS7JjOzs+0No=\n\n— rekor.sigstore.dev wNI9ajBGAiEAtheTF6mFEOtwqaF/PGFxamncQ+rT2rA734TP/OjP5kcCIQCl/oRpqIjov00UT+5VKG8fLMhgI1jSac4eo3Qj/P3WZg==\n",
"hashes": [
"85353cd9a9f73b95fe9b8485ff3f148d0f56fc9c7a3db5b7c620d2a2d12e2a9c",
"0cc8335884f815c18839f29ace1b37c746adad11356b8a5cbfa167cbeb808443",
"f6fe658eb13e1e1f57de8cba9bf4e671280eb52f9f6bc35fd81eafc327de4ab5",
"7d77a252188e8b91a076f96facf21faa5a016b59cb0cd57e674a1c59841d7900",
"944293fb06190afd3c479109329b95f8d76a23f91a2a597d19057e07eeff7a1e",
"0c337489a4b3b4a40124637325a2e6678b6b6b3f61e4bf3fd5420b8afc8afdcf",
"a5b65041ca1db92dfbf1f4f75bd49907375fc39a3d9ba594d59e6fb7cd63d63c",
"22236b034cc807b2db264874e6eb024ea7df80865730d1de5c679880b323f438",
"e39ca57a9ef3838bed5ea291b72d74aba0a1f25eb99c5e794e0258be0c2cc80a",
"6d74c0bbe5419b1192e081ddac105eacb56aea1f3235a06e421e27c3169d9b3f",
"ceaf34f13bc6c3de84dddc6e3db8179167f34716ba409673b10984f66a58699f",
"30e9e726aadcb6ac7bbf6f2fde398b2bbf0b7d046457762ac9e02b8d21e11c1d",
"bc30181b823f379622a790121978d3d0714f9461d30b66c956e193de8bd88484",
"87be4aa339a65dfa55e73992c1ed81a171255787425c398e1358964913ec34dd",
"8dacd805eba9cbcab35b1b872de5552b814e1ebe4a2af6ed6dd45b4c9e83b6fd",
"1d89e601d6234555b5199a1627efc7ac4278ea00ece2e45031444249e2740e8b",
"c003144cec9ef54e4cecd361b1088ae0c1a418286323e3941354d3480519edb7",
"968ca46b8665a8532975b366a52e35f57350b84c37a29b755017d2e33957eb89",
"958202826697e3bf2f1b7ab3c8da63a8e2997fef47a6274d90a7b935329af90c",
"9bc8e601d7371c40caaafbc82a61a1aa88a502fa81c5986c92d5e65e1e7c5a20"
],
"logIndex": 9229185,
"rootHash": "b7896df84536495d22c8583ddde73898f64447f34a4a76814bb2633b3b3ed0da",
"treeSize": 9283153
},
"signedEntryTimestamp": "MEUCIQCeCUQ4Cieft4qTPTDIe7IoT6RTmAbRCAhPEh/7dLkLNgIgAmlYGHfr5Nsr7cho92pzWAIsSz7SLrEL1b0zyKBe/eU="
}
}
Loading