fix: pass cap add/drop to ssh session #2032
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jun 12, 2025 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 478536747927014966604268391406291608487560174132 (0x53d254759f6876b1e838c7b9c81481e3c57b5a34)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jun 10 15:23:29 2025 UTC
Not After : Jun 10 15:33:29 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
cf:28:2a:8a:cd:91:f2:ee:99:68:7e:a0:63:d6:78:
fa:a9:9d:97:16:69:03:17:c4:b4:b7:d5:cf:52:e3:
f0:09
Y:
31:d9:32:96:2e:05:79:d4:7b:16:91:40:dd:ff:e7:
a2:11:84:8b:02:d0:b3:46:e2:4e:6a:3c:a3:ad:a6:
25:b4
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
2F:91:92:16:4D:81:02:57:D3:42:23:4B:3E:79:31:02:92:97:08:42
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABl1pwddMAAAQDAEgwRgIhAJVoMROqWe59S7fp/UHjgUpvXIs88UqQH13ISxrRiztrAiEAggbJVyZsS6GhTU5ILbIuBqfzx1npc6gHXikKYVt72ns=
Signature Algorithm: ECDSA-SHA384
30:64:02:30:58:b5:11:fd:5f:77:74:49:da:0c:6a:ad:db:73:
7b:b3:67:01:78:a2:99:c4:8e:4e:f1:61:5b:5e:59:75:53:1a:
6c:dc:61:f9:da:05:aa:08:7e:91:0b:db:a5:47:35:ca:02:30:
7c:c5:65:85:12:5c:6f:b9:20:ca:a7:5e:40:2a:3a:40:f5:5c:
55:f4:15:df:6b:6c:40:6a:b5:a1:83:90:1a:ff:0a:30:19:36:
91:81:49:18:60:18:80:8f:ec:d0:36:c7
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJmMWJmYzRhYWUzZmRiMDBlYWExZjA5ODYxMDEyYzhmNjhiM2RkNTY1N2NjMTYxMzBiOGViZTdmYzNkNjcxNDVhIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRDVCY1FsRk5EUDlpazV0VzdRTDRLalZqMlVENzV3R3dja1pwMExtTkxVcUFpRUE5Rjd0NHh2cU5XSW9LaWJRRHpwam04R1dlREh5VHhUT2RIbU9WaVRYRm44PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4eFowRjNTVUpCWjBsVlZUbEtWV1JhT1c5a2NraHZUMDFsTlhsQ1UwSTBPRlkzVjJwUmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVxUlhkTlZGVjVUWHBKTlZkb1kwNU5hbFYzVG1wRmQwMVVWWHBOZWtrMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVY2ZVdkeGFYTXlVamgxTmxwaFNEWm5XVGxhTkN0eGJXUnNlRnB3UVhobVJYUk1abFlLZWpGTWFqaEJhM2d5VkV0WFRHZFdOVEZJYzFkclZVUmtMeXRsYVVWWlUweEJkRU42VW5WS1QyRnFlV3B5WVZsc2RFdFBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZNTlVkVENrWnJNa0pCYkdaVVVXbE9URkJ1YTNoQmNFdFlRMFZKZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0QldVUldVakJTUVZGSUwwSkNOSGRJU1VWaFlraFdhbGxUTld0aFZ6Rm9ZVmM1UVZreWFHaGhWelZ1WkZkR2VWcEROV3RhV0ZsM1MxRlpTd3BMZDFsQ1FrRkhSSFo2UVVKQlVWRmlZVWhTTUdOSVRUWk1lVGxvV1RKT2RtUlhOVEJqZVRWdVlqSTVibUpIVlhWWk1qbDBUVU56UjBOcGMwZEJVVkZDQ21jM09IZEJVV2RGU0ZGM1ltRklVakJqU0UwMlRIazVhRmt5VG5aa1Z6VXdZM2sxYm1JeU9XNWlSMVYxV1RJNWRFMUpSMHhDWjI5eVFtZEZSVUZrV2pVS1FXZFJRMEpJTUVWbGQwSTFRVWhqUVROVU1IZGhjMkpJUlZSS2FrZFNOR050VjJNelFYRktTMWh5YW1WUVN6TXZhRFJ3ZVdkRE9IQTNielJCUVVGSFdBcFhia0l4TUhkQlFVSkJUVUZUUkVKSFFXbEZRV3hYWjNoRk5uQmFOMjR4VEhRcmJqbFJaVTlDVTIwNVkybDZlbmhUY0VGbVdHTm9URWQwUjB4UE1uTkRDa2xSUTBOQ2MyeFlTbTE0VEc5aFJrNVVhMmQwYzJrMFIzQXZVRWhYWld4NmNVRmtaVXRSY0doWE0zWmhaWHBCUzBKblozRm9hMnBQVUZGUlJFRjNUbTRLUVVSQ2EwRnFRbGwwVWtnNVdETmtNRk5rYjAxaGNUTmlZek4xZWxwM1JqUnZjRzVGYW1zM2VGbFdkR1ZYV0ZaVVIyMTZZMWxtYm1GQ1lXOUpabkJGVEFveU5sWklUbU52UTAxSWVrWmFXVlZUV0Vjck5VbE5jVzVZYTBGeFQydEVNVmhHV0RCR1pEbHlZa1ZDY1hSaFIwUnJRbkl2UTJwQldrNXdSMEpUVW1obkNrZEpRMUEzVGtFeWVIYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1749569009,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 234188338,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n114408409\nsVKIiz6FtLFZZjN327T0+lxKxHrcVutblHXHWYJz5Nk=\n\n— rekor.sigstore.dev wNI9ajBGAiEAw9e4H6u7nU5ujzbFtyvkZG8LR0vV9Rf5rGtWfdxHoVICIQCAnrJaHIFTFqSBqF/coqVEaxAd1pRx3GjWzi08W9l9lA==\n",
"hashes": [
"dc50063cfc5e7b5cd4b5b4185f4fffb83544278589c9cb290cc34821daea9421",
"b311a31defe6a8600ddaf99d78cf93bc40f0e5ae48f432e43a673efd1b9fcd28",
"7b5b29754d5d424cff6573a6b946a58e7da530ed5898be0426e393d843c8b11f",
"25ba3b1d7a6aa5804e4637631acf515cbbea8ed5f01b6656e6e9b75f04fd7395",
"2ea492e5bb09929a5d276dd4de3c1dd7d13f3a8de4058adf9f1e9b050c1d3ac2",
"2c98741c1732374f210678a759cf86fbb8408dc090d288232cfeefe4840dd146",
"5824d60cd025b9b5e9f93cee8a511d36ed27cd41eda0c95ca0e4550aeff2bf24",
"fabe17504fc5012d3d9f99fb3190b26101f7a3d410fe0d30b5055979b6d73db7",
"14fa7498a9b4d2aa957521e94d7186f194f61a6bcfa3b27708c89764248d3367",
"0bb5ed5be96e3f16808c7e78273cf48930e249d226e31cb73d72dc1898c83fef",
"2da0c00a6fa7c38bd7ee355c2f5f592e1328208f3f9ad7679936c8909dc1ce8d",
"5c0857282bd8b28c20101d544b8198322644f38f4210490a9b928f67ba98e6ad",
"82031fe287492baff9e78fd4ac42a84d816e4b9268d7213e283d96ef29611aee",
"36d478a1f0461f7bf871d28bc97b6ac66e59ca0437f6bdcb09437d40d6c60a69",
"990b22f42f8b402e327db8cc7711b91ecfe6549b6e90c03d2d6104974fc7e62f",
"c49be60bb90270c33e88b30e392bb43870d72ae5c9e83def34c9be3676b71630",
"a7d9806568f8a3976d3a8936bcd871783a0c7fa663722040f89ec650635f06e0",
"49ddec8149106ccc3e5f5707320daa00b4a4c6f2bae617c8672c6209b7a3b916",
"e95c337487f00cff2ae064b2e99cecb797d74d46478a3f85fee46f687937530b",
"09bddfbb478ed1dfef5b42d9ef25bda38708fdc09500075d05b811e510067904",
"28bef7dd5ea6da629ab333e879b45895dde0f9771448d95d9ba1a75c6e0cee43",
"7f8d9c3883e7ac1f71f8760a67eed40245ca8e4ee4f6db6fc75326e7f8250b0a",
"8d41346e74939a5f891f3127aab0321f182b1339eff318efee29889c124c5d56",
"1b809d3f3ff18e8a962381bcef8b5958f78ff7c0c9a6c7b28a1aedcf48af06d5",
"9ad6b97c7fe0170c49ff47d3f321a99f7b05098d06d51639e7921f966d0b2273",
"eeff2a3c73432deae976e68cc74e9e6ff3308284307334e7fdc606297ffdc19e"
],
"logIndex": 112284076,
"rootHash": "b152888b3e85b4b159663377dbb4f4fa5c4ac47adc56eb5b9475c7598273e4d9",
"treeSize": 114408409
},
"signedEntryTimestamp": "MEQCIF+x4WjuPyedgSbmJwBrBxEX36K39d+8/we+WjH3+fYSAiAKeUWpl2R8F50ZFsudGlmsVEzfOlK+ujwpIuRPo9Pr5w=="
}
}
Loading