Skip to content

fix(apko-as-apk): avoid re-resolving already-installed packages when …

c5d75a3
Select commit
Loading
Failed to load commit list.
Draft

apko as apk #1920

fix(apko-as-apk): avoid re-resolving already-installed packages when …
c5d75a3
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Dec 12, 2025 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 723848017830018258579336056880292945005739274355 (0x7eca77bb8861cc0e4cba6df249878f92e0907073)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Dec 12 18:00:37 2025 UTC
            Not After : Dec 12 18:10:37 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    b5:32:69:3d:be:52:54:10:c5:8b:35:88:18:29:cc:
                    d8:bc:cd:8a:ac:56:30:55:f8:2b:f0:c3:1f:77:7e:
                    6a:44
                Y:
                    dd:f8:a8:7b:39:a4:c2:a1:fc:e6:e7:2d:9f:20:02:
                    a1:94:28:28:62:15:43:a2:7e:15:7e:b0:6b:b0:a0:
                    30:1b
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                14:09:23:74:14:AC:05:F5:E6:DA:9F:25:13:4F:27:CF:6B:FE:58:B6
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:scott-moser-work-v2@chainguard-workstations.iam.gserviceaccount.com
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmxO4zswAAAQDAEcwRQIgLa6y5x6uTPdcQesft9Ft6FueJeAvsd76Efy6CUx0KagCIQDw5tFsja6Mg3emCY/scfw3PC8TAC8QKC+GyqnTY0GzdA==

    Signature Algorithm: ECDSA-SHA384
         30:64:02:30:0b:44:76:8b:83:5d:c8:9f:85:0a:16:46:c1:a9:
         ac:e9:20:2b:c1:f9:15:60:c3:1a:c8:43:c6:eb:4b:7a:33:6f:
         41:96:64:be:a5:d9:e0:87:ab:2f:c9:00:c8:7f:f7:bf:02:30:
         62:1d:14:63:8c:fb:e7:9c:34:64:ed:15:da:18:80:d2:c6:09:
         b6:5b:71:9e:d4:be:5c:d7:47:88:7d:56:1e:e2:28:7b:34:79:
         81:10:7b:18:bc:fd:0d:24:fa:74:03:41

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJjYzkxNDE1ZjBiNzQxZGY5NjAxMDVlOTMwOGI0NDk2ZDRkOWZhZmM3MTE5NmQ2MDgyNDBjMjVmZDc0N2RmYzYzIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJQk9peHdvY2JtTFQrV0QvMzQzZ2pRTkVNYlQxRkRJaXRSdUFUZHJZQS8rNkFpQWlsaGpGaEIxNkRuZVFaSXNPUUZoem1vMmhJV09ERHBiZnpobnJTTnNJUWc9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXJla05EUVc5TFowRjNTVUpCWjBsVlpuTndNM1UwYUdoNlFUVk5kVzB6ZVZOWlpWQnJkVU5SWTBoTmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFxUlhsTlZHZDNUVVJOTTFkb1kwNU5hbFY0VFdwRmVVMVVaM2hOUkUwelYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVYwVkVwd1VHSTFVMVpDUkVacGVsZEpSME51VFRKTWVrNXBjWGhYVFVaWU5Fc3ZSRVFLU0ROa0syRnJWR1FyUzJnM1QyRlVRMjltZW0wMWVUSm1TVUZMYUd4RFoyOVphRlpFYjI0MFZtWnlRbkp6UzBGM1J6WlBRMEZoUlhkblowZGtUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZHUVd0cUNtUkNVM05DWmxodE1uQTRiRVV3T0c1Nk1uWXJWMHhaZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDFWUldVUldVakJTUVZGSUwwSkZZM2RTV1VaRVl6Sk9kbVJJVVhSaVZ6bDZXbGhKZEdReU9YbGhlVEV5VFd0Q2FtRkhSbkJpYldReFdWaEthd3BNV0dSMlkyMTBlbVJIUmpCaFZ6bDFZM2sxY0ZsWE1IVmFNMDVzWTI1YWNGa3lWbWhaTWs1MlpGYzFNRXh0VG5aaVZFRndRbWR2Y2tKblJVVkJXVTh2Q2sxQlJVSkNRblJ2WkVoU2QyTjZiM1pNTWtacVdUSTVNV0p1VW5wTWJXUjJZakprYzFwVE5XcGlNakIzUzNkWlMwdDNXVUpDUVVkRWRucEJRa05CVVdRS1JFSjBiMlJJVW5kamVtOTJUREpHYWxreU9URmlibEo2VEcxa2RtSXlaSE5hVXpWcVlqSXdkMmRaYjBkRGFYTkhRVkZSUWpGdWEwTkNRVWxGWmtGU05ncEJTR2RCWkdkRVpGQlVRbkY0YzJOU1RXMU5Xa2hvZVZwYWVtTkRiMnR3WlhWT05EaHlaaXRJYVc1TFFVeDViblZxWjBGQlFWcHpWSFZOTjAxQlFVRkZDa0YzUWtoTlJWVkRTVU15ZFhOMVkyVnlhM296V0VWSWNrZzNabEppWldoaWJtbFlaMHczU0dVcmFFZzRkV2RzVFdSRGJXOUJhVVZCT0U5aVVtSkpNblVLYWtsT00zQm5iVkEzU0VnNFRucDNka1YzUVhaRlEyZDJhSE54Y0RBeVRrSnpNMUYzUTJkWlNVdHZXa2w2YWpCRlFYZE5SRnAzUVhkYVFVbDNRekJTTWdwcE5FNWtlVW9yUmtOb1drZDNZVzF6TmxOQmNuZG1hMVpaVFUxaGVVVlFSell3ZERaTk1qbENiRzFUSzNCa2JtZG9Obk4yZVZGRVNXWXZaUzlCYWtKcENraFNVbXBxVUhadWJrUlNhemRTV0dGSFNVUlRlR2R0TWxjelIyVXhURFZqTVRCbFNXWldXV1UwYVdnM1RraHRRa1ZJYzFsMlVEQk9TbEJ3TUVFd1JUMEtMUzB0TFMxRlRrUWdRMFZTVkVsR1NVTkJWRVV0TFMwdExRbz0ifX19fQ==",
  "integratedTime": 1765562437,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 762045746,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n640197187\nRx0ullrM8CsOvm8pC8myawqBh2oiivEYr/rFMUZpZsQ=\n\n— rekor.sigstore.dev wNI9ajBEAiBxvNVFe7+MyHZNuVbqs1YAoK4eLqr0+WzAKMPnuRhOMgIgeb5w0dyE+XuskWLLzMVHek/W8nReMfiUz+sBmcx2dBE=\n",
      "hashes": [
        "94a7efd0e684b68b1cc64122a5c65ccdd862f1fbc9d3a16d67e30887bf4c9329",
        "702a411efa566d56ca90946032db8bef68b3fe9070c2714cb4f7da79a2fed47c",
        "39a35aad862b6b3b8a4122f46fa82379adb9bbe75b7dabecc762ad285d4ee320",
        "8fa215ac3a7d5fc120a52eb2af8518bf015109f95d6df5c617971b441e561b4d",
        "e82c9ce03091304fff78ad085fbda805a47cb592a2183e835c83f7297abbf433",
        "24bf8965eaa8c4abbe13b2b407573977a83fd9cd63b0283546fc2f3caff8d772",
        "80fac08f42df20c90e8c2e7afaff5596ae103168e4b27ed1841cf8c8fa3efb29",
        "711f559825295c864903eeebf3528076cd3309056702068ba5b45ffce68857bf",
        "8d66d99f887cabc76f96044f31d9c9c03118cd5b620626cb9e0055389551a1e9",
        "1c44e04dfcb23c67c3e4098a6c20b20deefeac16f10680bb70e95f56be4b8c4f",
        "c982da84317d16fb4c2bf855f35526d76fc15d7bca66203aa4b1d1c6bc27787b",
        "aee6edc6c27d266ceefa27af3fa2c41d5f7c3a165cf7757723bc2e5dd3a2a15f",
        "14661cce54e423fefc4917378cd2ac294d029b68208480cdc581d994926f3d79",
        "ae7e368ae0c200858ec9fa28503c2fd6029569e5902497cdf330a96ffc81da7c",
        "580cccbc0ba00a24f2b32e8a7a4b5ece85dc33a6c734288124a556c7d13b9b50",
        "64e17a657a42c03ca1bf309c1dedd8c311e17094aedbf97257140d9a841a28bf",
        "af576b46316ba6b44fd65cb024c7837b06f6d3552b5fcefefb6f2c33a9322031",
        "c084e13c2353dbf4b28beed11ac573104bc094066fb071ff1a55b7b140e23ef7",
        "d4593eced7b9ce5f0ee55f34596fbb1dc81cbd88f729fd4c408e0b71777deaf4",
        "7fb8d0c8a6fe1ffa89f5b060d020ee0e42a63c7bc414501ae1578b8d059fba68",
        "3903c886538e2cc147f26a08b6be423d5c61d63c2eb207784bec18068c5e39ec",
        "5fabe4c73d29a312b60c8951babffb2db11dcf78835e3e5063f80b93f7b05e30",
        "6665246241c1cb507bdb726b12088abdea5374762b3facb66b8a0e0d8be2e556",
        "4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
      ],
      "logIndex": 640141484,
      "rootHash": "471d2e965accf02b0ebe6f290bc9b26b0a81876a228af118affac531466966c4",
      "treeSize": 640197187
    },
    "signedEntryTimestamp": "MEUCIFzezjuPeZMOGVI74mx8Q1d6/Uh7LuwbEX9rFijthbDBAiEAy/7O+G+KeYUdE3hxpWK+t21uxfC82tTxJ2HiLgfeab0="
  }
}