sbom: Use layer digest for layer package version #2018
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jan 14, 2026 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 701493428019431035129344950343038739917922584112 (0x7ae00da070836ccf7dfce5e01cf7b3cb73234630)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Jan 14 16:27:48 2026 UTC
Not After : Jan 14 16:37:48 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
f2:2f:c9:db:7c:67:47:df:5e:97:7f:56:fe:88:e2:
fc:9d:4a:1e:f1:a6:ca:5a:ca:df:8a:68:57:4e:f6:
71:77
Y:
9d:af:fa:23:4f:bf:2f:66:cd:07:1a:01:e8:20:eb:
cb:d7:5b:01:5e:68:16:02:7c:23:bb:e9:5a:94:f7:
5d:85
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
F9:E8:CC:5F:CC:1E:84:69:27:84:EF:66:45:89:B5:A8:C6:5A:50:03
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:billy@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABm71VslQAAAQDAEcwRQIgcap6fc1PzV65950L6wCbMi937/KvOWta9dMmPnYhEBsCIQCZSayhYuWNN1xJG93sa4Jg0EW67OJpv5bsw6bSJ5ATxw==
Signature Algorithm: ECDSA-SHA384
30:65:02:30:40:d5:1d:83:e1:dc:30:e5:40:e1:18:db:6c:19:
f4:59:fd:19:a1:5b:c4:d3:64:49:b4:26:b7:0c:cd:2a:07:6a:
c5:95:58:7e:86:1d:38:92:68:3d:69:fa:51:c0:14:7c:02:31:
00:e7:67:58:ca:70:10:28:7d:70:75:68:22:71:25:49:2d:e5:
2f:7b:8c:f7:4a:fe:03:a0:90:35:8d:54:7c:52:52:52:de:9c:
e5:90:c8:f3:30:e2:ba:90:9a:c2:93:eb:85
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI0ZDBkNTY5NTkzMTNlOWFjMWJkMzJlNzNjMWQwYTA4MTMyNTE0NzFiNjkzYjlhZjMwNDFkMGU4NWUzZGI1ZTc4In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJRk03VzA4NW1YTlRCSFJXVXVIUUFDOEN5eTN2eDJYcHhrRG5EZnRjN29nTkFpQmQ1OGkvL2VIRnNMSVVwYzE4QURaUXZmVG9LakdvTmdjOWxQNjFmc2dRY3c9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjZWRU5EUVd4UFowRjNTVUpCWjBsVlpYVkJUbTlJUTBSaVRUazVMMDlZWjBoUVpYcDVNMDFxVW1wQmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDFVUlRCTlZGbDVUbnBSTkZkb1kwNU5hbGwzVFZSRk1FMVVXWHBPZWxFMFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVU0YVM5S01qTjRibEk1T1dWc016bFhMMjlxYVM5S01VdElka2R0ZVd4eVN6TTBjRzhLVmpBM01tTllaV1J5TDI5cVZEYzRkbHB6TUVoSFowaHZTVTkyVERFeGMwSlliV2RYUVc1M2FuVXJiR0ZzVUdSa2FHRlBRMEZZU1hkblowWjFUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlVyWldwTkNsZzRkMlZvUjJ0dWFFODViVkpaYlRGeFRWcGhWVUZOZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBsbldVUldVakJTUVZGSUwwSkNaM2RHYjBWVldXMXNjMkpJYkVGWk1taG9ZVmMxYm1SWFJubGFRelZyV2xoWmQwdFJXVXRMZDFsQ1FrRkhSQXAyZWtGQ1FWRlJZbUZJVWpCalNFMDJUSGs1YUZreVRuWmtWelV3WTNrMWJtSXlPVzVpUjFWMVdUSTVkRTFEYzBkRGFYTkhRVkZSUW1jM09IZEJVV2RGQ2toUmQySmhTRkl3WTBoTk5reDVPV2haTWs1MlpGYzFNR041Tlc1aU1qbHVZa2RWZFZreU9YUk5TVWRMUW1kdmNrSm5SVVZCWkZvMVFXZFJRMEpJZDBVS1pXZENORUZJV1VFelZEQjNZWE5pU0VWVVNtcEhValJqYlZkak0wRnhTa3RZY21wbFVFc3pMMmcwY0hsblF6aHdOMjgwUVVGQlIySjJWbGQ1VmtGQlFRcENRVTFCVW5wQ1JrRnBRbmh4Ym5BNWVsVXZUbGh5YmpOdVVYWnlRVXB6ZVV3elpuWTRjVGcxWVRGeU1UQjVXU3RrYVVWUlIzZEphRUZLYkVweVMwWnBDalZaTUROWVJXdGlNMlY0Y21kdFJGRlNZbkp6TkcxdEwyeDFla1J3ZEVsdWEwSlFTRTFCYjBkRFEzRkhVMDAwT1VKQlRVUkJNbWRCVFVkVlEwMUZSRllLU0ZsUWFETkVSR3hSVDBWWk1qSjNXamxHYmpsSFlVWmllRTVPYTFOaVVXMTBkM3BPUzJka2NYaGFWbGxtYjFsa1QwcEtiMUJYYmpaVlkwRlZaa0ZKZUFwQlQyUnVWMDF3ZDBWRGFEbGpTRlp2U1c1RmJGTlRNMnhNTTNWTk9UQnlLMEUyUTFGT1dURlZaa1pLVTFWME5tTTFXa1JKT0hwRWFYVndRMkYzY0ZCeUNtaFJQVDBLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
"integratedTime": 1768408068,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 821386356,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n699482241\ngNSbz/OYUTZWyW9cNPhykTKFK/QjJ4QFTbrqzjrM7bA=\n\n— rekor.sigstore.dev wNI9ajBFAiEAgHTwCfSQKFtJ/Pu7Zhow2bsQvGAsD3NP6m1g5Tr3Ag4CIEeSn1m5gZi6WkpsaT7EHoXrTSNKFRG7KedgsXPLmN6E\n",
"hashes": [
"70a0a4a668a4406260b4e72541a0e7615e7a2a4da7ac170b05c32b336f71f08d",
"44261ac10a3c15c69e9d087d2c9b5874382283f67945abd2c3aa1d3b1efb6c5d",
"703e6bbd2a376480eb4c39436d4460ed36bd5ee8c212800753cbb5f1161c7ee4",
"0dbf2d3b339cec68dfecc14b6e273b2beecad87d5d12ea1508802ea07d3ea7d0",
"1bff333b18f3fc2733d1d35fead31adb504f6fa8e5d2df946853d70a9ad6dd6b",
"bd6114afdc483f50eae4be1bf85c3c2e0c1a9eca40c45463e0551ca4ce0ea10f",
"edbddfb9ea493578bd42c36f231d7aa6dfc52ebce6fe291f7a78036a5b663967",
"9ab560f76c208f59656b7137daf3b9b668920005a289a76e94af46274f765f94",
"d7626b2fb0168ac035af2dba248ad8f3ea94f58079c50b61e311999eb1b79807",
"6443036abc2642620d9f0bdc842855afcce432ae362a6abb4fd6f9f6b4198be2",
"086e794d25ac4fa755b0851b8fe8fbc1c69b73b069c225e340bdd3b7194f71be",
"f4a1602b1e90a4b68d5e8e69b2c18e917e847ef3d66e162614aeddfed3915afc",
"a575736806625fc25b923703d9b9b216be9fcb17ccce5178b8f4b5b1ccbec788",
"fbb6d3f291334fca5a6df4be9b5300382c18da8c6232eb1deb1d2e54001d4c0a",
"2c7839ab2a5cbabba1f79e095a0cf74de592fe1b8e45cfecd81e1951304a5541",
"1d59690bca9fb88f0f0096c82e588a162ac451fc0b9d4dd35cffd018cc57f39d",
"385df44883c1d2317849bb19195e601f7342f41af7b16bdd68d9528df1d9abe7",
"ba2c538d8ee960e245d2d3549759b56d6b64cda7a634ecf1401b1f239c54f00c",
"a3c340e6d1b7d03d1269166ad4189b726dcc965af060d57c87afe593887a1cb0",
"40d3826bf31d2c5e3f63f0ca53fa284838dd4caa9d0cda66e684857dfcb71311",
"17d3124394a6a05afe868003725a5d158e76fd32df1c39cd3d86fd64d60ee602",
"4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
],
"logIndex": 699482094,
"rootHash": "80d49bcff398513656c96f5c34f8729132852bf4232784054dbaeace3accedb0",
"treeSize": 699482241
},
"signedEntryTimestamp": "MEQCIF6510pAIWzRU3iC6IKOqYzg8zu9Jn0OOBJ9qxgjjEeHAiAjJfRB2APDF+UneAdKTtSiLNYmXwP5WTKXZV7DNvyurQ=="
}
}
Loading