Skip to content

Bail on any file related errors

5296d5b
Select commit
Loading
Failed to load commit list.
Merged

Check for validity of the cached expanded APK more thoroughly #1987

Bail on any file related errors
5296d5b
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Jan 5, 2026 in 0s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 579192651021121543093453445237906420885765188745 (0x6573e58f48646e81544d46bf4cea3c4a21bb6c89)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Dec 17 18:44:58 2025 UTC
            Not After : Dec 17 18:54:58 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    29:c9:78:7e:53:7a:a9:15:c2:bd:f8:f0:3f:ad:88:
                    cb:bf:d5:1a:f1:47:f1:ac:d6:08:1d:ed:4e:41:04:
                    0b:5c
                Y:
                    ff:e4:77:76:d1:e2:4a:e5:d1:1e:e7:9f:41:a7:e9:
                    01:7a:c4:69:21:a1:95:c5:da:11:ac:30:56:11:b0:
                    08:e8
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                C5:16:F5:C0:5B:3A:7B:BA:D3:98:E6:BF:81:F2:4E:40:A1:24:4C:FE
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:markus.thoemmes@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmy2hNKsAAAQDAEgwRgIhALvuyb+trG0BlLtrE+eDw4M7RBQYL+S6kMfOj0eQWubJAiEAwPZE2qAxgAaOi2WxDZMv5TL2QY6OT0THR5AM61Z+fwk=

    Signature Algorithm: ECDSA-SHA384
         30:65:02:31:00:c0:35:76:4d:f3:0a:ea:3f:d8:ec:cc:11:9d:
         d7:3a:76:40:ad:e5:f1:6f:72:64:c1:b7:02:d3:25:c9:05:1e:
         5a:c5:53:ad:0a:dc:77:6d:d7:fe:c7:e1:85:e8:b6:87:a3:02:
         30:18:0d:cc:4c:d7:64:54:31:83:82:48:99:8e:b6:b6:dc:a2:
         28:27:81:0b:5c:70:76:60:6b:15:bd:31:9c:6f:b0:58:66:16:
         1a:73:b0:8c:12:19:50:6c:16:29:88:a8:4d

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJhM2YwNjJmN2FlZjlhNjhkNzc4MDdjN2U0MDdmNDdjMmFlNWViYzcxYjNmZTIxMDZjN2M1M2U5MzljYWE1N2MzIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQnZqUHJJWUpsZGNzRXZYdzdqd0VZUEFGVm1yQTJkZXpRRkhyM2VGUUdRWkFpRUFwUWhsdjRrVWFmQjBGelhpbzVOamhaY3haZytnQkpFT1RiSHJ5Y242T1NVPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXlSRU5EUVd3MlowRjNTVUpCWjBsVldsaFFiR293YUd0aWIwWlZWRlZoTDFSUGJ6aFRhVWMzWWtscmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFxUlROTlZHY3dUa1JWTkZkb1kwNU5hbFY0VFdwRk0wMVVaekZPUkZVMFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZMWTJ3MFpteE9ObkZTV0VOMlptcDNVRFl5U1hrM0wxWkhka1pJT0dGNlYwTkNNM1FLVkd0RlJVTXhlaTgxU0dReU1HVktTelZrUldVMU5UbENjQ3RyUW1WelVuQkpZVWRXZUdSdlVuSkVRbGRGWWtGSk5rdFBRMEZZTUhkblowWTFUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlY0VW1JeENuZEdjelpsTjNKVWJVOWhMMmRtU2s5UlMwVnJWRkEwZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB4QldVUldVakJTUVZGSUwwSkRTWGRKU1VWbFlsZEdlV0V6Vm5wTWJsSnZZakpXZEdKWFZucFJSMDV2V1Zkc2RWb3pWbWhqYlZGMVdrZFdNZ3BOUTJ0SFEybHpSMEZSVVVKbk56aDNRVkZGUlVjeWFEQmtTRUo2VDJrNGRsbFhUbXBpTTFaMVpFaE5kVm95T1haYU1uaHNURzFPZG1KVVFYSkNaMjl5Q2tKblJVVkJXVTh2VFVGRlNVSkNNRTFITW1nd1pFaENlazlwT0haWlYwNXFZak5XZFdSSVRYVmFNamwyV2pKNGJFeHRUblppVkVOQ2FYZFpTMHQzV1VJS1FrRklWMlZSU1VWQloxSTVRa2h6UVdWUlFqTkJUakE1VFVkeVIzaDRSWGxaZUd0bFNFcHNiazUzUzJsVGJEWTBNMnA1ZEM4MFpVdGpiMEYyUzJVMlR3cEJRVUZDYlhreWFFNUxjMEZCUVZGRVFVVm5kMUpuU1doQlRIWjFlV0lyZEhKSE1FSnNUSFJ5UlN0bFJIYzBUVGRTUWxGWlRDdFRObXROWms5cU1HVlJDbGQxWWtwQmFVVkJkMUJhUlRKeFFYaG5RV0ZQYVRKWGVFUmFUWFkxVkV3eVVWazJUMVF3VkVoU05VRk5OakZhSzJaM2EzZERaMWxKUzI5YVNYcHFNRVVLUVhkTlJHRkJRWGRhVVVsNFFVMUJNV1JyTTNwRGRXOHZNazk2VFVWYU0xaFBibHBCY21WWWVHSXpTbXQzWW1ORE1IbFlTa0pTTldGNFZrOTBRM1I0TXdwaVpHWXJlQ3RIUmpaTVlVaHZkMGwzUjBFelRWUk9aR3RXUkVkRVoydHBXbXB5WVRJelMwbHZTalJGVEZoSVFqSlpSM05XZGxSSFkySTNRbGxhYUZsaENtTTNRMDFGYUd4UllrSlpjR2xMYUU0S0xTMHRMUzFGVGtRZ1EwVlNWRWxHU1VOQlZFVXRMUzB0TFFvPSJ9fX19",
  "integratedTime": 1765997098,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 769041349,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n669555967\nay57xTW7Le7HH/80t1G4vf8w0TlaVApgJVnSFTbZHUA=\n\n— rekor.sigstore.dev wNI9ajBFAiAoR+FKe7klHCkOFo9ppglOHkJshyNiygDukVb9be8yiwIhAKV8eQYx2PMEGTwExAb1itnBJVhmLdon6Dv1bolUgtjX\n",
      "hashes": [
        "f7d75312c85cb636d4076768677ec16c746ac4348c0e5e7aac10aedaf1004121",
        "f28a9299b4cf9a9f72902993c53c10aeb5c70495a7a36f8ef495efc940c4d60a",
        "9eaede6c1e16db73eb93058700e62a0a1e7622526a66c56d820b47351c465b35",
        "c9eb22aa1826fc2ae0403872b87da0a980dccb60af8855ae0ec8e725f6591bb2",
        "0207d8ad1f1161f23014e1407017068d55fb45cad6db8232aa5297d1be061892",
        "d13f9363d031a18498501c72827168e971facf36ddc1ef26edac3d6fee406079",
        "3b234a7539e83fffa09ce817062f7257213e672bfcc4937e3146e9c7cfb60989",
        "c764b3c220f7c65f2efedfc00c0b84e4ad7f13c02b8d2bba33241cd35d339f73",
        "2b8c3a09d44bacf0a9236a7541664e317db8429f50328a1583f2b0c849a55adb",
        "9481b62d6c67b3bcfdffeedc89ab4a7923a388567a046b505d36159bcb0ed910",
        "19b19f628b0df976cc4566605203b66eb3c885d88f9c7782628d0ac62744aa9e",
        "4be88b422e92d9b97c47a2141fdf2f23392173076dd4f88acb2a3437563c1d85",
        "c23a6efdd574c08b5094b2aef9fdbb6874c5da0f7898f1f16a97647c7fcdaf7e",
        "da2804bb59ae663d250ae3f6af212ca304a243cb87938c46218e0d13a87d0b31",
        "5cfda565d2dde1b5252a77a8172f5d70e57b095d1975ef972924e37d31bc3828",
        "17e6bed524599b3e539486d93cf3d351cb3c2a7cdb53a9763ce5e2036c35c4a9",
        "aba6c2d74b815852cdb12877d3b54ac1836ec2ef363b8b976f7093cb26e8490d",
        "7a1824d0a0bec6be4212aac35d60034335086a0c771465f2f9f16c4e336a5e9a",
        "8e966fb0da62d541c145ef93a0c5b78798825824fbaa2e048009fcf03638e76d",
        "ab15504914b588f62faf2e90fefe1cc74d782786ecebfa780f4e05121f277be3",
        "4a94a31402d0c62e7002c040d0a6f85113d7cd73a04070009836e13c8796a0e2",
        "6699f2f476a94ff4aef79ece42625c35b6b18134a19cf9656b359f44a0cd7ed7",
        "067a3f57d5b9fb338ddd681536b85a01b608fcbe6d6ef4933ef803be67f4f2b2",
        "f77b31120ccefe0edc190e22db2b4f270489e0665a852a101720c5d4b6503de6",
        "051100510dbffb45d51da1fb79e9a3402f327aa2b84bb856efb25e5ccb209d3b",
        "5fabe4c73d29a312b60c8951babffb2db11dcf78835e3e5063f80b93f7b05e30",
        "6665246241c1cb507bdb726b12088abdea5374762b3facb66b8a0e0d8be2e556",
        "4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
      ],
      "logIndex": 647137087,
      "rootHash": "6b2e7bc535bb2deec71fff34b751b8bdff30d1395a540a602559d21536d91d40",
      "treeSize": 669555967
    },
    "signedEntryTimestamp": "MEYCIQDmXoVIGpl/xfFRau38GxHQF8He03Hw0axVu5NQZ8M8WwIhAOODs37L/i6xCrcc259eoHQz3G83YsjFnblv6Tq6DCKU"
  }
}