Skip to content

Update GAR guidance for JS

342a18d
Select commit
Loading
Failed to load commit list.
Open

Update GAR guidance for JS #3331

Update GAR guidance for JS
342a18d
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded May 15, 2026 in 12s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 243474808489225667708927094325367961211065555473 (0x2aa5c9baddd6ba9f97d8f0f50d1e831b3c635a11)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: May 15 19:30:08 2026 UTC
            Not After : May 15 19:40:08 2026 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    2c:fd:45:58:2a:bd:71:45:b8:20:88:43:d4:21:85:
                    00:05:5b:08:a1:ff:e3:40:66:9f:6f:b3:23:c3:d6:
                    79:d3
                Y:
                    33:28:7e:99:63:e9:fc:ac:2c:c5:79:db:a1:99:73:
                    a0:60:c1:e9:66:a4:2d:1e:ed:75:88:a1:e0:80:d2:
                    86:ae
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                00:CD:EF:AB:40:2D:CC:E0:AF:5A:D5:66:7B:AC:2F:F8:9B:99:1B:0E
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:sally.stumbo@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABni0eHfcAAAQDAEcwRQIhAIWcMnxls3bAGGOA6QQIWtTgQdVAJERoLhZN/5ma5oTMAiBR5LtUEg4M3DHWpGNflB8ib++ctAzP7fhEdxmseBZdOQ==

    Signature Algorithm: ECDSA-SHA384
         30:65:02:30:71:7e:b7:34:34:d7:75:be:d6:70:f2:3c:ee:38:
         a3:bc:e9:0f:8a:b1:7b:22:a0:24:88:a0:8d:6d:38:fa:cc:6f:
         cc:a6:87:3b:33:c3:5f:89:f4:20:65:80:94:80:ee:f7:02:31:
         00:b2:9e:4d:da:f4:cf:70:25:cd:05:1f:fd:08:b3:4e:2c:88:
         53:91:4e:7d:a5:0d:a8:2d:09:70:19:47:35:11:9c:db:01:67:
         2c:66:00:52:44:34:e4:e0:19:2e:9a:14:fe

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIwZGZhMWIyZjcwY2RkMzhlYTE3YTg4MWRjMzYxN2ZhOTlkYTc5ZThmMDkyNzgyYmIxZTg3M2JkZTE0ZjBhMWZmIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURnYVE3am1oWWJVWDhiV0ErTnV4cCtIcFdwa3E0eEEwNlVkdjZueVYzV3VBSWhBTlJGRFdFbnRUOGpzSktzdktqVCtCc1J4aUNublA4UUFZZVlyVVF2WW8rYiIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhSRU5EUVd4eFowRjNTVUpCWjBsVlMzRllTblYwTTFkMWNDdFlNbEJFTVVSU05rUkhlbmhxVjJoRmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVVUlRGTlZHdDZUVVJCTkZkb1kwNU5hbGwzVGxSRk1VMVVhekJOUkVFMFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZNVURGR1YwTnhPV05WVnpSSlNXaEVNVU5IUmtGQlZtSkRTMGd2TkRCQ2JXNHlLM29LU1RoUVYyVmtUWHBMU0RaYVdTdHVPSEpEZWtabFpIVm9iVmhQWjFsTlNIQmFjVkYwU0hVeE1XbExTR2RuVGt0SGNuRlBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZCVFROMkNuRXdRWFI2VDBOMlYzUldiV1UyZDNZclNuVmFSM2MwZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0UldVUldVakJTUVZGSUwwSkNPSGRJV1VWaVl6SkdjMkpJYTNWak0xSXhZbGRLZGxGSFRtOVpWMngxV2pOV2FHTnRVWFZhUjFZeVRVTnJSd3BEYVhOSFFWRlJRbWMzT0hkQlVVVkZSekpvTUdSSVFucFBhVGgyV1ZkT2FtSXpWblZrU0UxMVdqSTVkbG95ZUd4TWJVNTJZbFJCY2tKbmIzSkNaMFZGQ2tGWlR5OU5RVVZKUWtJd1RVY3lhREJrU0VKNlQyazRkbGxYVG1waU0xWjFaRWhOZFZveU9YWmFNbmhzVEcxT2RtSlVRMEpwWjFsTFMzZFpRa0pCU0ZjS1pWRkpSVUZuVWpoQ1NHOUJaVUZDTWtGT01EbE5SM0pIZUhoRmVWbDRhMlZJU214dVRuZExhVk5zTmpRemFubDBMelJsUzJOdlFYWkxaVFpQUVVGQlFncHVhVEJsU0daalFVRkJVVVJCUldOM1VsRkphRUZKVjJOTmJuaHNjek5pUVVkSFQwRTJVVkZKVjNSVVoxRmtWa0ZLUlZKdlRHaGFUaTgxYldFMWIxUk5Da0ZwUWxJMVRIUlZSV2MwVFRORVNGZHdSMDVtYkVJNGFXSXJLMk4wUVhwUU4yWm9SV1I0YlhObFFscGtUMVJCUzBKblozRm9hMnBQVUZGUlJFRjNUbThLUVVSQ2JFRnFRbmhtY21Nd1RrNWtNWFowV25jNGFucDFUMHRQT0RaUkswdHpXSE5wYjBOVFNXOUpNWFJQVUhKTllqaDViV2g2YzNwM01TdEtPVU5DYkFwblNsTkJOM1pqUTAxUlEzbHVhek5oT1UwNWQwcGpNRVpJTHpCSmN6QTBjMmxHVDFKVWJqSnNSR0ZuZEVOWVFWcFNlbFZTYms1elFscDVlRzFCUmtwRkNrNVBWR2RIVXpaaFJsQTBQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
  "integratedTime": 1778873409,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 1549871064,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1427977535\n+giYD3538UjNscQg268Rka3KiSBPUMcm7Bgff8fVOT0=\n\n— rekor.sigstore.dev wNI9ajBGAiEAxAHfSbIkq06DNiUTkQAb6lWSdZ+PF+P89PydmxaVqqMCIQDkCNopwg+9vdiQU1yzWp3wFb/H3qI3RuqnhSolumcIcA==\n",
      "hashes": [
        "b57817984b06448ad195589d694dc5e5a2125c9e4abbb56adce652320ce69530",
        "af0752ecb428d6cd7b73abcd3ba25407b9afc091455b7695344ec5991a242245",
        "ed2e930a6bc75697b57229fea59aeb4cd8e241339dafd3599a081a67d93debdf",
        "af7821541fb187335512384b46f894abd5655cd0f53f26a653db46d08eb03e02",
        "bbb0301065252f957b2327036bebe5960db9fff867c785c4d6f1117ec29ff510",
        "e1078ce210b411e9988851cceb19b0d5f3b12241a459ce7d0e81a688322ece76",
        "8f846b338656e02bf81ab1a422beec7e8d7974298a3744bf6dbf71eb6588e87f",
        "8b0406eaf25514674baed95ff5b7610ed7d1726fc2fc4970aeeb6eccc5217928",
        "a8f53de78e1ad0ef6cedb834a02374652ac349d34d3be0206dd77b1e98247127",
        "07e36db3c26d29dc9988793858c5f8532c7bc4399c96a4f09ac3b0b8bde80d21",
        "55b8511a0e3ccca31ff957907aafa2da81ce8dd08cff52772e94902038e93d73",
        "7a6a4de1cfdc54fa2801e97710b99235507474d1c4359ebd86e09ce94aa6424e",
        "a4dd2c2c4ae31004447b5a0f2b6295a455eee9eb9090b9897e35009102588805",
        "6683da3519b1e53b3442081b6babdf7c99636744a2fa73bfe624ff8aa3760e21",
        "1d48b95d797a987645695e9af8c4c5281b7e8d6d372e00801ad2b8696905ca20",
        "88cac9dab23cd96a7a65aebb5bd4c4d869f4b7f55d5cde38cb4703e592244609",
        "4ec5b5a9c57b198752a2bbcbb5bc49737db340732716fec1f7503ad863e424ec",
        "ee11b3736c6f0873eba4ffe8dad689fb424cb182cc5fb88a23dd90821e2b8bab",
        "80e3ac1d6de81dde564644c9d8bbcc31058264b8c33396223c839ad92b030df5",
        "04a07d6583fcb5f67db036d6499a1a82a2ada0f9c1a2f0b682845e73241877d9",
        "793f85e3bd60d8725f778dd4e23e0bd4f20192de2b2db1d077fa4e47fae594ed",
        "0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
      ],
      "logIndex": 1427966802,
      "rootHash": "fa08980f7e77f148cdb1c420dbaf1191adca89204f50c726ec181f7fc7d5393d",
      "treeSize": 1427977535
    },
    "signedEntryTimestamp": "MEYCIQCfPi0feVXY86wV+wMEVBtUfePyNZ8AUdafNlgM8J0EngIhAPzVmuhzDC0GveQCFANgqLWbezmvygf8QS6vEMPfFfal"
  }
}