sonarcube false positives: handle renamed rule #789
Closed
Chainguard Enforce / Enforce - Commit Signing
succeeded
Feb 4, 2025 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 701663187218470665323620612108752540063037884809 (0x7ae7aa5de35ffc98fadc7027e590955cf94f8989)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Feb 4 00:43:29 2025 UTC
Not After : Feb 4 00:53:29 2025 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
86:7e:f6:72:67:be:a3:34:35:be:41:11:08:90:1a:
27:4d:af:fc:e5:17:0b:f7:ad:f7:0d:9c:d1:5d:9d:
46:12
Y:
c8:29:87:91:cd:ac:56:86:72:33:36:e2:8c:4a:b1:
61:c8:e7:c2:58:f0:13:69:5f:de:95:69:09:fe:bb:
6b:e6
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
88:A8:25:53:53:31:2A:7F:2F:E9:F6:61:CC:15:87:F8:0B:2A:2A:87
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABlM5ph24AAAQDAEgwRgIhANRvgKnl16zHFYnrEQt0A/IB13clcHWbaEjQXVw6Wk4UAiEAtcs5uo6yn/rT5qyZKkHG603R2k+UX5xylynty6uI3J0=
Signature Algorithm: ECDSA-SHA384
30:64:02:30:08:b6:cb:b3:d8:29:08:64:13:55:17:eb:7a:b1:
6a:4c:f8:4f:26:d5:64:f6:cf:79:d4:e3:a1:79:3f:a7:34:23:
f3:89:9f:31:39:1e:fa:a1:65:c9:4e:4e:ae:c2:04:e0:02:30:
3c:5e:61:3e:d9:58:97:47:0d:3a:12:49:38:ee:b3:ac:da:47:
8d:2b:f8:5b:cc:36:c4:14:57:07:c9:7e:f6:85:cf:11:05:2a:
4c:d8:ae:5e:a4:a5:c2:62:79:a4:82:c9
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIzYzk2NzE4ODRmMDIzM2ZmNTdhZjk0ZjBhNTQ2OTBkZWYwNjU5OTkyMDEwMTQwMGZhYmEyMDdiYTE5MTA0MDQxIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURBbEdOWWZDblBLaElrWUpvdVZ2ZGE2VzdJeXpzc0IwemdwbVNzdXBrVm1nSWhBTjR4cDlQTVAzeG5lN3VhNWdCVHNJL0RIdklxYmlybk12MGwrRGVCaFRVWiIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhWRU5EUVd4NVowRjNTVUpCWjBsVlpYVmxjVmhsVG1ZdlNtbzJNMGhCYmpWYVExWllVR3hRYVZscmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDFxUVRCTlJFRXdUWHBKTlZkb1kwNU5hbFYzVFdwQk1FMUVRVEZOZWtrMVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZvYmpjeVkyMWxLMjk2VVRGMmEwVlNRMHBCWVVvd01uWXZUMVZZUXk5bGREbDNNbU1LTUZZeVpGSm9URWxMV1dWU2VtRjRWMmh1U1hwT2RVdE5VM0pHYUhsUFprTlhVRUZVWVZZdlpXeFhhMG92Y25SeU5YRlBRMEZZYzNkblowWXpUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZwUzJkc0NsVXhUWGhMYmpoMk5tWmFhSHBDVjBnclFYTnhTMjlqZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0bldVUldVakJTUVZGSUwwSkRRWGRJYjBWall6TlNiR1J0VlhWWmJWWm9aRWhTY0ZwVlFtcGhSMFp3WW0xa01WbFlTbXRNYlZKc1pHcEJjQXBDWjI5eVFtZEZSVUZaVHk5TlFVVkNRa0owYjJSSVVuZGplbTkyVERKR2Fsa3lPVEZpYmxKNlRHMWtkbUl5WkhOYVV6VnFZakl3ZDB0M1dVdExkMWxDQ2tKQlIwUjJla0ZDUTBGUlpFUkNkRzlrU0ZKM1kzcHZka3d5Um1wWk1qa3hZbTVTZWt4dFpIWmlNbVJ6V2xNMWFtSXlNSGRuV1hOSFEybHpSMEZSVVVJS01XNXJRMEpCU1VWbVVWSTNRVWhyUVdSM1JHUlFWRUp4ZUhOalVrMXRUVnBJYUhsYVducGpRMjlyY0dWMVRqUTRjbVlyU0dsdVMwRk1lVzUxYW1kQlFRcEJXbFJQWVZsa2RVRkJRVVZCZDBKSlRVVlpRMGxSUkZWaU5FTndOV1JsYzNoNFYwbzJlRVZNWkVGUWVVRmtaRE5LV0VJeGJUSm9TVEJHTVdOUGJIQlBDa1pCU1doQlRGaE1UMkp4VDNOd0x6WXdLMkZ6YlZOd1FuaDFkRTR3WkhCUWJFWXJZMk53WTNBM1kzVnlhVTU1WkUxQmIwZERRM0ZIVTAwME9VSkJUVVFLUVRKalFVMUhVVU5OUVdreWVUZFFXVXRSYUd0Rk1WVllOak54ZUdGcmVqUlVlV0pXV2xCaVVHVmtWR3B2V0dzdmNIcFJhamcwYldaTlZHdGxLM0ZHYkFwNVZUVlBjbk5KUlRSQlNYZFFSalZvVUhSc1dXd3dZMDVQYUVwS1QwODJlbkpPY0VocVUzWTBWemgzTW5oQ1VsaENPR3dyT1c5WVVFVlJWWEZVVG1sMUNsaHhVMngzYlVvMWNFbE1TZ290TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1738629810,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 168410987,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n46508419\no7EfJRP9lUywvijO23ddnyspypJdmMSNUrlH05BEaYY=\n\n— rekor.sigstore.dev wNI9ajBFAiEA7DggLx5P8F285XPSgD9lbDQm4+7tGQmrH5YaQhyPBoICIHS+t0fInKZQG9aIczzI3Lrd11tfpviPEnwI+F6ddDIe\n",
"hashes": [
"8128486a4c6f4cc0ae68cf56a076dfe62aeb3e3bfa2b0bebd9ca81331a642420",
"7420b206d08d35299e46b7310360f62309fa2b9fa38d23c1840c9862bf0f0e7f",
"a22d4d0b80b838a2c90726e132bbbeb8081fdd8098ad2383f5c9f4f1b9371fd9",
"72672162fc2926d09709291e2ac4bd4f2138e783b4d3b070b433dbfe6d54ee59",
"b2d7b7bc6496588397d622edd3389619e4cc988cedf337dfc4a5967f991715e7",
"c3090bdbd641bfe591e73885660b9ebd33c6274603da60f3e013bb939935ef62",
"b910dd7cc3a0d2a8028ba9ac5270a2268ca8f9012176fe1eae91ae1fd595ee8b",
"b94c1c9c9a7f6975f8a625bd7b0c0f264309b2d0a61789886567ec7cc1ec0aa7",
"8efec1fb5ef631a89e48e535eb5379d59acebe214b4eb3dd121cd4542a6863d4",
"434acd901cd6a9c04892e3cdb40fd7c2163f26ee576dd87c676934c9a8b66f2f",
"6ab3190657a29d40cf3b512ead845a1695a52ff0a4503c6ec0ea15c24eb5ee2e",
"f5ed4825db7deab42b8626a39ed765817fc30dea39c3939be30fd7af098b5bd2",
"b93d01ea48ddd631a3ea11e4c26168efaacaea34649887884c2c1f66eec92fbe",
"7288c34221a840754b9e7fcba037905ae314fff866feee1ca8d07e5ebcbd06dc",
"50b3cd11b6d94f9f6f1d709c0e1e3d68e1b085a5ae9849df7f2ed8e9f80582f6",
"86e4b31b236d7483b38f379010122648fc8c4463a91f56cd79516b4634a8cc97",
"66c7b704f911fdc26feb62ef56e8831fe129808139bf7577a97746f074057f50",
"8d4f7eb608d320a51819e53b4fb463ab22fe17e80557db427705f6199d54b50b",
"bde9b268c8f435ad4b3236c1ffd0e692af13fa301bde8fb20844a001ac940015"
],
"logIndex": 46506725,
"rootHash": "a3b11f2513fd954cb0be28cedb775d9f2b29ca925d98c48d52b947d390446986",
"treeSize": 46508419
},
"signedEntryTimestamp": "MEQCIH/Yv4SebR7RnmFYiFKjsfj4bcXHSQ2oEIKglcFXJeHrAiAXNRBOPruYYZZcwf+e1qqNwWZ8mT9jNseqpDA49jCNrg=="
}
}
Loading