git pipeline: fix cherry-picking multiple commits #2284
Merged
Chainguard Enforce / Enforce - Commit Signing
succeeded
Jan 1, 2026 in 0s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 280771071217030117171300784364463260016398393594 (0x312e35d4398ff1f004612891c39a7e667c4160fa)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Dec 31 23:57:22 2025 UTC
Not After : Jan 1 00:07:22 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
be:b5:7c:cd:3d:0b:25:1c:2a:e9:7d:ae:db:45:a9:
7b:9c:b6:85:18:c1:ad:f2:03:27:6d:78:a5:3a:70:
72:0f
Y:
dc:8e:36:92:13:e7:af:72:ea:df:d7:5f:92:eb:c2:
d1:61:52:b8:ca:2d:0d:cf:fa:a7:3d:30:2e:c1:59:
38:11
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
C2:11:20:CB:35:FC:FA:D7:D2:7E:FF:E9:C7:4E:15:BA:73:2E:91:AE
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:steve.beattie@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABm3bYP1cAAAQDAEYwRAIgRwmp+83ckKCImeWdafNAfbvJE2NfDxYL3H7lOPAFJ4QCID2j5rG5hQYl52Oa5ocfxiizQymNuQIKBmUZCvmcUI5N
Signature Algorithm: ECDSA-SHA384
30:64:02:30:52:f6:c4:47:66:a2:e1:0d:4a:13:3a:50:19:24:
2d:10:7d:23:7c:0f:57:20:8a:d1:bc:cc:ff:ad:b8:01:55:51:
d2:c6:29:e5:0c:41:45:fe:27:a7:25:74:25:41:c7:19:02:30:
36:45:17:8a:6a:e6:57:38:9e:de:d8:9a:59:50:24:bf:5e:5e:
5c:0b:00:43:03:90:35:93:fb:0e:1c:0a:0f:91:5f:79:73:6a:
a5:8e:fd:51:0f:42:e5:4f:b3:94:aa:17
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI2Y2Y0ZDY0ZTdhZmUxMzU2ZWQ2ZjZhOTY4YTc2ZmEzOWQzOWMyMzQ1MTExMTBkNTg4ZmZiZmQwYjBhY2I4MTdhIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJRjlaWlJNRmcxMDlMeEVuMWlOaGxRYlp4YkUwelVtcWdaOG50WkNKcVFnL0FpRUFycTBOWlZKMlBuZmdzZnd3R2JWUjM5cDdKd0dIa0phZnYzajJwbjhKWHdrPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXdla05EUVd4eFowRjNTVUpCWjBsVlRWTTBNVEZFYlZBNFprRkZXVk5wVW5jMWNDdGFibmhDV1ZCdmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFxVFhoTmFrMHhUbnBKZVZkb1kwNU5hbGwzVFZSQmVFMUVRWGRPZWtsNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVYyY2xZNGVsUXdURXBTZDNFMldESjFNakJYY0dVMWVUSm9VbXBDY21aSlJFb3lNVFFLY0ZSd2QyTm5MMk5xYW1GVFJTdGxkbU4xY21ZeE1TdFROamhNVWxsV1N6UjVhVEJPZWk5eGJsQlVRWFYzVm1zMFJXRlBRMEZZYTNkblowWXhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlYzYUVWbkNubDZXRGdyZEdaVFpuWXZjSGd3TkZaMWJrMTFhMkUwZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0bldVUldVakJTUVZGSUwwSkRRWGRJYjBWall6TlNiR1J0VlhWWmJWWm9aRWhTY0ZwVlFtcGhSMFp3WW0xa01WbFlTbXRNYlZKc1pHcEJjQXBDWjI5eVFtZEZSVUZaVHk5TlFVVkNRa0owYjJSSVVuZGplbTkyVERKR2Fsa3lPVEZpYmxKNlRHMWtkbUl5WkhOYVV6VnFZakl3ZDB0M1dVdExkMWxDQ2tKQlIwUjJla0ZDUTBGUlpFUkNkRzlrU0ZKM1kzcHZka3d5Um1wWk1qa3hZbTVTZWt4dFpIWmlNbVJ6V2xNMWFtSXlNSGRuV1d0SFEybHpSMEZSVVVJS01XNXJRMEpCU1VWbGQxSTFRVWhqUVdSUlJHUlFWRUp4ZUhOalVrMXRUVnBJYUhsYVducGpRMjlyY0dWMVRqUTRjbVlyU0dsdVMwRk1lVzUxYW1kQlFRcEJXblF5TWtRNVdFRkJRVVZCZDBKSFRVVlJRMGxGWTBweFpuWk9NMHBEWjJsS2JteHVWMjU2VVVneU4zbFNUbXBZZHpoWFF6bDRLelZVYW5kQ1UyVkZDa0ZwUVRsdksyRjRkVmxWUjBwbFpHcHRkV0ZJU0RoWmIzTXdUWEJxWW10RFEyZGFiRWRSY2pWdVJrTlBWRlJCUzBKblozRm9hMnBQVUZGUlJFRjNUbTRLUVVSQ2EwRnFRbE01YzFKSVduRk1hRVJWYjFSUGJFRmFTa013VVdaVFRqaEVNV05uYVhSSE9IcFFLM1IxUVVaV1ZXUk1SMHRsVlUxUlZWZ3JTalpqYkFwa1ExWkNlSGhyUTAxRVdrWkdOSEJ4Tld4ak5HNTBOMWx0Ykd4UlNrdzVaVmhzZDB4QlJVMUVhMFJYVkN0M05HTkRaeXRTV0ROc2VtRnhWMDh2VmtWUUNsRjFWbEJ6TlZOeFJuYzlQUW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1767225442,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 786372206,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n665375593\nCWNGvYenZR78YDozGCtpf/Stua3lsbmyT571pqaStQk=\n\n— rekor.sigstore.dev wNI9ajBGAiEAwnZxCcgkmmykfhUHy0Ldu9Cs9zpOI9qOTIMFWpF6vS8CIQDv2Wcxr7SrEqOqwZiEw63zng/P6bZpIvB2B7uT3cbEjA==\n",
"hashes": [
"0f6826cf0a13c9b402c88c181711160ac2342834cee7aa9b55b8705c27bb70fa",
"eee17a3913b030338cab94911dce2f13f803645434da99d8e5e1b5aa9bfee81d",
"cb84265d9f77bfbc6b893d93b7631c7eb84f5f6d865562a7c230aad41edd52ab",
"a2304c56db268b943bac60fc539d1df2c256c1ced3bde03f445123d3de720eb3",
"6d10dbcc962044241b3a02e68c9e4e073c757ebb20edaf1153627db711142540",
"9204108fc0fddca4d028d2c97c7b49cd5c929ce61e5af830ef802cfd38008be7",
"a3e3f77a09abe2de430bc56314bcacfaa14cbaaf6652b9692653cc73018cb814",
"5eed795416342bdecbcc249f706b8db4ea8c6df3a074f9474d2c7154f1fe22ef",
"aacb744629281210294a1d4c89f5774d35f1e4d42587adad1b8c9c9d26d81690",
"62d0c6a6543ad6d63b2664ec04835e683568f9a5cb9644846b3805bc88898221",
"287f7fd9e8e235d7dc59e3f7babad874b86dcd9613356816e527eb0441174e81",
"21783ad7fbeadf0de4274cf535ea863b4a7de0f92bfdf52906a18bd41d3c43f7",
"8f7a8b79eda1ace535147c716c9ed438ec6c57a635a6fbefaec78404746b606d",
"a671a357c2412e18fefd750adf3fd0e4c999209b2cf9b382edf0a736f409bc83",
"70db862f880ff3d39f3461b9683b9b61832604815e56d8ab79d7215fd0629d3b",
"c0d8fe107a6abe9c6d4c3a24b7235743c3db019a71756ac08e3ebcecddc2a8fd",
"227f5aef02c7d8cd7d4b52a989750f2939f0fd8a536da472d535222a096f6801",
"1e8b1d7f380e5c60f068393c54b19e92a5f74670074cbac256a0b20b3da43b01",
"b2d52b99ca146b90cf9d5454607c8edf3846fd11308ba3fe0b7bea753806ce31",
"383a0f5600166851a26d297f433de4258808fd917dd9a4f2a1479c69f189e52d",
"edf6fceb8a32db50fd95a9b683dd2f589ff56f915e18cf094448ef3e80c07293",
"acbb266f2a4980f1844d2c4b57f878fbed6cf06f756f9e02c5cdda268533c648",
"a9e201eb2447714aac5fb07f25f2290d4298b77d36b0f51385825ca1124a638d",
"cfbba0a0230e6f1b5481a31253b9ca76258578880a7c83047591c76a1e0d0dba",
"5fabe4c73d29a312b60c8951babffb2db11dcf78835e3e5063f80b93f7b05e30",
"6665246241c1cb507bdb726b12088abdea5374762b3facb66b8a0e0d8be2e556",
"4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
],
"logIndex": 664467944,
"rootHash": "096346bd87a7651efc603a33182b697ff4adb9ade5b1b9b24f9ef5a6a692b509",
"treeSize": 665375593
},
"signedEntryTimestamp": "MEUCIQCK+KvFSGAFwbC1LTY1h6fIe4DggZchthobPmkjW+GZwQIgN3naMj5EfH19KG+bg1Mt9r3xikTIS5ABji5dBNaFfkY="
}
}
Loading