fix: allow running docker runner as non-root user #1646
+15
−5
Chainguard Enforce / Enforce - Commit Signing
succeeded
Nov 14, 2024 in 0s
Successfully verified commit signature.
CLAIM | DESCRIPTION | |
---|---|---|
✅ | Found Git signature | |
✅ | Validated Git signature | |
✅ | Validated Rekor entry | |
✅ | Allowed by policy |
Details
Certificate
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 191613704876601426682695458781940646751297574820 (0x219041750e72855a234459f3dfd93bbd2b8b97a4)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Nov 14 15:31:35 2024 UTC
Not After : Nov 14 15:41:35 2024 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
8a:48:d6:21:01:91:a0:df:43:df:a6:4d:a4:a7:5f:
70:b6:60:2f:51:e7:c1:11:d2:73:cc:58:58:2c:c7:
38:af
Y:
2d:8d:53:b4:1a:3c:25:fb:f8:fe:cc:2a:9f:e7:11:
d4:53:60:5d:71:a5:e2:5a:dd:db:9f:bd:ed:84:ea:
d3:56
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
5F:0C:41:76:20:E7:4D:C0:91:14:06:04:50:40:90:26:A9:23:17:2F
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:[email protected]
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABkytNI9MAAAQDAEcwRQIgZ9TQTusEO4Re2ucEQlerxBBGfRnqF2KDK5FD0/EKGw8CIQCK74xewgMRlJ0BdM8bPIvxRoUKJMHMQNCyO4z/k7WGJA==
Signature Algorithm: ECDSA-SHA384
30:64:02:30:73:6b:a2:23:30:6b:c5:3e:3a:aa:38:d4:72:09:
53:ea:23:f1:c5:25:12:3a:bd:98:8c:dc:9a:31:fd:cc:6a:cd:
85:2c:d2:9d:6a:a8:23:de:e7:2b:5b:bc:f6:50:e9:f6:02:30:
30:b2:93:b1:a9:56:d4:42:2b:12:8a:87:f4:11:2c:ef:0a:32:
12:29:3f:59:b1:27:78:59:55:e7:91:bc:68:c3:78:e0:36:5c:
9c:34:fb:71:d7:0e:65:7f:07:c1:37:2c
Rekor Entry
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiIxM2EzYWNkMTJhNGNjZmEwNjNjMGNkNzU2MDBjY2FiNTczYzFlYzQyNWRjMGZhNjhjMzllMGE0Y2MxYTQyMmFjIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJQWpiZG5icUVEVE9CWkRjbjdTdHBWbUNNQlduM1BCTVlGcnlkbVEvejN3dkFpQWFLSW9SZlo1RzZrRXc3eVJWdHVwRnFhM1FSdWE3cWMxaENHOC9SSkJGZ1E9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXJSRU5EUVc0clowRjNTVUpCWjBsVlNWcENRbVJSTlhsb1ZtOXFVa1p1ZWpNNWF6ZDJVM1ZNYkRaUmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFJlRTFVUlRCTlZGVjZUVlJOTVZkb1kwNU5hbEY0VFZSRk1FMVVWVEJOVkUweFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZwYTJwWFNWRkhVbTlPT1VRek5scE9jRXRrWm1OTVdtZE1NVWh1ZDFKSVUyTTRlRmtLVjBONlNFOUxPSFJxVms4d1IycDNiQ3N2YWl0NlEzRm1OWGhJVlZVeVFtUmpZVmhwVjNRelltNDNNM1JvVDNKVVZuRlBRMEZhTkhkblowZGhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZZZDNoQ0NtUnBSRzVVWTBOU1JrRlpSVlZGUTFGS2NXdHFSbms0ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDFSbldVUldVakJTUVZGSUwwSkZVWGRSYjBaQlpESTVlV0V6VGpCWldGSndZakkwZEdReU9YbGhNRUpxWVVkR2NHSnRaREZaV0VwclRGaGtkZ3BqYlhSNlpFZEdNR0ZYT1hWamVUVndXVmN3ZFZvelRteGpibHB3V1RKV2FGa3lUblprVnpVd1RHMU9kbUpVUVhCQ1oyOXlRbWRGUlVGWlR5OU5RVVZDQ2tKQ2RHOWtTRkozWTNwdmRrd3lSbXBaTWpreFltNVNla3h0WkhaaU1tUnpXbE0xYW1JeU1IZExkMWxMUzNkWlFrSkJSMFIyZWtGQ1EwRlJaRVJDZEc4S1pFaFNkMk42YjNaTU1rWnFXVEk1TVdKdVVucE1iV1IyWWpKa2MxcFROV3BpTWpCM1oxbHZSME5wYzBkQlVWRkNNVzVyUTBKQlNVVm1RVkkyUVVoblFRcGtaMFJrVUZSQ2NYaHpZMUpOYlUxYVNHaDVXbHA2WTBOdmEzQmxkVTQwT0hKbUswaHBia3RCVEhsdWRXcG5RVUZCV2sxeVZGTlFWRUZCUVVWQmQwSklDazFGVlVOSlIyWlZNRVUzY2tKRWRVVllkSEp1UWtWS1dIRTRVVkZTYmpCYU5taGthV2Q1ZFZKUk9WQjRRMmh6VUVGcFJVRnBkU3ROV0hOSlJFVmFVMlFLUVZoVVVFZDZlVXc0VldGR1EybFVRbnBGUkZGemFuVk5MelZQTVdocFVYZERaMWxKUzI5YVNYcHFNRVZCZDAxRVduZEJkMXBCU1hkak1uVnBTWHBDY2dwNFZEUTJjV3BxVldObmJGUTJhVkI0ZUZOVlUwOXlNbGxxVG5saFRXWXpUV0Z6TWtaTVRrdGtZWEZuYWpOMVkzSlhOM295VlU5dU1rRnFRWGR6Y0U5NENuRldZbFZSYVhOVGFXOW1NRVZUZW5aRGFrbFRTMVE1V25OVFpEUlhWbGh1YTJKNGIzY3phbWRPYkhsalRsQjBlREYzTld4bWQyWkNUbmwzUFFvdExTMHRMVVZPUkNCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2c9PSJ9fX19",
"integratedTime": 1731598296,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 148911688,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n27007641\nYuQ6D35gM8odCN4JmlpVrxVBZCFbos5s8JJ16lbS0xY=\n\n— rekor.sigstore.dev wNI9ajBEAiAdTyWTBampSXT/2NWHC9KXua9h8S2qJ3Gz9/PBYUs81AIgYgPZVFS7atWI9hIj62jPqqCkhhwv9Q2Py4nQgf+geV8=\n",
"hashes": [
"c30f679e9d73f29916c89866f8793a921fa9d214372361eff9f6ee1112b82a0d",
"1e69ab3a9e63da46db5800d86a7fd2ffcd52ce22e0ab152135c43467d3939614",
"4139af6cf5ee67fa609e7e21541284cc9bab2e913720504aa66169c0ec9f50ca",
"203ff3ba164a9c658c37cc1312ecd33cfbd46fc1285cc383b6df5aeb2f491a28",
"0da2198670757651d986dfc96bf1cb5379a7ed301662d3cc8fdb4453c2dff932",
"b27e9cbcc9359059319922452219d168a853eaea54e3af1f4232f05358edefc7",
"81d6277b0d8fe31602d8fdca24a1aab88a3189032019526154b74a2c6c4a7789",
"5719a093a6c711d5d8c5d7ad97a4f9317598777e29a26545a8325510d0c44354",
"860e0cacd324251c3e5beb60e0e5c233702c1268a68d0d56a4e29496b91b11aa",
"c57c8e8201f97743ea04cb3617d8d34a927015be3a14bd6bef209bdf58ede801",
"d9ca8f9ba737c135a036e7e0d398b76842a5490537158cd5a64a647be629ca42",
"9d1e4cc0f9a3bd7812b3491902008472f7191185d860b4ba08147b893fc98fb5",
"6b80d431591b7a7b2a1e8150d6d99d322723efb4e0ca8836b09afff9826568a0",
"19771ebc9349a542c29bf85242e99cbb30e3ec1ccb4a43e59bbe9d25859b7c97",
"a6ab4e4da2b8935eb7b64babe5319cf8792d35818018cee8f4c319937a06dd05",
"e25505d183aef579080d7297034c0c4b377a55e0d8dd3640826a0e796992dbe6",
"81ffbd9b9e760773e79169ced28e0a755be3713dd65472eb09b7f50e8558285c"
],
"logIndex": 27007426,
"rootHash": "62e43a0f7e6033ca1d08de099a5a55af154164215ba2ce6cf09275ea56d2d316",
"treeSize": 27007641
},
"signedEntryTimestamp": "MEUCIEzJLhl11dCgWLGHn/2QYcuO3Mpa9bM8XVcsfmjELTW+AiEAwrvT+5YKgz227u6moEpR/B8y1C9jPm0BOTmSpVBOlV0="
}
}
Loading