Skip to content

image-mapper: add matcher that identifies iamguarded images

229063a
Select commit
Loading
Failed to load commit list.
Merged

image-mapper: add matcher that identifies iamguarded images #254

image-mapper: add matcher that identifies iamguarded images
229063a
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Dec 15, 2025 in 1s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Details
Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 235657350424906156396255875252126865966930379883 (0x29473db662b44958cff946b85523e8a2af48c46b)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Dec 15 17:46:02 2025 UTC
            Not After : Dec 15 17:56:02 2025 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    6c:e0:f4:dd:ce:2b:38:4b:e7:8b:f3:5f:09:44:5e:
                    c4:25:f3:c2:52:f6:57:e7:e0:4e:4e:66:0c:bc:c8:
                    aa:bb
                Y:
                    c1:ad:5b:ed:d6:89:fb:c4:a5:4f:8b:f8:5c:a2:dd:
                    59:13:84:ba:48:28:4e:4d:63:df:87:c6:cc:3b:68:
                    53:20
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                E4:06:61:95:64:6A:0A:96:55:DF:1D:12:04:DD:7B:81:8F:D3:32:E4
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:[email protected]
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABmyMeiLUAAAQDAEcwRQIgMQlg+n0a9ypQYSTpXxsYZ6r+W5ZonblQhFPiwr17JtECIQD5gXKZYtgqSDaKfTgPlVpqmCKhClbd3IBXQVbtiZqtIg==

    Signature Algorithm: ECDSA-SHA384
         30:64:02:30:36:e8:ca:8c:80:df:53:c3:04:7e:af:7a:8a:ab:
         c5:f6:65:cf:61:c2:b3:cb:33:48:cb:5c:f9:e6:9a:ca:53:8c:
         e7:17:a8:ee:3a:51:cd:7c:7f:2d:af:ff:00:92:ae:bb:02:30:
         61:04:2f:75:df:b3:6a:b0:32:2c:4d:fa:f4:71:97:19:08:b8:
         00:41:d3:e1:b0:60:fc:b5:11:1b:91:d3:7f:89:3d:52:6b:29:
         ad:e4:a1:1b:e3:83:e0:11:2f:a0:1b:a9

Rekor Entry

Details
{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJkOTA2Y2U3YzczNTQ2MWQwMWM2OTJjMTMyZjViZjc0ZDE4YTdkYWE0Y2M2YmM1YWEwYTEzMTIwMWMxMDFjOGZjIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUURZZTRYYUFHOFFCeS9vdUc1czVlZ1pwUE9nVnNuZjJJZDVseWNUN3BtZXRRSWhBTjBySXlCUHlOd0g1VmpvSmJ6R05mQnhnWVh0RjUxQ2RXbmhrMkhaT1M2OCIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjZla05EUVd4aFowRjNTVUpCWjBsVlMxVmpPWFJ0U3pCVFZtcFFLMVZoTkZaVFVHOXZjVGxKZUVkemQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZlRTFxUlRGTlZHTXdUbXBCZVZkb1kwNU5hbFY0VFdwRk1VMVVZekZPYWtGNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZpVDBRd00yTTBjazlGZG01cEwwNW1RMVZTWlhoRFdIcDNiRXd5Vml0bVoxUnJOVzBLUkV4NlNYRnlka0p5Vm5aME1XOXVOM2hMVmxCcEwyaGpiM1F4V2tVMFV6WlRRMmhQVkZkUVptZzRZazFQTW1oVVNVdFBRMEZZVlhkblowWjRUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlUxUVZwb0NteFhVbkZEY0ZwV00zZ3dVMEpPTVRkbldTOVVUWFZSZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBwUldVUldVakJTUVZGSUwwSkNjM2RIV1VWWVkyMDVhVXh0U214ak0xSkJXVEpvYUdGWE5XNWtWMFo1V2tNMWExcFlXWGRMVVZsTFMzZFpRZ3BDUVVkRWRucEJRa0ZSVVdKaFNGSXdZMGhOTmt4NU9XaFpNazUyWkZjMU1HTjVOVzVpTWpsdVlrZFZkVmt5T1hSTlEzTkhRMmx6UjBGUlVVSm5OemgzQ2tGUlowVklVWGRpWVVoU01HTklUVFpNZVRsb1dUSk9kbVJYTlRCamVUVnVZakk1Ym1KSFZYVlpNamwwVFVsSFMwSm5iM0pDWjBWRlFXUmFOVUZuVVVNS1FraDNSV1ZuUWpSQlNGbEJNMVF3ZDJGellraEZWRXBxUjFJMFkyMVhZek5CY1VwTFdISnFaVkJMTXk5b05IQjVaME00Y0Rkdk5FRkJRVWRpU1hnMlNRcDBVVUZCUWtGTlFWSjZRa1pCYVVGNFExZEVObVpTY2pOTGJFSm9TazlzWmtkNGFHNXhkalZpYkcxcFpIVldRMFZWSzB4RGRsaHpiVEJSU1doQlVHMUNDbU53YkdreVEzQkpUbTl3T1U5QksxWlhiWEZaU1hGRlMxWjBNMk5uUm1SQ1ZuVXlTbTF4TUdsTlFXOUhRME54UjFOTk5EbENRVTFFUVRKalFVMUhVVU1LVFVSaWIzbHZlVUV6TVZCRVFrZzJkbVZ2Y1hKNFpscHNlakpJUTNNNGMzcFRUWFJqSzJWaFlYbHNUMDAxZUdWdk4ycHdVbnBZZUM5TVlTOHZRVXBMZFFwMWQwbDNXVkZSZG1Sa0szcGhja0Y1VEVVek5qbElSMWhIVVdrMFFVVklWRFJpUW1jdlRGVlNSelZJVkdZMGF6bFZiWE53Y21WVGFFY3JUMFEwUWtWMkNtOUNkWEFLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
  "integratedTime": 1765820762,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 764783183,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 1193050959916656506\n643509856\nyjGO3FbKkHNqcaMV2sHAnTkn1qXoNVXv7jK8UbX6Eqo=\n\n— rekor.sigstore.dev wNI9ajBFAiEApVVb1bOgJDfZxgNRyC2Vu+1VFKTzENBe6aCHu+W7f6kCIDEmj+2Ltl+9A/DzJsGUVGpseEdZcybJbGnuMIVlNRsp\n",
      "hashes": [
        "e2001249b9832a0dc445e93acbc14246cff83281c46da1bf2e15e431c115e9a1",
        "9583dbebaa344fb8ac14c6e2837ec8e4e29ccc9c79e7e0c55ab618270376d262",
        "c12eb4865ba51218552dcf5971c99370b4682efb92f766a87d875e4fbb10796c",
        "28276dac5113a64ddf1148f719056c2520dc0b514188da9bf1eacc342f24e535",
        "a8a9bddf015afc6a10a8c9dede9758949b98060e458b0caf00f25312f7dbfe49",
        "0998c978da31a8855dcccf3aeb59d046a1efc6095fc85ce38964e56cdafd3538",
        "fac07d19818a479d1968e3551fb9c95d7593586e419232f42865be6f0bf789c0",
        "e41220f3a69ecb021a788de43e40dbc3a991659c8dc207d8e0f2bac164a5a417",
        "c922ed66aff52c5ade61f92be9121612d629c72e59f63aa5aa7f4526ee631fac",
        "f3015baf70dbae92f97b2037d2343c684fc911cc8697ba28f3c07098be8a4b09",
        "5e9c8071bdcec52b7d269d263e4007c0d1c8b64b34e30d0346eaa6b5dc0fa920",
        "9babcc5feb1d7b470ddc2f47055cadaadf528d7f74ee4466a92ded3b0fca9f9b",
        "3e8c97d5e220b11c2044b8298c9c3ca980d125552fb481e22835bb7d6b5b3b0c",
        "5d800711040947629bd6c07aceface26cf1b9dff012d7683b0a960d62221db8d",
        "e2cd14106baec030148003bb88efc9350382ad8aadbf1b8ed5ede8a30ad45e12",
        "eb16674a0ab04cdbc040479408bb94d9ec3fc6df39bf2d72d5126e34a0431632",
        "acbe92f72a3405b9a8e56699df8f9c8e59665a3ea938747d380dbad713db7d12",
        "55ed97602b060ad224d2370665d9360882ac332d79b7d7c2678b958d2a71577b",
        "187ace7baf6be513e478f3f3e94d034dc21cf70e2d6d0af752b5b7ea7a19226e",
        "4627b0b7bd01f6c4776f392f5b220f65487688f55f358506be7ff4b52c9377b5",
        "26cf23e40fc37575d3820ed7e0253d5a8e80572d64174c6caab3ddc9a9a2fa37",
        "d63e250d357c3fe1884e7e829f9bf8daecb724ae3606d3e63e424cb7921c332d",
        "5fabe4c73d29a312b60c8951babffb2db11dcf78835e3e5063f80b93f7b05e30",
        "6665246241c1cb507bdb726b12088abdea5374762b3facb66b8a0e0d8be2e556",
        "4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
      ],
      "logIndex": 642878921,
      "rootHash": "ca318edc56ca90736a71a315dac1c09d3927d6a5e83555efee32bc51b5fa12aa",
      "treeSize": 643509856
    },
    "signedEntryTimestamp": "MEYCIQCuobIt/sZt7I10F9BL9RFzu+nMFMw3CajXpSnY+Z1pfQIhAMnl8dlOloNewhZSrL8k4AIjdAh7XvXlBC23xE9T1jn1"
  }
}