ci: allow production.cloudfront.docker.com in harden-runner egress #2552
+2
−0
Chainguard Enforce / Enforce - Commit Signing
succeeded
May 29, 2026 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 567931174884628566437110284325374830901098304687 (0x637aea2754f5057d1bcd0fad94f34d132841d4af)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: May 29 19:09:10 2026 UTC
Not After : May 29 19:19:10 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
29:07:ba:0d:aa:6b:25:04:60:0c:aa:41:56:3a:db:
6a:10:c6:54:7b:de:9d:4b:e4:0a:6e:28:c4:47:3b:
94:8b
Y:
81:02:3b:bc:71:b6:24:43:81:f9:99:2f:69:43:2e:
7f:cb:6a:0d:63:f2:c9:c3:23:4c:07:93:f8:b5:ba:
cd:70
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
27:57:46:0F:29:70:81:DD:97:80:39:D0:A1:BF:BA:3E:51:41:07:B9
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:jeremy.harrington@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Unknown extension 1.3.6.1.4.1.57264.1.24
Signed Certificate Timestamp:
BHoAeAB2AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnnUj8CAAAAQDAEcwRQIgS38ALKnFO3UQKcaY14tM+Iw382uNjM5uayub9Me8r7MCIQClxeV38cZiwfEQLr/ZG0EnI33rK2n6mM9zX8rGNpc4jw==
Signature Algorithm: ECDSA-SHA384
30:65:02:30:5d:a5:67:b7:2a:ab:e2:e9:0b:b3:75:6a:b2:8d:
a0:7f:c4:4c:3f:0a:8c:87:fa:3f:5d:e5:15:9e:7f:35:36:ba:
52:fb:c2:68:30:b4:89:8b:16:d3:c2:fd:ae:06:86:b0:02:31:
00:ee:9d:9a:91:15:48:d6:a1:25:4b:05:c9:60:84:9a:18:9d:
8c:9b:6e:be:67:71:bd:4c:28:42:ef:21:87:33:5c:83:9a:f1:
5c:36:81:10:26:f6:d2:17:76:df:12:51:8b
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJjNmI2M2Q2YWVlNmM3MjM4MTdkZjY4YTA0OWE4YjZjNzM4NTU5MGViMzYzYWE1NTYyNTNmODU2ZDBhYmZjMTUxIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQXBkM0Qza2VVWjB1L09vVlZZOVlXS01MVjZGRmE2RU8vZEpsQS9DZStla0FpRUFoRUoxOEV6YXA1RmUwQ0QwempaVzR6WGVPWHMvczBBNUFSc2I2aEh4TGtZPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVUk9ha05EUVhKNVowRjNTVUpCWjBsVldUTnljVW94VkRGQ1dEQmllbEVyZEd4UVRrNUZlV2hDTVVzNGQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDVVU1RWTlZHdDNUMVJGZDFkb1kwNU5hbGwzVGxSSk5VMVVhM2hQVkVWM1YycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZMVVdVMlJHRndja3BSVW1kRVMzQkNWbXB5WW1Gb1JFZFdTSFpsYmxWMmEwTnRORzhLZUVWak4yeEpkVUpCYW5VNFkySlphMUUwU0RWdFV6bHdVWGsxTDNreWIwNVpMMHhLZDNsT1RVSTFVRFIwWW5KT1kwdFBRMEZrYzNkblowaFlUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZLTVdSSENrUjViSGRuWkRKWVowUnVVVzlpS3paUWJFWkNRamRyZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB4bldVUldVakJTUVZGSUwwSkRVWGRKYjBWbllXMVdlVnBYTVRWTWJXaG9ZMjVLY0dKdFpEQmlNalZCV1RKb2FHRlhOVzVrVjBaNVdrTTFhd3BhV0ZsM1MxRlpTMHQzV1VKQ1FVZEVkbnBCUWtGUlVXSmhTRkl3WTBoTk5reDVPV2haTWs1MlpGYzFNR041Tlc1aU1qbHVZa2RWZFZreU9YUk5RM05IQ2tOcGMwZEJVVkZDWnpjNGQwRlJaMFZJVVhkaVlVaFNNR05JVFRaTWVUbG9XVEpPZG1SWE5UQmplVFZ1WWpJNWJtSkhWWFZaTWpsMFRVWnpSME5wYzBjS1FWRlJRbWMzT0hkQlVtZEZWRkY0VEZFeWFGWmxSVEZWVjFoc1RsSkZSWGhVTVZKS1RrVXhSVkpVVWxCV1IzUXpWRzV3Vm1WRk1UWlNWazVKVFcxbmR3cGFSV2hEWldzNWNGWlliRk5oVmxZMVZXMHhSMkZzYTNsUFZFWnBZbXhLTmxSSE1XdGtiVWw1V2toT1lWVjZWbkZaYWtsM1RVbEhTMEpuYjNKQ1owVkZDa0ZrV2pWQloxRkRRa2gzUldWblFqUkJTRmxCTTFRd2QyRnpZa2hGVkVwcVIxSTBZMjFYWXpOQmNVcExXSEpxWlZCTE15OW9OSEI1WjBNNGNEZHZORUVLUVVGSFpXUlRVSGRKUVVGQlFrRk5RVko2UWtaQmFVSk1abmRCYzNGalZUZGtVa0Z3ZUhCcVdHa3dlalJxUkdaNllUUXlUWHB0TlhKTE5YWXdlRGQ1ZGdwemQwbG9RVXRZUmpWWVpuaDRiVXhDT0ZKQmRYWTVhMkpSVTJOcVptVnpjbUZtY1ZsNk0wNW1lWE5aTW14NmFWQk5RVzlIUTBOeFIxTk5ORGxDUVUxRUNrRXlaMEZOUjFWRFRVWXliRm8zWTNGeEsweHdRemRPTVdGeVMwNXZTQzlGVkVRNFMycEpaalpRTVROc1JsbzFMMDVVWVRaVmRuWkRZVVJETUdsWmMxY0tNRGhNT1hKbllVZHpRVWw0UVU4MlpHMXdSVlpUVG1Gb1NsVnpSbmxYUTBWdGFHbGtha3AwZFhadFpIaDJWWGR2VVhVNGFHaDZUbU5uTlhKNFdFUmhRZ3BGUTJJeU1HaGtNak40U2xKcGR6MDlDaTB0TFMwdFJVNUVJRU5GVWxSSlJrbERRVlJGTFMwdExTMEsifX19fQ==",
"integratedTime": 1780081750,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 1672334477,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n1550634820\nvJj56d55ZxIPrhGhCOuKezXtD6Vjro2PTyQ0ZAqLWlE=\n\n— rekor.sigstore.dev wNI9ajBGAiEA6d+q5ZQuEsv992aQaXM5EULcwB0wfX1G74T96geDVCQCIQCcO4UPb9lCzVb3HGhUdc9N2gy9GcwgG/PTA72Hwd7fNQ==\n",
"hashes": [
"29b990999e8ba02fbdd5a72141e6e9d61c774c71687cdd29027ee22e82e08f89",
"a7c9bb618ac9260cf224926475c12d7229169da21083812b67079e5cebc2d3b4",
"662aca56f9b32962fd3e87f91c49968056f81540f693ce27559664ce514a1ce5",
"c04d37455caac65835abc30472f8e16c46f0e459c01e96ed3805d33e2bbd2993",
"e27423631d76a1de68f4e6d56a2730ba10dab2e1bd4e0f933ed23d090bede55c",
"60a538b30a928ae15cd143b9efa2b1c9b807290dad6da2f0df83983e6fdda0b7",
"e4b6f8140829f425a95a23b7946457641b5ea914def831f67224c17a55192cfd",
"048d808297a765ea3eb5d30ec7b52bcccb68c8993addfa331089e407cafd351a",
"5fc1c7e23127efb6f43397c6e98daa0caa55175be504852754ed35f8fc6be0ef",
"0efb876dce05b0c8c1fc18dbf9d2af412df5032d4998ee161b375365b5a25936",
"6c8e8356411d284c4b5fa56f2f63b4e319b5e6bd328bc3c279869511e6d6b844",
"91f4352a4cd99f4738bf14a05c74ef3b194a10c99153700b5331b164562063ba",
"ef8c58b36c574ccc5803d44c40d47ac034b7dfa01ccafce902741c6ed680adfb",
"c4b303d3ccd1c42c1c3e52087d08780400fda6c14593d5dbc7e974324f4e1456",
"683ecb6aa718c86374c34cda10353814e71cf59e6969cdc1d3d9bb176c15f567",
"e3f30aba7efd98967242c999dc2930be01409c22d5cec2e93eaca50e96259f2c",
"23fe729ce42e77321de05367a50ec75ee9ae04056ac1d8ea35adb8824e113886",
"11d0afd388bb92a7d6cc8e4db890a1190e3ecee2ec5a275bb4e2e7eea21bbae6",
"72b700a9f8cb32f3be956b6c836cbd3aa0be91e95f26e3254be33335bb1e57b8",
"6e8ed541408a4bdcae52bf228b9c1a99e0dc27cc5abd85fe68663e31ada25771",
"5b23584e13eadaa34ada52e92aaf50f7b0af376a532176d1f8b949169507dbbe",
"e9bd8ce5cc7f34a2ec53e74ed5fa7577cd7ee4b8257c37ff404aa65f250fd2fa",
"867fa9a6eeefc254828bb5b52f967be746e901dafe5940092d25276fca8bcb79",
"af99e7f7e99b81440be26f2779383f5e362475fda10ff72f64cb0d47fbf47015",
"793f85e3bd60d8725f778dd4e23e0bd4f20192de2b2db1d077fa4e47fae594ed",
"0ce09ea12328bc8bcb13192122f8aca30f40b8d5e0796b3810293247a11ca985"
],
"logIndex": 1550430215,
"rootHash": "bc98f9e9de7967120fae11a108eb8a7b35ed0fa563ae8d8f4f2434640a8b5a51",
"treeSize": 1550634820
},
"signedEntryTimestamp": "MEYCIQDmo1ETGY5XpVv9yj9nEcY0qmGtbVrD/lFwGl5ofn+dDQIhAP/g8zd1YlXPqApg1cM7G3UHn7zsvR/7zA5h1a4V7EZq"
}
}
Loading