Skip to content
This repository has been archived by the owner on Apr 4, 2024. It is now read-only.

update knative serving and grpc for security #189

Merged
merged 2 commits into from
Oct 25, 2023

k8s

f00b4ad
Select commit
Loading
Failed to load commit list.
Merged

update knative serving and grpc for security #189

k8s
f00b4ad
Select commit
Loading
Failed to load commit list.
Chainguard Enforce / Enforce - Commit Signing succeeded Oct 25, 2023 in 1s

Successfully verified commit signature.

CLAIM DESCRIPTION
Found Git signature
Validated Git signature
Validated Rekor entry
Allowed by policy

Details

Certificate

Certificate:
    Data:
        Version: 3 (0x2)
        Serial Number: 561062891241277990018888040936184156262102571843 (0x6246ee1fc67da0b1b0b3b899a09f7cc020699b43)
    Signature Algorithm: ECDSA-SHA384
        Issuer: O=sigstore.dev,CN=sigstore-intermediate
        Validity
            Not Before: Oct 25 22:29:12 2023 UTC
            Not After : Oct 25 22:39:12 2023 UTC
        Subject:         Subject Public Key Info:
            Public Key Algorithm: ECDSA
                Public-Key: (256 bit)
                X:
                    11:4d:3f:76:e7:c2:49:9a:f0:cc:af:e1:99:9d:05:
                    6d:00:60:ec:a6:47:34:44:18:2d:17:77:2b:32:84:
                    e2:04
                Y:
                    4a:9b:94:40:93:d4:e1:de:7a:8f:56:db:61:b4:f1:
                    85:c2:52:d6:6b:d5:5c:91:26:87:b2:bf:c1:8a:39:
                    94:5d
                Curve: P-256
        X509v3 extensions:
            X509v3 Key Usage: critical
                Digital Signature
            X509v3 Extended Key Usage:
                Code Signing
            X509v3 Subject Key Identifier:
                BC:BE:20:0E:72:E5:50:3E:6E:75:F7:91:11:D3:76:BC:9C:1A:DA:CD
            X509v3 Authority Key Identifier:
                keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
            X509v3 Subject Alternative Name: critical
                email:kleung@chainguard.dev
            oidcIssuer:
                https://accounts.google.com
            Unknown extension 1.3.6.1.4.1.57264.1.8
            Signed Certificate Timestamp:
                BHsAeQB3AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABi2j0wdYAAAQDAEgwRgIhANTBNFUOQCxeDH3W3ikzbTx9H4rRiI800sxKb6EgeMS+AiEAgGd85nj8UUjoCUHAf2vJ9by/Nwd5ZXyP9iY8RM8YeFA=

    Signature Algorithm: ECDSA-SHA384
         30:65:02:30:47:98:b8:7e:37:ca:c5:87:45:14:61:37:96:1d:
         3e:2b:30:4b:60:5d:1d:54:ed:0a:67:8d:50:28:4a:30:2a:96:
         ef:96:d3:f8:47:ec:c8:14:88:83:67:48:a9:70:ab:38:02:31:
         00:bf:c9:3e:a7:68:ee:81:26:ba:4b:83:00:37:68:1b:09:5e:
         66:63:73:d4:14:12:c3:dd:33:c1:b7:07:df:6a:fb:a2:07:77:
         da:32:c1:0c:d4:de:ca:13:dd:e6:82:28:80

Rekor Entry

{
  "body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI2NmE5M2RkNmU0ODMwZTk1M2MyNDkyYWQ2NjMyMjczMTIzMmYyY2I3ZmY5YmZmMTNlYWZmNjNmYTMxMWM2ZDhiIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FWUNJUUNVem9NR0xodlJGd2tMTHVTWlJxeGhLN3FBYS9seTRvK2crZlY1TG1tMkZRSWhBTnA5MDRrNHRJQ3d1bjgySENDWGJUMDFienAvNWJSSTg5aTZQQkVkY0ZvZiIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTjZla05EUVd4WFowRjNTVUpCWjBsVldXdGlkVWc0V2psdlRFZDNjemRwV205S09UaDNRMEp3YlRCTmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcE5lRTFFU1RGTmFrbDVUMVJGZVZkb1kwNU5hazE0VFVSSk1VMXFTWHBQVkVWNVYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZGVlRBdlpIVm1RMU5hY25kNlN5OW9iVm93Um1KUlFtYzNTMXBJVGtWUldVeFNaRE1LUzNwTFJUUm5Va3R0TlZKQmF6bFVhRE51Y1ZCV2RIUm9kRkJIUm5kc1RGZGhPVlpqYTFOaFNITnlMMEpwYW0xVldHRlBRMEZZVVhkblowWjNUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlYyVERSbkNrUnVUR3hWUkRWMVpHWmxVa1ZrVGpKMlNuZGhNbk13ZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDBsM1dVUldVakJTUVZGSUwwSkNhM2RHTkVWV1lUSjRiR1JYTlc1UlIwNXZXVmRzZFZvelZtaGpiVkYxV2tkV01rMURhMGREYVhOSFFWRlJRZ3BuTnpoM1FWRkZSVWN5YURCa1NFSjZUMms0ZGxsWFRtcGlNMVoxWkVoTmRWb3lPWFphTW5oc1RHMU9kbUpVUVhKQ1oyOXlRbWRGUlVGWlR5OU5RVVZKQ2tKQ01FMUhNbWd3WkVoQ2VrOXBPSFpaVjA1cVlqTldkV1JJVFhWYU1qbDJXako0YkV4dFRuWmlWRU5DYVhkWlMwdDNXVUpDUVVoWFpWRkpSVUZuVWprS1FraHpRV1ZSUWpOQlRqQTVUVWR5UjNoNFJYbFplR3RsU0Vwc2JrNTNTMmxUYkRZME0ycDVkQzgwWlV0amIwRjJTMlUyVDBGQlFVSnBNbW93ZDJSWlFRcEJRVkZFUVVWbmQxSm5TV2hCVGxSQ1RrWlZUMUZEZUdWRVNETlhNMmxyZW1KVWVEbElOSEpTYVVrNE1EQnplRXRpTmtWblpVMVRLMEZwUlVGblIyUTRDalZ1YWpoVlZXcHZRMVZJUVdZeWRrbzVZbmt2VG5ka05WcFllVkE1YVZrNFVrMDRXV1ZHUVhkRFoxbEpTMjlhU1hwcU1FVkJkMDFFWVVGQmQxcFJTWGNLVWpWcE5HWnFaa3Q0V1dSR1JrZEZNMnhvTUN0TGVrSk1XVVl3WkZaUE1FdGFOREZSUzBWdmQwdHdZblpzZEZBMFVpdDZTVVpKYVVSYU1HbHdZMHR6TkFwQmFrVkJkamhySzNBeWFuVm5VMkUyVXpSTlFVNHlaMkpEVmpWdFdUTlFWVVpDVEVRelZGQkNkSGRtWm1GMmRXbENNMlpoVFhORlRURk9OMHRGT1ROdENtZHBhVUVLTFMwdExTMUZUa1FnUTBWU1ZFbEdTVU5CVkVVdExTMHRMUW89In19fX0=",
  "integratedTime": 1698272953,
  "logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
  "logIndex": 45419494,
  "verification": {
    "inclusionProof": {
      "checkpoint": "rekor.sigstore.dev - 2605736670972794746\n41260163\n89TbWBCIbrAaFLjczhzVDJwCVsVP9NnLwhjuWAM+PR4=\nTimestamp: 1698274280115640143\n\n— rekor.sigstore.dev wNI9ajBFAiBqe+Dpwpo230Rb255zNzqpaUAdpKtkT2SMjg/FsaDx2QIhANwKsfdmOB89UXHmk0BUeR/UF+pZ/pKkASqXHCU0QLem\n",
      "hashes": [
        "0ec24b41fc377e059dad88047a6ee0a145e5e4ae445ea95f18beefeefbd20412",
        "559aeb385e337c27d79a4268d00c06f4c3652dfa56633595c95361c14c3bd0df",
        "75abdf84e5b8a8e502640008699a6542b03f60f0f17e68d73355e0306c2c5435",
        "88324d31e424f10ba3c690d8a50605be19db59993301e984a958c6c8e73888c4",
        "3075f71d5da37a9e6a0d6b53a1ad93fc3b2cc36896f95688096e16cad813c0dd",
        "7e52dfd1b64460b96047223e3e16a9db22650d8eab1302cd54fe0b2b3c4645ae",
        "68aa7d497c2f356eda0efd4ec3c66152cae7d282e9a5273c361c4e7567df1acb",
        "c2e4c595b85438f378d4b860ab1da55eae1ab01c195170ac6aebf2f9f2bd44f3",
        "ad9cf8d73cee7f7b1c5f91e8b38d52665e646aa8a2fe6406998fdd6671ea1eb5",
        "97c5b7414da2fe5a7771b5d5ddad9afb8989ffd40aa82fb64cdf22a897b09d1c",
        "37c44e73808af884e95ca9b4706b76e88d600df0e5af565e27886a06e1108490",
        "c1b7a70b866060349f5f9e490f28eb0d78398d856a051c34dc36662c2ac6bcc2",
        "3320f00741d9c46f940ede00116dd155fefa28625aa673186172f379f6869afb",
        "bdfa81d4b6491b95342ee7eed7a21603972fa9cf845174f812b8579a3154f89a",
        "70b439830827082ee4c755efb88df07a9e87e5baa69a3d63695b5df59d31944b",
        "728a562329a60e6d167781ceea79e72bc5ec2f3d1f82f25bd7f781251d69ec4b",
        "728ab53960e5f37edba8f3ce0af3a7cd731661e31140838abe7654aefc4c443a",
        "b6b5bf40ebe9f57076f9d880690a4e69e5b56a457e7524dc7d38037c293e121c",
        "12a5c36838e5ac885e63fd8243f774fa9a781017aa2e56aadbfd28722ca8e406",
        "6969c49bd73f19bf28a5eaeabd331ddd60502defb2cd3d96e17b741c80adec6c"
      ],
      "logIndex": 41256063,
      "rootHash": "f3d4db5810886eb01a14b8dcce1cd50c9c0256c54ff4d9cbc218ee58033e3d1e",
      "treeSize": 41260163
    },
    "signedEntryTimestamp": "MEUCIGN4OERZ2wfSpzFtHoUWdGwAUZ+Y5TzNVyW3u2E5mtCeAiEAoe+gTBqQjk74xmdObbv3rGaHqAgCMvSsbfe0PubCWww="
  }
}