apk: repo: introduce backtracking support for better virtual package resolution #2093
Chainguard Enforce / Enforce - Commit Signing
succeeded
Feb 26, 2026 in 1s
Successfully verified commit signature.
| CLAIM | DESCRIPTION | |
|---|---|---|
| ✅ | Found Git signature | |
| ✅ | Validated Git signature | |
| ✅ | Validated Rekor entry | |
| ✅ | Allowed by policy |
Details
Certificate
Details
Certificate:
Data:
Version: 3 (0x2)
Serial Number: 49576895866919212482355319849600626970091318521 (0x8af1ada8ea2c00c8710ff0c7728e320a9d3ecf9)
Signature Algorithm: ECDSA-SHA384
Issuer: O=sigstore.dev,CN=sigstore-intermediate
Validity
Not Before: Feb 26 17:18:23 2026 UTC
Not After : Feb 26 17:28:23 2026 UTC
Subject: Subject Public Key Info:
Public Key Algorithm: ECDSA
Public-Key: (256 bit)
X:
aa:01:cb:d4:f5:88:c4:67:99:f2:35:73:31:45:48:
0e:f7:c1:bc:14:9f:2b:e2:6c:a3:e8:2d:e5:19:21:
b8:3d
Y:
a6:05:2c:d1:52:36:83:86:fc:68:89:16:d3:98:be:
e2:39:cd:ab:a1:61:05:d9:c8:f0:de:1b:e2:9d:14:
1c:0e
Curve: P-256
X509v3 extensions:
X509v3 Key Usage: critical
Digital Signature
X509v3 Extended Key Usage:
Code Signing
X509v3 Subject Key Identifier:
F3:EF:17:9D:3D:45:8C:EA:54:63:EC:35:7E:92:98:CB:B9:08:F5:50
X509v3 Authority Key Identifier:
keyid:DF:D3:E9:CF:56:24:11:96:F9:A8:D8:E9:28:55:A2:C6:2E:18:64:3F
X509v3 Subject Alternative Name: critical
email:arturo.borrero@chainguard.dev
oidcIssuer:
https://accounts.google.com
Unknown extension 1.3.6.1.4.1.57264.1.8
Signed Certificate Timestamp:
BHkAdwB1AN09MGrGxxEyYxkeHJlnNwKiSl643jyt/4eKcoAvKe6OAAABnJr1dpgAAAQDAEYwRAIgHMCdxaYBJrVX+cgI2MzILw3KjfZ4iSclyU28BwRnicACIFcJN5jAl9k2KGtgEKWTKc6RkNumQ5UK/TbhLUorrhKw
Signature Algorithm: ECDSA-SHA384
30:65:02:30:2d:21:c1:d7:ef:d2:ae:3c:ef:d0:2d:34:52:f6:
fb:4a:4e:e0:ae:25:be:8f:fe:4d:35:97:6c:62:43:4b:59:d5:
44:33:77:cb:5b:9f:b8:f8:80:70:ea:e7:23:04:4b:db:02:31:
00:ae:d2:7b:a8:f4:f5:1e:70:03:1f:70:34:bd:a4:3f:fe:ef:
82:2b:8b:b7:77:f2:a7:e0:16:12:28:23:05:55:77:97:ed:57:
7c:1e:36:b4:37:91:03:78:c8:52:b0:77:78
Rekor Entry
Details
{
"body": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiJmMjY0ZWNiOWQ3NjU1ZjY2ZTFjOGI4MjJiYjVhYTc3YzdmZDE0ZDUzNmY1ZjRkYTM4NDhkYmU0Y2EyZWZmZTNiIn19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FVUNJQWltcG5GYmZuNGpZQWJlY0lSTC8vUU5sV2RSalgzSFBDcUdSdWo1b0Vub0FpRUE4ZVptRE9BeVlDdUoxRHNkWlNEY3o4T3dEMzRQUmMweXRWUmxpWVg5VWFBPSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVTXhWRU5EUVd4MVowRjNTVUpCWjBsVlEwczRZVEp2Tm1sM1FYbElSVkE0VFdSNWFtcEpTMjVVTjFCcmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFpkMDFxU1RKTlZHTjRUMFJKZWxkb1kwNU5hbGwzVFdwSk1rMVVZM2xQUkVsNlYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZ4WjBoTU1WQlhTWGhIWlZvNGFsWjZUVlZXU1VSMlprSjJRbE5tU3l0S2MyOHJaM1FLTlZKcmFIVkVNbTFDVTNwU1ZXcGhSR2gyZUc5cFVtSlViVXczYVU5ak1uSnZWMFZHTW1OcWR6Tm9kbWx1VWxGalJIRlBRMEZZYjNkblowWXlUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlU0S3poWUNtNVVNVVpxVDNCVldTdDNNV1p3UzFsNU4ydEpPVlpCZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDB0M1dVUldVakJTUVZGSUwwSkRSWGRJTkVWa1dWaEtNR1JZU25aTWJVcDJZMjVLYkdOdE9VRlpNbWhvWVZjMWJtUlhSbmxhUXpWcldsaFpkd3BMVVZsTFMzZFpRa0pCUjBSMmVrRkNRVkZSWW1GSVVqQmpTRTAyVEhrNWFGa3lUblprVnpVd1kzazFibUl5T1c1aVIxVjFXVEk1ZEUxRGMwZERhWE5IQ2tGUlVVSm5OemgzUVZGblJVaFJkMkpoU0ZJd1kwaE5Oa3g1T1doWk1rNTJaRmMxTUdONU5XNWlNamx1WWtkVmRWa3lPWFJOU1VkS1FtZHZja0puUlVVS1FXUmFOVUZuVVVOQ1NITkZaVkZDTTBGSVZVRXpWREIzWVhOaVNFVlVTbXBIVWpSamJWZGpNMEZ4U2t0WWNtcGxVRXN6TDJnMGNIbG5Remh3TjI4MFFRcEJRVWRqYlhaV01tMUJRVUZDUVUxQlVtcENSVUZwUVdOM1NqTkdjR2RGYlhSV1pqVjVRV3BaZWsxbmRrUmpjVTQ1Ym1sS1NubFlTbFJpZDBoQ1IyVktDbmRCU1dkV2Qyc3piVTFEV0RKVVdXOWhNa0ZSY0ZwTmNIcHdSMUV5TmxwRWJGRnlPVTUxUlhSVGFYVjFSWEpCZDBObldVbExiMXBKZW1vd1JVRjNUVVFLWVVGQmQxcFJTWGRNVTBoQ01Tc3ZVM0pxZW5Zd1F6QXdWWFppTjFOck4yZHlhVmNyYWk4MVRrNWFaSE5aYTA1TVYyUldSVTB6Wmt4WE5TczBLMGxDZHdvMmRXTnFRa1YyWWtGcVJVRnlkRW8zY1ZCVU1VaHVRVVJJTTBFd2RtRlJMeTkxSzBOTE5IVXpaQzlMYmpSQ1dWTkxRMDFHVmxobFdEZFdaRGhJYW1Fd0NrNDFSVVJsVFdoVGMwaGtOQW90TFMwdExVVk9SQ0JEUlZKVVNVWkpRMEZVUlMwdExTMHRDZz09In19fX0=",
"integratedTime": 1772126304,
"logID": "c0d23d6ad406973f9559f3ba2d1ca01f84147d8ffc5b8445c224f98b9591801d",
"logIndex": 997938930,
"verification": {
"inclusionProof": {
"checkpoint": "rekor.sigstore.dev - 1193050959916656506\n876034835\n8OZ5vpr8vWrkPhq8pmHRcLjlmbIC5/1G6a4o8dtegFA=\n\n— rekor.sigstore.dev wNI9ajBEAiBQKx1/1cjvsWHh+aoKZY5ee8+Y7K3dQDcoXMWwBkZl8wIgQt4AEi4/HYFDQnCSjolkF6LYJGxXwmcS0g8Gv5fHW/8=\n",
"hashes": [
"eae04a0ad4656512ca42ab84681e3e52b50744ada0319dd754f1ca07b0cdae6e",
"3bcd6ebf0bc65a32eaee5cd3cc1d086328f3dcc3079a2320bc1781bfa6acbc1d",
"359f5631dfd366909c09754d9939302b8302f51efa6365ef52a4b94101cdb62e",
"084d95ca75439d63ecc060bd2521f98561c12d14f049a548a8a7e8c8304bced5",
"69ae3c54ab7f0cca36bccce16b1f471c8d745e01cfec3a697cd732d53fcc4d98",
"bf88cebc39b67ec71e1b5f7a430d26d40b2e1bc1255526dd2665b4c49b3b5e39",
"00c16abba79a79671f50280a3850adabb5ce5bfc630ac8cca678527de6ca2836",
"768497337ff9d9976db922eccfc1bf0c37d40fea8b908efc202d1e2097d69da4",
"e635097a3da191b2c4f2d66c7e8a24358f97a8a43f7959402b4faa503f1315bd",
"981900720b3decd397a08686eeee2509328808ff92a4136a32ab4d198fcc3aab",
"5822c71432d2290c0fca8d03010b1de7815387b2499d8375bf4f9784e9c946f8",
"e29ea9b66291155bfb19e76af9643669cb6a373f04306e11ba6bb8228a9f81cd",
"98e017d1bb7972ef4aeff70dd3453af7fb4e70f1d751bed4f6a86b2ac5e16014",
"78fea5b905059335fad5478ec439d29b64fab817262c3f47b44486f798e70978",
"9eabed3ec12ded723086fa584ce0db7c6b0c7c8fbdfef8a05f44f11703901431",
"2e724b4deeda58130763c0018996565e7c3078e50f6cf8e12f38e0c36f004e32",
"d19bd8e161d7fb8a7bb95620db75bf418f80977a9562d4093b967232ae9c12b1",
"d990b72e751b2ce49eed6a3b141d10de6f960ea9ebaf9aac4a74aa4865b6f5a1",
"66578a61e44ac141771cfdc73b49311cc55e26063737f7ae1a29d58655566aad",
"7cb02f138e8da82555f3a129076a4a9302651638c593b9ed5f7942f8f899b88a",
"4f80ea583e36840b4dfaf5fc8ca096aa80b899e13825e908f4bc5818270fcb53"
],
"logIndex": 876034668,
"rootHash": "f0e679be9afcbd6ae43e1abca661d170b8e599b202e7fd46e9ae28f1db5e8050",
"treeSize": 876034835
},
"signedEntryTimestamp": "MEUCIQDm9FkLs2z1NyTT9/nBo0j0hZ9idWSYBgVcJ6sKK26XjAIgc0zT7iZRGsqyNC3CRji0PWY7x4JylO2sZTIMwQsbkfc="
}
}
Loading