From 2b5aedb4de2aeeb0475e3ded47357ca55312e8a1 Mon Sep 17 00:00:00 2001 From: Sigstore Bot <86837369+sigstore-bot@users.noreply.github.com> Date: Tue, 28 Feb 2023 09:34:43 +0100 Subject: [PATCH 1/8] Add staged repository metadata (#673) Signed-off-by: GitHub Co-authored-by: GitHub --- repository/staged/root.json | 144 ++++++++++++++++++ repository/staged/targets.json | 136 +++++++++++++++++ repository/staged/targets/artifact.pub | 4 + repository/staged/targets/ctfe.pub | 4 + repository/staged/targets/ctfe_2022.pub | 4 + repository/staged/targets/fulcio.crt.pem | 13 ++ .../targets/fulcio_intermediate_v1.crt.pem | 14 ++ repository/staged/targets/fulcio_v1.crt.pem | 13 ++ repository/staged/targets/rekor.pub | 4 + repository/staged/targets/trusted_root.json | 91 +++++++++++ 10 files changed, 427 insertions(+) create mode 100644 repository/staged/root.json create mode 100644 repository/staged/targets.json create mode 100644 repository/staged/targets/artifact.pub create mode 100644 repository/staged/targets/ctfe.pub create mode 100644 repository/staged/targets/ctfe_2022.pub create mode 100644 repository/staged/targets/fulcio.crt.pem create mode 100644 repository/staged/targets/fulcio_intermediate_v1.crt.pem create mode 100644 repository/staged/targets/fulcio_v1.crt.pem create mode 100644 repository/staged/targets/rekor.pub create mode 100644 repository/staged/targets/trusted_root.json diff --git a/repository/staged/root.json b/repository/staged/root.json new file mode 100644 index 00000000..eabcfed2 --- /dev/null +++ b/repository/staged/root.json @@ -0,0 +1,144 @@ +{ + "signed": { + "_type": "root", + "spec_version": "1.0", + "version": 6, + "expires": "2023-08-28T07:54:10Z", + "keys": { + "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEEXsz3SZXFb8jMV42j6pJlyjbjR8K\nN3Bwocexq6LMIb5qsWKOQvLN16NUefLc4HswOoumRsVVaajSpQS6fobkRw==\n-----END PUBLIC KEY-----\n" + } + }, + "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE0ghrh92Lw1Yr3idGV5WqCtMDB8Cx\n+D8hdC4w2ZLNIplVRoVGLskYa3gheMyOjiJ8kPi15aQ2//7P+oj7UvJPGw==\n-----END PUBLIC KEY-----\n" + } + }, + "45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAELrWvNt94v4R085ELeeCMxHp7PldF\n0/T1GxukUh2ODuggLGJE0pc1e8CSBf6CS91Fwo9FUOuRsjBUld+VqSyCdQ==\n-----END PUBLIC KEY-----\n" + } + }, + "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEinikSsAQmYkNeH5eYq/CnIzLaacO\nxlSaawQDOwqKy/tCqxq5xxPSJc21K4WIhs9GyOkKfzueY3GILzcMJZ4cWw==\n-----END PUBLIC KEY-----\n" + } + }, + "e1863ba02070322ebc626dcecf9d881a3a38c35c3b41a83765b6ad6c37eaec2a": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEWRiGr5+j+3J5SsH+Ztr5nE2H2wO7\nBV+nO3s93gLca18qTOzHY1oWyAGDykMSsGTUBSt9D+An0KfKsD2mfSM42Q==\n-----END PUBLIC KEY-----\n" + } + }, + "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEzBzVOmHCPojMVLSI364WiiV8NPrD\n6IgRxVliskz/v+y3JER5mcVGcONliDcWMC5J2lfHmjPNPhb4H7xm8LzfSA==\n-----END PUBLIC KEY-----\n" + } + }, + "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c": { + "keytype": "ecdsa-sha2-nistp256", + "scheme": "ecdsa-sha2-nistp256", + "keyid_hash_algorithms": [ + "sha256", + "sha512" + ], + "keyval": { + "public": "-----BEGIN PUBLIC KEY-----\nMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEy8XKsmhBYDI8Jc0GwzBxeKax0cm5\nSTKEU65HPFunUn41sT8pi0FjM4IkHz/YUmwmLUO0Wt7lxhj6BkLIK4qYAw==\n-----END PUBLIC KEY-----\n" + } + } + }, + "roles": { + "root": { + "keyids": [ + "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", + "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", + "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", + "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", + "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de" + ], + "threshold": 3 + }, + "snapshot": { + "keyids": [ + "45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b" + ], + "threshold": 1 + }, + "targets": { + "keyids": [ + "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", + "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", + "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", + "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", + "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de" + ], + "threshold": 3 + }, + "timestamp": { + "keyids": [ + "e1863ba02070322ebc626dcecf9d881a3a38c35c3b41a83765b6ad6c37eaec2a" + ], + "threshold": 1 + } + }, + "consistent_snapshot": true + }, + "signatures": [ + { + "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", + "sig": "" + }, + { + "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", + "sig": "" + }, + { + "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", + "sig": "" + }, + { + "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", + "sig": "" + }, + { + "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", + "sig": "" + } + ] +} \ No newline at end of file diff --git a/repository/staged/targets.json b/repository/staged/targets.json new file mode 100644 index 00000000..92b06794 --- /dev/null +++ b/repository/staged/targets.json @@ -0,0 +1,136 @@ +{ + "signed": { + "_type": "targets", + "spec_version": "1.0", + "version": 6, + "expires": "2023-08-28T07:54:10Z", + "targets": { + "artifact.pub": { + "length": 177, + "hashes": { + "sha256": "59ebf97a9850aecec4bc39c1f5c1dc46e6490a6b5fd2a6cacdcac0c3a6fc4cbf", + "sha512": "308fd1d1d95d7f80aa33b837795251cc3e886792982275e062409e13e4e236ffc34d676682aa96fdc751414de99c864bf132dde71581fa651c6343905e3bf988" + }, + "custom": { + "sigstore": { + "status": "Active", + "usage": "Unknown" + } + } + }, + "ctfe.pub": { + "length": 177, + "hashes": { + "sha256": "7fcb94a5d0ed541260473b990b99a6c39864c1fb16f3f3e594a5a3cebbfe138a", + "sha512": "4b20747d1afe2544238ad38cc0cc3010921b177d60ac743767e0ef675b915489bd01a36606c0ff83c06448622d7160f0d866c83d20f0c0f44653dcc3f9aa0bd4" + }, + "custom": { + "sigstore": { + "status": "Active", + "uri": "https://ctfe.sigstore.dev/test", + "usage": "CTFE" + } + } + }, + "ctfe_2022.pub": { + "length": 178, + "hashes": { + "sha256": "270488a309d22e804eeb245493e87c667658d749006b9fee9cc614572d4fbbdc", + "sha512": "e83fa4f427b24ee7728637fad1b4aa45ebde2ba02751fa860694b1bb16059a490328f9985e51cc70e4d237545315a1bc866dc4fdeef2f6248d99cc7a6077bf85" + }, + "custom": { + "sigstore": { + "status": "Active", + "uri": "https://ctfe.sigstore.dev/2022", + "usage": "CTFE" + } + } + }, + "fulcio.crt.pem": { + "length": 744, + "hashes": { + "sha256": "f360c53b2e13495a628b9b8096455badcb6d375b185c4816d95a5d746ff29908", + "sha512": "0713252a7fd17f7f3ab12f88a64accf2eb14b8ad40ca711d7fe8b4ecba3b24db9e9dffadb997b196d3867b8f9ff217faf930d80e4dab4e235c7fc3f07be69224" + }, + "custom": { + "sigstore": { + "status": "Expired", + "uri": "https://fulcio.sigstore.dev", + "usage": "Fulcio" + } + } + }, + "fulcio_intermediate_v1.crt.pem": { + "length": 789, + "hashes": { + "sha256": "f8cbecf186db7714624a5f4e99da31a917cbef70a94dd6921f5c3ca969dfe30a", + "sha512": "0f99f47dbc26c5f1e3cba0bfd9af4245a26e5cb735d6ef005792ec7e603f66fdb897de985973a6e50940ca7eff5e1849719e967b5ad2dac74a29115a41cf6f21" + }, + "custom": { + "sigstore": { + "status": "Active", + "uri": "https://fulcio.sigstore.dev", + "usage": "Fulcio" + } + } + }, + "fulcio_v1.crt.pem": { + "length": 740, + "hashes": { + "sha256": "f989aa23def87c549404eadba767768d2a3c8d6d30a8b793f9f518a8eafd2cf5", + "sha512": "f2e33a6dc208cee1f51d33bbea675ab0f0ced269617497985f9a0680689ee7073e4b6f8fef64c91bda590d30c129b3070dddce824c05bc165ac9802f0705cab6" + }, + "custom": { + "sigstore": { + "status": "Active", + "uri": "https://fulcio.sigstore.dev", + "usage": "Fulcio" + } + } + }, + "rekor.pub": { + "length": 178, + "hashes": { + "sha256": "dce5ef715502ec9f3cdfd11f8cc384b31a6141023d3e7595e9908a81cb6241bd", + "sha512": "0ae7705e02db33e814329746a4a0e5603c5bdcd91c96d072158d71011a2695788866565a2fec0fe363eb72cbcaeda39e54c5fe8d416daf9f3101fdba4217ef35" + }, + "custom": { + "sigstore": { + "status": "Active", + "uri": "https://rekor.sigstore.dev", + "usage": "Rekor" + } + } + }, + "trusted_root.json": { + "length": 4567, + "hashes": { + "sha256": "cec894ad77f79b1cb324150f6363012bcef7492954f3ab9134f932e6aa2e2e20", + "sha512": "08be2fd75c19e654caad30852847c566f97e6245f2bbcc54d347d6bdec7e879135e3395b5633b9e3b85d739fdb9b4eb8c09ddc70495792bc2ea65c8caf770d27" + } + } + } + }, + "signatures": [ + { + "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", + "sig": "" + }, + { + "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", + "sig": "" + }, + { + "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", + "sig": "" + }, + { + "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", + "sig": "" + }, + { + "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", + "sig": "" + } + ] +} \ No newline at end of file diff --git a/repository/staged/targets/artifact.pub b/repository/staged/targets/artifact.pub new file mode 100644 index 00000000..d6e745bd --- /dev/null +++ b/repository/staged/targets/artifact.pub @@ -0,0 +1,4 @@ +-----BEGIN PUBLIC KEY----- +MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEhyQCx0E9wQWSFI9ULGwy3BuRklnt +IqozONbbdbqz11hlRJy9c7SG+hdcFl9jE9uE/dwtuwU2MqU9T/cN0YkWww== +-----END PUBLIC KEY----- \ No newline at end of file diff --git a/repository/staged/targets/ctfe.pub b/repository/staged/targets/ctfe.pub new file mode 100644 index 00000000..1bb1488c --- /dev/null +++ b/repository/staged/targets/ctfe.pub @@ -0,0 +1,4 @@ +-----BEGIN PUBLIC KEY----- +MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEbfwR+RJudXscgRBRpKX1XFDy3Pyu +dDxz/SfnRi1fT8ekpfBd2O1uoz7jr3Z8nKzxA69EUQ+eFCFI3zeubPWU7w== +-----END PUBLIC KEY----- \ No newline at end of file diff --git a/repository/staged/targets/ctfe_2022.pub b/repository/staged/targets/ctfe_2022.pub new file mode 100644 index 00000000..32fa2ad1 --- /dev/null +++ b/repository/staged/targets/ctfe_2022.pub @@ -0,0 +1,4 @@ +-----BEGIN PUBLIC KEY----- +MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEiPSlFi0CmFTfEjCUqF9HuCEcYXNK +AaYalIJmBZ8yyezPjTqhxrKBpMnaocVtLJBI1eM3uXnQzQGAJdJ4gs9Fyw== +-----END PUBLIC KEY----- diff --git a/repository/staged/targets/fulcio.crt.pem b/repository/staged/targets/fulcio.crt.pem new file mode 100644 index 00000000..6a06ff30 --- /dev/null +++ b/repository/staged/targets/fulcio.crt.pem @@ -0,0 +1,13 @@ +-----BEGIN CERTIFICATE----- +MIIB+DCCAX6gAwIBAgITNVkDZoCiofPDsy7dfm6geLbuhzAKBggqhkjOPQQDAzAq +MRUwEwYDVQQKEwxzaWdzdG9yZS5kZXYxETAPBgNVBAMTCHNpZ3N0b3JlMB4XDTIx +MDMwNzAzMjAyOVoXDTMxMDIyMzAzMjAyOVowKjEVMBMGA1UEChMMc2lnc3RvcmUu +ZGV2MREwDwYDVQQDEwhzaWdzdG9yZTB2MBAGByqGSM49AgEGBSuBBAAiA2IABLSy +A7Ii5k+pNO8ZEWY0ylemWDowOkNa3kL+GZE5Z5GWehL9/A9bRNA3RbrsZ5i0Jcas +taRL7Sp5fp/jD5dxqc/UdTVnlvS16an+2Yfswe/QuLolRUCrcOE2+2iA5+tzd6Nm +MGQwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYE +FMjFHQBBmiQpMlEk6w2uSu1KBtPsMB8GA1UdIwQYMBaAFMjFHQBBmiQpMlEk6w2u +Su1KBtPsMAoGCCqGSM49BAMDA2gAMGUCMH8liWJfMui6vXXBhjDgY4MwslmN/TJx +Ve/83WrFomwmNf056y1X48F9c4m3a3ozXAIxAKjRay5/aj/jsKKGIkmQatjI8uup +Hr/+CxFvaJWmpYqNkLDGRU+9orzh5hI2RrcuaQ== +-----END CERTIFICATE----- \ No newline at end of file diff --git a/repository/staged/targets/fulcio_intermediate_v1.crt.pem b/repository/staged/targets/fulcio_intermediate_v1.crt.pem new file mode 100644 index 00000000..6d1c298b --- /dev/null +++ b/repository/staged/targets/fulcio_intermediate_v1.crt.pem @@ -0,0 +1,14 @@ +-----BEGIN CERTIFICATE----- +MIICGjCCAaGgAwIBAgIUALnViVfnU0brJasmRkHrn/UnfaQwCgYIKoZIzj0EAwMw +KjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0y +MjA0MTMyMDA2MTVaFw0zMTEwMDUxMzU2NThaMDcxFTATBgNVBAoTDHNpZ3N0b3Jl +LmRldjEeMBwGA1UEAxMVc2lnc3RvcmUtaW50ZXJtZWRpYXRlMHYwEAYHKoZIzj0C +AQYFK4EEACIDYgAE8RVS/ysH+NOvuDZyPIZtilgUF9NlarYpAd9HP1vBBH1U5CV7 +7LSS7s0ZiH4nE7Hv7ptS6LvvR/STk798LVgMzLlJ4HeIfF3tHSaexLcYpSASr1kS +0N/RgBJz/9jWCiXno3sweTAOBgNVHQ8BAf8EBAMCAQYwEwYDVR0lBAwwCgYIKwYB +BQUHAwMwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQU39Ppz1YkEZb5qNjp +KFWixi4YZD8wHwYDVR0jBBgwFoAUWMAeX5FFpWapesyQoZMi0CrFxfowCgYIKoZI +zj0EAwMDZwAwZAIwPCsQK4DYiZYDPIaDi5HFKnfxXx6ASSVmERfsynYBiX2X6SJR +nZU84/9DZdnFvvxmAjBOt6QpBlc4J/0DxvkTCqpclvziL6BCCPnjdlIB3Pu3BxsP +mygUY7Ii2zbdCdliiow= +-----END CERTIFICATE----- \ No newline at end of file diff --git a/repository/staged/targets/fulcio_v1.crt.pem b/repository/staged/targets/fulcio_v1.crt.pem new file mode 100644 index 00000000..3afc46bb --- /dev/null +++ b/repository/staged/targets/fulcio_v1.crt.pem @@ -0,0 +1,13 @@ +-----BEGIN CERTIFICATE----- +MIIB9zCCAXygAwIBAgIUALZNAPFdxHPwjeDloDwyYChAO/4wCgYIKoZIzj0EAwMw +KjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0y +MTEwMDcxMzU2NTlaFw0zMTEwMDUxMzU2NThaMCoxFTATBgNVBAoTDHNpZ3N0b3Jl +LmRldjERMA8GA1UEAxMIc2lnc3RvcmUwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAT7 +XeFT4rb3PQGwS4IajtLk3/OlnpgangaBclYpsYBr5i+4ynB07ceb3LP0OIOZdxex +X69c5iVuyJRQ+Hz05yi+UF3uBWAlHpiS5sh0+H2GHE7SXrk1EC5m1Tr19L9gg92j +YzBhMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRY +wB5fkUWlZql6zJChkyLQKsXF+jAfBgNVHSMEGDAWgBRYwB5fkUWlZql6zJChkyLQ +KsXF+jAKBggqhkjOPQQDAwNpADBmAjEAj1nHeXZp+13NWBNa+EDsDP8G1WWg1tCM +WP/WHPqpaVo0jhsweNFZgSs0eE7wYI4qAjEA2WB9ot98sIkoF3vZYdd3/VtWB5b9 +TNMea7Ix/stJ5TfcLLeABLE4BNJOsQ4vnBHJ +-----END CERTIFICATE----- \ No newline at end of file diff --git a/repository/staged/targets/rekor.pub b/repository/staged/targets/rekor.pub new file mode 100644 index 00000000..050ef601 --- /dev/null +++ b/repository/staged/targets/rekor.pub @@ -0,0 +1,4 @@ +-----BEGIN PUBLIC KEY----- +MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE2G2Y+2tabdTV5BcGiBIx0a9fAFwr +kBbmLSGtks4L3qX6yYY0zufBnhC8Ur/iy55GhWP/9A/bY2LhC30M9+RYtw== +-----END PUBLIC KEY----- diff --git a/repository/staged/targets/trusted_root.json b/repository/staged/targets/trusted_root.json new file mode 100644 index 00000000..bb4e6fcd --- /dev/null +++ b/repository/staged/targets/trusted_root.json @@ -0,0 +1,91 @@ +{ + "mediaType": "application/vnd.dev.sigstore.trustedroot+json;version=0.1", + "tlogs": [ + { + "baseUrl": "https://rekor.sigstore.dev", + "hashAlgorithm": "SHA2_256", + "publicKey": { + "rawBytes": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE2G2Y+2tabdTV5BcGiBIx0a9fAFwrkBbmLSGtks4L3qX6yYY0zufBnhC8Ur/iy55GhWP/9A/bY2LhC30M9+RYtw==", + "keyDetails": "PKIX_ECDSA_P256_SHA_256", + "validFor": { + "start": "2021-01-12T11:53:27.000Z" + } + }, + "logId": { + "keyId": "wNI9atQGlz+VWfO6LRygH4QUfY/8W4RFwiT5i5WRgB0=" + } + } + ], + "certificateAuthorities": [ + { + "subject": { + "organization": "sigstore.dev", + "commonName": "sigstore" + }, + "uri": "https://fulcio.sigstore.dev", + "certChain": { + "certificates": [ + { + "rawBytes": "MIIB+DCCAX6gAwIBAgITNVkDZoCiofPDsy7dfm6geLbuhzAKBggqhkjOPQQDAzAqMRUwEwYDVQQKEwxzaWdzdG9yZS5kZXYxETAPBgNVBAMTCHNpZ3N0b3JlMB4XDTIxMDMwNzAzMjAyOVoXDTMxMDIyMzAzMjAyOVowKjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTB2MBAGByqGSM49AgEGBSuBBAAiA2IABLSyA7Ii5k+pNO8ZEWY0ylemWDowOkNa3kL+GZE5Z5GWehL9/A9bRNA3RbrsZ5i0JcastaRL7Sp5fp/jD5dxqc/UdTVnlvS16an+2Yfswe/QuLolRUCrcOE2+2iA5+tzd6NmMGQwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYEFMjFHQBBmiQpMlEk6w2uSu1KBtPsMB8GA1UdIwQYMBaAFMjFHQBBmiQpMlEk6w2uSu1KBtPsMAoGCCqGSM49BAMDA2gAMGUCMH8liWJfMui6vXXBhjDgY4MwslmN/TJxVe/83WrFomwmNf056y1X48F9c4m3a3ozXAIxAKjRay5/aj/jsKKGIkmQatjI8uupHr/+CxFvaJWmpYqNkLDGRU+9orzh5hI2RrcuaQ==" + } + ] + }, + "validFor": { + "start": "2021-03-07T03:20:29.000Z", + "end": "2022-12-31T23:59:59.999Z" + } + }, + { + "subject": { + "organization": "sigstore.dev", + "commonName": "sigstore" + }, + "uri": "https://fulcio.sigstore.dev", + "certChain": { + "certificates": [ + { + "rawBytes": "MIIB9zCCAXygAwIBAgIUALZNAPFdxHPwjeDloDwyYChAO/4wCgYIKoZIzj0EAwMwKjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0yMTEwMDcxMzU2NTlaFw0zMTEwMDUxMzU2NThaMCoxFTATBgNVBAoTDHNpZ3N0b3JlLmRldjERMA8GA1UEAxMIc2lnc3RvcmUwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAT7XeFT4rb3PQGwS4IajtLk3/OlnpgangaBclYpsYBr5i+4ynB07ceb3LP0OIOZdxexX69c5iVuyJRQ+Hz05yi+UF3uBWAlHpiS5sh0+H2GHE7SXrk1EC5m1Tr19L9gg92jYzBhMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRYwB5fkUWlZql6zJChkyLQKsXF+jAfBgNVHSMEGDAWgBRYwB5fkUWlZql6zJChkyLQKsXF+jAKBggqhkjOPQQDAwNpADBmAjEAj1nHeXZp+13NWBNa+EDsDP8G1WWg1tCMWP/WHPqpaVo0jhsweNFZgSs0eE7wYI4qAjEA2WB9ot98sIkoF3vZYdd3/VtWB5b9TNMea7Ix/stJ5TfcLLeABLE4BNJOsQ4vnBHJ" + }, + { + "rawBytes": "MIICGjCCAaGgAwIBAgIUALnViVfnU0brJasmRkHrn/UnfaQwCgYIKoZIzj0EAwMwKjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0yMjA0MTMyMDA2MTVaFw0zMTEwMDUxMzU2NThaMDcxFTATBgNVBAoTDHNpZ3N0b3JlLmRldjEeMBwGA1UEAxMVc2lnc3RvcmUtaW50ZXJtZWRpYXRlMHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE8RVS/ysH+NOvuDZyPIZtilgUF9NlarYpAd9HP1vBBH1U5CV77LSS7s0ZiH4nE7Hv7ptS6LvvR/STk798LVgMzLlJ4HeIfF3tHSaexLcYpSASr1kS0N/RgBJz/9jWCiXno3sweTAOBgNVHQ8BAf8EBAMCAQYwEwYDVR0lBAwwCgYIKwYBBQUHAwMwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQU39Ppz1YkEZb5qNjpKFWixi4YZD8wHwYDVR0jBBgwFoAUWMAeX5FFpWapesyQoZMi0CrFxfowCgYIKoZIzj0EAwMDZwAwZAIwPCsQK4DYiZYDPIaDi5HFKnfxXx6ASSVmERfsynYBiX2X6SJRnZU84/9DZdnFvvxmAjBOt6QpBlc4J/0DxvkTCqpclvziL6BCCPnjdlIB3Pu3BxsPmygUY7Ii2zbdCdliiow=" + } + ] + }, + "validFor": { + "start": "2022-04-13T20:06:15.000Z" + } + } + ], + "ctlogs": [ + { + "baseUrl": "https://ctfe.sigstore.dev/test", + "hashAlgorithm": "SHA2_256", + "publicKey": { + "rawBytes": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEbfwR+RJudXscgRBRpKX1XFDy3PyudDxz/SfnRi1fT8ekpfBd2O1uoz7jr3Z8nKzxA69EUQ+eFCFI3zeubPWU7w==", + "keyDetails": "PKIX_ECDSA_P256_SHA_256", + "validFor": { + "start": "2021-03-14T00:00:00.000Z", + "end": "2022-10-31T23:59:59.999Z" + } + }, + "logId": { + "keyId": "CGCS8ChS/2hF0dFrJ4ScRWcYrBY9wzjSbea8IgY2b3I=" + } + }, + { + "baseUrl": "https://ctfe.sigstore.dev/2022", + "hashAlgorithm": "SHA2_256", + "publicKey": { + "rawBytes": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEiPSlFi0CmFTfEjCUqF9HuCEcYXNKAaYalIJmBZ8yyezPjTqhxrKBpMnaocVtLJBI1eM3uXnQzQGAJdJ4gs9Fyw==", + "keyDetails": "PKIX_ECDSA_P256_SHA_256", + "validFor": { + "start": "2022-10-20T00:00:00.000Z" + } + }, + "logId": { + "keyId": "3T0wasbHETJjGR4cmWc3AqJKXrjePK3/h4pygC8p7o4=" + } + } + ], + "timestampAuthorities": [] +} From 8e23a523511bdfcc46bf86093fee9241f15661de Mon Sep 17 00:00:00 2001 From: Bob Callaway Date: Tue, 28 Feb 2023 18:49:30 +0000 Subject: [PATCH 2/8] sign-root-targets for bobcallaway (#674) Signed-off-by: Bob Callaway --- repository/staged/root.json | 2 +- repository/staged/targets.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/repository/staged/root.json b/repository/staged/root.json index eabcfed2..f2542f3e 100644 --- a/repository/staged/root.json +++ b/repository/staged/root.json @@ -134,7 +134,7 @@ }, { "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", - "sig": "" + "sig": "304502205c7b76ad222ffe16fed152f5bbf1c18b3df4814bf93703fea4605ae335914953022100a9d187ee02a4babe12b1646b572171bac60b23b0846ff3f067ded075194b549c" }, { "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", diff --git a/repository/staged/targets.json b/repository/staged/targets.json index 92b06794..306c7849 100644 --- a/repository/staged/targets.json +++ b/repository/staged/targets.json @@ -130,7 +130,7 @@ }, { "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", - "sig": "" + "sig": "3045022100968006fba63357bfbe81a6bd43228f46586fd5a15cd2519fc00d629636687ef1022002b2766ee0d845d48db09a8787d375d535d10573f4fc227b06a8b4ec46b883f4" } ] } \ No newline at end of file From bc8918c1460ce6168030420cbb361f313cce8dfd Mon Sep 17 00:00:00 2001 From: Joshua Lock Date: Tue, 28 Feb 2023 18:53:18 +0000 Subject: [PATCH 3/8] sign-root-targets for joshuagl (#675) Signed-off-by: Joshua Lock --- repository/staged/root.json | 2 +- repository/staged/targets.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/repository/staged/root.json b/repository/staged/root.json index f2542f3e..58e2b955 100644 --- a/repository/staged/root.json +++ b/repository/staged/root.json @@ -138,7 +138,7 @@ }, { "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", - "sig": "" + "sig": "30440220724e672fd7a2dbd338dfea683712a77bc1579ae5061dbc501d498ade02ea3aeb022012758bd3f1d4d245d92a692d26f743ad7a1f9af0982d1983a8619186c1fbcdd4" } ] } \ No newline at end of file diff --git a/repository/staged/targets.json b/repository/staged/targets.json index 306c7849..a5e5cbaa 100644 --- a/repository/staged/targets.json +++ b/repository/staged/targets.json @@ -114,7 +114,7 @@ "signatures": [ { "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", - "sig": "" + "sig": "3044022061696eb6f8b51dd576b283f1326721fc1287ed87301f96b2b694e711efd0308702205a8f8b30c093032400d0e8a2d16388cebc3ad36fddd78baed7e8f6199a95aec8" }, { "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", From 0afb63104a18eb878a447a74b08a555262524a29 Mon Sep 17 00:00:00 2001 From: dlorenc Date: Tue, 28 Feb 2023 13:54:43 -0500 Subject: [PATCH 4/8] sign-root-targets for dlorenc (#677) Signed-off-by: Dan Lorenc --- repository/staged/root.json | 2 +- repository/staged/targets.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/repository/staged/root.json b/repository/staged/root.json index 58e2b955..d03a8e91 100644 --- a/repository/staged/root.json +++ b/repository/staged/root.json @@ -122,7 +122,7 @@ "signatures": [ { "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", - "sig": "" + "sig": "3044022079941eab7035ffd603354ee9a072ad87ad24e084f2aa52a718f76b21545d90190220368a65bb4ac83a9938885f5bba6a0b9a25c9979c85d85840497a95e47466eafb" }, { "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", diff --git a/repository/staged/targets.json b/repository/staged/targets.json index a5e5cbaa..805b36ed 100644 --- a/repository/staged/targets.json +++ b/repository/staged/targets.json @@ -118,7 +118,7 @@ }, { "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", - "sig": "" + "sig": "3046022100b1c637be9b9ca306538a686f24943fa1bceb0e6efaeb8d8c66182502a6e1a651022100a9c002f701ecf37f7fbf493bd2a97751f1280d9786fb34fafa13b78182f59822" }, { "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", From c1c041773ed1b54e86b7074a8bc012abd110ecd0 Mon Sep 17 00:00:00 2001 From: Santiago Torres Date: Wed, 1 Mar 2023 02:24:02 -0500 Subject: [PATCH 5/8] sign-root-targets for SantiagoTorres (#683) Signed-off-by: Santiago Torres Arias --- repository/staged/root.json | 2 +- repository/staged/targets.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/repository/staged/root.json b/repository/staged/root.json index d03a8e91..6574cd1b 100644 --- a/repository/staged/root.json +++ b/repository/staged/root.json @@ -130,7 +130,7 @@ }, { "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", - "sig": "" + "sig": "304402207875857b20d8258e0c888e55516cb50593746543cd3c34c9743efb2921cb2a660220127107a67b585e67d3df0538a6be1f5d4834857d1d88da9f8a6b8b8ac8998904" }, { "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", diff --git a/repository/staged/targets.json b/repository/staged/targets.json index 805b36ed..9da52ac8 100644 --- a/repository/staged/targets.json +++ b/repository/staged/targets.json @@ -126,7 +126,7 @@ }, { "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", - "sig": "" + "sig": "3045022100c508e1c2ac28ff5beb50aa2868f55fcba73fe17ea02d73d76b334778a65aba8102203ffd85878fd0f8ec78f8124a5229720c2d91536608d5487022fe502d6e4d7649" }, { "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", From 6987ee6d0d9c4cbec703104069ed65410fa9bd59 Mon Sep 17 00:00:00 2001 From: Marina Moore Date: Wed, 1 Mar 2023 02:24:52 -0500 Subject: [PATCH 6/8] sign-root-targets for mnm678 (#685) Signed-off-by: Marina Moore --- repository/staged/root.json | 2 +- repository/staged/targets.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/repository/staged/root.json b/repository/staged/root.json index 6574cd1b..0b2c06bf 100644 --- a/repository/staged/root.json +++ b/repository/staged/root.json @@ -126,7 +126,7 @@ }, { "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", - "sig": "" + "sig": "3045022100ca33d35657c55b93c827ecad61be61e6d91da886d413f5083894a70d6e9af1cd022049d2b8b50d34a4e48cb3832a17a82c1ec1ae6b61af2a6db6e7d1c63d81a0dae7" }, { "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", diff --git a/repository/staged/targets.json b/repository/staged/targets.json index 9da52ac8..d096a05a 100644 --- a/repository/staged/targets.json +++ b/repository/staged/targets.json @@ -122,7 +122,7 @@ }, { "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", - "sig": "" + "sig": "30450221009b51e35eb5f6fbe664d8d9f2131a0293d6bf4e9128debba563892d17e51c4132022056cf3a48a482dc09d56b78ffacf13a5045054b7861b154239fc6b78c44b282e7" }, { "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", From 889d87dd393899fb14dd54e996579931bf0f0cc0 Mon Sep 17 00:00:00 2001 From: Sigstore Bot <86837369+sigstore-bot@users.noreply.github.com> Date: Wed, 1 Mar 2023 09:23:44 +0100 Subject: [PATCH 7/8] Update Snapshot and Timestamp (#687) Signed-off-by: sigstore-review-bot --- repository/staged/snapshot.json | 56 ++++++++++++++++++++++++++++++++ repository/staged/timestamp.json | 24 ++++++++++++++ 2 files changed, 80 insertions(+) create mode 100644 repository/staged/snapshot.json create mode 100644 repository/staged/timestamp.json diff --git a/repository/staged/snapshot.json b/repository/staged/snapshot.json new file mode 100644 index 00000000..afe74b4e --- /dev/null +++ b/repository/staged/snapshot.json @@ -0,0 +1,56 @@ +{ + "signed": { + "_type": "snapshot", + "spec_version": "1.0", + "version": 72, + "expires": "2023-03-22T07:40:30Z", + "meta": { + "rekor.json": { + "length": 797, + "hashes": { + "sha256": "9d2e1a5842937d8e0d3e3759170b0ad15c56c5df36afc5cf73583ddd283a463b", + "sha512": "176e9e710ddddd1b357a7d7970831bae59763395a0c18976110cbd35b25e5412dc50f356ec421a7a30265670cf7aec9ed84ee944ba700ec2394b9c876645b960" + }, + "version": 3 + }, + "revocation.json": { + "length": 800, + "hashes": { + "sha256": "6f60848ba8fb0955a02abfd1232fb3845dc9ee9f418bf03521a7ddb48217e040", + "sha512": "a965dddd0d0edef6c59e84cf02ecf5a53299f633fd339b2b61814a4219ab4df672a6390f265b8b29e1c8cea9368ea3440df013790759d50231a30df1c1f02551" + }, + "version": 2 + }, + "root.json": { + "length": 5297, + "hashes": { + "sha256": "f5ad897c9414cca99629f400ac3585e41bd8ebb44c5af07fb08dd636a9eced9c", + "sha512": "7445ddfdd338ef786c324fc3d68f75be28cb95b7fb581d2a383e3e5dde18aa17029a5636ec0a22e9631931bbcb34057788311718ea41e21e7cdd3c0de13ede42" + }, + "version": 2 + }, + "staging.json": { + "length": 401, + "hashes": { + "sha256": "cda57759abac5375397eea3531d7ca51e3a67da9a2dc93f2cdab749e2ae73149", + "sha512": "e9e59587bde453144c7079884a880c706f1d43f26e8bb23fac2b96a99569a2a30ae6cf51ec51c2454f760ce83d4c20915e062aede7f319b3da6a6ed1d26ca281" + }, + "version": 2 + }, + "targets.json": { + "length": 4737, + "hashes": { + "sha256": "79698024b773e7c669b8c5def0031fdc7cd2ab7785d80f7f72a7495472f63218", + "sha512": "e19872e801ccefee869177d72a6f929197fd02faaa823fbd0f0bb6a0833ef7246040f90c313a271fbb2d29ac7ca5cab7aa09d422a9ec85950f2ad297fc455915" + }, + "version": 6 + } + } + }, + "signatures": [ + { + "keyid": "45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b", + "sig": "304402200750a6706a7f38ddda3875dd04a1ed718acd06731ef9d3c3aacbe54df3210088022047fe3d63c59f1e62d22cc9ae6bedd7f553f00485b1f425456f1b11bf9f49827a" + } + ] +} \ No newline at end of file diff --git a/repository/staged/timestamp.json b/repository/staged/timestamp.json new file mode 100644 index 00000000..ee8e5121 --- /dev/null +++ b/repository/staged/timestamp.json @@ -0,0 +1,24 @@ +{ + "signed": { + "_type": "timestamp", + "spec_version": "1.0", + "version": 72, + "expires": "2023-03-15T07:40:31Z", + "meta": { + "snapshot.json": { + "length": 1973, + "hashes": { + "sha256": "f8f80ec4771ca2d29e722a576466a17ed176ae2fc101b4bf1a4b928353631b41", + "sha512": "a943c8c7a190162388828b74cc9381070fdea3a19ab7eac639a0c41ebd23cb3a9b9e81ce6039d4282349936a1c4ecd08425005653cb3cb6a2e02d1d01d00fccb" + }, + "version": 72 + } + } + }, + "signatures": [ + { + "keyid": "e1863ba02070322ebc626dcecf9d881a3a38c35c3b41a83765b6ad6c37eaec2a", + "sig": "304402204ace97e2eaee86ae93cd638f485cf5a614c7fb93d1d65247d85b69d79dde33f50220249ca60defe598cf1181ce9188f0c8e07a2c77e874563cd572e1f5afecd35112" + } + ] +} \ No newline at end of file From ac79df7d7ced9a5373c466575f76e21a40708302 Mon Sep 17 00:00:00 2001 From: Fredrik Skogman Date: Wed, 1 Mar 2023 11:21:39 +0100 Subject: [PATCH 8/8] publish for kommendorkapten (#688) Signed-off-by: Fredrik Skogman --- .../root.json => repository/6.root.json} | 0 .../6.targets.json} | 0 repository/repository/72.snapshot.json | 12 +-- repository/repository/root.json | 32 ++----- repository/repository/snapshot.json | 12 +-- repository/repository/targets.json | 29 ++++-- ...95792bc2ea65c8caf770d27.trusted_root.json} | 0 ...54f3ab9134f932e6aa2e2e20.trusted_root.json | 91 +++++++++++++++++++ repository/repository/timestamp.json | 10 +- repository/staged/snapshot.json | 56 ------------ repository/staged/targets/artifact.pub | 4 - repository/staged/targets/ctfe.pub | 4 - repository/staged/targets/ctfe_2022.pub | 4 - repository/staged/targets/fulcio.crt.pem | 13 --- .../targets/fulcio_intermediate_v1.crt.pem | 14 --- repository/staged/targets/fulcio_v1.crt.pem | 13 --- repository/staged/targets/rekor.pub | 4 - repository/staged/timestamp.json | 24 ----- 18 files changed, 138 insertions(+), 184 deletions(-) rename repository/{staged/root.json => repository/6.root.json} (100%) rename repository/{staged/targets.json => repository/6.targets.json} (100%) rename repository/{staged/targets/trusted_root.json => repository/targets/08be2fd75c19e654caad30852847c566f97e6245f2bbcc54d347d6bdec7e879135e3395b5633b9e3b85d739fdb9b4eb8c09ddc70495792bc2ea65c8caf770d27.trusted_root.json} (100%) create mode 100644 repository/repository/targets/cec894ad77f79b1cb324150f6363012bcef7492954f3ab9134f932e6aa2e2e20.trusted_root.json delete mode 100644 repository/staged/snapshot.json delete mode 100644 repository/staged/targets/artifact.pub delete mode 100644 repository/staged/targets/ctfe.pub delete mode 100644 repository/staged/targets/ctfe_2022.pub delete mode 100644 repository/staged/targets/fulcio.crt.pem delete mode 100644 repository/staged/targets/fulcio_intermediate_v1.crt.pem delete mode 100644 repository/staged/targets/fulcio_v1.crt.pem delete mode 100644 repository/staged/targets/rekor.pub delete mode 100644 repository/staged/timestamp.json diff --git a/repository/staged/root.json b/repository/repository/6.root.json similarity index 100% rename from repository/staged/root.json rename to repository/repository/6.root.json diff --git a/repository/staged/targets.json b/repository/repository/6.targets.json similarity index 100% rename from repository/staged/targets.json rename to repository/repository/6.targets.json diff --git a/repository/repository/72.snapshot.json b/repository/repository/72.snapshot.json index e6c50039..afe74b4e 100644 --- a/repository/repository/72.snapshot.json +++ b/repository/repository/72.snapshot.json @@ -3,7 +3,7 @@ "_type": "snapshot", "spec_version": "1.0", "version": 72, - "expires": "2023-03-22T00:09:39Z", + "expires": "2023-03-22T07:40:30Z", "meta": { "rekor.json": { "length": 797, @@ -38,19 +38,19 @@ "version": 2 }, "targets.json": { - "length": 4188, + "length": 4737, "hashes": { - "sha256": "5dbc142fcda89c914175b4e8570a2745d41f8ff799625b8890e6e56e009038ca", - "sha512": "e9397f3c1b84c7c7e52f91e4e62409c66af42bde74f93e12005054ee5fc00a1811685306276bea115dc1e4679cd8e6d9aeb49115e9493872b0c1c9308f93714a" + "sha256": "79698024b773e7c669b8c5def0031fdc7cd2ab7785d80f7f72a7495472f63218", + "sha512": "e19872e801ccefee869177d72a6f929197fd02faaa823fbd0f0bb6a0833ef7246040f90c313a271fbb2d29ac7ca5cab7aa09d422a9ec85950f2ad297fc455915" }, - "version": 5 + "version": 6 } } }, "signatures": [ { "keyid": "45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b", - "sig": "304502205a3364cefd870314d1bd7f4a9a97c3198e985964a7ed81cd08543a8feef33279022100f3a57fa9531d15d4cdda1aae416d41a12259817803b501fbab691c42d2fce0ca" + "sig": "304402200750a6706a7f38ddda3875dd04a1ed718acd06731ef9d3c3aacbe54df3210088022047fe3d63c59f1e62d22cc9ae6bedd7f553f00485b1f425456f1b11bf9f49827a" } ] } \ No newline at end of file diff --git a/repository/repository/root.json b/repository/repository/root.json index 38f80f94..0b2c06bf 100644 --- a/repository/repository/root.json +++ b/repository/repository/root.json @@ -2,8 +2,8 @@ "signed": { "_type": "root", "spec_version": "1.0", - "version": 5, - "expires": "2023-04-18T18:13:43Z", + "version": 6, + "expires": "2023-08-28T07:54:10Z", "keys": { "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99": { "keytype": "ecdsa-sha2-nistp256", @@ -122,35 +122,23 @@ "signatures": [ { "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", - "sig": "3045022100fc1c2be509ce50ea917bbad1d9efe9d96c8c2ebea04af2717aa3d9c6fe617a75022012eef282a19f2d8bd4818aa333ef48a06489f49d4d34a20b8fe8fc867bb25a7a" + "sig": "3044022079941eab7035ffd603354ee9a072ad87ad24e084f2aa52a718f76b21545d90190220368a65bb4ac83a9938885f5bba6a0b9a25c9979c85d85840497a95e47466eafb" }, { "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", - "sig": "30450221008a4392ae5057fc00778b651e61fea244766a4ae58db84d9f1d3810720ab0f3b702207c49e59e8031318caf02252ecea1281cecc1e5986c309a9cef61f455ecf7165d" + "sig": "3045022100ca33d35657c55b93c827ecad61be61e6d91da886d413f5083894a70d6e9af1cd022049d2b8b50d34a4e48cb3832a17a82c1ec1ae6b61af2a6db6e7d1c63d81a0dae7" }, { - "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", - "sig": "3046022100da1b8dc5d53aaffbbfac98de3e23ee2d2ad3446a7bed09fac0f88bae19be2587022100b681c046afc3919097dfe794e0d819be891e2e850aade315bec06b0c4dea221b" - }, - { - "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", - "sig": "3046022100b534e0030e1b271133ecfbdf3ba9fbf3becb3689abea079a2150afbb63cdb7c70221008c39a718fd9495f249b4ab8788d5b9dc269f0868dbe38b272f48207359d3ded9" - }, - { - "keyid": "2f64fb5eac0cf94dd39bb45308b98920055e9a0d8e012a7220787834c60aef97", - "sig": "3045022100fc1c2be509ce50ea917bbad1d9efe9d96c8c2ebea04af2717aa3d9c6fe617a75022012eef282a19f2d8bd4818aa333ef48a06489f49d4d34a20b8fe8fc867bb25a7a" - }, - { - "keyid": "eaf22372f417dd618a46f6c627dbc276e9fd30a004fc94f9be946e73f8bd090b", - "sig": "30450221008a4392ae5057fc00778b651e61fea244766a4ae58db84d9f1d3810720ab0f3b702207c49e59e8031318caf02252ecea1281cecc1e5986c309a9cef61f455ecf7165d" + "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", + "sig": "304402207875857b20d8258e0c888e55516cb50593746543cd3c34c9743efb2921cb2a660220127107a67b585e67d3df0538a6be1f5d4834857d1d88da9f8a6b8b8ac8998904" }, { - "keyid": "f505595165a177a41750a8e864ed1719b1edfccd5a426fd2c0ffda33ce7ff209", - "sig": "3046022100da1b8dc5d53aaffbbfac98de3e23ee2d2ad3446a7bed09fac0f88bae19be2587022100b681c046afc3919097dfe794e0d819be891e2e850aade315bec06b0c4dea221b" + "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", + "sig": "304502205c7b76ad222ffe16fed152f5bbf1c18b3df4814bf93703fea4605ae335914953022100a9d187ee02a4babe12b1646b572171bac60b23b0846ff3f067ded075194b549c" }, { - "keyid": "75e867ab10e121fdef32094af634707f43ddd79c6bab8ad6c5ab9f03f4ea8c90", - "sig": "3046022100b534e0030e1b271133ecfbdf3ba9fbf3becb3689abea079a2150afbb63cdb7c70221008c39a718fd9495f249b4ab8788d5b9dc269f0868dbe38b272f48207359d3ded9" + "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", + "sig": "30440220724e672fd7a2dbd338dfea683712a77bc1579ae5061dbc501d498ade02ea3aeb022012758bd3f1d4d245d92a692d26f743ad7a1f9af0982d1983a8619186c1fbcdd4" } ] } \ No newline at end of file diff --git a/repository/repository/snapshot.json b/repository/repository/snapshot.json index e6c50039..afe74b4e 100644 --- a/repository/repository/snapshot.json +++ b/repository/repository/snapshot.json @@ -3,7 +3,7 @@ "_type": "snapshot", "spec_version": "1.0", "version": 72, - "expires": "2023-03-22T00:09:39Z", + "expires": "2023-03-22T07:40:30Z", "meta": { "rekor.json": { "length": 797, @@ -38,19 +38,19 @@ "version": 2 }, "targets.json": { - "length": 4188, + "length": 4737, "hashes": { - "sha256": "5dbc142fcda89c914175b4e8570a2745d41f8ff799625b8890e6e56e009038ca", - "sha512": "e9397f3c1b84c7c7e52f91e4e62409c66af42bde74f93e12005054ee5fc00a1811685306276bea115dc1e4679cd8e6d9aeb49115e9493872b0c1c9308f93714a" + "sha256": "79698024b773e7c669b8c5def0031fdc7cd2ab7785d80f7f72a7495472f63218", + "sha512": "e19872e801ccefee869177d72a6f929197fd02faaa823fbd0f0bb6a0833ef7246040f90c313a271fbb2d29ac7ca5cab7aa09d422a9ec85950f2ad297fc455915" }, - "version": 5 + "version": 6 } } }, "signatures": [ { "keyid": "45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b", - "sig": "304502205a3364cefd870314d1bd7f4a9a97c3198e985964a7ed81cd08543a8feef33279022100f3a57fa9531d15d4cdda1aae416d41a12259817803b501fbab691c42d2fce0ca" + "sig": "304402200750a6706a7f38ddda3875dd04a1ed718acd06731ef9d3c3aacbe54df3210088022047fe3d63c59f1e62d22cc9ae6bedd7f553f00485b1f425456f1b11bf9f49827a" } ] } \ No newline at end of file diff --git a/repository/repository/targets.json b/repository/repository/targets.json index 35985780..d096a05a 100644 --- a/repository/repository/targets.json +++ b/repository/repository/targets.json @@ -2,8 +2,8 @@ "signed": { "_type": "targets", "spec_version": "1.0", - "version": 5, - "expires": "2023-04-18T18:13:43Z", + "version": 6, + "expires": "2023-08-28T07:54:10Z", "targets": { "artifact.pub": { "length": 177, @@ -101,25 +101,36 @@ "usage": "Rekor" } } + }, + "trusted_root.json": { + "length": 4567, + "hashes": { + "sha256": "cec894ad77f79b1cb324150f6363012bcef7492954f3ab9134f932e6aa2e2e20", + "sha512": "08be2fd75c19e654caad30852847c566f97e6245f2bbcc54d347d6bdec7e879135e3395b5633b9e3b85d739fdb9b4eb8c09ddc70495792bc2ea65c8caf770d27" + } } } }, "signatures": [ - { - "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", - "sig": "3045022100bf03c32b59f65285b91118172503c9f7e5f65fea0d4647f31adfb6cf18ed09db022069778e655e4198a3346ea9239dacb111571c7e7ed4c96d166ddce06306486a9c" - }, { "keyid": "2e61cd0cbf4a8f45809bda9f7f78c0d33ad11842ff94ae340873e2664dc843de", - "sig": "30440220562f52b2243e66d8dff72dbf67a29faf82ad60ecbe0638acd4ab00338244f0b102206051db1fbe5a7815b4076096d5f8002c0dc1ecce8d9ef9d696cdacff50c7463a" + "sig": "3044022061696eb6f8b51dd576b283f1326721fc1287ed87301f96b2b694e711efd0308702205a8f8b30c093032400d0e8a2d16388cebc3ad36fddd78baed7e8f6199a95aec8" }, { "keyid": "ff51e17fcf253119b7033f6f57512631da4a0969442afcf9fc8b141c7f2be99c", - "sig": "3045022100df19bbbabed7672c8e797152d6b97aa1f14fdcd6e10ce0e41703d5e7ad37c2e502200583577549f561079273460afe2b827b16d5e76a63616390bf956ee5f24d60eb" + "sig": "3046022100b1c637be9b9ca306538a686f24943fa1bceb0e6efaeb8d8c66182502a6e1a651022100a9c002f701ecf37f7fbf493bd2a97751f1280d9786fb34fafa13b78182f59822" }, { "keyid": "25a0eb450fd3ee2bd79218c963dce3f1cc6118badf251bf149f0bd07d5cabe99", - "sig": "304502207d79f0ee8965f82c24fc5b96d6fbfa760b1f7192fd829a64a32ec03c579220310221008498a536dcc7aefd267875267f08cb27f8ae455dc6d8c53fe628e2fda2772dd4" + "sig": "30450221009b51e35eb5f6fbe664d8d9f2131a0293d6bf4e9128debba563892d17e51c4132022056cf3a48a482dc09d56b78ffacf13a5045054b7861b154239fc6b78c44b282e7" + }, + { + "keyid": "f5312f542c21273d9485a49394386c4575804770667f2ddb59b3bf0669fddd2f", + "sig": "3045022100c508e1c2ac28ff5beb50aa2868f55fcba73fe17ea02d73d76b334778a65aba8102203ffd85878fd0f8ec78f8124a5229720c2d91536608d5487022fe502d6e4d7649" + }, + { + "keyid": "7f7513b25429a64473e10ce3ad2f3da372bbdd14b65d07bbaf547e7c8bbbe62b", + "sig": "3045022100968006fba63357bfbe81a6bd43228f46586fd5a15cd2519fc00d629636687ef1022002b2766ee0d845d48db09a8787d375d535d10573f4fc227b06a8b4ec46b883f4" } ] } \ No newline at end of file diff --git a/repository/staged/targets/trusted_root.json b/repository/repository/targets/08be2fd75c19e654caad30852847c566f97e6245f2bbcc54d347d6bdec7e879135e3395b5633b9e3b85d739fdb9b4eb8c09ddc70495792bc2ea65c8caf770d27.trusted_root.json similarity index 100% rename from repository/staged/targets/trusted_root.json rename to repository/repository/targets/08be2fd75c19e654caad30852847c566f97e6245f2bbcc54d347d6bdec7e879135e3395b5633b9e3b85d739fdb9b4eb8c09ddc70495792bc2ea65c8caf770d27.trusted_root.json diff --git a/repository/repository/targets/cec894ad77f79b1cb324150f6363012bcef7492954f3ab9134f932e6aa2e2e20.trusted_root.json b/repository/repository/targets/cec894ad77f79b1cb324150f6363012bcef7492954f3ab9134f932e6aa2e2e20.trusted_root.json new file mode 100644 index 00000000..bb4e6fcd --- /dev/null +++ b/repository/repository/targets/cec894ad77f79b1cb324150f6363012bcef7492954f3ab9134f932e6aa2e2e20.trusted_root.json @@ -0,0 +1,91 @@ +{ + "mediaType": "application/vnd.dev.sigstore.trustedroot+json;version=0.1", + "tlogs": [ + { + "baseUrl": "https://rekor.sigstore.dev", + "hashAlgorithm": "SHA2_256", + "publicKey": { + "rawBytes": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE2G2Y+2tabdTV5BcGiBIx0a9fAFwrkBbmLSGtks4L3qX6yYY0zufBnhC8Ur/iy55GhWP/9A/bY2LhC30M9+RYtw==", + "keyDetails": "PKIX_ECDSA_P256_SHA_256", + "validFor": { + "start": "2021-01-12T11:53:27.000Z" + } + }, + "logId": { + "keyId": "wNI9atQGlz+VWfO6LRygH4QUfY/8W4RFwiT5i5WRgB0=" + } + } + ], + "certificateAuthorities": [ + { + "subject": { + "organization": "sigstore.dev", + "commonName": "sigstore" + }, + "uri": "https://fulcio.sigstore.dev", + "certChain": { + "certificates": [ + { + "rawBytes": "MIIB+DCCAX6gAwIBAgITNVkDZoCiofPDsy7dfm6geLbuhzAKBggqhkjOPQQDAzAqMRUwEwYDVQQKEwxzaWdzdG9yZS5kZXYxETAPBgNVBAMTCHNpZ3N0b3JlMB4XDTIxMDMwNzAzMjAyOVoXDTMxMDIyMzAzMjAyOVowKjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTB2MBAGByqGSM49AgEGBSuBBAAiA2IABLSyA7Ii5k+pNO8ZEWY0ylemWDowOkNa3kL+GZE5Z5GWehL9/A9bRNA3RbrsZ5i0JcastaRL7Sp5fp/jD5dxqc/UdTVnlvS16an+2Yfswe/QuLolRUCrcOE2+2iA5+tzd6NmMGQwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYEFMjFHQBBmiQpMlEk6w2uSu1KBtPsMB8GA1UdIwQYMBaAFMjFHQBBmiQpMlEk6w2uSu1KBtPsMAoGCCqGSM49BAMDA2gAMGUCMH8liWJfMui6vXXBhjDgY4MwslmN/TJxVe/83WrFomwmNf056y1X48F9c4m3a3ozXAIxAKjRay5/aj/jsKKGIkmQatjI8uupHr/+CxFvaJWmpYqNkLDGRU+9orzh5hI2RrcuaQ==" + } + ] + }, + "validFor": { + "start": "2021-03-07T03:20:29.000Z", + "end": "2022-12-31T23:59:59.999Z" + } + }, + { + "subject": { + "organization": "sigstore.dev", + "commonName": "sigstore" + }, + "uri": "https://fulcio.sigstore.dev", + "certChain": { + "certificates": [ + { + "rawBytes": "MIIB9zCCAXygAwIBAgIUALZNAPFdxHPwjeDloDwyYChAO/4wCgYIKoZIzj0EAwMwKjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0yMTEwMDcxMzU2NTlaFw0zMTEwMDUxMzU2NThaMCoxFTATBgNVBAoTDHNpZ3N0b3JlLmRldjERMA8GA1UEAxMIc2lnc3RvcmUwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAT7XeFT4rb3PQGwS4IajtLk3/OlnpgangaBclYpsYBr5i+4ynB07ceb3LP0OIOZdxexX69c5iVuyJRQ+Hz05yi+UF3uBWAlHpiS5sh0+H2GHE7SXrk1EC5m1Tr19L9gg92jYzBhMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRYwB5fkUWlZql6zJChkyLQKsXF+jAfBgNVHSMEGDAWgBRYwB5fkUWlZql6zJChkyLQKsXF+jAKBggqhkjOPQQDAwNpADBmAjEAj1nHeXZp+13NWBNa+EDsDP8G1WWg1tCMWP/WHPqpaVo0jhsweNFZgSs0eE7wYI4qAjEA2WB9ot98sIkoF3vZYdd3/VtWB5b9TNMea7Ix/stJ5TfcLLeABLE4BNJOsQ4vnBHJ" + }, + { + "rawBytes": "MIICGjCCAaGgAwIBAgIUALnViVfnU0brJasmRkHrn/UnfaQwCgYIKoZIzj0EAwMwKjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0yMjA0MTMyMDA2MTVaFw0zMTEwMDUxMzU2NThaMDcxFTATBgNVBAoTDHNpZ3N0b3JlLmRldjEeMBwGA1UEAxMVc2lnc3RvcmUtaW50ZXJtZWRpYXRlMHYwEAYHKoZIzj0CAQYFK4EEACIDYgAE8RVS/ysH+NOvuDZyPIZtilgUF9NlarYpAd9HP1vBBH1U5CV77LSS7s0ZiH4nE7Hv7ptS6LvvR/STk798LVgMzLlJ4HeIfF3tHSaexLcYpSASr1kS0N/RgBJz/9jWCiXno3sweTAOBgNVHQ8BAf8EBAMCAQYwEwYDVR0lBAwwCgYIKwYBBQUHAwMwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQU39Ppz1YkEZb5qNjpKFWixi4YZD8wHwYDVR0jBBgwFoAUWMAeX5FFpWapesyQoZMi0CrFxfowCgYIKoZIzj0EAwMDZwAwZAIwPCsQK4DYiZYDPIaDi5HFKnfxXx6ASSVmERfsynYBiX2X6SJRnZU84/9DZdnFvvxmAjBOt6QpBlc4J/0DxvkTCqpclvziL6BCCPnjdlIB3Pu3BxsPmygUY7Ii2zbdCdliiow=" + } + ] + }, + "validFor": { + "start": "2022-04-13T20:06:15.000Z" + } + } + ], + "ctlogs": [ + { + "baseUrl": "https://ctfe.sigstore.dev/test", + "hashAlgorithm": "SHA2_256", + "publicKey": { + "rawBytes": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEbfwR+RJudXscgRBRpKX1XFDy3PyudDxz/SfnRi1fT8ekpfBd2O1uoz7jr3Z8nKzxA69EUQ+eFCFI3zeubPWU7w==", + "keyDetails": "PKIX_ECDSA_P256_SHA_256", + "validFor": { + "start": "2021-03-14T00:00:00.000Z", + "end": "2022-10-31T23:59:59.999Z" + } + }, + "logId": { + "keyId": "CGCS8ChS/2hF0dFrJ4ScRWcYrBY9wzjSbea8IgY2b3I=" + } + }, + { + "baseUrl": "https://ctfe.sigstore.dev/2022", + "hashAlgorithm": "SHA2_256", + "publicKey": { + "rawBytes": "MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEiPSlFi0CmFTfEjCUqF9HuCEcYXNKAaYalIJmBZ8yyezPjTqhxrKBpMnaocVtLJBI1eM3uXnQzQGAJdJ4gs9Fyw==", + "keyDetails": "PKIX_ECDSA_P256_SHA_256", + "validFor": { + "start": "2022-10-20T00:00:00.000Z" + } + }, + "logId": { + "keyId": "3T0wasbHETJjGR4cmWc3AqJKXrjePK3/h4pygC8p7o4=" + } + } + ], + "timestampAuthorities": [] +} diff --git a/repository/repository/timestamp.json b/repository/repository/timestamp.json index beb4f9c6..ee8e5121 100644 --- a/repository/repository/timestamp.json +++ b/repository/repository/timestamp.json @@ -3,13 +3,13 @@ "_type": "timestamp", "spec_version": "1.0", "version": 72, - "expires": "2023-03-15T00:09:39Z", + "expires": "2023-03-15T07:40:31Z", "meta": { "snapshot.json": { - "length": 1975, + "length": 1973, "hashes": { - "sha256": "bb61446104540a235ee99bc442173fe5c4288310fe2899796c2c95595e854495", - "sha512": "4360802e25569863954832b045f4d1633fb2f60f78d79089912352da156348b19fe59672339d9b5d51b65b50ec09558412bbf88b871dabc232a396dae9e1c10e" + "sha256": "f8f80ec4771ca2d29e722a576466a17ed176ae2fc101b4bf1a4b928353631b41", + "sha512": "a943c8c7a190162388828b74cc9381070fdea3a19ab7eac639a0c41ebd23cb3a9b9e81ce6039d4282349936a1c4ecd08425005653cb3cb6a2e02d1d01d00fccb" }, "version": 72 } @@ -18,7 +18,7 @@ "signatures": [ { "keyid": "e1863ba02070322ebc626dcecf9d881a3a38c35c3b41a83765b6ad6c37eaec2a", - "sig": "304502201757ccc0c3cd15f94091a1b9a7d7f2437df0dbd91faec32e917a8f89ee430332022100fdf0ec87714e951e5f8cdbc0d48b321c3522b4c985a1609417dc05f05124c207" + "sig": "304402204ace97e2eaee86ae93cd638f485cf5a614c7fb93d1d65247d85b69d79dde33f50220249ca60defe598cf1181ce9188f0c8e07a2c77e874563cd572e1f5afecd35112" } ] } \ No newline at end of file diff --git a/repository/staged/snapshot.json b/repository/staged/snapshot.json deleted file mode 100644 index afe74b4e..00000000 --- a/repository/staged/snapshot.json +++ /dev/null @@ -1,56 +0,0 @@ -{ - "signed": { - "_type": "snapshot", - "spec_version": "1.0", - "version": 72, - "expires": "2023-03-22T07:40:30Z", - "meta": { - "rekor.json": { - "length": 797, - "hashes": { - "sha256": "9d2e1a5842937d8e0d3e3759170b0ad15c56c5df36afc5cf73583ddd283a463b", - "sha512": "176e9e710ddddd1b357a7d7970831bae59763395a0c18976110cbd35b25e5412dc50f356ec421a7a30265670cf7aec9ed84ee944ba700ec2394b9c876645b960" - }, - "version": 3 - }, - "revocation.json": { - "length": 800, - "hashes": { - "sha256": "6f60848ba8fb0955a02abfd1232fb3845dc9ee9f418bf03521a7ddb48217e040", - "sha512": "a965dddd0d0edef6c59e84cf02ecf5a53299f633fd339b2b61814a4219ab4df672a6390f265b8b29e1c8cea9368ea3440df013790759d50231a30df1c1f02551" - }, - "version": 2 - }, - "root.json": { - "length": 5297, - "hashes": { - "sha256": "f5ad897c9414cca99629f400ac3585e41bd8ebb44c5af07fb08dd636a9eced9c", - "sha512": "7445ddfdd338ef786c324fc3d68f75be28cb95b7fb581d2a383e3e5dde18aa17029a5636ec0a22e9631931bbcb34057788311718ea41e21e7cdd3c0de13ede42" - }, - "version": 2 - }, - "staging.json": { - "length": 401, - "hashes": { - "sha256": "cda57759abac5375397eea3531d7ca51e3a67da9a2dc93f2cdab749e2ae73149", - "sha512": "e9e59587bde453144c7079884a880c706f1d43f26e8bb23fac2b96a99569a2a30ae6cf51ec51c2454f760ce83d4c20915e062aede7f319b3da6a6ed1d26ca281" - }, - "version": 2 - }, - "targets.json": { - "length": 4737, - "hashes": { - "sha256": "79698024b773e7c669b8c5def0031fdc7cd2ab7785d80f7f72a7495472f63218", - "sha512": "e19872e801ccefee869177d72a6f929197fd02faaa823fbd0f0bb6a0833ef7246040f90c313a271fbb2d29ac7ca5cab7aa09d422a9ec85950f2ad297fc455915" - }, - "version": 6 - } - } - }, - "signatures": [ - { - "keyid": "45b283825eb184cabd582eb17b74fc8ed404f68cf452acabdad2ed6f90ce216b", - "sig": "304402200750a6706a7f38ddda3875dd04a1ed718acd06731ef9d3c3aacbe54df3210088022047fe3d63c59f1e62d22cc9ae6bedd7f553f00485b1f425456f1b11bf9f49827a" - } - ] -} \ No newline at end of file diff --git a/repository/staged/targets/artifact.pub b/repository/staged/targets/artifact.pub deleted file mode 100644 index d6e745bd..00000000 --- a/repository/staged/targets/artifact.pub +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEhyQCx0E9wQWSFI9ULGwy3BuRklnt -IqozONbbdbqz11hlRJy9c7SG+hdcFl9jE9uE/dwtuwU2MqU9T/cN0YkWww== ------END PUBLIC KEY----- \ No newline at end of file diff --git a/repository/staged/targets/ctfe.pub b/repository/staged/targets/ctfe.pub deleted file mode 100644 index 1bb1488c..00000000 --- a/repository/staged/targets/ctfe.pub +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEbfwR+RJudXscgRBRpKX1XFDy3Pyu -dDxz/SfnRi1fT8ekpfBd2O1uoz7jr3Z8nKzxA69EUQ+eFCFI3zeubPWU7w== ------END PUBLIC KEY----- \ No newline at end of file diff --git a/repository/staged/targets/ctfe_2022.pub b/repository/staged/targets/ctfe_2022.pub deleted file mode 100644 index 32fa2ad1..00000000 --- a/repository/staged/targets/ctfe_2022.pub +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEiPSlFi0CmFTfEjCUqF9HuCEcYXNK -AaYalIJmBZ8yyezPjTqhxrKBpMnaocVtLJBI1eM3uXnQzQGAJdJ4gs9Fyw== ------END PUBLIC KEY----- diff --git a/repository/staged/targets/fulcio.crt.pem b/repository/staged/targets/fulcio.crt.pem deleted file mode 100644 index 6a06ff30..00000000 --- a/repository/staged/targets/fulcio.crt.pem +++ /dev/null @@ -1,13 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIB+DCCAX6gAwIBAgITNVkDZoCiofPDsy7dfm6geLbuhzAKBggqhkjOPQQDAzAq -MRUwEwYDVQQKEwxzaWdzdG9yZS5kZXYxETAPBgNVBAMTCHNpZ3N0b3JlMB4XDTIx -MDMwNzAzMjAyOVoXDTMxMDIyMzAzMjAyOVowKjEVMBMGA1UEChMMc2lnc3RvcmUu -ZGV2MREwDwYDVQQDEwhzaWdzdG9yZTB2MBAGByqGSM49AgEGBSuBBAAiA2IABLSy -A7Ii5k+pNO8ZEWY0ylemWDowOkNa3kL+GZE5Z5GWehL9/A9bRNA3RbrsZ5i0Jcas -taRL7Sp5fp/jD5dxqc/UdTVnlvS16an+2Yfswe/QuLolRUCrcOE2+2iA5+tzd6Nm -MGQwDgYDVR0PAQH/BAQDAgEGMBIGA1UdEwEB/wQIMAYBAf8CAQEwHQYDVR0OBBYE -FMjFHQBBmiQpMlEk6w2uSu1KBtPsMB8GA1UdIwQYMBaAFMjFHQBBmiQpMlEk6w2u -Su1KBtPsMAoGCCqGSM49BAMDA2gAMGUCMH8liWJfMui6vXXBhjDgY4MwslmN/TJx -Ve/83WrFomwmNf056y1X48F9c4m3a3ozXAIxAKjRay5/aj/jsKKGIkmQatjI8uup -Hr/+CxFvaJWmpYqNkLDGRU+9orzh5hI2RrcuaQ== ------END CERTIFICATE----- \ No newline at end of file diff --git a/repository/staged/targets/fulcio_intermediate_v1.crt.pem b/repository/staged/targets/fulcio_intermediate_v1.crt.pem deleted file mode 100644 index 6d1c298b..00000000 --- a/repository/staged/targets/fulcio_intermediate_v1.crt.pem +++ /dev/null @@ -1,14 +0,0 @@ ------BEGIN CERTIFICATE----- -MIICGjCCAaGgAwIBAgIUALnViVfnU0brJasmRkHrn/UnfaQwCgYIKoZIzj0EAwMw -KjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0y -MjA0MTMyMDA2MTVaFw0zMTEwMDUxMzU2NThaMDcxFTATBgNVBAoTDHNpZ3N0b3Jl -LmRldjEeMBwGA1UEAxMVc2lnc3RvcmUtaW50ZXJtZWRpYXRlMHYwEAYHKoZIzj0C -AQYFK4EEACIDYgAE8RVS/ysH+NOvuDZyPIZtilgUF9NlarYpAd9HP1vBBH1U5CV7 -7LSS7s0ZiH4nE7Hv7ptS6LvvR/STk798LVgMzLlJ4HeIfF3tHSaexLcYpSASr1kS -0N/RgBJz/9jWCiXno3sweTAOBgNVHQ8BAf8EBAMCAQYwEwYDVR0lBAwwCgYIKwYB -BQUHAwMwEgYDVR0TAQH/BAgwBgEB/wIBADAdBgNVHQ4EFgQU39Ppz1YkEZb5qNjp -KFWixi4YZD8wHwYDVR0jBBgwFoAUWMAeX5FFpWapesyQoZMi0CrFxfowCgYIKoZI -zj0EAwMDZwAwZAIwPCsQK4DYiZYDPIaDi5HFKnfxXx6ASSVmERfsynYBiX2X6SJR -nZU84/9DZdnFvvxmAjBOt6QpBlc4J/0DxvkTCqpclvziL6BCCPnjdlIB3Pu3BxsP -mygUY7Ii2zbdCdliiow= ------END CERTIFICATE----- \ No newline at end of file diff --git a/repository/staged/targets/fulcio_v1.crt.pem b/repository/staged/targets/fulcio_v1.crt.pem deleted file mode 100644 index 3afc46bb..00000000 --- a/repository/staged/targets/fulcio_v1.crt.pem +++ /dev/null @@ -1,13 +0,0 @@ ------BEGIN CERTIFICATE----- -MIIB9zCCAXygAwIBAgIUALZNAPFdxHPwjeDloDwyYChAO/4wCgYIKoZIzj0EAwMw -KjEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MREwDwYDVQQDEwhzaWdzdG9yZTAeFw0y -MTEwMDcxMzU2NTlaFw0zMTEwMDUxMzU2NThaMCoxFTATBgNVBAoTDHNpZ3N0b3Jl -LmRldjERMA8GA1UEAxMIc2lnc3RvcmUwdjAQBgcqhkjOPQIBBgUrgQQAIgNiAAT7 -XeFT4rb3PQGwS4IajtLk3/OlnpgangaBclYpsYBr5i+4ynB07ceb3LP0OIOZdxex -X69c5iVuyJRQ+Hz05yi+UF3uBWAlHpiS5sh0+H2GHE7SXrk1EC5m1Tr19L9gg92j -YzBhMA4GA1UdDwEB/wQEAwIBBjAPBgNVHRMBAf8EBTADAQH/MB0GA1UdDgQWBBRY -wB5fkUWlZql6zJChkyLQKsXF+jAfBgNVHSMEGDAWgBRYwB5fkUWlZql6zJChkyLQ -KsXF+jAKBggqhkjOPQQDAwNpADBmAjEAj1nHeXZp+13NWBNa+EDsDP8G1WWg1tCM -WP/WHPqpaVo0jhsweNFZgSs0eE7wYI4qAjEA2WB9ot98sIkoF3vZYdd3/VtWB5b9 -TNMea7Ix/stJ5TfcLLeABLE4BNJOsQ4vnBHJ ------END CERTIFICATE----- \ No newline at end of file diff --git a/repository/staged/targets/rekor.pub b/repository/staged/targets/rekor.pub deleted file mode 100644 index 050ef601..00000000 --- a/repository/staged/targets/rekor.pub +++ /dev/null @@ -1,4 +0,0 @@ ------BEGIN PUBLIC KEY----- -MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE2G2Y+2tabdTV5BcGiBIx0a9fAFwr -kBbmLSGtks4L3qX6yYY0zufBnhC8Ur/iy55GhWP/9A/bY2LhC30M9+RYtw== ------END PUBLIC KEY----- diff --git a/repository/staged/timestamp.json b/repository/staged/timestamp.json deleted file mode 100644 index ee8e5121..00000000 --- a/repository/staged/timestamp.json +++ /dev/null @@ -1,24 +0,0 @@ -{ - "signed": { - "_type": "timestamp", - "spec_version": "1.0", - "version": 72, - "expires": "2023-03-15T07:40:31Z", - "meta": { - "snapshot.json": { - "length": 1973, - "hashes": { - "sha256": "f8f80ec4771ca2d29e722a576466a17ed176ae2fc101b4bf1a4b928353631b41", - "sha512": "a943c8c7a190162388828b74cc9381070fdea3a19ab7eac639a0c41ebd23cb3a9b9e81ce6039d4282349936a1c4ecd08425005653cb3cb6a2e02d1d01d00fccb" - }, - "version": 72 - } - } - }, - "signatures": [ - { - "keyid": "e1863ba02070322ebc626dcecf9d881a3a38c35c3b41a83765b6ad6c37eaec2a", - "sig": "304402204ace97e2eaee86ae93cd638f485cf5a614c7fb93d1d65247d85b69d79dde33f50220249ca60defe598cf1181ce9188f0c8e07a2c77e874563cd572e1f5afecd35112" - } - ] -} \ No newline at end of file