Skip to content

Instantly share code, notes, and snippets.

@JamieMagee
Created April 28, 2025 04:13
Show Gist options
  • Save JamieMagee/e34eefdf0ee407fb0c78638c57566838 to your computer and use it in GitHub Desktop.
Save JamieMagee/e34eefdf0ee407fb0c78638c57566838 to your computer and use it in GitHub Desktop.
Rubygems Sigstore Validation
{
"mediaType": "application/vnd.dev.sigstore.bundle.v0.3+json",
"messageSignature": {
"signature": "MEQCIAJnRsQ5Y7ufVFzztm/8DiujpoTep3XT/3zo1+c4sJhWAiARpaaM2NSGL2mLxHpV1rzjqAhTw0SGnLnoZNOvGj6wsg==",
"messageDigest": {
"digest": "f+Jw4tA/L7BsGZY+mHSJ2eukbeXn+NZ/9ACf3qzdV4g=",
"algorithm": "SHA2_256"
}
},
"verificationMaterial": {
"certificate": {
"rawBytes": "LS0tLS1CRUdJTiBDRVJUSUZJQ0FURS0tLS0tCk1JSUhORENDQnJ1Z0F3SUJBZ0lVVFE0TXdZUy9wS3IrVGxmOEhJWDBKVXFvT0Zrd0NnWUlLb1pJemowRUF3TXcKTnpFVk1CTUdBMVVFQ2hNTWMybG5jM1J2Y21VdVpHVjJNUjR3SEFZRFZRUURFeFZ6YVdkemRHOXlaUzFwYm5SbApjbTFsWkdsaGRHVXdIaGNOTWpVd05ESTBNVFV4T1RNeFdoY05NalV3TkRJME1UVXlPVE14V2pBQU1Ga3dFd1lICktvWkl6ajBDQVFZSUtvWkl6ajBEQVFjRFFnQUVOaHo3WjlWVnh0MmM3SnpaNUNqTktjbGlnUm94bWo0MTA2TGcKb1huYjNVYzdVQytLaTRnZ0tEU2FrZnZobjBSSXdzWHNZZTBwa2IzRitTeC95RXlRUHFPQ0Jkb3dnZ1hXTUE0RwpBMVVkRHdFQi93UUVBd0lIZ0RBVEJnTlZIU1VFRERBS0JnZ3JCZ0VGQlFjREF6QWRCZ05WSFE0RUZnUVVmaFptCi9QaWZuTnc4dlZSc2Z3c0tjZUc2bDJVd0h3WURWUjBqQkJnd0ZvQVUzOVBwejFZa0VaYjVxTmpwS0ZXaXhpNFkKWkQ4d2ZRWURWUjBSQVFIL0JITXdjWVp2YUhSMGNITTZMeTluYVhSb2RXSXVZMjl0TDJSbGNHVnVaR0ZpYjNRdgpaR1Z3Wlc1a1lXSnZkQzFqYjNKbEx5NW5hWFJvZFdJdmQyOXlhMlpzYjNkekwyZGxiWE10Y21Wc1pXRnpaUzEwCmJ5MXlkV0o1WjJWdGN5NTViV3hBY21WbWN5OTBZV2R6TDNZd0xqTXhNQzR3TURrR0Npc0dBUVFCZzc4d0FRRUUKSzJoMGRIQnpPaTh2ZEc5clpXNHVZV04wYVc5dWN5NW5hWFJvZFdKMWMyVnlZMjl1ZEdWdWRDNWpiMjB3RlFZSwpLd1lCQkFHRHZ6QUJBZ1FIY21Wc1pXRnpaVEEyQmdvckJnRUVBWU8vTUFFREJDZ3habVl4WlRFeE1ERmxaVE5rCk9HWXdZVGMxWXpKalpUWmlabVUwTUROaU5qQXhPV0kyTkRZek1DZ0dDaXNHQVFRQmc3OHdBUVFFR2tkbGJYTWcKTFNCU1pXeGxZWE5sSUhSdklGSjFZbmxIWlcxek1DZ0dDaXNHQVFRQmc3OHdBUVVFR21SbGNHVnVaR0ZpYjNRdgpaR1Z3Wlc1a1lXSnZkQzFqYjNKbE1DQUdDaXNHQVFRQmc3OHdBUVlFRW5KbFpuTXZkR0ZuY3k5Mk1DNHpNVEF1Ck1EQTdCZ29yQmdFRUFZTy9NQUVJQkMwTUsyaDBkSEJ6T2k4dmRHOXJaVzR1WVdOMGFXOXVjeTVuYVhSb2RXSjEKYzJWeVkyOXVkR1Z1ZEM1amIyMHdmd1lLS3dZQkJBR0R2ekFCQ1FSeERHOW9kSFJ3Y3pvdkwyZHBkR2gxWWk1agpiMjB2WkdWd1pXNWtZV0p2ZEM5a1pYQmxibVJoWW05MExXTnZjbVV2TG1kcGRHaDFZaTkzYjNKclpteHZkM012CloyVnRjeTF5Wld4bFlYTmxMWFJ2TFhKMVlubG5aVzF6TG5sdGJFQnlaV1p6TDNSaFozTXZkakF1TXpFd0xqQXcKT0FZS0t3WUJCQUdEdnpBQkNnUXFEQ2d4Wm1ZeFpURXhNREZsWlROa09HWXdZVGMxWXpKalpUWmlabVUwTUROaQpOakF4T1dJMk5EWXpNQjBHQ2lzR0FRUUJnNzh3QVFzRUR3d05aMmwwYUhWaUxXaHZjM1JsWkRBOUJnb3JCZ0VFCkFZTy9NQUVNQkM4TUxXaDBkSEJ6T2k4dloybDBhSFZpTG1OdmJTOWtaWEJsYm1SaFltOTBMMlJsY0dWdVpHRmkKYjNRdFkyOXlaVEE0QmdvckJnRUVBWU8vTUFFTkJDb01LREZtWmpGbE1URXdNV1ZsTTJRNFpqQmhOelZqTW1ObApObUptWlRRd00ySTJNREU1WWpZME5qTXdJZ1lLS3dZQkJBR0R2ekFCRGdRVURCSnlaV1p6TDNSaFozTXZkakF1Ck16RXdMakF3R0FZS0t3WUJCQUdEdnpBQkR3UUtEQWc1TXpFMk16QTNNekF0QmdvckJnRUVBWU8vTUFFUUJCOE0KSFdoMGRIQnpPaTh2WjJsMGFIVmlMbU52YlM5a1pYQmxibVJoWW05ME1CZ0dDaXNHQVFRQmc3OHdBUkVFQ2d3SQpNamN6TkRjME56WXdmd1lLS3dZQkJBR0R2ekFCRWdSeERHOW9kSFJ3Y3pvdkwyZHBkR2gxWWk1amIyMHZaR1Z3ClpXNWtZV0p2ZEM5a1pYQmxibVJoWW05MExXTnZjbVV2TG1kcGRHaDFZaTkzYjNKclpteHZkM012WjJWdGN5MXkKWld4bFlYTmxMWFJ2TFhKMVlubG5aVzF6TG5sdGJFQnlaV1p6TDNSaFozTXZkakF1TXpFd0xqQXdPQVlLS3dZQgpCQUdEdnpBQkV3UXFEQ2d4Wm1ZeFpURXhNREZsWlROa09HWXdZVGMxWXpKalpUWmlabVUwTUROaU5qQXhPV0kyCk5EWXpNQmNHQ2lzR0FRUUJnNzh3QVJRRUNRd0hjbVZzWldGelpUQmhCZ29yQmdFRUFZTy9NQUVWQkZNTVVXaDAKZEhCek9pOHZaMmwwYUhWaUxtTnZiUzlrWlhCbGJtUmhZbTkwTDJSbGNHVnVaR0ZpYjNRdFkyOXlaUzloWTNScApiMjV6TDNKMWJuTXZNVFEyTkRVek1UY3dNVGN2WVhSMFpXMXdkSE12TVRBV0Jnb3JCZ0VFQVlPL01BRVdCQWdNCkJuQjFZbXhwWXpDQmlRWUtLd1lCQkFIV2VRSUVBZ1I3QkhrQWR3QjFBTjA5TUdyR3h4RXlZeGtlSEpsbk53S2kKU2w2NDNqeXQvNGVLY29BdktlNk9BQUFCbG1oaDgwWUFBQVFEQUVZd1JBSWdQMDZmakpPdnhxSXhVY0s5ZFdoNQpzSVk0SnYybEJoNktSOEExNGxUVlpUOENJRjdpU0pnZUsvU0UzOG9MR0ZXTWgvQ081U2YrUGQzMzBJbzNvOXY2CjN4UVpNQW9HQ0NxR1NNNDlCQU1EQTJjQU1HUUNNRkxCR1NhQ2ZWdnF1U1hGR2w1UlZ4YWRVeXEvMFFDcnZUNTAKcHM0ZVZQSFZRZGVIQmZZSmFqSytzVTZwOTFsSmZRSXdIYlFNQ1JpWTg3SXcyV2tsQzlJbFBobXB5dHVqd2N1Ugp0R1BLb3Y2Z3o1N1VMbVR4RCtoem9MSElTZy90RWNySQotLS0tLUVORCBDRVJUSUZJQ0FURS0tLS0tCg=="
},
"tlogEntries": [
{
"logId": {
"keyId": "wNI9atQGlz+VWfO6LRygH4QUfY/8W4RFwiT5i5WRgB0="
},
"logIndex": "202118658",
"kindVersion": {
"kind": "hashedrekord",
"version": "0.0.1"
},
"inclusionProof": {
"hashes": [
"dq99wehvF9AOJpYuqaKtw0i9ltXvF+F8Yftm4KybLYQ=",
"tmz8bojR/1NEs7cXwT4yJqxA21CCsQr8H4hnLYXec44=",
"9Df+saNC+11IYkEZwJSyhb0YIPOyJUl452kLdIzuRJ4=",
"ngQSJBmYSZBZ2ne2zW/+rRtQx2bqNtQgXVJjAzXBqe0=",
"7Bok6Zq6I6QJWCVtvVj1y7mvPvPTGpHclE4NlFX1hfM=",
"J9+mvwefTBbCTXU6F5QaTwMH1F4kq03RjVr2WhF/n9k=",
"Z8iVv+RMvdo4SPvKZJJo99vwi9vOgAfDPgOjcrY3yak=",
"aUlRtieuWt+IBCWtLMTIV7V70p5BkIGiMZ5m5CMXYAo=",
"qKeXX2boRrINq89UU3z6BEIKMYhPvtU9IXGFTtZuFUk=",
"MxlJojUl/Rfw7qqC9D7CBrq5SCOBPMpaNED0MGmoAqU=",
"/BABU1ES7L+0n7tIHTcN7QZAij6GJcrOYuIxH8KT6uc=",
"7N6jB94KQtn2vHhQDg2eyhu8ePKIlVubmWAZxsebCYo=",
"KV+MW5JUxrRfc1uqBlRku7rr9iNoMcPYUpa2w2RGb8c=",
"TFZzqXVlkqB0HywtoNLcsLW3GP6kC9360IVVQWwjq80=",
"0Km8UrfRhoUuq7G4OPTXTFR20l/6nmxe8V5EfzOhgx4=",
"gGNvqHSiyarbPiEG0lmBLLIhU2F6djF/wmlcFeaQdP8=",
"7v8qPHNDLerpduaMx06eb/MwgoQwczTn/cYGKX/9wZ4="
],
"logIndex": "80214396",
"rootHash": "+ALun0sYFcP36JGzRaSQ7nJ+i1BmShISO/dUioRBLe4=",
"treeSize": "80214397",
"checkpoint": {
"envelope": "rekor.sigstore.dev - 1193050959916656506\n80214397\n+ALun0sYFcP36JGzRaSQ7nJ+i1BmShISO/dUioRBLe4=\n\n— rekor.sigstore.dev wNI9ajBEAiAN7QKAuvnD59kiSo3qjhuYUGEKYaEZbh0UrwFp/p8OYgIgXy2trU2KopKDIe5Qm1ExhYXerq2e0FAaR4vhFljRaMs=\n"
}
},
"integratedTime": "1745507972",
"inclusionPromise": {
"signedEntryTimestamp": "MEQCIFrIs0FIRgCLoI7Ez9kObptQ68Lgm4x/U7+VOyspLCfAAiBroNcavMWlenw/Q5tZPtuXVSgkDE6Bpoac3yXgKYtFKA=="
},
"canonicalizedBody": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiaGFzaGVkcmVrb3JkIiwic3BlYyI6eyJkYXRhIjp7Imhhc2giOnsiYWxnb3JpdGhtIjoic2hhMjU2IiwidmFsdWUiOiI3ZmUyNzBlMmQwM2YyZmIwNmMxOTk2M2U5ODc0ODlkOWViYTQ2ZGU1ZTdmOGQ2N2ZmNDAwOWZkZWFjZGQ1Nzg4In19LCJzaWduYXR1cmUiOnsiY29udGVudCI6Ik1FUUNJQUpuUnNRNVk3dWZWRnp6dG0vOERpdWpwb1RlcDNYVC8zem8xK2M0c0poV0FpQVJwYWFNMk5TR0wybUx4SHBWMXJ6anFBaFR3MFNHbkxub1pOT3ZHajZ3c2c9PSIsInB1YmxpY0tleSI6eyJjb250ZW50IjoiTFMwdExTMUNSVWRKVGlCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2sxSlNVaE9SRU5EUW5KMVowRjNTVUpCWjBsVlZGRTBUWGRaVXk5d1MzSXJWR3htT0VoSldEQktWWEZ2VDBacmQwTm5XVWxMYjFwSmVtb3dSVUYzVFhjS1RucEZWazFDVFVkQk1WVkZRMmhOVFdNeWJHNWpNMUoyWTIxVmRWcEhWakpOVWpSM1NFRlpSRlpSVVVSRmVGWjZZVmRrZW1SSE9YbGFVekZ3WW01U2JBcGpiVEZzV2tkc2FHUkhWWGRJYUdOT1RXcFZkMDVFU1RCTlZGVjRUMVJOZUZkb1kwNU5hbFYzVGtSSk1FMVVWWGxQVkUxNFYycEJRVTFHYTNkRmQxbElDa3R2V2tsNmFqQkRRVkZaU1V0dldrbDZhakJFUVZGalJGRm5RVVZPYUhvM1dqbFdWbmgwTW1NM1NucGFOVU5xVGt0amJHbG5VbTk0YldvME1UQTJUR2NLYjFodVlqTlZZemRWUXl0TGFUUm5aMHRFVTJGclpuWm9iakJTU1hkeldITlpaVEJ3YTJJelJpdFRlQzk1UlhsUlVIRlBRMEprYjNkbloxaFhUVUUwUndwQk1WVmtSSGRGUWk5M1VVVkJkMGxJWjBSQlZFSm5UbFpJVTFWRlJFUkJTMEpuWjNKQ1owVkdRbEZqUkVGNlFXUkNaMDVXU0ZFMFJVWm5VVlZtYUZwdENpOVFhV1p1VG5jNGRsWlNjMlozYzB0alpVYzJiREpWZDBoM1dVUldVakJxUWtKbmQwWnZRVlV6T1ZCd2VqRlphMFZhWWpWeFRtcHdTMFpYYVhocE5Ga0tXa1E0ZDJaUldVUldVakJTUVZGSUwwSklUWGRqV1ZwMllVaFNNR05JVFRaTWVUbHVZVmhTYjJSWFNYVlpNamwwVERKU2JHTkhWblZhUjBacFlqTlJkZ3BhUjFaM1dsYzFhMWxYU25aa1F6RnFZak5LYkV4NU5XNWhXRkp2WkZkSmRtUXlPWGxoTWxwellqTmtla3d5Wkd4aVdFMTBZMjFXYzFwWFJucGFVekV3Q21KNU1YbGtWMG8xV2pKV2RHTjVOVFZpVjNoQlkyMVdiV041T1RCWlYyUjZURE5aZDB4cVRYaE5RelIzVFVSclIwTnBjMGRCVVZGQ1p6YzRkMEZSUlVVS1N6Sm9NR1JJUW5wUGFUaDJaRWM1Y2xwWE5IVlpWMDR3WVZjNWRXTjVOVzVoV0ZKdlpGZEtNV015Vm5sWk1qbDFaRWRXZFdSRE5XcGlNakIzUmxGWlN3cExkMWxDUWtGSFJIWjZRVUpCWjFGSVkyMVdjMXBYUm5wYVZFRXlRbWR2Y2tKblJVVkJXVTh2VFVGRlJFSkRaM2hhYlZsNFdsUkZlRTFFUm14YVZFNXJDazlIV1hkWlZHTXhXWHBLYWxwVVdtbGFiVlV3VFVST2FVNXFRWGhQVjBreVRrUlplazFEWjBkRGFYTkhRVkZSUW1jM09IZEJVVkZGUjJ0a2JHSllUV2NLVEZOQ1UxcFhlR3haV0U1c1NVaFNka2xHU2pGWmJteElXbGN4ZWsxRFowZERhWE5IUVZGUlFtYzNPSGRCVVZWRlIyMVNiR05IVm5WYVIwWnBZak5SZGdwYVIxWjNXbGMxYTFsWFNuWmtRekZxWWpOS2JFMURRVWREYVhOSFFWRlJRbWMzT0hkQlVWbEZSVzVLYkZwdVRYWmtSMFp1WTNrNU1rMUROSHBOVkVGMUNrMUVRVGRDWjI5eVFtZEZSVUZaVHk5TlFVVkpRa013VFVzeWFEQmtTRUo2VDJrNGRtUkhPWEphVnpSMVdWZE9NR0ZYT1hWamVUVnVZVmhTYjJSWFNqRUtZekpXZVZreU9YVmtSMVoxWkVNMWFtSXlNSGRtZDFsTFMzZFpRa0pCUjBSMmVrRkNRMUZTZUVSSE9XOWtTRkozWTNwdmRrd3laSEJrUjJneFdXazFhZ3BpTWpCMldrZFdkMXBYTld0WlYwcDJaRU01YTFwWVFteGliVkpvV1cwNU1FeFhUblpqYlZWMlRHMWtjR1JIYURGWmFUa3pZak5LY2xwdGVIWmtNMDEyQ2xveVZuUmplVEY1V2xkNGJGbFlUbXhNV0ZKMlRGaEtNVmx1Ykc1YVZ6RjZURzVzZEdKRlFubGFWMXA2VEROU2FGb3pUWFprYWtGMVRYcEZkMHhxUVhjS1QwRlpTMHQzV1VKQ1FVZEVkbnBCUWtOblVYRkVRMmQ0V20xWmVGcFVSWGhOUkVac1dsUk9hMDlIV1hkWlZHTXhXWHBLYWxwVVdtbGFiVlV3VFVST2FRcE9ha0Y0VDFkSk1rNUVXWHBOUWpCSFEybHpSMEZSVVVKbk56aDNRVkZ6UlVSM2QwNWFNbXd3WVVoV2FVeFhhSFpqTTFKc1drUkJPVUpuYjNKQ1owVkZDa0ZaVHk5TlFVVk5Ra000VFV4WGFEQmtTRUo2VDJrNGRsb3liREJoU0ZacFRHMU9kbUpUT1d0YVdFSnNZbTFTYUZsdE9UQk1NbEpzWTBkV2RWcEhSbWtLWWpOUmRGa3lPWGxhVkVFMFFtZHZja0puUlVWQldVOHZUVUZGVGtKRGIwMUxSRVp0V21wR2JFMVVSWGROVjFac1RUSlJORnBxUW1oT2VsWnFUVzFPYkFwT2JVcHRXbFJSZDAweVNUSk5SRVUxV1dwWk1FNXFUWGRKWjFsTFMzZFpRa0pCUjBSMmVrRkNSR2RSVlVSQ1NubGFWMXA2VEROU2FGb3pUWFprYWtGMUNrMTZSWGRNYWtGM1IwRlpTMHQzV1VKQ1FVZEVkbnBCUWtSM1VVdEVRV2MxVFhwRk1rMTZRVE5OZWtGMFFtZHZja0puUlVWQldVOHZUVUZGVVVKQ09FMEtTRmRvTUdSSVFucFBhVGgyV2pKc01HRklWbWxNYlU1MllsTTVhMXBZUW14aWJWSm9XVzA1TUUxQ1owZERhWE5IUVZGUlFtYzNPSGRCVWtWRlEyZDNTUXBOYW1ONlRrUmpNRTU2V1hkbWQxbExTM2RaUWtKQlIwUjJla0ZDUldkU2VFUkhPVzlrU0ZKM1kzcHZka3d5WkhCa1IyZ3hXV2sxYW1JeU1IWmFSMVozQ2xwWE5XdFpWMHAyWkVNNWExcFlRbXhpYlZKb1dXMDVNRXhYVG5aamJWVjJURzFrY0dSSGFERlphVGt6WWpOS2NscHRlSFprTTAxMldqSldkR041TVhrS1dsZDRiRmxZVG14TVdGSjJURmhLTVZsdWJHNWFWekY2VEc1c2RHSkZRbmxhVjFwNlRETlNhRm96VFhaa2FrRjFUWHBGZDB4cVFYZFBRVmxMUzNkWlFncENRVWRFZG5wQlFrVjNVWEZFUTJkNFdtMVplRnBVUlhoTlJFWnNXbFJPYTA5SFdYZFpWR014V1hwS2FscFVXbWxhYlZVd1RVUk9hVTVxUVhoUFYwa3lDazVFV1hwTlFtTkhRMmx6UjBGUlVVSm5OemgzUVZKUlJVTlJkMGhqYlZaeldsZEdlbHBVUW1oQ1oyOXlRbWRGUlVGWlR5OU5RVVZXUWtaTlRWVlhhREFLWkVoQ2VrOXBPSFphTW13d1lVaFdhVXh0VG5aaVV6bHJXbGhDYkdKdFVtaFpiVGt3VERKU2JHTkhWblZhUjBacFlqTlJkRmt5T1hsYVV6bG9XVE5TY0FwaU1qVjZURE5LTVdKdVRYWk5WRkV5VGtSVmVrMVVZM2ROVkdOMldWaFNNRnBYTVhka1NFMTJUVlJCVjBKbmIzSkNaMFZGUVZsUEwwMUJSVmRDUVdkTkNrSnVRakZaYlhod1dYcERRbWxSV1V0TGQxbENRa0ZJVjJWUlNVVkJaMUkzUWtoclFXUjNRakZCVGpBNVRVZHlSM2g0UlhsWmVHdGxTRXBzYms1M1Mya0tVMncyTkROcWVYUXZOR1ZMWTI5QmRrdGxOazlCUVVGQ2JHMW9hRGd3V1VGQlFWRkVRVVZaZDFKQlNXZFFNRFptYWtwUGRuaHhTWGhWWTBzNVpGZG9OUXB6U1ZrMFNuWXliRUpvTmt0U09FRXhOR3hVVmxwVU9FTkpSamRwVTBwblpVc3ZVMFV6T0c5TVIwWlhUV2d2UTA4MVUyWXJVR1F6TXpCSmJ6TnZPWFkyQ2pONFVWcE5RVzlIUTBOeFIxTk5ORGxDUVUxRVFUSmpRVTFIVVVOTlJreENSMU5oUTJaV2RuRjFVMWhHUjJ3MVVsWjRZV1JWZVhFdk1GRkRjblpVTlRBS2NITTBaVlpRU0ZaUlpHVklRbVpaU21GcVN5dHpWVFp3T1RGc1NtWlJTWGRJWWxGTlExSnBXVGczU1hjeVYydHNRemxKYkZCb2JYQjVkSFZxZDJOMVVncDBSMUJMYjNZMlozbzFOMVZNYlZSNFJDdG9lbTlNU0VsVFp5OTBSV055U1FvdExTMHRMVVZPUkNCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2c9PSJ9fX19"
}
]
}
}
cosign verify-blob-attestation \
--bundle dependabot-common-0.310.0.json \
--certificate-oidc-issuer https://token.actions.githubusercontent.com \
--certificate-identity-regexp '^https:\/\/github\.com\/dependabot\/dependabot-core\/.*' \
--new-bundle-format=true \
dependabot-common-0.310.0.gem
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment