1
+ {
2
+ "version": 1,
3
+ "attestation_bundles": [
4
+ {
5
+ "publisher": {
6
+ "kind": "GitLab",
7
+ "repository": "pep740-example/sampleproject",
8
+ "workflow_filepath": ".gitlab-ci.yml",
9
+ "environment": null
10
+ },
11
+ "attestations": [
12
+ {
13
+ "version": 1,
14
+ "verification_material": {
15
+ "certificate": "MIIFzjCCBVWgAwIBAgIURx4YEuI6Myhj4jhJP+tGhi6RH4swCgYIKoZIzj0EAwMwNzEVMBMGA1UEChMMc2lnc3RvcmUuZGV2MR4wHAYDVQQDExVzaWdzdG9yZS1pbnRlcm1lZGlhdGUwHhcNMjQxMTI3MTYxNTQyWhcNMjQxMTI3MTYyNTQyWjAAMFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAEWxmRAqBYCVpUzTruvIbOV/a5IbYhJR9bAih7W8ohK410IJBWCxRRbePpkEUTe2VBdNAzwKsIqEPYLUKx556e8KOCBHQwggRwMA4GA1UdDwEB/wQEAwIHgDATBgNVHSUEDDAKBggrBgEFBQcDAzAdBgNVHQ4EFgQUtjn/Wp4sE0yGAXgsjsypIeeiPgYwHwYDVR0jBBgwFoAU39Ppz1YkEZb5qNjpKFWixi4YZD8wXQYDVR0RAQH/BFMwUYZPaHR0cHM6Ly9naXRsYWIuY29tL3BlcDc0MC1leGFtcGxlL3NhbXBsZXByb2plY3QvLy5naXRsYWItY2kueW1sQHJlZnMvaGVhZHMvbWFpbjAgBgorBgEEAYO/MAEBBBJodHRwczovL2dpdGxhYi5jb20wIgYKKwYBBAGDvzABCAQUDBJodHRwczovL2dpdGxhYi5jb20wXwYKKwYBBAGDvzABCQRRDE9odHRwczovL2dpdGxhYi5jb20vcGVwNzQwLWV4YW1wbGUvc2FtcGxlcHJvamVjdC8vLmdpdGxhYi1jaS55bWxAcmVmcy9oZWFkcy9tYWluMDgGCisGAQQBg78wAQoEKgwoMGI3MDZiYmYxYjUwZTcyNjZiMzM3NjI1Njg1NjZkNmVjMGY3NmQ2OTAdBgorBgEEAYO/MAELBA8MDWdpdGxhYi1ob3N0ZWQwPwYKKwYBBAGDvzABDAQxDC9odHRwczovL2dpdGxhYi5jb20vcGVwNzQwLWV4YW1wbGUvc2FtcGxlcHJvamVjdDA4BgorBgEEAYO/MAENBCoMKDBiNzA2YmJmMWI1MGU3MjY2YjMzNzYyNTY4NTY2ZDZlYzBmNzZkNjkwHwYKKwYBBAGDvzABDgQRDA9yZWZzL2hlYWRzL21haW4wGAYKKwYBBAGDvzABDwQKDAg2NDg5NTczNjAxBgorBgEEAYO/MAEQBCMMIWh0dHBzOi8vZ2l0bGFiLmNvbS9wZXA3NDAtZXhhbXBsZTAYBgorBgEEAYO/MAERBAoMCDk4MTM0NDA5MF8GCisGAQQBg78wARIEUQxPaHR0cHM6Ly9naXRsYWIuY29tL3BlcDc0MC1leGFtcGxlL3NhbXBsZXByb2plY3QvLy5naXRsYWItY2kueW1sQHJlZnMvaGVhZHMvbWFpbjA4BgorBgEEAYO/MAETBCoMKDBiNzA2YmJmMWI1MGU3MjY2YjMzNzYyNTY4NTY2ZDZlYzBmNzZkNjkwFAYKKwYBBAGDvzABFAQGDARwdXNoMFEGCisGAQQBg78wARUEQwxBaHR0cHM6Ly9naXRsYWIuY29tL3BlcDc0MC1leGFtcGxlL3NhbXBsZXByb2plY3QvLS9qb2JzLzg0ODY5NzQ1NTkwFwYKKwYBBAGDvzABFgQJDAdwcml2YXRlMIGJBgorBgEEAdZ5AgQCBHsEeQB3AHUA3T0wasbHETJjGR4cmWc3AqJKXrjePK3/h4pygC8p7o4AAAGTbmgyrAAABAMARjBEAiAEy6m1+WMuQAW4WXQvhc7BotZSdJTWra7lhpsxRWMs5gIgLKK2xirEjEPMKYS8zYyfO+R3fVAwqDIZ0JuKpf5AVgkwCgYIKoZIzj0EAwMDZwAwZAIwF2MwWxICLdN/tyecQzhCVcp4najAHp2v1EklO53oTz/9Rdq/QSIt3EufKIfhBm4fAjA8mZGxgzOxecA5rCYGZlNL5CEPnLvCLzyDgyQ5Yr5CNCWZ0P9/E7UvK+Ht84kOLPc=",
16
+ "transparency_entries": [
17
+ {
18
+ "canonicalizedBody": "eyJhcGlWZXJzaW9uIjoiMC4wLjEiLCJraW5kIjoiZHNzZSIsInNwZWMiOnsiZW52ZWxvcGVIYXNoIjp7ImFsZ29yaXRobSI6InNoYTI1NiIsInZhbHVlIjoiZWJmOTFiZTUxMjkzNzkyYzYzODE0OTRkMzdjODZlM2RlNDZlZjUwYjFkNTU4ZTgzNmUyYWI5ODE4ODMzZjE1NSJ9LCJwYXlsb2FkSGFzaCI6eyJhbGdvcml0aG0iOiJzaGEyNTYiLCJ2YWx1ZSI6IjQ1Y2NkMTA2NjUwOGY4MTNlNmQzZWMwMjRiY2RkZjM2Y2VlNmUxZDM2ODE1YTVjOTJmMzExY2I4NTk2OGEzNGMifSwic2lnbmF0dXJlcyI6W3sic2lnbmF0dXJlIjoiTUVZQ0lRQ1J3ckZsaXlEZWdPQ0FDZkVlWjBmaFVrUVZMR0ZyZldzbDlndENueDhMU0FJaEFNYjY5UnZlVGU4Zk5FclNhZ3RSMU5vVjErcTlGOStzaEJIY0VDWjlTSEw0IiwidmVyaWZpZXIiOiJMUzB0TFMxQ1JVZEpUaUJEUlZKVVNVWkpRMEZVUlMwdExTMHRDazFKU1VaNmFrTkRRbFpYWjBGM1NVSkJaMGxWVW5nMFdVVjFTVFpOZVdocU5HcG9TbEFyZEVkb2FUWlNTRFJ6ZDBObldVbExiMXBKZW1vd1JVRjNUWGNLVG5wRlZrMUNUVWRCTVZWRlEyaE5UV015Ykc1ak0xSjJZMjFWZFZwSFZqSk5ValIzU0VGWlJGWlJVVVJGZUZaNllWZGtlbVJIT1hsYVV6RndZbTVTYkFwamJURnNXa2RzYUdSSFZYZElhR05PVFdwUmVFMVVTVE5OVkZsNFRsUlJlVmRvWTA1TmFsRjRUVlJKTTAxVVdYbE9WRkY1VjJwQlFVMUdhM2RGZDFsSUNrdHZXa2w2YWpCRFFWRlpTVXR2V2tsNmFqQkVRVkZqUkZGblFVVlhlRzFTUVhGQ1dVTldjRlY2VkhKMWRrbGlUMVl2WVRWSllsbG9TbEk1WWtGcGFEY0tWemh2YUVzME1UQkpTa0pYUTNoU1VtSmxVSEJyUlZWVVpUSldRbVJPUVhwM1MzTkpjVVZRV1V4VlMzZzFOVFpsT0V0UFEwSklVWGRuWjFKM1RVRTBSd3BCTVZWa1JIZEZRaTkzVVVWQmQwbElaMFJCVkVKblRsWklVMVZGUkVSQlMwSm5aM0pDWjBWR1FsRmpSRUY2UVdSQ1owNVdTRkUwUlVablVWVjBhbTR2Q2xkd05ITkZNSGxIUVZobmMycHplWEJKWldWcFVHZFpkMGgzV1VSV1VqQnFRa0puZDBadlFWVXpPVkJ3ZWpGWmEwVmFZalZ4VG1wd1MwWlhhWGhwTkZrS1drUTRkMWhSV1VSV1VqQlNRVkZJTDBKR1RYZFZXVnBRWVVoU01HTklUVFpNZVRsdVlWaFNjMWxYU1hWWk1qbDBURE5DYkdORVl6Qk5RekZzWlVkR2RBcGpSM2hzVEROT2FHSllRbk5hV0VKNVlqSndiRmt6VVhaTWVUVnVZVmhTYzFsWFNYUlpNbXQxWlZjeGMxRklTbXhhYmsxMllVZFdhRnBJVFhaaVYwWndDbUpxUVdkQ1oyOXlRbWRGUlVGWlR5OU5RVVZDUWtKS2IyUklVbmRqZW05MlRESmtjR1JIZUdoWmFUVnFZakl3ZDBsbldVdExkMWxDUWtGSFJIWjZRVUlLUTBGUlZVUkNTbTlrU0ZKM1kzcHZka3d5WkhCa1IzaG9XV2sxYW1JeU1IZFlkMWxMUzNkWlFrSkJSMFIyZWtGQ1ExRlNVa1JGT1c5a1NGSjNZM3B2ZGdwTU1tUndaRWQ0YUZscE5XcGlNakIyWTBkV2QwNTZVWGRNVjFZMFdWY3hkMkpIVlhaak1rWjBZMGQ0YkdOSVNuWmhiVlpxWkVNNGRreHRaSEJrUjNob0NsbHBNV3BoVXpVMVlsZDRRV050Vm0xamVUbHZXbGRHYTJONU9YUlpWMngxVFVSblIwTnBjMGRCVVZGQ1p6YzRkMEZSYjBWTFozZHZUVWRKTTAxRVdta0tXVzFaZUZscVZYZGFWR041VG1wYWFVMTZUVE5PYWtreFRtcG5NVTVxV210T2JWWnFUVWRaTTA1dFVUSlBWRUZrUW1kdmNrSm5SVVZCV1U4dlRVRkZUQXBDUVRoTlJGZGtjR1JIZUdoWmFURnZZak5PTUZwWFVYZFFkMWxMUzNkWlFrSkJSMFIyZWtGQ1JFRlJlRVJET1c5a1NGSjNZM3B2ZGt3eVpIQmtSM2hvQ2xscE5XcGlNakIyWTBkV2QwNTZVWGRNVjFZMFdWY3hkMkpIVlhaak1rWjBZMGQ0YkdOSVNuWmhiVlpxWkVSQk5FSm5iM0pDWjBWRlFWbFBMMDFCUlU0S1FrTnZUVXRFUW1sT2VrRXlXVzFLYlUxWFNURk5SMVV6VFdwWk1sbHFUWHBPZWxsNVRsUlpORTVVV1RKYVJGcHNXWHBDYlU1NldtdE9hbXQzU0hkWlN3cExkMWxDUWtGSFJIWjZRVUpFWjFGU1JFRTVlVnBYV25wTU1taHNXVmRTZWt3eU1XaGhWelIzUjBGWlMwdDNXVUpDUVVkRWRucEJRa1IzVVV0RVFXY3lDazVFWnpWT1ZHTjZUbXBCZUVKbmIzSkNaMFZGUVZsUEwwMUJSVkZDUTAxTlNWZG9NR1JJUW5wUGFUaDJXakpzTUdKSFJtbE1iVTUyWWxNNWQxcFlRVE1LVGtSQmRGcFlhR2hpV0VKeldsUkJXVUpuYjNKQ1owVkZRVmxQTDAxQlJWSkNRVzlOUTBSck5FMVVUVEJPUkVFMVRVWTRSME5wYzBkQlVWRkNaemM0ZHdwQlVrbEZWVkY0VUdGSVVqQmpTRTAyVEhrNWJtRllVbk5aVjBsMVdUSTVkRXd6UW14alJHTXdUVU14YkdWSFJuUmpSM2hzVEROT2FHSllRbk5hV0VKNUNtSXljR3haTTFGMlRIazFibUZZVW5OWlYwbDBXVEpyZFdWWE1YTlJTRXBzV201TmRtRkhWbWhhU0UxMllsZEdjR0pxUVRSQ1oyOXlRbWRGUlVGWlR5OEtUVUZGVkVKRGIwMUxSRUpwVG5wQk1sbHRTbTFOVjBreFRVZFZNMDFxV1RKWmFrMTZUbnBaZVU1VVdUUk9WRmt5V2tSYWJGbDZRbTFPZWxwclRtcHJkd3BHUVZsTFMzZFpRa0pCUjBSMmVrRkNSa0ZSUjBSQlVuZGtXRTV2VFVaRlIwTnBjMGRCVVZGQ1p6YzRkMEZTVlVWUmQzaENZVWhTTUdOSVRUWk1lVGx1Q21GWVVuTlpWMGwxV1RJNWRFd3pRbXhqUkdNd1RVTXhiR1ZIUm5SalIzaHNURE5PYUdKWVFuTmFXRUo1WWpKd2JGa3pVWFpNVXpseFlqSktla3g2WnpBS1QwUlpOVTU2VVRGT1ZHdDNSbmRaUzB0M1dVSkNRVWRFZG5wQlFrWm5VVXBFUVdSM1kyMXNNbGxZVW14TlNVZEtRbWR2Y2tKblJVVkJaRm8xUVdkUlF3cENTSE5GWlZGQ00wRklWVUV6VkRCM1lYTmlTRVZVU21wSFVqUmpiVmRqTTBGeFNrdFljbXBsVUVzekwyZzBjSGxuUXpod04yODBRVUZCUjFSaWJXZDVDbkpCUVVGQ1FVMUJVbXBDUlVGcFFVVjVObTB4SzFkTmRWRkJWelJYV0ZGMmFHTTNRbTkwV2xOa1NsUlhjbUUzYkdod2MzaFNWMDF6TldkSloweExTeklLZUdseVJXcEZVRTFMV1ZNNGVsbDVaazhyVWpObVZrRjNjVVJKV2pCS2RVdHdaalZCVm1kcmQwTm5XVWxMYjFwSmVtb3dSVUYzVFVSYWQwRjNXa0ZKZHdwR01rMTNWM2hKUTB4a1RpOTBlV1ZqVVhwb1ExWmpjRFJ1WVdwQlNIQXlkakZGYTJ4UE5UTnZWSG92T1ZKa2NTOVJVMGwwTTBWMVprdEpabWhDYlRSbUNrRnFRVGh0V2tkNFozcFBlR1ZqUVRWeVExbEhXbXhPVERWRFJWQnVUSFpEVEhwNVJHZDVVVFZaY2pWRFRrTlhXakJRT1M5Rk4xVjJTeXRJZERnMGEwOEtURkJqUFFvdExTMHRMVVZPUkNCRFJWSlVTVVpKUTBGVVJTMHRMUzB0Q2c9PSJ9XX19",
19
+ "inclusionPromise": {
20
+ "signedEntryTimestamp": "MEQCIEf0DL0CdIvZBoF9q0sYJeI2y8ywwtU6VeTrdG6UlOaSAiAOZKwhn7e01NJYxHVFGHkUUI2Z4/fCVhPyRNogRJh0iA=="
21
+ },
22
+ "inclusionProof": {
23
+ "checkpoint": {
24
+ "envelope": "rekor.sigstore.dev - 1193050959916656506\n30122734\neKxSpLhPmsuVutOHnq6yFj81/qweH0iJR9jwe3kbUQ8=\n\n— rekor.sigstore.dev wNI9ajBFAiAFQdwIoGspkAO/BRH3jFZsPasIPCJEZB0ZZwT3Ya4EHQIhAOm/Ijj82QDdv3wVuQ3VlZAlabXZZBfk3kBTKARAexwo\n"
25
+ },
26
+ "hashes": [
27
+ "+VppOCmIDzrWmE4W7I6Pv53NnMBcNRsFqfU9GO6PphE=",
28
+ "6Tekh+8zwHFbwKAwUnSVJSoz9UWgb+AWo3qbGSnZyt4=",
29
+ "4LhcnAJ0ygHa6VRNrOQ7wlSEqblWMrge2eOucvvlQAM=",
30
+ "DjMVn62Doaj1ttosoz/6g6X7XYqePW+8eNfSdwf+h+Q=",
31
+ "bd+3uUcW5z3ydt2HXQBp6cK5RSFj9rcoGZjg7Rkhl/o=",
32
+ "Thk4DnFs8p+RMOdDsZImAGdMuh0KB03OxO+OpYtKtOs=",
33
+ "+fFi7qqMze4wmH1L/Vadkpxb54WtRbzY2g0stC/iROw=",
34
+ "ABBbOV/bjpmhTzmyEWHL4Oezw7wDoPRu35y4sS9Ot0c=",
35
+ "NQSiB4z2DRJ4dk02TN0P7h7fvfoXQQKsbP1iishlbCg=",
36
+ "bIflDKfskAxhbt6KyYK9T3bP4LJQ6HCYaeeuD+Q0TZU=",
37
+ "nkvQxCN5e9I9u5D2Ve1JxCTkA/zYtYibp+WWQja89H8=",
38
+ "CZcT4Ba5Aj2Qcv6bZsLT3eyenbBmjXzu7qTAH4oLQAc=",
39
+ "oOecFfN3YqDOkbijS/ej1WF5Da/Gt/AZNhbwE9uoOE8=",
40
+ "4lUF0YOu9XkIDXKXA0wMSzd6VeDY3TZAgmoOeWmS2+Y=",
41
+ "gf+9m552B3PnkWnO0o4KdVvjcT3WVHLrCbf1DoVYKFw="
42
+ ],
43
+ "logIndex": "30122733",
44
+ "rootHash": "eKxSpLhPmsuVutOHnq6yFj81/qweH0iJR9jwe3kbUQ8=",
45
+ "treeSize": "30122734"
46
+ },
47
+ "integratedTime": "1732724143",
48
+ "kindVersion": {
49
+ "kind": "dsse",
50
+ "version": "0.0.1"
51
+ },
52
+ "logId": {
53
+ "keyId": "wNI9atQGlz+VWfO6LRygH4QUfY/8W4RFwiT5i5WRgB0="
54
+ },
55
+ "logIndex": "152026995"
56
+ }
57
+ ]
58
+ },
59
+ "envelope": {
60
+ "statement": "eyJfdHlwZSI6Imh0dHBzOi8vaW4tdG90by5pby9TdGF0ZW1lbnQvdjEiLCJzdWJqZWN0IjpbeyJuYW1lIjoicGVwNzQwX3NhbXBsZXByb2plY3QtMS4wLjAudGFyLmd6IiwiZGlnZXN0Ijp7InNoYTI1NiI6IjZjZGQ0YTFhMGE0OWFlZWY0NzI2NWU3YmY4ZWMxNjY3MjU3YjM5N2QzNGQ3MzFkYzdiN2FmMzQ5ZGVjYTFjZDgifX1dLCJwcmVkaWNhdGVUeXBlIjoiaHR0cHM6Ly9kb2NzLnB5cGkub3JnL2F0dGVzdGF0aW9ucy9wdWJsaXNoL3YxIiwicHJlZGljYXRlIjpudWxsfQ==",
61
+ "signature": "MEYCIQCRwrFliyDegOCACfEeZ0fhUkQVLGFrfWsl9gtCnx8LSAIhAMb69RveTe8fNErSagtR1NoV1+q9F9+shBHcECZ9SHL4"
62
+ }
63
+ }
64
+ ]
65
+ }
66
+ ]
67
+ }
0 commit comments