{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-07T18:02:46.008Z",
  "record_id": "VXI-EXT-SIGSTORE-BUNDLE-02-v1",
  "record_kind": "external_reference",
  "title": "Sigstore: Signing-time evidence after certificate expiry",
  "system": "Sigstore Bundle",
  "evidence_family": "software_supply_chain",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "Can a Sigstore signature remain verifiable after its short-lived certificate expires?",
  "near_questions": [
    "Does certificate expiry automatically invalidate a Sigstore artifact signature?",
    "What evidence places signing within certificate validity?",
    "How can a transparency-log timestamp support later verification?",
    "What role can an RFC 3161 timestamp play in a Sigstore bundle?",
    "Does a signing timestamp prove the artifact is safe?",
    "Which verifier trust policy applies after certificate expiry?",
    "Can an untrusted timestamp establish valid signing time?",
    "What must a historical signature check retain?",
    "Does signature authenticity establish a claim is still current?",
    "What remains unknown after a bundle passes verification?",
    "Which certificate validity interval matters to the verifier?",
    "Can timestamp evidence replace artifact evaluation?"
  ],
  "supported_claims": [
    {
      "claim": "Sigstore’s bundle documentation explains how trusted signing-time evidence can support verification after a short-lived signing certificate expires. The verifier must establish signing within the certificate’s validity and apply its trust policy. A timestamp does not by itself establish artifact safety or the truth of signed content.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "artifact safety",
    "truth of signed statements",
    "verification without trust-policy checks"
  ],
  "public_summary": "Sigstore’s bundle documentation explains how trusted signing-time evidence can support verification after a short-lived signing certificate expires. The verifier must establish signing within the certificate’s validity and apply its trust policy. A timestamp does not by itself establish artifact safety or the truth of signed content.",
  "related_record_ids": [
    "VXI-EXT-CEDAR-05-v1",
    "VXI-EXT-OWASP-ACS-01-v1",
    "VXI-EXT-OWASP-ACS-02-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "Sigstore bundle format",
    "source_url": "https://docs.sigstore.dev/about/bundle/",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-SIGSTORE-BUNDLE-02-v1",
    "candidate_record_sha256": "4934fe4fc9f16b15dfa0bd5502051fee489fb86f47e52009a489c9229955fcf6",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "The delivered snapshot preserves the review date shown. Recheck current primary documentation and deployment context before relying on present applicability; payment does not trigger fresh research."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "Sigstore’s bundle documentation explains how trusted signing-time evidence can support verification after a short-lived signing certificate expires. The verifier must establish signing within the certificate’s validity and apply its trust policy. A timestamp does not by itself establish artifact safety or the truth of signed content.",
    "required_buyer_context": "The bundle format, signing certificate, trusted timing evidence, verifier policy and claim about the signed artifact.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The full published answer and boundaries are free. Paid access saves the selected route and source versions, with an unsigned receipt when purchased. Preview coverage before paying. Fresh research, bespoke assessment and protected evidence are excluded.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "availability_endpoint": "/api/index/capabilities",
    "operational_status": "AUTOMATIC_SERVICE_CAPABILITIES_GATED",
    "checkout_url": "/index-access"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#sigstore-signing-time-verification",
  "machine_readable_record": "/varexis-index/records/sigstore-signing-time-verification.json"
}
