• It was issued by the public sigstore.dev instance
  • It is only valid for 10 minutes.
  • It includes several custom ASN.1 OIDs provided by Fulcio that give us useful identifiers as to what GitHub Actions workflow signed the commit: