Combined wrong-trust expectations rejected SELECTED VISIBLE OUTPUT — not a full log Selected visible output: clusterpolicy.kyverno.io/test-invalid-trust-expectations created resource Pod/default/test-invalid-trust was blocked reject-wrong-keyless-identity: subject mismatch expected .../.github/workflows/not-the-signing-workflow.yml@refs/heads/main received .../.github/workflows/sign-attest.yml@refs/heads/main reject-wrong-provenance-source: image attestations verification failed, verifiedCount: 0, requiredCount: 1; attestation checks failed RESULT: PASS - invalid identity/provenance DENIED as expected clusterpolicy.kyverno.io "test-invalid-trust-expectations" deleted CLEANUP: Temporary ClusterPolicy removed Original: https://github.com/devSatym/gcp-supply-chain-security/blob/cbbc807c0c150e106affa89fbb1b9e8349005749/docs/my-validation/10-invalid-trust-blocked.png Limitations: - One combined experiment changes two expected fields; not two isolated proofs. - The signer itself is not changed and the image is not shown being tampered with. - The transcript uses ellipses only for repeated canonical repository prefixes and omits incidental terminal metadata.