| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
There was a problem hiding this comment.
Backport of #27486 to release/v7.5.8 that adds a post-ESRP verification step in the macOS signing jobs to detect silent ESRP no-ops by scanning signed Mach-O binaries for the expected "Developer ID Application: Microsoft Corporation" string, failing the job if any are missing.
Changes:
Sorry, something went wrong.
| Back | FazBrowse Home | New Git URL |
Backport of #27486 to release/v7.5.8
Triggered by Patrick Meinecke (@SeeminglyScience) on behalf of Andy Jordan (@andyleejordan)
Original CL Label: CL-BuildPackaging
/cc @PowerShell/powershell-maintainers
Impact
REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.
Tooling Impact
Adds codesign --verify --deep --strict verification immediately after ESRP signing in Sign_macOS_* pipeline jobs. This ensures silent ESRP no-ops are caught in the signing job itself rather than discovered later in packaging, preventing publication of bad signed artifacts.
Customer Impact
Regression
REQUIRED: Check exactly one box.
This is not a regression.
Testing
Verified by next pipeline run. This is a pipeline YAML-only change adding a defensive verification step — no unit tests apply. The original change was validated during a release build where ESRP silently no-op'd; this check would have caught it at the sign stage.
Risk
REQUIRED: Check exactly one box.
Pipeline YAML only — no runtime code changes. The added step is read-only verification (codesign --verify) that fails fast rather than publishing a bad artifact. No customer-facing behavior is affected.