Fix sign and publish

This commit is contained in:
Michael Grafnetter
2024-08-13 06:32:19 +02:00
parent 461f7f2fa1
commit 399c765c47
6 changed files with 69 additions and 65 deletions
+4 -6
View File
@@ -40,13 +40,13 @@ jobs:
- name: Build Binaries
working-directory: Src
run: dotnet build --configuration Release --nologo
run: dotnet build --configuration Release --nologo
- name: Upload Desktop App as Artifact
uses: actions/upload-artifact@v4
with:
name: Fido2UI
path: Build/bin/Release/Fido2UI/*
path: Build/bin/Fido2UI/release/*
- name: Build PowerShell Module
working-directory: Scripts
@@ -57,7 +57,7 @@ jobs:
uses: actions/upload-artifact@v4
with:
name: PowerShell
path: Build/bin/Release/DSInternals.Passkeys
path: Build/publish/PSModule/Release/*
- name: Create NuGet Packages
working-directory: Src
@@ -67,7 +67,7 @@ jobs:
uses: actions/upload-artifact@v4
with:
name: NuGet
path: Build/bin/Release/Packages/*nupkg
path: Build/package/release/*nupkg
- name: Run Non-Interactive Unit Tests
working-directory: Src
@@ -107,8 +107,6 @@ jobs:
analyze:
name: CodeQL
runs-on: windows-latest
## Not licensed
if: false
permissions:
actions: read
contents: read
+51 -46
View File
@@ -74,10 +74,15 @@ jobs:
# Heuristics: The current list of required packages is defined in the project files.
key: ${{ runner.os }}-DotNET-NuGet-Release-${{ hashFiles('**/**/*.csproj') }}
- name: Build
- name: Build Binaries
working-directory: Src
run: dotnet build --configuration Release --nologo
- name: Build PowerShell Module
working-directory: Scripts
shell: PowerShell
run: .\Build-PowerShellModule.ps1 -Configuration Release
- name: Cache DotNet Global Tools
id: cache-dotnet-globaltools
uses: actions/cache@v4
@@ -101,70 +106,54 @@ jobs:
tenant-id: ${{ secrets.SIGNING_TENANT_ID }}
allow-no-subscriptions: true
- name: Sign Binaries
- name: Sign Binaries and Scripts
if: ${{ github.event.inputs.certificate_sign }}
shell: cmd
env:
SIGNING_VAULT_URL: ${{ secrets.SIGNING_VAULT_URL }}
SIGNING_CERTIFICATE_NAME: ${{ secrets.SIGNING_CERTIFICATE_NAME }}
working-directory: Build/bin/Release
working-directory: Build/bin
timeout-minutes: 1
run: |
for /f %%i in ('az account get-access-token --resource "https://vault.azure.net" --query accessToken --output tsv') do set KEYVAULT_TOKEN=%%i
AzureSignTool sign ^
DSInternals.Win32.WebAuthn/net472/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/net48/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/netcoreapp3.1/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/net5.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/net6.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/net7.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn.Adapter/net6.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/net7.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
Fido2UI/Fido2UI.exe ^
DSInternals.Win32.WebAuthn/release_net472/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_netcoreapp3.1/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net5.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net6.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net7.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn/release_net8.0/DSInternals.Win32.WebAuthn.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net472/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net48/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_netcoreapp3.1/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net5.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net6.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
DSInternals.Win32.WebAuthn.Adapter/release_net7.0/DSInternals.Win32.WebAuthn.Adapter.dll ^
Fido2UI/release/Fido2UI.exe ^
PSModule/Release/DSInternals.Passkeys/DSInternals.Passkeys.psd1 ^
PSModule/Release/DSInternals.Passkeys/DSInternals.Passkeys.psm1 ^
--file-digest sha256 ^
--timestamp-digest sha256 ^
--timestamp-rfc3161 http://timestamp.digicert.com ^
--azure-key-vault-url "%SIGNING_VAULT_URL%" ^
--azure-key-vault-accesstoken "%KEYVAULT_TOKEN%" ^
--azure-key-vault-certificate "%SIGNING_CERTIFICATE_NAME%"
xcopy "DSInternals.Win32.WebAuthn/net472/DSInternals.Win32.WebAuthn.dll" "Fido2UI/" /Y /I /F
xcopy "DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll" "Fido2UI/release/" /Y /I /F
xcopy "DSInternals.Win32.WebAuthn/release_net48/DSInternals.Win32.WebAuthn.dll" "PSModule/Release/DSInternals.Passkeys/net48/" /Y /I /F
xcopy "DSInternals.Win32.WebAuthn/release_net6.0/DSInternals.Win32.WebAuthn.dll" "PSModule/Release/DSInternals.Passkeys/net6.0/" /Y /I /F
- name: Upload Desktop App as Artifact
uses: actions/upload-artifact@v4
with:
name: Fido2UI
path: Build/bin/Release/Fido2UI/*
- name: Build PowerShell Module
working-directory: Scripts
shell: PowerShell
run: .\Build-PowerShellModule.ps1 -Configuration Release
- name: Sign PowerShell Module
if: ${{ github.event.inputs.certificate_sign }}
shell: cmd
env:
SIGNING_VAULT_URL: ${{ secrets.SIGNING_VAULT_URL }}
SIGNING_CERTIFICATE_NAME: ${{ secrets.SIGNING_CERTIFICATE_NAME }}
working-directory: Build/bin/Release/DSInternals.Passkeys
timeout-minutes: 1
run: |
for /f %%i in ('az account get-access-token --resource "https://vault.azure.net" --query accessToken --output tsv') do set KEYVAULT_TOKEN=%%i
AzureSignTool sign ^
DSInternals.Passkeys.psd1 ^
DSInternals.Passkeys.psm1 ^
--file-digest sha256 ^
--timestamp-digest sha256 ^
--timestamp-rfc3161 http://timestamp.digicert.com ^
--azure-key-vault-url "%SIGNING_VAULT_URL%" ^
--azure-key-vault-accesstoken "%KEYVAULT_TOKEN%" ^
--azure-key-vault-certificate "%SIGNING_CERTIFICATE_NAME%"
path: Build/bin/Fido2UI/release/*
- name: Upload PowerShell Module as Artifact
uses: actions/upload-artifact@v4
with:
name: PowerShell
path: Build/bin/Release/DSInternals.Passkeys
path: Build/bin/PSModule/Release
- name: Create NuGet Packages
working-directory: Src
@@ -176,7 +165,7 @@ jobs:
env:
SIGNING_VAULT_URL: ${{ secrets.SIGNING_VAULT_URL }}
SIGNING_CERTIFICATE_NAME: ${{ secrets.SIGNING_CERTIFICATE_NAME }}
working-directory: Build/bin/Release/Packages
working-directory: Build/package/release
run: |
for /f %%i in ('az account get-access-token --resource "https://vault.azure.net" --query accessToken --output tsv') do set KEYVAULT_TOKEN=%%i
NuGetKeyVaultSignTool sign *.nupkg ^
@@ -198,12 +187,17 @@ jobs:
uses: actions/upload-artifact@v4
with:
name: NuGet
path: Build/bin/Release/Packages/*nupkg
path: Build/package/release/*nupkg
- name: Create ZIP for GitHub Release
- name: Create Application ZIP for GitHub Release
if: ${{ github.event.inputs.create_github_release }}
working-directory: Build/bin/Release
run: 7z a -tzip -mx=9 -r packages/Fido2UI.zip Fido2UI
working-directory: Build
run: 7z a -tzip -mx=9 -r publish/Fido2UI.zip bin/Fido2UI/release
- name: Create Module ZIP for GitHub Release
if: ${{ github.event.inputs.create_github_release }}
working-directory: Build
run: 7z a -tzip -mx=9 -r publish/DSInternals.Passkeys.zip bin/PSModule/Release
- name: Create GitHub Release
if: ${{ github.event.inputs.create_github_release }}
@@ -228,6 +222,17 @@ jobs:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
upload_url: ${{ steps.create_release.outputs.upload_url }}
asset_path: Build/bin/Release/packages/Fido2UI.zip
asset_path: Build/publish/Fido2UI.zip
asset_name: FIDO2UI.zip
asset_content_type: applicaion/zip
- name: Upload PowerShell Module as Asset
if: ${{ github.event.inputs.create_github_release }}
uses: actions/upload-release-asset@v1
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
with:
upload_url: ${{ steps.create_release.outputs.upload_url }}
asset_path: Build/publish/DSInternals.Passkeys.zip
asset_name: DSInternals.Passkeys.zip
asset_content_type: applicaion/zip
+3 -2
View File
@@ -15,7 +15,7 @@ param(
[string[]] $frameworks = @('net48', 'net6.0')
[string] $repositoryRoot = Split-Path -Path $PSScriptRoot -Parent
[string] $buildRoot = Join-Path -Path $repositoryRoot -ChildPath 'Build\bin'
[string] $buildRoot = Join-Path -Path $repositoryRoot -ChildPath 'Build\bin\PSModule'
[string] $moduleSourcePath = Join-Path -Path $repositoryRoot -ChildPath 'Src\DSInternals.Passkeys'
[string] $libraryProject = Join-Path -Path $repositoryRoot -ChildPath 'Src\DSInternals.Win32.WebAuthn\DSInternals.Win32.WebAuthn.csproj'
@@ -24,12 +24,13 @@ foreach($currentConfiguration in $Configuration) {
[string] $moduleDestinationPath = Join-Path -Path $configurationOutputPath -ChildPath 'DSInternals.Passkeys'
# Copy module files (*.psd1, *.psm1,...)
New-Item -ItemType Directory -Path $moduleDestinationPath -Force | Out-Null
Copy-Item -Path $moduleSourcePath -Destination $configurationOutputPath -Container -Recurse -Verbose -Force | Out-Null
foreach($framework in $frameworks){
[string] $frameworkSpecificPath = Join-Path -Path $moduleDestinationPath -ChildPath $framework
# Copy the compiled binaries
dotnet.exe publish $libraryProject --output $frameworkSpecificPath --nologo --framework $framework --configuration $currentConfiguration --property:GenerateDocumentationFile=false --no-restore --no-build --self-contained false
dotnet.exe publish $libraryProject --output $frameworkSpecificPath --nologo --framework $framework --configuration $currentConfiguration --property:PublishDocumentationFile=false --no-restore --no-build --self-contained false
}
}
@@ -4,6 +4,7 @@
<TargetFramework>net7.0</TargetFramework>
<AppendTargetFrameworkToOutputPath>false</AppendTargetFrameworkToOutputPath>
<IsPackable>false</IsPackable>
<IsPublishable>false</IsPublishable>
</PropertyGroup>
<ItemGroup>
@@ -5,6 +5,7 @@
<Platform>windows</Platform>
<AppendTargetFrameworkToOutputPath>false</AppendTargetFrameworkToOutputPath>
<IsPackable>false</IsPackable>
<IsPublishable>false</IsPublishable>
</PropertyGroup>
<ItemGroup>
+9 -11
View File
@@ -5,14 +5,9 @@
<!--TODO: <Nullable>enable</Nullable>-->
<!-- Redirect output directories -->
<!-- TODO: Remove this WPF directory name fix (*_[0-9a-z]{8}_wpftmp$ suffix) once the compiler issue is resolved. -->
<SanitizedProjectDirectoryName>$([System.Text.RegularExpressions.Regex]::Replace($(MSBuildProjectName), '_[0-9a-z]{8}_wpftmp$', ''))</SanitizedProjectDirectoryName>
<BaseIntermediateOutputPath>..\..\Build\obj\$(Configuration)\$(SanitizedProjectDirectoryName)</BaseIntermediateOutputPath>
<IntermediateOutputPath>$(BaseIntermediateOutputPath)</IntermediateOutputPath>
<MSBuildProjectExtensionsPath>$(BaseIntermediateOutputPath)</MSBuildProjectExtensionsPath>
<OutputPath>..\..\Build\bin\$(Configuration)\$(SanitizedProjectDirectoryName)</OutputPath>
<PackageOutputPath>..\..\Build\bin\$(Configuration)\Packages</PackageOutputPath>
<VSTestResultsDirectory>..\..\Build\TestResults</VSTestResultsDirectory>
<UseArtifactsOutput>true</UseArtifactsOutput>
<ArtifactsPath>$(MSBuildThisFileDirectory)..\Build</ArtifactsPath>
<VSTestResultsDirectory>$(MSBuildThisFileDirectory)..\Build\TestResults</VSTestResultsDirectory>
<!-- Configure NuGet package properties -->
<Authors>Michael Grafnetter</Authors>
@@ -30,6 +25,9 @@
<NeutralLanguage>en-US</NeutralLanguage>
<IncludeSymbols>true</IncludeSymbols>
<!-- Configure publishing options -->
<PublishRelease>true</PublishRelease>
<!-- Configure MSTest properties -->
<VSTestLogger>html;trx</VSTestLogger>
<VSTestCollect>XPlat Code Coverage;Code Coverage</VSTestCollect>
@@ -48,14 +46,14 @@
'$(MSBuildProjectName)' == 'DSInternals.Win32.WebAuthn.Tests'
)">
<SignAssembly>true</SignAssembly>
<AssemblyOriginatorKeyFile>..\..\Keys\DSInternals.Private.snk</AssemblyOriginatorKeyFile>
<AssemblyOriginatorKeyFile>$(MSBuildThisFileDirectory)..\Keys\DSInternals.Private.snk</AssemblyOriginatorKeyFile>
<StrongNamePublicKey>002400000480000094000000060200000024000052534131000400000100010077154b93d8084f0f30c52174d6c93d25ffdc65e11ba1b125383e55c6095061df3c2f765401c21434aa413aa264b6eb3039d95c5f33a9d4eb7deb695b55e434d8dd9b42e0e86f3287498732d3a30d0ee22d8d58b2361f033351d5c1a64a16324ac6c42b5a4b14c12483b52a98a43f7e934df86b92cc8a9c4ee0f408d7b6d987e3</StrongNamePublicKey>
<DelaySign>false</DelaySign>
</PropertyGroup>
<ItemGroup>
<!-- Additional files to include in NuGet packages -->
<None Include="../Icons/package_black.png" Pack="true" PackagePath="/icon.png" Visible="false" />
<None Include="../../LICENSE" Pack="true" PackagePath="/" Visible="false" />
<None Include="$(MSBuildThisFileDirectory)Icons/package_black.png" Pack="true" PackagePath="/icon.png" Visible="false" />
<None Include="$(MSBuildThisFileDirectory)../LICENSE" Pack="true" PackagePath="/" Visible="false" />
</ItemGroup>
</Project>