mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
Move ESRP key codes into the certificate_logical_to_actual variable group
The `CP-…` key codes used for ESRP signing are now set from ADO via the `certificate_logical_to_actual` variable group. The templates reference the following variables instead of literal codes: - `$(authenticode_cert_id)` - `$(authenticode_test_cert_id)` - `$(nuget_cert_id)` - `$(apple_cert_id)` - `$(pgp_linux_cert_id)` - `$(pgp_release_cert_id)` `nupkg.yml`, `mac-package-build.yml`, and `linux-package-build.yml` pick up the new group import. `linux-package-build.yml` also now selects the PGP signing profile based on whether `jobName` starts with `mariner`, so `PowerShell-Packages-Stages.yml` no longer threads a `signingProfile` parameter in for the two Mariner jobs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -3,7 +3,6 @@ parameters:
|
||||
signedeDrop: 'drop_linux_sign_linux_x64'
|
||||
packageType: deb
|
||||
jobName: 'deb'
|
||||
signingProfile: 'CP-450779-pgpdetached'
|
||||
|
||||
jobs:
|
||||
- job: ${{ parameters.jobName }}
|
||||
@@ -20,6 +19,7 @@ jobs:
|
||||
- name: skipNugetSecurityAnalysis
|
||||
value: true
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_binskim_enabled
|
||||
@@ -34,8 +34,16 @@ jobs:
|
||||
value: $(Build.SourcesDirectory)/PowerShell/.config/tsaoptions.json
|
||||
- name: ob_sdl_credscan_suppressionsFile
|
||||
value: $(Build.SourcesDirectory)/PowerShell/.config/suppress.json
|
||||
- name: SigningProfile
|
||||
value: ${{ parameters.signingProfile }}
|
||||
# PGP signing profile selection: Mariner (Azure Linux) packages ship through
|
||||
# a different distribution channel and must be signed with the Mariner release
|
||||
# key; all other Linux packages use the standard PowerShell Linux key. Both
|
||||
# key codes come from the `certificate_logical_to_actual` variable group.
|
||||
- ${{ if startsWith(parameters.jobName, 'mariner') }}:
|
||||
- name: SigningProfile
|
||||
value: $(pgp_release_cert_id)
|
||||
- ${{ else }}:
|
||||
- name: SigningProfile
|
||||
value: $(pgp_linux_cert_id)
|
||||
|
||||
steps:
|
||||
- checkout: self
|
||||
|
||||
@@ -22,6 +22,7 @@ jobs:
|
||||
- name: skipNugetSecurityAnalysis
|
||||
value: true
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_binskim_enabled
|
||||
@@ -187,6 +188,7 @@ jobs:
|
||||
type: windows
|
||||
|
||||
variables:
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_binskim_enabled
|
||||
@@ -234,7 +236,7 @@ jobs:
|
||||
inline_operation: |
|
||||
[
|
||||
{
|
||||
"KeyCode": "CP-401337-Apple",
|
||||
"KeyCode": "$(apple_cert_id)",
|
||||
"OperationCode": "MacAppDeveloperSign",
|
||||
"ToolName": "sign",
|
||||
"ToolVersion": "1.0",
|
||||
@@ -253,7 +255,7 @@ jobs:
|
||||
inline_operation: |
|
||||
[
|
||||
{
|
||||
"KeyCode": "CP-401337-Apple",
|
||||
"KeyCode": "$(apple_cert_id)",
|
||||
"OperationCode": "MacAppNotarize",
|
||||
"ToolName": "sign",
|
||||
"ToolVersion": "1.0",
|
||||
|
||||
@@ -168,7 +168,7 @@ jobs:
|
||||
inline_operation: |
|
||||
[
|
||||
{
|
||||
"KeyCode": "CP-401337-Apple",
|
||||
"KeyCode": "$(apple_cert_id)",
|
||||
"OperationCode": "MacAppDeveloperSign",
|
||||
"ToolName": "sign",
|
||||
"ToolVersion": "1.0",
|
||||
|
||||
@@ -23,6 +23,7 @@ jobs:
|
||||
- group: mscodehub-feed-read-general
|
||||
- group: mscodehub-feed-read-akv
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
|
||||
steps:
|
||||
- checkout: self
|
||||
@@ -208,7 +209,7 @@ jobs:
|
||||
displayName: Sign nupkg files
|
||||
inputs:
|
||||
command: 'sign'
|
||||
cp_code: 'CP-401405'
|
||||
cp_code: '$(nuget_cert_id)'
|
||||
files_to_sign: '**\*.nupkg'
|
||||
search_root: '$(Pipeline.Workspace)\nupkg'
|
||||
|
||||
@@ -268,7 +269,7 @@ jobs:
|
||||
displayName: Sign nupkg files
|
||||
inputs:
|
||||
command: 'sign'
|
||||
cp_code: 'CP-401405'
|
||||
cp_code: '$(nuget_cert_id)'
|
||||
files_to_sign: '**\*.nupkg'
|
||||
search_root: '$(Pipeline.Workspace)\globaltools'
|
||||
|
||||
|
||||
@@ -6,11 +6,11 @@ parameters:
|
||||
steps:
|
||||
- powershell: |
|
||||
$shouldSign = $true
|
||||
$authenticodeCert = 'CP-230012'
|
||||
$msixCert = 'CP-230012'
|
||||
$authenticodeCert = '$(authenticode_cert_id)'
|
||||
$msixCert = '$(authenticode_cert_id)'
|
||||
if($env:IS_DAILY -eq 'true')
|
||||
{
|
||||
$authenticodeCert = 'CP-460906'
|
||||
$authenticodeCert = '$(authenticode_test_cert_id)'
|
||||
}
|
||||
if($env:SKIP_SIGNING -eq 'Yes')
|
||||
{
|
||||
|
||||
@@ -93,7 +93,6 @@ stages:
|
||||
signedDrop: 'drop_linux_sign_linux_fxd_x64_mariner'
|
||||
packageType: rpm-fxdependent #mariner-x64
|
||||
jobName: mariner_x64
|
||||
signingProfile: 'CP-459159-pgpdetached'
|
||||
|
||||
- template: /.pipelines/templates/linux-package-build.yml@self
|
||||
parameters:
|
||||
@@ -101,7 +100,6 @@ stages:
|
||||
signedDrop: 'drop_linux_sign_linux_fxd_arm64_mariner'
|
||||
packageType: rpm-fxdependent-arm64 #mariner-arm64
|
||||
jobName: mariner_arm64
|
||||
signingProfile: 'CP-459159-pgpdetached'
|
||||
|
||||
- template: /.pipelines/templates/linux-package-build.yml@self
|
||||
parameters:
|
||||
|
||||
@@ -315,7 +315,7 @@ jobs:
|
||||
displayName: Sign nupkg files
|
||||
inputs:
|
||||
command: 'sign'
|
||||
cp_code: 'CP-401405'
|
||||
cp_code: '$(nuget_cert_id)'
|
||||
files_to_sign: '**\*.nupkg'
|
||||
search_root: '$(ob_outputDirectory)\globaltool'
|
||||
condition: and(succeeded(), eq(variables['Architecture'], 'fxdependent'))
|
||||
|
||||
Reference in New Issue
Block a user