mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
This commit is contained in:
@@ -136,6 +136,7 @@ jobs:
|
||||
- name: DOTNET_SKIP_FIRST_TIME_EXPERIENCE
|
||||
value: 1
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_codeSignValidation_enabled
|
||||
|
||||
@@ -81,6 +81,7 @@ jobs:
|
||||
- name: NugetSecurityAnalysisWarningLevel
|
||||
value: none
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_codeSignValidation_enabled
|
||||
|
||||
@@ -128,7 +128,7 @@ steps:
|
||||
displayName: Sign 3rd Party files
|
||||
inputs:
|
||||
command: 'sign'
|
||||
signing_profile: 135020002
|
||||
signing_profile: $(msft_3rd_party_cert_id)
|
||||
files_to_sign: '**\*.dll;**\*.exe'
|
||||
search_root: $(Pipeline.Workspace)/thirdPartyToBeSigned
|
||||
|
||||
|
||||
@@ -17,6 +17,7 @@ jobs:
|
||||
- name: DOTNET_SKIP_FIRST_TIME_EXPERIENCE
|
||||
value: 1
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)/ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_codeSignValidation_enabled
|
||||
|
||||
@@ -18,6 +18,7 @@ jobs:
|
||||
- name: skipNugetSecurityAnalysis
|
||||
value: true
|
||||
- group: DotNetPrivateBuildAccess
|
||||
- group: certificate_logical_to_actual
|
||||
- name: ob_outputDirectory
|
||||
value: '$(Build.ArtifactStagingDirectory)\ONEBRANCH_ARTIFACT'
|
||||
- name: ob_sdl_binskim_enabled
|
||||
@@ -199,11 +200,35 @@ jobs:
|
||||
Set-Location $repoRoot
|
||||
|
||||
$exePath = New-ExePackage -ProductVersion $version -ProductTargetArchitecture $runtime -MsiLocationPath $msiLocation
|
||||
Write-Verbose -Verbose "setting vso[task.setvariable variable=exePath]$exePath"
|
||||
Write-Host "##vso[task.setvariable variable=exePath]$exePath"
|
||||
Write-Verbose -Verbose "exePath: $exePath"
|
||||
displayName: 'Make exe package'
|
||||
|
||||
$enginePath = Join-Path -Path '$(System.ArtifactsDirectory)\unsignedEngine' -ChildPath engine.exe
|
||||
Expand-ExePackageEngine -ExePath $exePath -EnginePath $enginePath
|
||||
displayName: 'Make exe and expand package'
|
||||
|
||||
- task: onebranch.pipeline.signing@1
|
||||
displayName: Sign MSI packages
|
||||
displayName: Sign exe engine
|
||||
inputs:
|
||||
command: 'sign'
|
||||
signing_profile: $(msft_3rd_party_cert_id)
|
||||
files_to_sign: '$(System.ArtifactsDirectory)\unsignedEngine\*.exe'
|
||||
search_root: '$(Pipeline.Workspace)'
|
||||
|
||||
- pwsh: |
|
||||
$repoRoot = "$env:REPOROOT"
|
||||
Import-Module "$repoRoot\build.psm1"
|
||||
Import-Module "$repoRoot\tools\packaging"
|
||||
|
||||
$exePath = '$(exePath)'
|
||||
$enginePath = Join-Path -Path '$(System.ArtifactsDirectory)\unsignedEngine' -ChildPath engine.exe
|
||||
$enginePath | Get-AuthenticodeSignature | out-string | Write-Verbose -verbose
|
||||
Compress-ExePackageEngine -ExePath $exePath -EnginePath $enginePath
|
||||
displayName: Compress signed exe package
|
||||
|
||||
- task: onebranch.pipeline.signing@1
|
||||
displayName: Sign exe packages
|
||||
inputs:
|
||||
command: 'sign'
|
||||
signing_profile: external_distribution
|
||||
|
||||
Reference in New Issue
Block a user