Verify Apple codesign immediately after ESRP signing (#27486)

This commit is contained in:
Andy Jordan
2026-05-20 14:27:17 -07:00
committed by GitHub
parent 90d3b7f2e3
commit 5e6ecd3701
+19
View File
@@ -184,4 +184,23 @@ jobs:
Expand-Archive -Path $zipFile -DestinationPath $signedDir -Force -Verbose
displayName: Expand Apple-signed Mach-O binaries into signed output
- pwsh: |
$signedDir = "$(ob_outputDirectory)/Signed-$(Runtime)"
$expected = 'Developer ID Application: Microsoft Corporation'
$missing = @()
Get-ChildItem $signedDir -Recurse -Include 'pwsh', '*.dylib' | ForEach-Object {
$bytes = [System.IO.File]::ReadAllBytes($_.FullName)
$text = [System.Text.Encoding]::Latin1.GetString($bytes)
if (-not $text.Contains($expected)) {
$missing += $_.FullName
Write-Host "##[error]Missing '$expected' signature in $($_.FullName)"
} else {
Write-Host "OK: $($_.FullName)"
}
}
if ($missing.Count -gt 0) {
throw "ESRP did not apply a Developer ID signature to $($missing.Count) file(s): $($missing -join ', ')"
}
displayName: 'Verify Developer ID signature on Mach-O binaries'
- template: /.pipelines/templates/step/finalize.yml@self