mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
[release/v7.5] Migrate MacOS Signing to OneBranch (#25304)
Co-authored-by: Justin Chung <124807742+jshigetomi@users.noreply.github.com> Co-authored-by: Justin Chung <chungjustin@microsoft.com>
This commit is contained in:
co-authored by
Justin Chung
Justin Chung
parent
efb55e20ac
commit
99c93ee38a
@@ -173,56 +173,43 @@ jobs:
|
||||
Get-ChildItem -Path $(Pipeline.Workspace) -Filter "*.zip" -File | Write-Verbose -Verbose
|
||||
displayName: Compress package files for signing
|
||||
|
||||
- task: SFP.build-tasks.custom-build-task-1.EsrpCodeSigning@5
|
||||
displayName: 'ESRP CodeSigning'
|
||||
- task: onebranch.pipeline.signing@1
|
||||
displayName: 'OneBranch CodeSigning Package'
|
||||
inputs:
|
||||
ConnectedServiceName: 'ESRPMacOSSigning'
|
||||
AppRegistrationClientId: '$(AppRegistrationClientId)'
|
||||
AppRegistrationTenantId: '$(AppRegistrationTenantId)'
|
||||
AuthAKVName: 'pwsh-CICD-Keyvault'
|
||||
AuthCertName: 'PS-macos-signing'
|
||||
AuthSignCertName: 'ESRP-OneCert' # this is not needed for pkg signing
|
||||
FolderPath: $(Pipeline.Workspace)
|
||||
Pattern: '*.zip'
|
||||
signConfigType: inlineSignParams
|
||||
inlineOperation: |
|
||||
[{
|
||||
command: 'sign'
|
||||
files_to_sign: '**/*-osx-*.zip'
|
||||
search_root: '$(Pipeline.Workspace)'
|
||||
inline_operation: |
|
||||
[
|
||||
{
|
||||
"KeyCode": "$(KeyCode)",
|
||||
"OperationSetCode": "MacAppDeveloperSign",
|
||||
"parameters": [
|
||||
{
|
||||
"parameterName": "hardening",
|
||||
"parameterValue": "enable"
|
||||
},
|
||||
{
|
||||
"parameterName": "OpusInfo",
|
||||
"parameterValue": "http://Microsoft.com"
|
||||
}
|
||||
],
|
||||
"OperationCode": "MacAppDeveloperSign",
|
||||
"ToolName": "sign",
|
||||
"ToolVersion": "1.0"
|
||||
}]
|
||||
SessionTimeout: 90
|
||||
ServiceEndpointUrl: '$(ServiceEndpointUrl)'
|
||||
MaxConcurrency: 25
|
||||
"ToolVersion": "1.0",
|
||||
"Parameters": {
|
||||
"Hardening": "Enable",
|
||||
"OpusInfo": "http://microsoft.com"
|
||||
}
|
||||
}
|
||||
]
|
||||
|
||||
- pwsh: |
|
||||
$signedPkg = Get-ChildItem -Path $(Pipeline.Workspace) -Filter "*osx*.zip" -File
|
||||
|
||||
|
||||
$signedPkg | ForEach-Object {
|
||||
Write-Verbose -Verbose "Signed package zip: $_"
|
||||
|
||||
|
||||
if (-not (Test-Path $_)) {
|
||||
throw "Package not found: $_"
|
||||
}
|
||||
|
||||
if (-not (Test-Path $env:ob_outputDirectory)) {
|
||||
$null = New-Item -Path $env:ob_outputDirectory -ItemType Directory
|
||||
|
||||
if (-not (Test-Path $(ob_outputDirectory))) {
|
||||
$null = New-Item -Path $(ob_outputDirectory) -ItemType Directory
|
||||
}
|
||||
|
||||
Expand-Archive -Path $_ -DestinationPath $env:ob_outputDirectory -Verbose
|
||||
Expand-Archive -Path $_ -DestinationPath $(ob_outputDirectory) -Verbose
|
||||
}
|
||||
|
||||
Write-Verbose -Verbose "Expanded pkg file:"
|
||||
Get-ChildItem -Path $env:ob_outputDirectory | Write-Verbose -Verbose
|
||||
Get-ChildItem -Path $(ob_outputDirectory) | Write-Verbose -Verbose
|
||||
displayName: Expand signed file
|
||||
|
||||
Reference in New Issue
Block a user