[release/v7.5.8] Verify Apple codesign immediately after ESRP signing (#27541)

Co-authored-by: Andy Jordan <2226434+andyleejordan@users.noreply.github.com>
This commit is contained in:
Patrick Meinecke
2026-05-28 15:02:28 -04:00
committed by GitHub
co-authored by Andy Jordan
parent be14d746bc
commit c3fb5fa008
+19
View File
@@ -184,4 +184,23 @@ jobs:
Expand-Archive -Path $zipFile -DestinationPath $signedDir -Force -Verbose
displayName: Expand Apple-signed Mach-O binaries into signed output
- pwsh: |
$signedDir = "$(ob_outputDirectory)/Signed-$(Runtime)"
$expected = 'Developer ID Application: Microsoft Corporation'
$missing = @()
Get-ChildItem $signedDir -Recurse -Include 'pwsh', '*.dylib' | ForEach-Object {
$bytes = [System.IO.File]::ReadAllBytes($_.FullName)
$text = [System.Text.Encoding]::Latin1.GetString($bytes)
if (-not $text.Contains($expected)) {
$missing += $_.FullName
Write-Host "##[error]Missing '$expected' signature in $($_.FullName)"
} else {
Write-Host "OK: $($_.FullName)"
}
}
if ($missing.Count -gt 0) {
throw "ESRP did not apply a Developer ID signature to $($missing.Count) file(s): $($missing -join ', ')"
}
displayName: 'Verify Developer ID signature on Mach-O binaries'
- template: /.pipelines/templates/step/finalize.yml@self