mirror of
https://github.com/PowerShell/PowerShell
synced 2026-06-08 12:12:50 +00:00
[release/v7.5.8] Verify Apple codesign immediately after ESRP signing (#27541)
Co-authored-by: Andy Jordan <2226434+andyleejordan@users.noreply.github.com>
This commit is contained in:
co-authored by
Andy Jordan
parent
be14d746bc
commit
c3fb5fa008
@@ -184,4 +184,23 @@ jobs:
|
||||
Expand-Archive -Path $zipFile -DestinationPath $signedDir -Force -Verbose
|
||||
displayName: Expand Apple-signed Mach-O binaries into signed output
|
||||
|
||||
- pwsh: |
|
||||
$signedDir = "$(ob_outputDirectory)/Signed-$(Runtime)"
|
||||
$expected = 'Developer ID Application: Microsoft Corporation'
|
||||
$missing = @()
|
||||
Get-ChildItem $signedDir -Recurse -Include 'pwsh', '*.dylib' | ForEach-Object {
|
||||
$bytes = [System.IO.File]::ReadAllBytes($_.FullName)
|
||||
$text = [System.Text.Encoding]::Latin1.GetString($bytes)
|
||||
if (-not $text.Contains($expected)) {
|
||||
$missing += $_.FullName
|
||||
Write-Host "##[error]Missing '$expected' signature in $($_.FullName)"
|
||||
} else {
|
||||
Write-Host "OK: $($_.FullName)"
|
||||
}
|
||||
}
|
||||
if ($missing.Count -gt 0) {
|
||||
throw "ESRP did not apply a Developer ID signature to $($missing.Count) file(s): $($missing -join ', ')"
|
||||
}
|
||||
displayName: 'Verify Developer ID signature on Mach-O binaries'
|
||||
|
||||
- template: /.pipelines/templates/step/finalize.yml@self
|
||||
|
||||
Reference in New Issue
Block a user