From c3fb5fa008aefcaee3a1a96cee3df0450830f55c Mon Sep 17 00:00:00 2001 From: Patrick Meinecke Date: Thu, 28 May 2026 15:02:28 -0400 Subject: [PATCH] [release/v7.5.8] Verify Apple codesign immediately after ESRP signing (#27541) Co-authored-by: Andy Jordan <2226434+andyleejordan@users.noreply.github.com> --- .pipelines/templates/mac.yml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/.pipelines/templates/mac.yml b/.pipelines/templates/mac.yml index cd49299461..2231d668b4 100644 --- a/.pipelines/templates/mac.yml +++ b/.pipelines/templates/mac.yml @@ -184,4 +184,23 @@ jobs: Expand-Archive -Path $zipFile -DestinationPath $signedDir -Force -Verbose displayName: Expand Apple-signed Mach-O binaries into signed output + - pwsh: | + $signedDir = "$(ob_outputDirectory)/Signed-$(Runtime)" + $expected = 'Developer ID Application: Microsoft Corporation' + $missing = @() + Get-ChildItem $signedDir -Recurse -Include 'pwsh', '*.dylib' | ForEach-Object { + $bytes = [System.IO.File]::ReadAllBytes($_.FullName) + $text = [System.Text.Encoding]::Latin1.GetString($bytes) + if (-not $text.Contains($expected)) { + $missing += $_.FullName + Write-Host "##[error]Missing '$expected' signature in $($_.FullName)" + } else { + Write-Host "OK: $($_.FullName)" + } + } + if ($missing.Count -gt 0) { + throw "ESRP did not apply a Developer ID signature to $($missing.Count) file(s): $($missing -join ', ')" + } + displayName: 'Verify Developer ID signature on Mach-O binaries' + - template: /.pipelines/templates/step/finalize.yml@self