Commit Graph
169 Commits
Author SHA1 Message Date
Anam Navied 6cee25f72d Remove unused step that clones Internal-PowerShellTeam-Tools repo in PMC publish pipeline (#27495) 2026-05-21 17:07:39 -07:00
Andy Jordan 5e6ecd3701 Verify Apple codesign immediately after ESRP signing (#27486) 2026-05-20 14:27:17 -07:00
Dongbo Wang b4d5395e89 Update the MSIXBundle-VPack pipeline to create VPack for both LTS and Stable channel packages (#27384) 2026-05-05 13:28:14 -07:00
Andy Jordan 36673f6d46 Correct typo in package parameters
It's been this way for a couple years which means we've been passing...something else?
2026-05-05 12:47:42 -07:00
Andy JordanandCopilot d49ade6597 Move ESRP key codes into the certificate_logical_to_actual variable group
The `CP-…` key codes used for ESRP signing are now set from ADO via the
`certificate_logical_to_actual` variable group. The templates reference
the following variables instead of literal codes:

- `$(authenticode_cert_id)`
- `$(authenticode_test_cert_id)`
- `$(nuget_cert_id)`
- `$(apple_cert_id)`
- `$(pgp_linux_cert_id)`
- `$(pgp_release_cert_id)`

`nupkg.yml`, `mac-package-build.yml`, and `linux-package-build.yml` pick
up the new group import. `linux-package-build.yml` also now selects the
PGP signing profile based on whether `jobName` starts with `mariner`, so
`PowerShell-Packages-Stages.yml` no longer threads a `signingProfile`
parameter in for the two Mariner jobs.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-05 12:47:42 -07:00
Andy JordanandCopilot 3d13188032 Fix executable permissions for pwsh and createdump
The tarball staging path used `Copy-Item`, which on *nix doesn't preserve
the source file mode, so `pwsh` ended up 644 in the `.tar.gz`. The Debian,
RPM, and macOS PKG paths explicitly `chmod` everything to 644 and then bump
`pwsh` back to 755, which silently demoted `createdump` (the .NET helper
that produces crash minidumps) along with it. Now we `chmod 755` both
executables in all package staging paths, guarded by `Test-Path` since
fxdependent builds don't bundle `createdump`.

Also added regression tests which check the permissions of `pwsh` inside
the Linux and macOS tarballs before we upload them.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-05 12:47:42 -07:00
Anam Navied ddff03a50f Create PowerShell package for arm debian distribution (#26925) 2026-05-05 11:29:02 -07:00
Andy JordanandCopilot b9bd8cbc59 Apply macOS entitlements to pwsh
Uses codesign in the macOS build step to apply entitlements from a plist.
This is required for the hardened runtime (which is required for notarization).

See: https://learn.microsoft.com/en-us/dotnet/core/install/macos-notarization-issues#default-entitlements

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-01 13:51:55 -07:00
Andy JordanandCopilot da95729be5 Add macOS binary code signing and package notarization
We still need to apply the template signing so that Guardian tasks pass
and so that script files are signed. After doing what's essentially
Windows signing, we sign and harden the binaries for macOS. Then we do
the same for the PKG installer, and finally notarize it. The ESRP
signing service requires a zip of files for Apple signing at all stages.
Now that we can use it via the OneBranch signing task we no longer need
the service connection or variable group that was trying to set it up.
Notarization requires the BundleId from Get-MacOSPackageIdentifierInfo.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
2026-05-01 13:51:55 -07:00
Justin ChungandJustin Chung d356e3f0e2 Fix changelog grab failure when only one header exists. (#27371)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
2026-04-28 10:19:06 -07:00
Justin ChungandJustin Chung 63544d18bc Download PMC Packages through TemplateContext (#27326)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
2026-04-22 15:25:39 -05:00
Justin ChungandJustin Chung d50bc2cb73 Correct Variable Template Reference in NonOfficial Pipeline Templates (#27275)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
2026-04-21 15:29:46 -05:00
Dongbo Wang 156906e050 PMC release: Use slash instead of back-slash for Linux container (#27315) 2026-04-21 13:05:14 -07:00
Dongbo Wang 558c886d87 Remove package verification from the notice pipeline (#27289) 2026-04-17 10:05:33 -07:00
72be78e6be Remove MSI from publishing pipeline (#27213)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
Co-authored-by: Aditya Patwardhan <adityap@microsoft.com>
2026-04-16 15:01:35 -04:00
Justin Chung 25e80cefdb Fix the package pipeline by adding in PDP-Media directory (#27254) 2026-04-10 14:27:13 -07:00
Dongbo Wang 073f4d61bd Build, package, and create VPack for the PowerShell-LTS store package within the same msixbundle-vpack pipeline (#150) (#27209) 2026-04-08 13:28:20 -07:00
Justin ChungandJustin Chung 22f62e859d Redo windows image fix to use latest image (#27198)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
2026-04-07 14:58:53 -05:00
Justin ChungandJustin Chung 45a80d9a48 Separate Store Package Creation, Skip Polling for Store Publish, Clean up PDP-Media (#27024)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
2026-04-01 13:20:45 -05:00
Justin ChungandJustin Chung a17f1761ec Select New MSIX Package Name (#27096)
Co-authored-by: Justin Chung <chungjustin@microsoft.com>
2026-03-25 18:56:16 +00:00
Justin ChungandCopilot f9be17e6b5 Separate Official and NonOfficial templates for ADO pipelines (#26897)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-03-24 15:37:51 -05:00
Copilot 8947ed62e6 release-upload-buildinfo: replace version-comparison channel gating with metadata flags (#27074) 2026-03-20 16:58:55 +00:00
Justin Chung 9c6a012e7d Update build to create two msix's and msixbundles for LTS and Stable (#27056) 2026-03-19 13:57:10 -07:00
Anam Navied 73186fb138 Fix PMC repo URL for RHEL10 (#27059) 2026-03-18 13:42:23 -07:00
Dongbo Wang e053a339a1 Create Linux LTS deb/rpm packages for LTS releases (#27049) 2026-03-17 14:47:59 -07:00
Dongbo Wang 8c9c9e1187 Create LTS pkg and non-LTS pkg for macOS for LTS releases (#27039) 2026-03-16 12:40:26 -07:00
Aditya Patwardhan 1f8bbe1e53 Fix the container image for vPack, MSIX vPack and Package pipelines (#27015) 2026-03-12 15:34:12 -04:00
Justin Chung eb1915e76b Hardcode Official templates (#26928) 2026-03-09 10:42:27 -07:00
Travis PlunkandCopilot 6e2b4c784a Split TPN manifest and Component Governance manifest (#26891)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-02-25 19:51:56 +00:00
Justin Chung 7311378cf9 Add version in description and pass store task on failure (#26885) 2026-02-24 12:59:25 -08:00
Dongbo Wang b58ec36093 Exclude .exe packages from publishing to GitHub (#26859) 2026-02-20 10:29:13 -08:00
Aditya Patwardhan 212c5f97e3 Update to .NET 11 SDK and update dependencies (#26783) 2026-02-18 16:35:10 -08:00
Justin Chung 0931a75d3e Fix buildinfo.json uploading for preview, LTS, and stable releases (#25571) 2026-01-20 16:26:59 -08:00
Aditya Patwardhan bd33c2d987 Update metadata.json to update the Latest attribute with a better name (#26380) 2026-01-14 14:38:37 -08:00
1241ad2794 Remove unused runCodesignValidationInjection variable from pipeline templates (#26412)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: TravisEz13 <10873629+TravisEz13@users.noreply.github.com>
Co-authored-by: Travis Plunk (HE/HIM) <tplunk@ntdev.microsoft.com>
2026-01-14 10:58:38 -05:00
Justin Chung 9ef5ec4734 Bring release changes from the v7.6.0-preview.6 release branch (#26627)
1. Fix the conditions used in `release-MSIX-Publish.yml`
2. Update `build.psm1` to not install dotnet format tool for ADO build.
2025-12-17 16:22:06 -08:00
Travis PlunkandCopilot 4aa65a77be Update the macos package name for preview releases to match the previous pattern (#26429)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-11-12 09:36:50 -08:00
Travis Plunk 1fd3ea835d Fix condition syntax for StoreBroker package tasks in MSIX pipeline (#26427) 2025-11-12 09:35:41 -08:00
Travis Plunk d412f040b8 Fix template path for rebuild branch check in package.yml (#26425) 2025-11-12 08:59:57 -08:00
Travis PlunkandCopilot 8b7e493dd9 Add rebuild branch support with conditional MSIX signing (#26415)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-11-10 14:03:27 -08:00
Travis Plunk 1934b837a6 Move package validation to package pipeline (#26414) 2025-11-10 13:51:02 -08:00
Travis PlunkandCopilot 3596ffa909 Optimize/split windows package signing (#26403)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-11-10 11:05:12 -08:00
Travis Plunk e7bf5621bf Improve ADO package build and validation across platforms (#26398) 2025-11-07 11:53:43 -08:00
Travis PlunkandCopilot c6cbd41a6a Add network isolation policy parameter to vPack pipeline (#26223)
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2025-10-21 16:39:12 -04:00
Justin Chung dbc09a1aab Separate Store Automation Service Endpoints, Resolve AppID (#26210) 2025-10-21 12:43:01 -07:00
Travis Plunk 7e081b30b8 Update vPack name (#26090) 2025-10-15 21:06:00 +00:00
Justin Chung 5e05175998 Make MSIX publish stage dependent on SetReleaseTagandContainerName stage 2025-10-10 16:15:26 -05:00
Aditya Patwardhan f1e2301e7f Add bootstrap to global tool validation step 2025-10-07 13:16:06 -07:00
Aditya Patwardhan d042a280b6 Merged PR 37066: Update the test image for SDK tests
Update the test image for SDK tests

----
#### AI description  (iteration 1)
#### PR Classification
This PR is a configuration update aimed at improving SDK test reliability by using an updated Ubuntu test image.

#### PR Summary
The pull request updates the pipeline configuration to reference a new test image version for SDK validation.
- `.pipelines/PowerShell-Release-Official.yml`: Changed `imageName` from `PSMMSUbuntu20.04-Secure` to `PSMMSUbuntu22.04-Secure`.
<!-- GitOpsUserAgent=GitOps.Apps.Server.pullrequestcopilot -->
2025-10-07 19:50:42 +00:00
Aditya Patwardhan 92beb64c14 Add Start-PSBootstrap to add installed dotnet to path 2025-10-06 11:59:48 -07:00