[release/v7.4.21] Support macOS signatures in nonofficial pipelines - #28051
Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit intoSep 22, 2026
Conversation
Co-authored-by: Justin Chung <[email protected]> Co-authored-by: Copilot App <[email protected]> Copilot-Session: 282853d0-d027-4558-9425-624a244cb9a3
Aditya Patwardhan (adityapatwardhan)
requested a review
from a team
as a code owner
September 21, 2026 22:47
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Copilot started reviewing on behalf of
Aditya Patwardhan (adityapatwardhan)
September 21, 2026 22:48
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The review identified two moderate createdump coverage gaps and a native-command handling nit that should be addressed before approval.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
This backport adds nonofficial macOS signature repair and validation while preserving strict official-build verification.
Changes:
- Adds macOS signature verification and ad-hoc repair.
- Propagates
OfficialBuildthrough packaging stages. - Updates validation and invokes the helper during package builds.
| File | Summary | Final review comments |
|---|---|---|
tools/packaging/Update-MacOSCodeSignature.ps1 |
Verifies and repairs macOS signatures. | Moderate (1 vote): include createdump in verification/repair. Nit (2 votes): use Start-NativeExecution for codesign calls on lines 28 and 46. |
.pipelines/templates/stages/PowerShell-Packages-Stages.yml |
Forwards official-build status. | No final comments. |
.pipelines/templates/mac.yml |
Validates Developer ID or ad-hoc signatures. | Moderate (1 vote): include createdump in the signing-job enumeration. |
.pipelines/templates/mac-package-build.yml |
Invokes signature processing during packaging. | No final comments. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+16
to
+29
| ) | ||
|
|
||
| $binaries = @( | ||
| Get-ChildItem -LiteralPath $Path -Recurse -File | | ||
| Where-Object { $_.Name -eq 'pwsh' -or $_.Extension -eq '.dylib' } | ||
| ) | ||
|
|
||
| if ($binaries.Count -eq 0) { | ||
| throw "No Mach-O binaries were found in '$Path'." | ||
| } | ||
|
|
||
| foreach ($binary in $binaries) { | ||
| & codesign --verify --deep --strict --verbose=4 $binary.FullName | ||
| if ($LASTEXITCODE -eq 0) { |
Aditya Patwardhan (adityapatwardhan)
enabled auto-merge (squash)
September 22, 2026 19:19
Patrick Meinecke (SeeminglyScience)
approved these changes
Sep 22, 2026
Aditya Patwardhan (adityapatwardhan)
merged commit Sep 22, 2026
8661c83
into
PowerShell:release/v7.4.21
40 checks passed
Justin Chung (jshigetomi)
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Backport of #27976 to release/v7.4.21
Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Justin Chung (@jshigetomi)
Original CL Label: CL-BuildPackaging
/cc @PowerShell/powershell-maintainers
Impact
REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.
Tooling Impact
Required packaging pipeline change that accepts or repairs ad-hoc Mach-O signatures in nonofficial builds while preserving production Developer ID requirements for official builds.
Customer Impact
Regression
REQUIRED: Check exactly one box.
This is not a regression.
Testing
The original PR was validated by coordinated nonofficial build 715578 and packages run 715615 for x64 and arm64 macOS signature handling; its YAML and inline PowerShell parsed successfully and PSScriptAnalyzer passed. The release-branch backport cherry-picked without conflicts,
git diff --check upstream/release/v7.4.21...HEADpassed, and the MCP PowerShell syntax validator reported the new helper valid with no conflict markers. Full platform validation is delegated to PR CI.Risk
REQUIRED: Check exactly one box.
High risk because the change affects macOS signing verification and package-pipeline behavior across official and nonofficial builds. Risk is mitigated by keeping official builds verification-only, limiting repair to failed nonofficial signatures, and requiring strict native codesign verification afterward.