Skip to content

[release/v7.5.12] Support macOS signatures in nonofficial pipelines - #28062

Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.5.12from
adityapatwardhan:backport/release/v7.5.12/27976-b376b3f34
Sep 23, 2026
Merged

Aditya Patwardhan (adityapatwardhan) merged 1 commit into
PowerShell:release/v7.5.12from
adityapatwardhan:backport/release/v7.5.12/27976-b376b3f34

Conversation

@adityapatwardhan

Copy link
Copy Markdown
Member

Backport of #27976 to release/v7.5.12

Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Justin Chung (@jshigetomi)

Original CL Label: CL-BuildPackaging

/cc @PowerShell/powershell-maintainers

Impact

REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.

Tooling Impact

  • Required tooling change
  • Optional tooling change (include reasoning)

Required release tooling change so nonofficial coordinated builds can accept or repair supported macOS signatures while official builds continue requiring the production Developer ID signature.

Customer Impact

  • Customer reported
  • Found internally

Regression

REQUIRED: Check exactly one box.

  • Yes
  • No

This is not a regression.

Testing

The original change was validated by coordinated nonofficial build 715578 for x64 and arm64 signature validation and packages nonofficial run 715615 for both macOS architectures, including strict native codesign verification. The changed YAML and inline PowerShell parsed successfully, PSScriptAnalyzer passed for the helper, and the backport cherry-picked cleanly with a clean worktree.

Risk

REQUIRED: Check exactly one box.

  • High
  • Medium
  • Low

High risk because this changes coordinated-build signature validation and macOS packaging behavior. The change is narrowly scoped to signature handling, was validated in successful coordinated and package pipeline runs for both x64 and arm64, and cherry-picked cleanly onto release/v7.5.12.

Co-authored-by: Justin Chung <[email protected]>
Co-authored-by: Copilot App <[email protected]>
Copilot-Session: 282853d0-d027-4558-9425-624a244cb9a3
Copilot AI lite review requested due to automatic review settings September 22, 2026 22:05
@adityapatwardhan Aditya Patwardhan (adityapatwardhan) added the CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log label Sep 22, 2026
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Unresolved moderate findings remain in signature invocation and Mach-O coverage.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 Medium severity

Open (1)
What changed in this PR

Backports macOS signature repair and validation for nonofficial release pipelines while preserving strict official-build verification.

Changes:

  • Adds signature verification and ad-hoc repair.
  • Propagates OfficialBuild through packaging jobs.
  • Updates coordinated-build and packaging validation.
File Summary Findings
tools/​packaging/​Update-MacOSCodeSignature.ps1 Repairs and verifies macOS signatures. Moderate: use Start-NativeExecution and include createdump; nit: respect caller verbosity.
.pipelines/​templates/​stages/​PowerShell-Packages-Stages.yml Passes official-build state to macOS jobs. None.
.pipelines/​templates/​mac.yml Validates official and ad-hoc signatures. None.
.pipelines/​templates/​mac-package-build.yml Runs signature repair before packaging. None.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +28 to +29
& codesign --verify --deep --strict --verbose=4 $binary.FullName
if ($LASTEXITCODE -eq 0) {
@adityapatwardhan
Aditya Patwardhan (adityapatwardhan) merged commit 30b4252 into PowerShell:release/v7.5.12 Sep 23, 2026
38 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CL-BuildPackaging Indicates that a PR should be marked as a build or packaging change in the Change Log

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants