[release/v7.5.12] Support macOS signatures in nonofficial pipelines - #28062
Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit intoSep 23, 2026
Conversation
Co-authored-by: Justin Chung <[email protected]> Co-authored-by: Copilot App <[email protected]> Copilot-Session: 282853d0-d027-4558-9425-624a244cb9a3
Aditya Patwardhan (adityapatwardhan)
requested a review
from a team
as a code owner
September 22, 2026 22:05
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Copilot started reviewing on behalf of
Aditya Patwardhan (adityapatwardhan)
September 22, 2026 22:07
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Unresolved moderate findings remain in signature invocation and Mach-O coverage.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (1)
What changed in this PR
Backports macOS signature repair and validation for nonofficial release pipelines while preserving strict official-build verification.
Changes:
- Adds signature verification and ad-hoc repair.
- Propagates
OfficialBuildthrough packaging jobs. - Updates coordinated-build and packaging validation.
| File | Summary | Findings |
|---|---|---|
tools/packaging/Update-MacOSCodeSignature.ps1 |
Repairs and verifies macOS signatures. | Moderate: use Start-NativeExecution and include createdump; nit: respect caller verbosity. |
.pipelines/templates/stages/PowerShell-Packages-Stages.yml |
Passes official-build state to macOS jobs. | None. |
.pipelines/templates/mac.yml |
Validates official and ad-hoc signatures. | None. |
.pipelines/templates/mac-package-build.yml |
Runs signature repair before packaging. | None. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+28
to
+29
| & codesign --verify --deep --strict --verbose=4 $binary.FullName | ||
| if ($LASTEXITCODE -eq 0) { |
Dongbo Wang (daxian-dbw)
approved these changes
Sep 23, 2026
Justin Chung (jshigetomi)
approved these changes
Sep 23, 2026
Aditya Patwardhan (adityapatwardhan)
merged commit Sep 23, 2026
30b4252
into
PowerShell:release/v7.5.12
38 checks passed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Backport of #27976 to release/v7.5.12
Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Justin Chung (@jshigetomi)
Original CL Label: CL-BuildPackaging
/cc @PowerShell/powershell-maintainers
Impact
REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.
Tooling Impact
Required release tooling change so nonofficial coordinated builds can accept or repair supported macOS signatures while official builds continue requiring the production Developer ID signature.
Customer Impact
Regression
REQUIRED: Check exactly one box.
This is not a regression.
Testing
The original change was validated by coordinated nonofficial build 715578 for x64 and arm64 signature validation and packages nonofficial run 715615 for both macOS architectures, including strict native codesign verification. The changed YAML and inline PowerShell parsed successfully, PSScriptAnalyzer passed for the helper, and the backport cherry-picked cleanly with a clean worktree.
Risk
REQUIRED: Check exactly one box.
High risk because this changes coordinated-build signature validation and macOS packaging behavior. The change is narrowly scoped to signature handling, was validated in successful coordinated and package pipeline runs for both x64 and arm64, and cherry-picked cleanly onto release/v7.5.12.