[release/v7.6.7] Support macOS signatures in nonofficial pipelines - #28076
Merged
Aditya Patwardhan (adityapatwardhan) merged 1 commit intoSep 24, 2026
Conversation
Co-authored-by: Justin Chung <[email protected]> Co-authored-by: Copilot App <[email protected]> Copilot-Session: 282853d0-d027-4558-9425-624a244cb9a3
Aditya Patwardhan (adityapatwardhan)
requested review from
a team and
Justin Chung (jshigetomi)
as code owners
September 23, 2026 23:30
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
Copilot started reviewing on behalf of
Aditya Patwardhan (adityapatwardhan)
September 23, 2026 23:31
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Fix the incorrect checkout paths and wrap all native codesign calls as requested.
Get a fresh assessment by requesting another Copilot review.
Review effort: Lite
Findings: 1
Open (2)
What changed in this PR
Backports macOS signature validation and repair for nonofficial packaging pipelines while preserving official-build verification.
Changes:
- Adds ad-hoc signature repair and verification.
- Propagates
OfficialBuildto macOS package jobs. - Accepts Developer ID or ad-hoc signatures for coordinated validation.
| File | Summary |
|---|---|
tools/packaging/Update-MacOSCodeSignature.ps1 |
Adds signature validation and repair; native codesign calls require the repository’s execution wrapper. |
.pipelines/templates/stages/PowerShell-Packages-Stages.yml |
Passes official-build configuration to macOS jobs. |
.pipelines/templates/mac.yml |
Validates supported macOS signatures. |
.pipelines/templates/mac-package-build.yml |
Runs signature processing; entitlements and script paths must include the PowerShell checkout directory. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+85
to
+87
| EntitlementsPath = "$(Build.SourcesDirectory)/assets/macos-entitlements.plist" | ||
| } | ||
| displayName: 'Verify Apple codesign on signed binaries' | ||
| & "$(Build.SourcesDirectory)/tools/packaging/Update-MacOSCodeSignature.ps1" @signatureParameters |
| } | ||
|
|
||
| foreach ($binary in $binaries) { | ||
| & codesign --verify --deep --strict --verbose=4 $binary.FullName |
Justin Chung (jshigetomi)
approved these changes
Sep 24, 2026
Aditya Patwardhan (adityapatwardhan)
merged commit Sep 24, 2026
c1b47f7
into
PowerShell:release/v7.6.7
39 checks passed
Aditya Patwardhan (adityapatwardhan)
deleted the
backport/release/v7.6.7/27976-b376b3f34
branch
September 24, 2026 17:11
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.


Backport of #27976 to release/v7.6.7
Triggered by Aditya Patwardhan (@adityapatwardhan) on behalf of Justin Chung (@jshigetomi)
Original CL Label: CL-BuildPackaging
/cc @PowerShell/powershell-maintainers
Impact
REQUIRED: Choose either Tooling Impact or Customer Impact (or both). At least one checkbox must be selected.
Tooling Impact
Required packaging pipeline change that accepts supported Microsoft Developer ID or ad-hoc signatures for nonofficial coordinated builds, repairs Mach-O binaries that fail native verification on macOS package agents, and retains production Developer ID verification for official builds.
Customer Impact
Regression
REQUIRED: Check exactly one box.
This is not a regression.
Testing
The original change was validated in coordinated nonofficial build 715578 for x64 and arm64 signature validation and packages run 715615 for both macOS package architectures with strict native codesign verification. The changed YAML and inline PowerShell parsed successfully, PSScriptAnalyzer passed for the new helper, and local scenarios covered nonofficial repair and official verification-only behavior. For this conflict-free backport, the cherry-picked PowerShell helper passed parser validation, all changed files were checked for conflict markers, git diff --check passed, and CI will provide final release-branch validation.
Risk
REQUIRED: Check exactly one box.
High risk because this changes macOS package signing and validation behavior in release pipelines. The change is narrowly scoped to Mach-O signature handling, preserves verification-only behavior for official builds, requires strict native codesign verification before packaging, and was validated in coordinated nonofficial x64 and arm64 builds.