Skip to content

Switch signing command to msbuild - #64555

Merged
Jake Bailey (jakebailey) merged 7 commits into
microsoft:mainfrom
jakebailey:experiment-msbuild-signing
Sep 30, 2026
Merged

Jake Bailey (jakebailey) merged 7 commits into
microsoft:mainfrom
jakebailey:experiment-msbuild-signing

Conversation

@jakebailey

Copy link
Copy Markdown
Member

This should get .NET Core 3.1 out of our pipeline, and reduce copy pasting from the upstream template that provides signing creds.

I've already tested this out on this branch and it works.

DDSignFiles requires an out-of-support runtime. Using the MicroBuild
MSBuild interface could avoid that dependency, pending verification in
an official signing pipeline.
Avoid duplicating signing setup that the official template already owns,
so prerequisite and service connection changes are maintained centrally.
Keep explicit .NET setup to avoid relying on the agent image, and preserve
release validation before signing setup.
Expose signing progress in pipeline logs instead of leaving long silent
intervals while waiting for signing to complete.
Signing uses controlled filenames and certificate identifiers. Reject
unexpected characters explicitly rather than maintaining general-purpose
XML and MSBuild escaping for inputs this pipeline does not need.
Release-tag validation must precede the build and signing commands, but
need not precede signing plugin installation. Reserve MicroBuild presteps
for .NET setup rather than coupling release validation to plugin setup.
Scheduled build tagging does not need to precede MicroBuild setup.
Keep presteps limited to .NET installation in both release pipelines.
Copilot AI balanced review requested due to automatic review settings September 30, 2026 16:51
@typescript-automation typescript-automation Bot added Author: Team For Uncommitted Bug PR for untriaged, rejected, closed or missing bug labels Sep 30, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The signing build does not discover the added NuGet configuration from its repository-root working directory.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Migrates release signing from the legacy .NET Core signing command to MSBuild-based MicroBuild signing.

Changes:

  • Adds an MSBuild signing project and NuGet configuration.
  • Generates MSBuild signing items from release artifacts.
  • Updates pipelines to use template-provided signing credentials and .NET 8.
File Description
Herebyfile.mjs Invokes MSBuild-based signing.
tools/​signing/​Sign.csproj Defines the signing target.
tools/​signing/​NuGet.config Configures the MicroBuild feed.
tools/​pipelines/​typescript-build.yml Enables template signing for TypeScript builds.
tools/​pipelines/​vscode-typescript-build.yml Enables template signing for extension builds.

💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread Herebyfile.mjs
Comment thread Herebyfile.mjs Outdated
Avoid deriving the plugin root from DDSignFiles' app folder, whose
internal layout is unrelated to MSBuild plugin discovery. Use an explicit
pipeline setting for real signing and signature verification so a missing
configured plugin fails rather than falling back to fake signing.
@jakebailey
Jake Bailey (jakebailey) added this pull request to the merge queue Sep 30, 2026
Merged via the queue into microsoft:main with commit 5f5dee5 Sep 30, 2026
29 of 30 checks passed
@jakebailey
Jake Bailey (jakebailey) deleted the experiment-msbuild-signing branch September 30, 2026 20:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Author: Team For Uncommitted Bug PR for untriaged, rejected, closed or missing bug

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

3 participants