Switch signing command to msbuild - #64555
Merged
Jake Bailey (jakebailey) merged 7 commits intoSep 30, 2026
Merged
Jake Bailey (jakebailey) merged 7 commits into
Jake Bailey (jakebailey) merged 7 commits into
Conversation
DDSignFiles requires an out-of-support runtime. Using the MicroBuild MSBuild interface could avoid that dependency, pending verification in an official signing pipeline.
Avoid duplicating signing setup that the official template already owns, so prerequisite and service connection changes are maintained centrally. Keep explicit .NET setup to avoid relying on the agent image, and preserve release validation before signing setup.
Expose signing progress in pipeline logs instead of leaving long silent intervals while waiting for signing to complete.
Signing uses controlled filenames and certificate identifiers. Reject unexpected characters explicitly rather than maintaining general-purpose XML and MSBuild escaping for inputs this pipeline does not need.
Release-tag validation must precede the build and signing commands, but need not precede signing plugin installation. Reserve MicroBuild presteps for .NET setup rather than coupling release validation to plugin setup.
Scheduled build tagging does not need to precede MicroBuild setup. Keep presteps limited to .NET installation in both release pipelines.
Copilot started reviewing on behalf of
Jake Bailey (jakebailey)
September 30, 2026 16:52
View session
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The signing build does not discover the added NuGet configuration from its repository-root working directory.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Migrates release signing from the legacy .NET Core signing command to MSBuild-based MicroBuild signing.
Changes:
- Adds an MSBuild signing project and NuGet configuration.
- Generates MSBuild signing items from release artifacts.
- Updates pipelines to use template-provided signing credentials and .NET 8.
| File | Description |
|---|---|
Herebyfile.mjs |
Invokes MSBuild-based signing. |
tools/signing/Sign.csproj |
Defines the signing target. |
tools/signing/NuGet.config |
Configures the MicroBuild feed. |
tools/pipelines/typescript-build.yml |
Enables template signing for TypeScript builds. |
tools/pipelines/vscode-typescript-build.yml |
Enables template signing for extension builds. |
💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.
Ryan Cavanaugh (RyanCavanaugh)
approved these changes
Sep 30, 2026
Avoid deriving the plugin root from DDSignFiles' app folder, whose internal layout is unrelated to MSBuild plugin discovery. Use an explicit pipeline setting for real signing and signature verification so a missing configured plugin fails rather than falling back to fake signing.
Jake Bailey (jakebailey)
requested a review
from Ryan Cavanaugh (RyanCavanaugh)
September 30, 2026 19:38
Ryan Cavanaugh (RyanCavanaugh)
approved these changes
Sep 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

This should get .NET Core 3.1 out of our pipeline, and reduce copy pasting from the upstream template that provides signing creds.
I've already tested this out on this branch and it works.