Skip to content

Use the latest ESRP signing key code - #41640

Merged
Blue (OneBlue) merged 4 commits into
masterfrom
user/oneblue/update-signing-keys
Sep 28, 2026
Merged

Blue (OneBlue) merged 4 commits into
masterfrom
user/oneblue/update-signing-keys

Conversation

@OneBlue

Copy link
Copy Markdown
Collaborator

Summary of the Pull Request

PR Checklist

  • Closes: Link to issue #xxx
  • Communication: I've discussed this with core contributors already. If work hasn't been agreed, this work might be rejected
  • Tests: Added/updated if needed and all pass
  • Localization: All end user facing strings can be localized
  • Dev docs: Added/updated if needed
  • Documentation updated: If checked, please file a pull request on our docs repo and link it here: #xxx

Detailed Description of the Pull Request / Additional comments

Validation Steps Performed

Copilot AI lite review requested due to automatic review settings September 17, 2026 22:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🔵 Needs a closer look

Signing configuration changes warrant final human verification.

Pull request overview

Updates release signing pipelines to use the latest ESRP signing key and SHA384 digests.

Changes:

  • Replaces key CP-230012 with CP-501332.
  • Updates file and timestamp digests from SHA256 to SHA384.
  • Applies changes to binary, CAB, and MSIX signing.
File summaries
File Changes
.pipelines/package-stage.yml Updated bundle signing configuration.
.pipelines/build-job.yml Updated binary and CAB signing configuration.
Review details
  • Files reviewed: 2/2 changed files
  • Comments generated: 0
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Copilot AI review requested due to automatic review settings September 22, 2026 17:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved review issues were identified.

Review effort: Lite
Findings: None

Copilot AI review requested due to automatic review settings September 22, 2026 18:20

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The reviewed updates are consistent, with no unresolved issues.

Review effort: Lite
Findings: None

@OneBlue
Blue (OneBlue) marked this pull request as ready for review September 22, 2026 21:27
@OneBlue
Blue (OneBlue) requested a review from a team as a code owner September 22, 2026 21:27

@ranm-msft ranm-msft left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified the key rotation is complete on this branch: I fetched both pipeline files at head f22400c and counted occurrences - build-job.yml has 4x CP-501332 and 0x CP-230012, package-stage.yml has 2x CP-501332 and 0x CP-230012. So all six sign/verify operations moved together and nothing is left straddling the old key.

Not approving only because I can't independently confirm CP-501332 is the correct ESRP key for this product - that part needs someone with the signing-config source of truth. If that's already confirmed, this looks ready to go from a completeness standpoint.

@OneBlue
Blue (OneBlue) merged commit c9e9750 into master Sep 28, 2026
12 checks passed
@OneBlue
Blue (OneBlue) deleted the user/oneblue/update-signing-keys branch September 28, 2026 18:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants