Repository navigation
Use the latest ESRP signing key code - #41640
Conversation
There was a problem hiding this comment.
🔵 Needs a closer look
Signing configuration changes warrant final human verification.
Pull request overview
Updates release signing pipelines to use the latest ESRP signing key and SHA384 digests.
Changes:
- Replaces key
CP-230012withCP-501332. - Updates file and timestamp digests from SHA256 to SHA384.
- Applies changes to binary, CAB, and MSIX signing.
File summaries
| File | Changes |
|---|---|
.pipelines/package-stage.yml |
Updated bundle signing configuration. |
.pipelines/build-job.yml |
Updated binary and CAB signing configuration. |
Review details
- Files reviewed: 2/2 changed files
- Comments generated: 0
- Review effort level: Lite
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Co-authored-by: Copilot <[email protected]>
ranm-msft
left a comment
There was a problem hiding this comment.
Verified the key rotation is complete on this branch: I fetched both pipeline files at head f22400c and counted occurrences - build-job.yml has 4x CP-501332 and 0x CP-230012, package-stage.yml has 2x CP-501332 and 0x CP-230012. So all six sign/verify operations moved together and nothing is left straddling the old key.
Not approving only because I can't independently confirm CP-501332 is the correct ESRP key for this product - that part needs someone with the signing-config source of truth. If that's already confirmed, this looks ready to go from a completeness standpoint.
Summary of the Pull Request
PR Checklist
Detailed Description of the Pull Request / Additional comments
Validation Steps Performed