Releases and PR previews now sign the app binary, the MSI, the NSIS
installer and its uninstaller. "Verify signatures" fails the job on any
unsigned or untimestamped .exe/.msi, so an unsigned installer can't ship
quietly.
- windows-signing-setup.ps1 fetches Microsoft.ArtifactSigning.Client 1.0.128
and a job-local .NET 10.0.12 runtime, each pinned by hash. Nothing is
installed on the build VM. It also writes the dlib metadata and exports
TAURI_CONFIG with bundle.windows.signCommand.
- windows-sign.ps1 runs the installed signtool with /dlib, SHA-256 and the
Microsoft timestamp server, with retries. Credentials come only from the
AZURE_* environment. The metadata excludes every credential type except
EnvironmentCredential, because InteractiveBrowserCredential would hang a
job running as SYSTEM.
- The signing files go in the workspace, not %TEMP%, because the uninstaller
is signed from 32-bit makensis and WOW64 redirects SYSTEM's %TEMP%.
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>