Skip to content

[gh] Sign Windows builds with Azure Trusted Signing - #368

Merged
gabrieldonadel merged 3 commits into
mainfrom
@gabrieldonadel/azure
Aug 20, 2026
Merged

gabrieldonadel merged 3 commits into
mainfrom
@gabrieldonadel/azure

Conversation

@gabrieldonadel

@gabrieldonadel gabrieldonadel commented Aug 19, 2026 •

Copy link
Copy Markdown
Member

Why

Windows builds of Orbit are currently unsigned and this sometimes causes users to get "malware" warnings on Windows.

How

This updates the release workflow to sign Windows builds using azure/trusted-signing-action@v2 and GitHub OIDC for authentication instead of stored credentials.

Test Plan

  • Trigger a workflow_dispatch run of the Build workflow on this branch and confirm both signing steps succeed.
  • Download the windows-exe artifact and verify the signature on Setup.exe and on expo-orbit.exe inside the nupkg (file Properties > Digital Signatures, or signtool verify /pa). The signer should be "650 Industries, Inc." with a timestamp.

@gabrieldonadel gabrieldonadel added the skip-changelog-check Skips changelog check step. label Aug 19, 2026
@gabrieldonadel
gabrieldonadel merged commit dfb71f6 into main Aug 20, 2026
4 checks passed
@gabrieldonadel
gabrieldonadel deleted the @gabrieldonadel/azure branch August 20, 2026 19:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

skip-changelog-check Skips changelog check step.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants