verify-macos-signature.d.mts 3.0 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182
  1. import type { MacOSSigningEnvironment } from './desktop-release-environment.mjs'
  2. /**
  3. * Reject signature metadata that does not name the company release authority and team.
  4. * @param details - Output from `codesign --display --verbose=4`.
  5. * @param expected - Public release identity.
  6. */
  7. export function assertMacOSSignatureDetails(details: string, expected: MacOSSigningEnvironment): void
  8. /**
  9. * Require the signature properties Apple validates for executable runtime content.
  10. * @param details - Output from `codesign --display --verbose=4`.
  11. * @param expected - Public release identity.
  12. */
  13. export function assertMacOSRuntimeSignatureDetails(details: string, expected: MacOSSigningEnvironment): void
  14. /**
  15. * Sign one Mach-O file using the packaging-owned CSC_KEYCHAIN; missing setup rejects before signing.
  16. * @param path - Writable standalone Mach-O file.
  17. * @param identifier - Stable code-signing identifier derived from the release app ID and CAS digest.
  18. * @param expected - Public release identity.
  19. * @param entitlements - Optional entitlement plist for this executable.
  20. * @returns Resolves after codesign exits successfully.
  21. */
  22. export function signMacOSRuntimeCode(
  23. path: string,
  24. identifier: string,
  25. expected: MacOSSigningEnvironment,
  26. entitlements?: string,
  27. ): Promise<void>
  28. /**
  29. * Verify one Mach-O file embedded in the runtime tree.
  30. * @param path - Mach-O file to inspect.
  31. * @param expected - Public release identity.
  32. */
  33. export function verifyMacOSRuntimeCode(path: string, expected: MacOSSigningEnvironment): void
  34. /**
  35. * Verify the full application signature and its release owner.
  36. * @param appPath - Path to the packaged `.app` directory.
  37. * @param expected - Public release identity.
  38. */
  39. export function verifyMacOSSignature(appPath: string, expected: MacOSSigningEnvironment): void
  40. /**
  41. * Verify an independently distributed application's signature, ticket, and Gatekeeper acceptance.
  42. * @param appPath - Path to the stapled `.app` directory.
  43. * @param expected - Public release identity.
  44. */
  45. export function verifyMacOSNotarizedApplication(appPath: string, expected: MacOSSigningEnvironment): void
  46. /**
  47. * Verify the release identity, stapled ticket, and Gatekeeper acceptance of one disk image.
  48. * @param diskImagePath - Path to the packaged `.dmg` file.
  49. * @param expected - Public release identity.
  50. */
  51. export function verifyMacOSDiskImage(
  52. diskImagePath: string,
  53. expected: MacOSSigningEnvironment,
  54. ): void
  55. /** Electron-builder fields required to locate a signed macOS application. */
  56. export interface MacOSAfterSignContext {
  57. readonly electronPlatformName: string
  58. readonly appOutDir: string
  59. readonly packager: {
  60. readonly appInfo: {
  61. readonly productFilename: string
  62. }
  63. }
  64. }
  65. /**
  66. * Verify the macOS application produced by electron-builder's signing phase.
  67. * @param context - electron-builder hook context.
  68. * @param expected - Public release identity.
  69. */
  70. export function verifyMacOSSignatureAfterSign(
  71. context: MacOSAfterSignContext,
  72. expected: MacOSSigningEnvironment,
  73. ): void