[release/3.x] Remove the certificate allowlist for nupkg verification.#6596
Merged
riarenas merged 1 commit intodotnet:release/3.xfrom Nov 19, 2020
Merged
Conversation
mmitche
approved these changes
Nov 19, 2020
|
Hello @riarenas! Because this pull request has the p.s. you can customize the way I help with merging this pull request, such as holding this pull request until a specific person approves. Simply @mention me (
|
|
Apologies, while this PR appears ready to be merged, it looks like |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
release/3.x port of #6593 to unblock signing validation
This will need a followup PR to update the hardcoded version of the signcheck tool in this branch of arcade.
Customer Impact
signing validation jobs will fail
Regression
No, a cert update + not knowing a lot about this particular allowlist came back to bite us when a new certificate came into play
Risk
Low. This removes some extra validation that NuGet confirmed is not necessary, and a test build of arcade master succeeded with the same change: https://dev.azure.com/dnceng/internal/_build/results?buildId=892591&view=results
Workarounds
repositories can disable signing validation altogether, which would be dangerous