Automate validation of Nuget signatures
See original GitHub issueWe need to automate validation that our NuGet packages are signed.
Specifically this means running nuget verify -all
on every nupkg after signing completes. If that fails, upload will fail later.
We should not rely on remembering to do this manually. Perhaps this is a dupe, but I can’t find it.
Issue Analytics
- State:
- Created 5 years ago
- Comments:8 (8 by maintainers)
Top Results From Across the Web
NuGet signed-package verification - .NET CLI
You can sign a NuGet package to enable package consumers to validate the package's authenticity and integrity. If verification is enabled, .NET ...
Read more >Package Signatures Technical Details · NuGet/Home Wiki
At signing time, a certificate MUST be within its validity period according to the package writer and MUST NOT be revoked. At validation...
Read more >Package Signature Verification - Robot
Package Signature is a method through which NuGet Packages prove that they come from trusted sources. A package is signed by using a ......
Read more >How to verify Package Signature when using Nuget. ...
I need to validate the subject and issuer details to validate right source of the package. var s = SignedPackageArchiveUtility.
Read more >Why NuGet Package Signing Is Not (Yet) for Me - Haacked
With signatureValidationMode set to require , NuGet rejects package installation unless the package is signed by a trusted signer. Let's take a ...
Read more >
Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free
Top Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
I’m closing this issue as SignCheck already perform such validation and we’re going to use it in our builds.
Thanks!