From 2a0bb64d1868b37058e6474ed5e2148545faea5f Mon Sep 17 00:00:00 2001 From: ethernet Date: Fri, 7 Aug 2026 19:31:09 -0400 Subject: [PATCH] fix: signing uses the azureSignOptions schema --- apps/desktop/scripts/run-electron-builder.mjs | 13 +++++++------ 1 file changed, 7 insertions(+), 6 deletions(-) diff --git a/apps/desktop/scripts/run-electron-builder.mjs b/apps/desktop/scripts/run-electron-builder.mjs index a1c60b1a489ae..92a71cf6b7c18 100644 --- a/apps/desktop/scripts/run-electron-builder.mjs +++ b/apps/desktop/scripts/run-electron-builder.mjs @@ -53,20 +53,21 @@ args.push(...process.argv.slice(2)) // commas, and no quoting survives the cmd.exe hops between the outer build // script, npm's lifecycle spawn, and this script. This spawn is the first // one with no shell in between, so values pass through verbatim. +// (azureSignOptions is the 26.x schema; the old win.sign.type=azure shape +// fails validation.) if ( args.includes("--win") && process.env.AZURE_SIGN_ENDPOINT && process.env.AZURE_CLIENT_ID && - !args.some((a) => a.startsWith("-c.win.sign")) + !args.some((a) => a.includes("azureSignOptions")) ) { console.log(`[run-electron-builder] Windows signing: Azure Trusted Signing at ${process.env.AZURE_SIGN_ENDPOINT}`) args.push( "-c.win.signAndEditExecutable=true", - "-c.win.sign.type=azure", - `-c.win.sign.endpoint=${process.env.AZURE_SIGN_ENDPOINT}`, - `-c.win.sign.codeSigningAccountName=${process.env.AZURE_SIGN_ACCOUNT}`, - `-c.win.sign.certificateProfileName=${process.env.AZURE_SIGN_PROFILE}`, - `-c.win.sign.publisherName=${process.env.AZURE_SIGN_PUBLISHER}` + `-c.win.azureSignOptions.endpoint=${process.env.AZURE_SIGN_ENDPOINT}`, + `-c.win.azureSignOptions.codeSigningAccountName=${process.env.AZURE_SIGN_ACCOUNT}`, + `-c.win.azureSignOptions.certificateProfileName=${process.env.AZURE_SIGN_PROFILE}`, + `-c.win.azureSignOptions.publisherName=${process.env.AZURE_SIGN_PUBLISHER}` ) }