Conversation
Co-authored-by: Amund211 <14028449+Amund211@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Add Windows binary signing to testing.yml
Add Windows binary signing with Azure Trusted Signing
Jan 15, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Note
Blocked: waiting for Azure Artifact Signing (formerly Trusted Signing) to support individual developers in Norway.
As of 2026-07-24, Public Trust certificates require an organization in a supported country/region — Norway was added to that list on 2026-07-23, alongside Switzerland. Individual developers must still be located in the USA or Canada, and Microsoft has stated individual onboarding for Public Trust is paused with no announced timeline for expansion.
Since Prism is signed by an individual, not a registered company, we can't complete identity validation yet. Keeping this PR open until that changes.
Implements code signing for Windows executables in the CI pipeline using Azure Trusted Signing with OIDC authentication.
Changes
id-token: writefor Azure OIDC authenticationAzure/trusted-signing-action@v0signtool verifybefore artifact uploadWorkflow Order
The signing steps execute after PyInstaller build but before artifact upload:
Build → Store binary → Azure login → Sign → Verify → Upload artifactAll three new steps are Windows-conditional (
env.OS_NAME == 'windows').Original prompt
💡 You can make Copilot smarter by setting up custom instructions, customizing its development environment and configuring Model Context Protocol (MCP) servers. Learn more Copilot coding agent tips in the docs.