Feature: Add post-build Authenticode signing support for --compile -t exe
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 35/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Tranquilo
- Stack tecnológico
- csharp, typescript
- Área
- build-system, ci-cd, cli, documentation, security
Línea de trabajo
Start with the --compile -t exe CLI entry point and trace how ManualBundler and SdkBundler hand the final executable to PEPacker. Define the cross-platform signing-tool flow and error handling, then update docs/antivirus-false-positives.md and the README; done means signed executables verify successfully, failures are actionable and non-zero, and CI covers a test certificate.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Motivation
Compiled single-file executables (sharpts --compile script.ts -t exe) are unsigned and get flagged by behavioral AV engines as suspected packers/droppers — see #4 (WithSecure DeepGuard quarantines the output as W32/Malware!DeepGuard.n).
This pattern is intrinsic to the apphost-plus-appended-bundle format that both our ManualBundler and the SdkBundler (Microsoft's HostWriter) produce. Rewriting the bundler does not fix it — a differently-shaped unsigned bundle is still an unsigned bundle. Authenticode signing is the real long-term mitigation: once the signing cert earns some reputation, heuristic flags largely stop firing.
Proposed behavior
Add post-build signing as an opt-in step after bundling, for -t exe output only.
CLI surface (rough sketch, open to revision):
sharpts --compile script.ts -t exe \
--sign <path-to-pfx-or-cert-thumbprint> \
[--sign-pass <password>] \
[--sign-timestamp <rfc3161-url>] \
[--sign-digest sha256]
--signaccepts either a.pfxpath or a certificate store thumbprint (sha1:ABCD...). Default digestsha256. Default timestamp server is the DigiCert RFC3161 endpoint; overridable.- Password can also come from
SHARPTS_SIGN_PASSenv var to keep it out of shell history. - Signing runs after the bundler produces the final
.exe. On failure, the.exeremains on disk unsigned and the tool exits non-zero with a clear error.
Implementation notes
- On Windows, shell out to
signtool.exeif it is onPATHor resolvable from a Windows SDK install. Fallback toSignToolfrom the .NET SDK if present. - On Linux/macOS, shell out to
osslsigncodeif available; otherwise emit a clear error saying the platform needsosslsigncodeinstalled and point at install instructions. - Keep the signing logic in
PEPacker(separate repo/package) alongside the bundling code, so the--signflag is thin glue in SharpTS. - The apphost is already signed by Microsoft when shipped in the SDK; our byte-patching invalidates that signature, which is expected. Our re-signing replaces it.
Out of scope for this issue
- EV / OV certificate procurement guidance — covered in a separate docs issue.
- Authenticode signing for DLL output (
-t dll) — possible, but drop-indotnet script.dllexecution does not really need it. Can be a follow-up.
Docs work
- Add
docs/antivirus-false-positives.mdexplaining why single-file .NET outputs trigger behavioral AV and pointing to--signas the fix. - README section on
--signwith a worked example (self-test with a self-signed cert on a dev machine; production example with a real code-signing cert).
Acceptance criteria
sharpts --compile hello.ts -t exe --sign test.pfx --sign-pass ...produces an.exethatsigntool verify /pa /v hello.exereports asSuccessfully verified.- On sign failure (bad password, expired cert, missing
signtool), the tool prints an actionable error and exits non-zero. - CI gains a test that produces a signed exe with a self-generated test cert and verifies the signature. Cross-platform via
osslsigncodeif feasible.
Related
- #4 — WithSecure / F-Secure DeepGuard false-positive on compiled exe. Signing does not guarantee the FP goes away on day one (cert reputation needs to accrue) but is the recognized long-term path.
- Lenguaje dominante
- C#
- Estrellas
- 156
- Forks
- 4
- Merge medio
- 2 h 30 min
- PR fusionados (30 d)
- 179
Preparar el entorno
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de nickna/SharpTS
-
deferred enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 25/100
nickna/SharpTS#1405 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
deferred enhancement epic
Dificultad 5/5 Más de una semana Aptitud para principiantes 15/100
nickna/SharpTS#1400 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
deferred enhancement
Dificultad 5/5 Más de una semana Aptitud para principiantes 30/100
Los mantenedores suelen responder en 1 día
-
Publish managed and Native AOT variants through HomebrewQuizá libre de nuevo @nickna la tomó hace 64 días y no hay ningún pull request abierto. Abierto
nickna/SharpTS#1357 · 1 asignado ·
Los mantenedores suelen responder en 1 día
-
Publish managed and Native AOT variants through WinGetQuizá libre de nuevo @nickna la tomó hace 64 días y no hay ningún pull request abierto. Abierto
nickna/SharpTS#1356 · 1 asignado ·
Los mantenedores suelen responder en 1 día
Todos los issues de nickna/SharpTS
Issues similares
-
type/automation type/tech-debt
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
Los mantenedores suelen responder en 1 día
-
[Tool] DirectBenchAbiertohas-image has-readme needs-attention new-tool repo-verified
Dificultad 1/5 1-3 horas Aptitud para principiantes 62/100
shanselman/TinyToolTown#844 · 2 comentarios ·
Los mantenedores suelen responder en 3 días
-
StoreImmediately test is flaky and fails on Linux and macOSPosiblemente ocupada @jcannon98188 la tomó hoy. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
-
area:frontend FE P3
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
klasolsson81/jobbliggaren#2067 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
grame-cncm/faust#1344 · 1 comentario ·
Los mantenedores suelen responder en 1 día