Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

signingscript: sign_authenticode_file can't check if MSIX is already signed

未关闭
#376 0 条评论 1 个 reaction 已指派 0 人 在 GitHub 查看

维护者通常 1 天内回复

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
功能
描述清晰度
基本清楚
活跃度
停滞
技术栈
python
领域
security, tooling

调研方向

从 signingscript/src/signingscript/sign.py 大约第 1290 行开始,然后检查 winsign.osslsigncode.is_signed() 和 winsign.makemsix 模块。完成标准是签名检查能够区分已签名的 PE/MSI 文件和 MSIX 文件,并使用相应的 winsign 路径。

由索引模型根据 Issue 内容生成。

描述

signingscript

Since https://github.com/mozilla-releng/winsign/pull/23 , winsign supports signing MSIX files with makemsix. signingscript checks whether a file is already signed with winsign.osslsigncode.is_signed(), which is not effective with the Zip-based MSIX. winsign should probably expose a generic is_signed() function that can check PE/MSI via winsign.osslsigncode.is_signed() or MSIX via winsign.makemsix.is_signed() (which does not yet exist).

osslsigncode just can't make sense of the file, is_signed() always returns False, so I don't think this causes any issues.

主要语言
Python
星标
16
派生
38
平均合并
1 天 3 小时
30 天内合并 PR
17

环境准备

我们还没有检查这个项目的环境配置文件。先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

mozilla-releng/scriptworker-scripts 的其他 Issue

查看 mozilla-releng/scriptworker-scripts 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。