Add extension signature verification service#162285
Merged
Merged
Conversation
- support verifying signed extension in remote when downloading locally
Member
|
@dtivel Went through the PR and updated with following changes
Can you please test if the feature is working with new changes? Once confirmed, I will merge changes to main. |
sandy081
previously approved these changes
Oct 11, 2022
Member
Author
|
@sandy081, I pushed 1 commit for a bug I found. Otherwise, the latest changes look good. Thanks so much for your review and for putting the PR in good shape. |
sandy081
approved these changes
Oct 18, 2022
lramos15
approved these changes
Oct 18, 2022
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Progress on #162284.
This change adds a new service (
IExtensionSignatureVerificationService) which will verify signed extensions installed from Visual Studio Marketplace. Unsigned extensions will skip verification. The actual signature verification engine is not included in this PR. Verification is behind a feature flag, which is disabled by default.This change also modifies existing install/update telemetry to include:
isSigned: a boolean value indicating whether or not the extension is signedwasVerified: a boolean value indicating whether or not signature verification succeedederrorcodeDetails: a string value indicating the signature verification error, if availableCC @isidorn, @joaomoreno, @sandy081