diff --git a/tools/devops/automation/templates/build/sign-and-notarized.yml b/tools/devops/automation/templates/build/sign-and-notarized.yml index de458c9ac961..01270391c473 100644 --- a/tools/devops/automation/templates/build/sign-and-notarized.yml +++ b/tools/devops/automation/templates/build/sign-and-notarized.yml @@ -153,3 +153,11 @@ steps: - pwsh: $(Build.SourcesDirectory)/release-scripts/notarize.ps1 -FolderForApps $(Build.SourcesDirectory)/package/notarized displayName: 'ESRP notarizing packages' + +- pwsh: | + $notarizedRoot = $(Build.SourcesDirectory)/package/notarized + Get-ChildItem -Path $notarizedRoot -Filter *.pkg -Recurse -File | ForEach-Object { + Write-Host "pkgutil --check-signature $($_.FullName)" + pkgutil --check-signature $_.FullName + } + displayName: 'Verify ESRP notarization'