diff --git a/src/Microsoft.DotNet.SignTool/Microsoft.DotNet.SignTool.csproj b/src/Microsoft.DotNet.SignTool/Microsoft.DotNet.SignTool.csproj index a8a4139ac75..a5049856117 100644 --- a/src/Microsoft.DotNet.SignTool/Microsoft.DotNet.SignTool.csproj +++ b/src/Microsoft.DotNet.SignTool/Microsoft.DotNet.SignTool.csproj @@ -27,7 +27,7 @@ - + diff --git a/src/Microsoft.DotNet.VersionTools/lib/Microsoft.DotNet.VersionTools.csproj b/src/Microsoft.DotNet.VersionTools/lib/Microsoft.DotNet.VersionTools.csproj index ab45b2ad16c..101d83c78c7 100644 --- a/src/Microsoft.DotNet.VersionTools/lib/Microsoft.DotNet.VersionTools.csproj +++ b/src/Microsoft.DotNet.VersionTools/lib/Microsoft.DotNet.VersionTools.csproj @@ -16,7 +16,6 @@ - diff --git a/src/SignCheck/Microsoft.SignCheck/Microsoft.DotNet.SignCheckLibrary.csproj b/src/SignCheck/Microsoft.SignCheck/Microsoft.DotNet.SignCheckLibrary.csproj index 2c996e68c3a..a7fe10a34ed 100644 --- a/src/SignCheck/Microsoft.SignCheck/Microsoft.DotNet.SignCheckLibrary.csproj +++ b/src/SignCheck/Microsoft.SignCheck/Microsoft.DotNet.SignCheckLibrary.csproj @@ -18,11 +18,10 @@ - - - - - + + + + diff --git a/src/SignCheck/Microsoft.SignCheck/Verification/NupkgVerifier.cs b/src/SignCheck/Microsoft.SignCheck/Verification/NupkgVerifier.cs index db6764994be..8d676df6023 100644 --- a/src/SignCheck/Microsoft.SignCheck/Verification/NupkgVerifier.cs +++ b/src/SignCheck/Microsoft.SignCheck/Verification/NupkgVerifier.cs @@ -33,18 +33,19 @@ public override SignatureVerificationResult VerifySignature(string path, string private bool IsSigned(string path) { - IEnumerable providers = SignatureVerificationProviderFactory.GetSignatureVerificationProviders(); - var packageSignatureVerifier = new PackageSignatureVerifier(providers); - + List providers = new() + { + new IntegrityVerificationProvider(), + new SignatureTrustAndValidityVerificationProvider(), + }; var verifierSettings = SignedPackageVerifierSettings.GetVerifyCommandDefaultPolicy(); - IEnumerable verificationProviders = SignatureVerificationProviderFactory.GetSignatureVerificationProviders(); - var verifier = new PackageSignatureVerifier(verificationProviders); + var packageSignatureVerifier = new PackageSignatureVerifier(providers); using (var pr = new PackageArchiveReader(path)) { Task verifySignatureResult = packageSignatureVerifier.VerifySignaturesAsync(pr, verifierSettings, CancellationToken.None); - return verifySignatureResult.Result.Valid; + return verifySignatureResult.Result.IsValid; } } }