Skip to content

Document application identity for native apphost - #56353

Open
hoyosjs wants to merge 3 commits into
mainfrom
hoyosjs-patch-1
Open

hoyosjs wants to merge 3 commits into
mainfrom
hoyosjs-patch-1

Conversation

@hoyosjs

@hoyosjs hoyosjs commented Oct 9, 2026 •

Copy link
Copy Markdown
Member

Added section on application identity for apphost executable - include guidance for signing identity implications.


Internal previews

File Preview link
docs/core/deploying/macos.md Learn preview

Build report

Added section on application identity for apphost executable.
@hoyosjs
hoyosjs requested review from a team and adegeo as code owners October 9, 2026 22:22
Copilot AI balanced review requested due to automatic review settings October 9, 2026 22:22
@dotnetrepoman dotnetrepoman Bot added this to the October 2026 milestone Oct 9, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new heading misnests entitlement sections, and the added content has signing terminology and Markdown validation issues.

4 open findings
What changed in this PR

Documents macOS apphost identity and signing considerations for Keychain approvals and management policies.

Changes:

  • Recommends launching the native apphost.
  • Explains stable signing identities across releases.
  • Links to Apple signing guidance.
File Description
docs/​core/​deploying/​macos.md Adds application identity guidance for macOS apphosts.

🧠 Review effort: Balanced


💡 Add a code-review agent skill for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/core/deploying/macos.md Outdated
Comment thread docs/core/deploying/macos.md Outdated
Comment thread docs/core/deploying/macos.md Outdated
Comment thread docs/core/deploying/macos.md
Use [Apple's developer documentation](https://developer.apple.com/documentation/security/notarizing_macos_software_before_distribution) to sign and notarize the app native binaries. .NET creates a native *apphost* executable as the entry point for your app. This apphost must be signed and, if your app uses special capabilities, it must be assigned the appropriate **entitlements**.

### Application identity

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This falls into the "don't do this" + unsupported category. We also shouldn't write an tests that validate the behavior.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants