Nefarius.Tools.SignRelay.MSBuild
1.0.0
Prefix Reserved
See the version list below for details.
dotnet add package Nefarius.Tools.SignRelay.MSBuild --version 1.0.0
NuGet\Install-Package Nefarius.Tools.SignRelay.MSBuild -Version 1.0.0
<PackageReference Include="Nefarius.Tools.SignRelay.MSBuild" Version="1.0.0"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
<PackageVersion Include="Nefarius.Tools.SignRelay.MSBuild" Version="1.0.0" />
<PackageReference Include="Nefarius.Tools.SignRelay.MSBuild"> <PrivateAssets>all</PrivateAssets> <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets> </PackageReference>
paket add Nefarius.Tools.SignRelay.MSBuild --version 1.0.0
#r "nuget: Nefarius.Tools.SignRelay.MSBuild, 1.0.0"
#:package Nefarius.Tools.SignRelay.MSBuild@1.0.0
#addin nuget:?package=Nefarius.Tools.SignRelay.MSBuild&version=1.0.0
#tool nuget:?package=Nefarius.Tools.SignRelay.MSBuild&version=1.0.0
Nefarius.Tools.SignRelay.MSBuild
MSBuild targets that call signrelay submit after Publish (opt-in). Keeps code-signing keys off the CI runner.
About
This package injects a SignRelaySign target into consuming projects. When enabled, it resolves files to sign (publish output preferred), invokes the signrelay global tool in-place, and records a stamp file so incremental builds do not re-submit.
Features
- Opt-in via
SignRelayEnabled(default false — local builds never hit the network) - Hooks after
Publishby default (SignRelayAfterTargets) - Prefers
$(PublishDir)$(TargetFileName), falls back to$(TargetPath) - Explicit
<SignRelayFile>items for multi-file jobs - Passes the CI token via
SIGN_RELAY_CI_TOKEN(not--tokenon the process command line) - Stamp-file incrementality under
$(IntermediateOutputPath)
Limitations
- Requires the Nefarius.Tools.SignRelay global tool on
PATH(orSignRelayToolPath) - Signs in-place only (no
--outputdirectory mode from MSBuild) - Ordering versus
Pack/ archive targets is your responsibility — pack afterSignRelaySignif archives must contain signed binaries - Does not install or update the global tool for you
Supported systems
| Surface | Supported |
|---|---|
| Package consume | SDK-style projects restoring NuGet packages (.NET SDK 10.0.100+ recommended; package is content-only) |
| Host OS for MSBuild | Windows, Linux, macOS (wherever dotnet publish and signrelay run) |
| Signing | Performed by a separate Windows agent; not by this package |
Install
Pin the MSBuild package and the CLI tool to the same published version:
<ItemGroup>
<PackageReference Include="Nefarius.Tools.SignRelay.MSBuild" Version="1.0.0" PrivateAssets="all" />
</ItemGroup>
dotnet tool install --global Nefarius.Tools.SignRelay --version 1.0.0
Check NuGet / releases for the version to pin. Do not use Version="*".
Enable (CI only)
Signing is off by default so local builds never hit the network.
export SIGN_RELAY_CI_TOKEN='…' # must match SignRelay__CiToken on the server
dotnet publish -c Release \
/p:SignRelayEnabled=true \
/p:SignRelayServer=https://relay.example.com
You may set /p:SignRelayToken=... instead of the environment variable; the targets still forward the value into SIGN_RELAY_CI_TOKEN for the CLI process (it is not placed on the signrelay command line).
Properties
| Property | Default | Description |
|---|---|---|
SignRelayEnabled |
false |
Master switch |
SignRelayServer |
(required when enabled) | Relay base URL |
SignRelayToken |
$(SIGN_RELAY_CI_TOKEN) |
CI bearer token (env-forwarded to the CLI) |
SignRelayTimeout |
00:45:00 |
Passed to --timeout |
SignRelayToolPath |
(resolve from PATH / ~/.dotnet/tools) |
Absolute path to signrelay |
SignRelaySignTargetPath |
true |
When no SignRelayFile items, sign publish output then $(TargetPath) |
SignRelayAfterTargets |
Publish |
Hook point |
Items
<ItemGroup>
<SignRelayFile Include="$(PublishDir)MyApp.exe" />
<SignRelayFile Include="$(PublishDir)MyApp.dll" />
</ItemGroup>
Behavior
- Signs in-place (
signrelay submit --in-place). - Uses a stamp file under
$(IntermediateOutputPath)so incremental builds do not re-submit after the binary was already signed. - Ordering versus
Pack/ archive targets is your responsibility — run packing afterSignRelaySignif archives must contain signed binaries.
Build prerequisites (contributors)
| Tool | Version |
|---|---|
| .NET SDK | 10.0.100 minimum (rollForward: latestFeature in repo global.json) |
| Git | 2.40+ recommended (MinVer tags use v prefix) |
git clone https://github.com/nefarius/SignRelay.git
cd SignRelay
dotnet restore SignRelay.sln
dotnet pack src/SignRelay.MSBuild/SignRelay.MSBuild.csproj -c Release -o ./artifacts/nuget
Or via NUKE: ./build.sh PackMsBuild / .\build.ps1 PackMsBuild.
Support policy
- Use the SignRelay issue tracker for defects in these targets.
- Operational setup (relay, tokens, agent, proxies) is out of scope — read CI-INTEGRATION.md first.
- Incomplete reproductions may be closed.
Docs
License
MIT — Copyright (c) 2026 Benjamin Höglinger-Stelzer.
Legal / trademark notes
Windows, .NET, and other product names are trademarks of their respective owners. References here are for identification only.
Sources / credits
- Project: nefarius/SignRelay
- Companion CLI: Nefarius.Tools.SignRelay
- Versioning: MinVer
Learn more about Target Frameworks and .NET Standard.
This package has no dependencies.
NuGet packages
This package is not used by any NuGet packages.
GitHub repositories
This package is not used by any popular GitHub repositories.
| Version | Downloads | Last Updated |
|---|---|---|
| 1.3.0 | 138 | 9/3/2026 |
| 1.2.0 | 132 | 9/2/2026 |
| 1.1.1 | 136 | 9/2/2026 |
| 1.1.0 | 123 | 9/2/2026 |
| 1.0.0 | 139 | 9/2/2026 |
| 1.0.0-pre010 | 126 | 9/1/2026 |
| 1.0.0-pre009 | 133 | 9/1/2026 |
| 1.0.0-pre008 | 181 | 7/29/2026 |