Nefarius.Tools.SignRelay.MSBuild 1.1.0

Prefix Reserved
There is a newer version of this package available.
See the version list below for details.
dotnet add package Nefarius.Tools.SignRelay.MSBuild --version 1.1.0
                    
NuGet\Install-Package Nefarius.Tools.SignRelay.MSBuild -Version 1.1.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Nefarius.Tools.SignRelay.MSBuild" Version="1.1.0">
  <PrivateAssets>all</PrivateAssets>
  <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Nefarius.Tools.SignRelay.MSBuild" Version="1.1.0" />
                    
Directory.Packages.props
<PackageReference Include="Nefarius.Tools.SignRelay.MSBuild">
  <PrivateAssets>all</PrivateAssets>
  <IncludeAssets>runtime; build; native; contentfiles; analyzers</IncludeAssets>
</PackageReference>
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Nefarius.Tools.SignRelay.MSBuild --version 1.1.0
                    
#r "nuget: Nefarius.Tools.SignRelay.MSBuild, 1.1.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Nefarius.Tools.SignRelay.MSBuild@1.1.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Nefarius.Tools.SignRelay.MSBuild&version=1.1.0
                    
Install as a Cake Addin
#tool nuget:?package=Nefarius.Tools.SignRelay.MSBuild&version=1.1.0
                    
Install as a Cake Tool

Nefarius.Tools.SignRelay.MSBuild

NuGet .NET License

MSBuild targets that call signrelay submit after Publish (opt-in). Keeps code-signing keys off the CI runner.

About

This package injects a SignRelaySign target into consuming projects. When enabled, it resolves files to sign (publish output preferred), invokes the signrelay global tool in-place, and records a stamp file so incremental builds do not re-submit.

Features

  • Opt-in via SignRelayEnabled (default false — local builds never hit the network)
  • Hooks after Publish by default (SignRelayAfterTargets)
  • Prefers $(PublishDir)$(TargetFileName), falls back to $(TargetPath)
  • Explicit <SignRelayFile> items for multi-file jobs
  • Passes the CI token via SIGN_RELAY_CI_TOKEN (not --token on the process command line)
  • Stamp-file incrementality under $(IntermediateOutputPath)

Limitations

  • Requires the Nefarius.Tools.SignRelay global tool on PATH (or SignRelayToolPath)
  • Signs in-place only (no --output directory mode from MSBuild)
  • Ordering versus Pack / archive targets is your responsibility — pack after SignRelaySign if archives must contain signed binaries
  • Does not install or update the global tool for you

Supported systems

Surface Supported
Package consume SDK-style projects restoring NuGet packages (.NET SDK 10.0.100+ recommended; package is content-only)
Host OS for MSBuild Windows, Linux, macOS (wherever dotnet publish and signrelay run)
Signing Performed by a separate Windows agent; not by this package

Install

Pin the MSBuild package and the CLI tool to the same published version:

<ItemGroup>
  <PackageReference Include="Nefarius.Tools.SignRelay.MSBuild" Version="1.0.0" PrivateAssets="all" />
</ItemGroup>
dotnet tool install --global Nefarius.Tools.SignRelay --version 1.0.0

Check NuGet / releases for the version to pin. Do not use Version="*".

Enable (CI only)

Signing is off by default so local builds never hit the network.

export SIGN_RELAY_CI_TOKEN='…'   # must match SignRelay__CiToken on the server
dotnet publish -c Release \
  /p:SignRelayEnabled=true \
  /p:SignRelayServer=https://relay.example.com

You may set /p:SignRelayToken=... instead of the environment variable; the targets still forward the value into SIGN_RELAY_CI_TOKEN for the CLI process (it is not placed on the signrelay command line).

Properties

Property Default Description
SignRelayEnabled false Master switch
SignRelayServer (required when enabled) Relay base URL
SignRelayToken $(SIGN_RELAY_CI_TOKEN) CI bearer token (env-forwarded to the CLI)
SignRelayTimeout 00:45:00 Passed to --timeout
SignRelayToolPath (resolve from PATH / ~/.dotnet/tools) Absolute path to signrelay
SignRelaySignTargetPath true When no SignRelayFile items, sign publish output then $(TargetPath)
SignRelayAfterTargets Publish Hook point

Items

<ItemGroup>
  <SignRelayFile Include="$(PublishDir)MyApp.exe" />
  <SignRelayFile Include="$(PublishDir)MyApp.dll" />
</ItemGroup>

Behavior

  • Signs in-place (signrelay submit --in-place).
  • Uses a stamp file under $(IntermediateOutputPath) so incremental builds do not re-submit after the binary was already signed.
  • Ordering versus Pack / archive targets is your responsibility — run packing after SignRelaySign if archives must contain signed binaries.

Build prerequisites (contributors)

Tool Version
.NET SDK 10.0.100 minimum (rollForward: latestFeature in repo global.json)
Git 2.40+ recommended (MinVer tags use v prefix)
git clone https://github.com/nefarius/SignRelay.git
cd SignRelay
dotnet restore SignRelay.sln
dotnet pack src/SignRelay.MSBuild/SignRelay.MSBuild.csproj -c Release -o ./artifacts/nuget

Or via NUKE: ./build.sh PackMsBuild / .\build.ps1 PackMsBuild.

Support policy

  • Use the SignRelay issue tracker for defects in these targets.
  • Operational setup (relay, tokens, agent, proxies) is out of scope — read CI-INTEGRATION.md first.
  • Incomplete reproductions may be closed.

Docs

License

MIT — Copyright (c) 2026 Benjamin Höglinger-Stelzer.

Windows, .NET, and other product names are trademarks of their respective owners. References here are for identification only.

Sources / credits

There are no supported framework assets in this package.

Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.3.0 138 9/3/2026
1.2.0 132 9/2/2026
1.1.1 136 9/2/2026
1.1.0 123 9/2/2026
1.0.0 139 9/2/2026
1.0.0-pre010 126 9/1/2026
1.0.0-pre009 133 9/1/2026
1.0.0-pre008 181 7/29/2026