Applications and updates · GraphQL type

ApplicationSignature type

Code-signing verification state of an ApplicationInstall, evaluated on the endpoint by the platform's native verifier. Reference: Code Signing Services Reference: WinVerifyTrust function (wintrust.h)

Fields

Field Name Description
status - ApplicationSignatureStatus! Outcome of the signature verification. See ApplicationSignatureStatus for the meaning of each value.
signer - String! Human-readable signer identity: the organization of the leaf signing certificate (macOS Developer ID / Windows Authenticode subject), or the snap store publisher on Linux. Empty when the application is unsigned, ad-hoc signed, or the signer could not be determined.
thumbprint - String! Lowercase hex SHA-256 fingerprint of the DER-encoded leaf signing certificate. Currently reported on macOS only; empty when no certificate chain is available (unsigned or ad-hoc signed) and on other platforms.
teamIdentifier - String! Apple Developer Program Team ID of the signing identity (macOS only). Empty on other platforms and for unsigned or ad-hoc signed applications.
signedAt - Time Secure timestamp embedded in the signature (macOS secure timestamp / Authenticode countersignature). Null when the signature carries no timestamp or the application is unsigned.

Used by

Example

Example

{
  "status": "UNKNOWN",
  "signer": "abc123",
  "thumbprint": "abc123",
  "teamIdentifier": "xyz789",
  "signedAt": "2021-10-07T18:23:25.829Z"
}