More info on that GitHub thread
See link
After several back-and-forth exchanges with Microsoft Support, this is their latest response to the ticket I opened nearly two months ago:
- For the existing certificates, Artifact Signing daily renewed certs should not see the warning messages or should see reduced warning messages.
- For the new certificate, the first-time run will see the warning message; the user can upload the file via Submit a file for malware analysis - Microsoft Security Intelligence to build the reputation quicker.
This looks to me the be the intended behavior: Azure Artifact Signing will not provide instant reputation anymore (nor does any other code signing certificate).
This is a user’s report, not necessarily official info from Microsoft…