You don't even need signing for Microsoft's system to do what it does - it can operate on unsigned code, it's all hash based.
You don't even need signing for Microsoft's system to do what it does - it can operate on unsigned code, it's all hash based.
Or really any reason. They're not supposed to exert editorial control but that's how it has been happening in practice.
Is there a concrete example of this? We know this isn't blanket policy, because of a recent story (https://news.ycombinator.com/item?id=45376977) that contradicts it. I can't find a reference to any macOS app failing notarization due to API calls.
So in other words, using private APIs in and of itself isn't an issue. Neither is it an issue if your application is one that serves up adult content, or is an alternate App Store, or anything else that Apple might reject from its own App Store for policy reasons. It's basically doing what you might expect a virus scanner to do.