Skip to content

Give the updater a public key to check signatures against - #4

Merged
thorstenalpers merged 1 commit into
mainfrom
feat/updater-pubkey
Aug 31, 2026
Merged

Give the updater a public key to check signatures against#4
thorstenalpers merged 1 commit into
mainfrom
feat/updater-pubkey

Conversation

@thorstenalpers

Copy link
Copy Markdown
Owner

Fills in plugins.updater.pubkey, which has been an empty placeholder since the updater was wired up. Without it a signed installer still ships an app that verifies nothing it downloads — which is the whole point of signing one.

The value is the content of openeventviewer.key.pub verbatim, the same form the other Tauri projects on this machine use.

.gitignore gains *.key

npx tauri signer generate -w openeventviewer.key writes the private half into the working directory. It landed in this repository's root, this repository is public, and one git add -A was the entire distance between those two facts. It was never staged and never reached the history — checked — but the guard belongs here regardless.

Still to do, outside this PR

The private half has to become the secret TAURI_SIGNING_PRIVATE_KEY. Until it does, the release stops at the preflight added in #3 rather than after a six-minute build.

🤖 Generated with Claude Code

The placeholder left when the updater was wired up. Without it a signed
installer would still ship an app that verifies nothing it downloads,
which is the whole point of signing one.

`.gitignore` gains the keys as well. The command the documentation gives
writes the private half into the working directory, this repository is
public, and one `git add -A` is the entire distance between those two
facts.
@thorstenalpers
thorstenalpers merged commit 1e48cfa into main Aug 31, 2026
2 checks passed
@thorstenalpers
thorstenalpers deleted the feat/updater-pubkey branch August 31, 2026 14:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant