Skip to content

fix(ci): publish the Tauri v2 Windows updater artifact - #48

Merged
0libote merged 3 commits into
mainfrom
fix/beta-publish-v2-updater-artifacts
Sep 25, 2026
Merged

0libote merged 3 commits into
mainfrom
fix/beta-publish-v2-updater-artifacts

Conversation

@0libote

@0libote 0libote commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Why

Publish the continuous pre-release has been red on every push to main since #47 (Windows updater archive not found in artifact), so no continuous beta has shipped for two days.

#47 wired in createUpdaterArtifacts: true (Tauri v2) but looked for the artifacts the legacy v1Compatible mode produces. With true, the bundler re-uses the NSIS installer itself as the update bundle and signs it in place — there is no -setup.nsis.zip:

bundle\nsis\Kivo_0.1.0_x64-setup.exe
bundle\nsis\Kivo_0.1.0_x64-setup.exe.sig

(tauri-bundler 2.9.4, bundle.rs: Self contained updater, no need to zip; the v2 docs list -setup.exe / -setup.exe.sig as the Windows updater pair.)

What

  • ci.yml — windows-beta uploads *-setup.exe + *-setup.exe.sig; publish-continuous finds and requires both (plus the macOS .sig), and passes the installer to build-continuous-manifest.ts.
  • release.yml — same stale .nsis.zip comment corrected, plus a latent bug: the Authenticode step re-signed the installer after tauri-action had recorded the updater signature and the asset id, so latest.json would have pointed at bytes that no longer match it. The replacement step re-runs tauri signer sign over the signed installer and rewrites the Windows manifest entries (signature + a name-based url, which survives the clobbered re-upload's new asset id).
  • scripts/refresh-updater-signature.ts — pure, locally tested rewrite of <platform>* manifest entries; fails loudly when nothing matches.
  • deps — lucide-react 1.48.0, motion 13.4.3, vite 8.3.1 (+ in-range transitive refresh), and Cargo patch bumps (hyper-util, rustls-platform-verifier, thiserror). bun outdated is now empty.

Verification

bun run check      # typecheck, Biome, Oxlint, Knip, theme, tests, bridge/packaging/parity gates
bun test:ui        # 24 Playwright tests
bun run build
bun check:rust && cargo clippy --locked --all-targets -- -D warnings && cargo test --locked   # 121 tests

Both workflows parse, the publish shell block passes bash -n, and the refresh script was exercised against a fixture manifest (patches windows-x86_64 + windows-x86_64-nsis, leaves darwin-aarch64 alone, exits non-zero when the platform is absent).

Notes

The beta publisher waited for a -setup.nsis.zip that Tauri v2 never
produces: with createUpdaterArtifacts: true the NSIS installer is the
update bundle and is signed in place. Upload and publish the installer
plus its .sig instead.
Tauri v2 re-uses the installer as the update bundle, so signing it with
signtool after tauri-action had already recorded the signature and the
asset id left latest.json pointing at bytes that no longer match. Re-sign
the installer and rewrite its manifest entry with a name-based url.
lucide-react 1.48.0, motion 13.4.3, vite 8.3.1 plus the in-range
transitive refresh from bun update; hyper-util, rustls-platform-verifier
and thiserror patch releases in Cargo.lock.
@sonarqubecloud

Copy link
Copy Markdown

@0libote
0libote merged commit 30bb9e8 into main Sep 25, 2026
21 of 22 checks passed
@0libote
0libote deleted the fix/beta-publish-v2-updater-artifacts branch September 25, 2026 00:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant