fix(ci): publish the Tauri v2 Windows updater artifact - #48
Merged
Merged
Conversation
The beta publisher waited for a -setup.nsis.zip that Tauri v2 never produces: with createUpdaterArtifacts: true the NSIS installer is the update bundle and is signed in place. Upload and publish the installer plus its .sig instead.
Tauri v2 re-uses the installer as the update bundle, so signing it with signtool after tauri-action had already recorded the signature and the asset id left latest.json pointing at bytes that no longer match. Re-sign the installer and rewrite its manifest entry with a name-based url.
lucide-react 1.48.0, motion 13.4.3, vite 8.3.1 plus the in-range transitive refresh from bun update; hyper-util, rustls-platform-verifier and thiserror patch releases in Cargo.lock.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Why
Publish the continuous pre-releasehas been red on every push tomainsince #47 (Windows updater archive not found in artifact), so no continuous beta has shipped for two days.#47 wired in
createUpdaterArtifacts: true(Tauri v2) but looked for the artifacts the legacyv1Compatiblemode produces. Withtrue, the bundler re-uses the NSIS installer itself as the update bundle and signs it in place — there is no-setup.nsis.zip:(
tauri-bundler2.9.4,bundle.rs: Self contained updater, no need to zip; the v2 docs list-setup.exe/-setup.exe.sigas the Windows updater pair.)What
windows-betauploads*-setup.exe+*-setup.exe.sig;publish-continuousfinds and requires both (plus the macOS.sig), and passes the installer tobuild-continuous-manifest.ts..nsis.zipcomment corrected, plus a latent bug: the Authenticode step re-signed the installer after tauri-action had recorded the updater signature and the asset id, solatest.jsonwould have pointed at bytes that no longer match it. The replacement step re-runstauri signer signover the signed installer and rewrites the Windows manifest entries (signature + a name-based url, which survives the clobbered re-upload's new asset id).<platform>*manifest entries; fails loudly when nothing matches.lucide-react1.48.0,motion13.4.3,vite8.3.1 (+ in-range transitive refresh), and Cargo patch bumps (hyper-util,rustls-platform-verifier,thiserror).bun outdatedis now empty.Verification
Both workflows parse, the publish shell block passes
bash -n, and the refresh script was exercised against a fixture manifest (patcheswindows-x86_64+windows-x86_64-nsis, leavesdarwin-aarch64alone, exits non-zero when the platform is absent).Notes
glibadvisory (needs gtk 0.20 / a Tauri bump — tracked inci.yml), and Dependabot'sbunecosystem, which stays disabled until bun: support bun.lock lockfileVersion 2 and 3 dependabot/dependabot-core#16071 ships Bun 1.4 support.