Jauto publishes Windows x64 and universal macOS installers from .github/workflows/desktop-release.yml. A release is created only after dependency audit, lint, tests, type checks, web and desktop frontend builds, native builds, installer smoke tests, and all applicable signature checks succeed.
WINDOWS_CERTIFICATE: base64-encoded PFX Authenticode certificate.WINDOWS_CERTIFICATE_PASSWORD: PFX password.APPLE_CERTIFICATE: base64-encoded Developer ID Application PKCS#12 certificate.APPLE_CERTIFICATE_PASSWORD: PKCS#12 and temporary keychain password.APPLE_SIGNING_IDENTITY: full Developer ID Application identity.APPLE_ID: Apple developer account email.APPLE_PASSWORD: app-specific Apple ID password.APPLE_TEAM_ID: Apple Developer team identifier.
If all Windows credentials are configured, the Windows installers are Authenticode-signed. If all Apple credentials are configured, the macOS application is Developer ID-signed and notarized. Without credentials, the workflow publishes unsigned Windows installers and an ad-hoc signed macOS installer. A partially configured credential set is rejected to avoid silently producing an incorrectly signed release. Secrets are read only by the release workflow and are never available to pull-request jobs.
- Update every version together.
pnpm check:release-versionverifies the root, workspace packages, Tauri configuration, and Cargo package. - Update
CHANGELOG.mdand.github/release-notes/desktop.md. - Run
pnpm install --frozen-lockfile,pnpm audit --prod --audit-level moderate,pnpm lint,pnpm test, andpnpm typecheck. - Merge the release commit into
master, or run Desktop release manually. - Confirm the release contains
.msiand.exeinstallers, a.dmg, andSHA256SUMS.txt.
The release tag is configured in the workflow. Signing and notarization are applied automatically when the complete platform credential set is available.