Skip to content

feat: add safe signed desktop updates - #87

Merged
kev1n77 merged 2 commits into
mainfrom
codex/desktop-updater
Jul 21, 2026
Merged

kev1n77 merged 2 commits into
mainfrom
codex/desktop-updater

Conversation

@kev1n77

@kev1n77 kev1n77 commented Jul 21, 2026

Copy link
Copy Markdown
Owner

Summary

  • add a backend-controlled Tauri updater that accepts only a compile-time trusted public key and the fixed HTTPS GitHub Release endpoint
  • recheck the selected version, restore managed proxy settings, return capture to Gateway, and create a restorable SQLCipher snapshot before installation
  • add an Updates settings view with availability, release notes, download progress, fail-closed unconfigured state, and minimum-window coverage
  • document release signing inputs and update SEC-004 / REL-001 progress

Verification

  • npm run desktop:check (46 tests)
  • npm run desktop:build
  • npx playwright test --config apps/desktop/playwright.config.ts -g "signed update controls"
  • python scripts/verify_supply_chain.py
  • python -m unittest discover -s scripts/tests -v
  • cargo fmt --all -- --check
  • cargo fmt --manifest-path apps/desktop/src-tauri/Cargo.toml -- --check
  • cargo metadata --manifest-path apps/desktop/src-tauri/Cargo.toml --no-deps --format-version 1

Full native tests are delegated to CI because the local vendored OpenSSL build requires Perl modules not present in the workstation Git distribution.

@kev1n77
kev1n77 merged commit 474071d into main Jul 21, 2026
10 checks passed
@kev1n77
kev1n77 deleted the codex/desktop-updater branch July 21, 2026 09:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant