Decky/app/UPDATES.md

2.8 KiB

Installer and signed updates

Decky is distributed on Windows as a per-user Tauri NSIS installer. Installed copies update from signed Forgejo release assets; they never run git pull.

Trust model

Two signing systems are independent:

  • The Tauri updater signature is mandatory. It proves an update was made with Decky's updater private key before the installer is executed.
  • Windows Authenticode signing is optional but recommended for wider distribution because it reduces SmartScreen warnings. It requires a separate code-signing certificate and is not configured yet.

Decky's permanent updater key is stored outside the repository:

%USERPROFILE%\.tauri\decky.key
%USERPROFILE%\.tauri\decky.key.password

Back up both files securely. Never regenerate this key after shipping: existing installations would reject every artifact signed by a replacement key.

Forgejo layout

The installed app checks this stable, public HTTPS URL:

https://git.elijahkuntz.com/Elijah/Decky/raw/branch/main/releases/latest.json

releases/latest.json contains the newest semantic version, release notes, versioned installer URL, and the contents of its .sig file. Installer assets are attached to immutable Forgejo releases such as v0.2.0.

The repository and release assets must be readable without authentication. Tauri cannot attach the user's Forgejo credentials to an updater request.

Preparing a release locally

Keep all three version fields synchronized with Set-Version.ps1, commit the release, and tag that exact commit:

powershell -ExecutionPolicy Bypass -File .\scripts\Set-Version.ps1 -Version 0.2.1
powershell -ExecutionPolicy Bypass -File .\scripts\Prepare-Release.ps1 -Version 0.2.1 -Notes "Release notes"
git tag v0.2.1
git push origin main v0.2.1

The preparation script runs dependency installation, validation, tests, the Tauri build, and creates:

artifacts/release/v0.2.1/
  Decky_0.2.1_x64-setup.exe
  Decky_0.2.1_x64-setup.exe.sig
  latest.json

To publish manually, set FORGEJO_TOKEN only in the current process and run:

powershell -ExecutionPolicy Bypass -File .\scripts\Publish-ForgejoRelease.ps1 -Version 0.2.1 -Notes "Release notes"

The publisher creates the Forgejo release, uploads all three assets, and updates the tracked releases/latest.json through the Forgejo API.

Forgejo Actions

.forgejo/workflows/release.yml performs the same process when a v* tag is pushed. Configure a trusted Windows runner whose label matches windows-latest, then add these repository secrets:

  • TAURI_SIGNING_PRIVATE_KEY: contents of decky.key
  • TAURI_SIGNING_PRIVATE_KEY_PASSWORD: contents of decky.key.password

The short-lived ${{ forgejo.token }} publishes only to this repository. The workflow intentionally runs only for trusted tags, never pull requests.