{"slug":"desktop-packaging-tauri","title":"desktop-packaging-tauri","summary":"Tauri 2.x bundling, code signing, auto-updater, platform installers, CI/CD","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-29T15:28:05.730495Z","repo":{"url":"https://github.com/agents-inc/skills","stars":24,"forks":8,"license":"MIT","updatedAt":"2026-09-07T17:50:55Z"},"bodyHtml":"<hr>\n<h2>name: desktop-packaging-tauri\ndescription: Tauri 2.x bundling, code signing, auto-updater, platform installers, CI/CD</h2>\n<h1>Tauri 2.x Bundling &amp; Distribution</h1>\n<blockquote>\n<p><strong>Quick Guide:</strong> Configure bundling in <code>tauri.conf.json</code> under <code>bundle</code>. Platform targets: NSIS/MSI (Windows), DMG/app bundle (macOS), deb/rpm/AppImage (Linux). Code signing is required for macOS distribution (Apple notarization) and recommended for Windows (SmartScreen). The auto-updater uses Ed25519 (Minisign) signatures -- generate keys with <code>cargo tauri signer generate</code>, set <code>TAURI_SIGNING_PRIVATE_KEY</code> at build time. Cross-platform CI uses <code>tauri-apps/tauri-action</code> with a matrix strategy. Optimize binary size with <code>[profile.release]</code> settings in <code>Cargo.toml</code>.</p>\n<p><strong>Current version:</strong> Tauri 2.x (stable). Updater artifacts use <code>createUpdaterArtifacts: true</code> (not the v1 <code>\"v1Compatible\"</code> unless migrating).</p>\n</blockquote>\n<hr>\n<p>&lt;critical_requirements&gt;</p>\n<h2>CRITICAL: Before Using This Skill</h2>\n<blockquote>\n<p><strong>All code must follow project conventions in CLAUDE.md</strong> (kebab-case, named exports, import ordering, <code>import type</code>, named constants)</p>\n</blockquote>\n<p><strong>(You MUST set <code>TAURI_SIGNING_PRIVATE_KEY</code> as an environment variable at build time for updater artifacts -- never commit the private key)</strong></p>\n<p><strong>(You MUST configure code signing for macOS distribution -- unsigned apps are blocked by Gatekeeper)</strong></p>\n<p><strong>(You MUST use <code>bundle.identifier</code> as a valid reverse-domain string -- it is used for code signing, app data paths, and store submissions)</strong></p>\n<p><strong>(You MUST build platform-specific installers on their native OS -- cross-compilation is limited to NSIS via <code>cargo-xwin</code>)</strong></p>\n<p><strong>(You MUST set <code>createUpdaterArtifacts: true</code> in <code>bundle</code> to generate <code>.sig</code> files alongside installers)</strong></p>\n<p>&lt;/critical_requirements&gt;</p>\n<hr>\n<p><strong>Auto-detection:</strong> tauri.conf.json bundle, cargo tauri build, bundle targets, NSIS, MSI, DMG, AppImage, deb, rpm, code signing, notarization, APPLE_SIGNING_IDENTITY, certificateThumbprint, tauri-plugin-updater, createUpdaterArtifacts, TAURI_SIGNING_PRIVATE_KEY, sidecar, externalBin, tauri-action, cargo tauri signer, Minisign, installer hooks</p>\n<p><strong>When to use:</strong></p>\n<ul>\n<li>Configuring <code>tauri.conf.json</code> bundle settings (targets, icons, resources, identifier)</li>\n<li>Building platform-specific installers (NSIS, MSI, DMG, deb, rpm, AppImage)</li>\n<li>Setting up macOS code signing and Apple notarization</li>\n<li>Setting up Windows code signing (OV/EV certificates, Azure Trusted Signing)</li>\n<li>Configuring the auto-updater plugin with Ed25519 signature verification</li>\n<li>Optimizing Tauri app binary size (Rust release profile, frontend bundle)</li>\n<li>Bundling sidecar binaries or extra resources</li>\n<li>Creating GitHub Actions CI/CD for cross-platform builds</li>\n<li>Customizing NSIS installers with hooks or templates</li>\n</ul>\n<p><strong>When NOT to use:</strong></p>\n<ul>\n<li>Tauri command/IPC bridge, permissions, plugins, window management (use the Tauri framework skill)</li>\n<li>Frontend framework or build tool configuration (separate skills)</li>\n<li>General Rust programming or Cargo configuration not specific to Tauri bundling</li>\n<li>Mobile distribution to App Store / Google Play (different workflow)</li>\n</ul>\n<p><strong>Key patterns covered:</strong></p>\n<ul>\n<li>Bundle configuration in <code>tauri.conf.json</code> (<a href=\"examples/core.md\">examples/core.md</a>)</li>\n<li>Platform-specific installer options (<a href=\"examples/core.md\">examples/core.md</a>)</li>\n<li>macOS code signing and notarization (<a href=\"examples/code-signing.md\">examples/code-signing.md</a>)</li>\n<li>Windows code signing (<a href=\"examples/code-signing.md\">examples/code-signing.md</a>)</li>\n<li>Auto-updater setup with Ed25519 signatures (<a href=\"examples/updater.md\">examples/updater.md</a>)</li>\n<li>Binary size optimization (<a href=\"examples/core.md\">examples/core.md</a>)</li>\n<li>Sidecar binaries and resources (<a href=\"examples/core.md\">examples/core.md</a>)</li>\n<li>GitHub Actions cross-platform CI/CD (<a href=\"examples/ci-cd.md\">examples/ci-cd.md</a>)</li>\n<li>NSIS installer hooks and customization (<a href=\"examples/core.md\">examples/core.md</a>)</li>\n</ul>\n<p><strong>Detailed resources:</strong></p>\n<ul>\n<li><a href=\"examples/core.md\">examples/core.md</a> - Bundle config, platform targets, size optimization, sidecars, NSIS hooks</li>\n<li><a href=\"examples/code-signing.md\">examples/code-signing.md</a> - macOS notarization, Windows signing, CI/CD signing setup</li>\n<li><a href=\"examples/updater.md\">examples/updater.md</a> - Auto-updater plugin, key generation, endpoint format, JS/Rust usage</li>\n<li><a href=\"examples/ci-cd.md\">examples/ci-cd.md</a> - GitHub Actions workflow, matrix strategy, secrets</li>\n<li><a href=\"reference.md\">reference.md</a> - Bundle config field reference, CLI commands, platform target table</li>\n</ul>\n<hr>\n\n<hr>\n\n<hr>\n<p>&lt;decision_framework&gt;</p>\n<h2>Decision Framework</h2>\n<h3>Which Installer Format?</h3>\n<pre><code>Target platform?\n|-- Windows\n|   +-- Need MSI for enterprise deployment? -&gt; msi (WiX, Windows-only build)\n|   +-- General distribution? -&gt; nsis (recommended, cross-compilable)\n|-- macOS\n|   +-- App Store? -&gt; app bundle + App Store signing\n|   +-- Direct download? -&gt; dmg + Developer ID + notarization\n|-- Linux\n|   +-- Targeting Debian/Ubuntu? -&gt; deb\n|   +-- Targeting Fedora/RHEL? -&gt; rpm\n|   +-- Maximum portability? -&gt; appimage (larger, ~70+ MB)\n|   +-- Sandboxed distribution? -&gt; snap or flatpak (manual setup)\n+-- All platforms? -&gt; Use \"all\" target with CI matrix\n</code></pre>\n<h3>Code Signing Decision</h3>\n<pre><code>Distributing publicly?\n|-- macOS\n|   +-- App Store? -&gt; Apple Distribution certificate\n|   +-- Direct download? -&gt; Developer ID Application + notarization (REQUIRED)\n|   +-- Internal/testing only? -&gt; Ad-hoc signing (signingIdentity: \"-\")\n|-- Windows\n|   +-- Microsoft Store? -&gt; Store signing\n|   +-- Direct download? -&gt; OV or EV certificate (prevents SmartScreen warnings)\n|   +-- Internal only? -&gt; Optional but recommended\n+-- Linux\n    +-- Code signing is not required for Linux distribution\n</code></pre>\n<h3>Updater Strategy</h3>\n<pre><code>Need auto-updates?\n|-- YES -&gt; tauri-plugin-updater\n|   +-- Simple static hosting? -&gt; Static JSON endpoint (GitHub Releases, S3)\n|   +-- Dynamic update logic? -&gt; Dynamic endpoint (returns 200/204)\n|   +-- Need update UI? -&gt; JS-side check() + downloadAndInstall()\n|   +-- Background updates? -&gt; Rust-side updater with AppHandle\n+-- NO -&gt; Skip updater config, omit createUpdaterArtifacts\n</code></pre>\n<p>&lt;/decision_framework&gt;</p>\n<hr>\n<p>&lt;red_flags&gt;</p>\n<h2>RED FLAGS</h2>\n<p><strong>High Priority Issues:</strong></p>\n<ul>\n<li>Committing <code>TAURI_SIGNING_PRIVATE_KEY</code> to source control -- store as CI secret, never in repo</li>\n<li>Missing <code>createUpdaterArtifacts: true</code> when using the updater -- no <code>.sig</code> files generated, updates fail</li>\n<li>Building macOS installer on Linux/Windows -- cross-compilation not supported for DMG/app bundle</li>\n<li>Using <code>\"targets\": \"all\"</code> in CI without a matrix strategy -- builds all formats for the current OS only</li>\n<li>Missing <code>bundle.identifier</code> or using an invalid format -- breaks code signing, app data paths, and store submissions</li>\n<li>Distributing unsigned macOS app -- Gatekeeper blocks it, users cannot open it</li>\n</ul>\n<p><strong>Medium Priority Issues:</strong></p>\n<ul>\n<li>AppImage on Ubuntu 22.04+ targeting older distros -- higher glibc requirement breaks compatibility</li>\n<li>Missing <code>strip = true</code> in release profile -- debug symbols inflate binary by 10-20%</li>\n<li>Using <code>opt-level = 3</code> instead of <code>\"s\"</code> or <code>\"z\"</code> when binary size matters -- optimizes for speed, not size</li>\n<li>WebView2 <code>skip</code> install mode without guarantee runtime is present -- app crashes on startup</li>\n<li>NSIS <code>perUser</code> mode when app needs system-wide installation -- installs to <code>%LOCALAPPDATA%</code>, not Program Files</li>\n</ul>\n<p><strong>Gotchas &amp; Edge Cases:</strong></p>\n<ul>\n<li><code>opt-level = \"s\"</code> vs <code>\"z\"</code> -- sometimes <code>\"z\"</code> produces smaller binaries, sometimes <code>\"s\"</code> does. Test both.</li>\n<li>macOS ad-hoc signing (<code>signingIdentity: \"-\"</code>) still triggers Gatekeeper warnings -- only useful for development</li>\n<li>NSIS is the only format supporting cross-compilation from Linux/macOS to Windows (via <code>cargo-xwin</code>)</li>\n<li>Sidecar binary filenames must include the Rust target triple suffix -- Tauri resolves the correct one at runtime</li>\n<li>Updater endpoint template variables (<code>{{target}}</code>, <code>{{arch}}</code>, <code>{{current_version}}</code>) are Tauri-specific, not environment variables</li>\n<li>AppImage bundles are ~70+ MB because they include all dependencies -- deb/rpm are 2-6 MB but require system packages</li>\n<li>Windows WebView2 runtime is bundled by default with <code>embedBootstrapper</code> -- older <code>downloadBootstrapper</code> mode requires internet at install time</li>\n<li>Snap/Flatpak packages run in a sandbox -- DBus communication is blocked unless declared in the manifest</li>\n<li><code>removeUnusedCommands: true</code> (Tauri 2.4+) strips commands not in capability files -- ensure all needed commands are listed in ACL</li>\n<li>Free Apple Developer accounts cannot notarize apps -- a paid $99/year account is required for distribution</li>\n</ul>\n<p>&lt;/red_flags&gt;</p>\n<hr>\n<p>&lt;critical_reminders&gt;</p>\n<h2>CRITICAL REMINDERS</h2>\n<blockquote>\n<p><strong>All code must follow project conventions in CLAUDE.md</strong> (kebab-case, named exports, import ordering, <code>import type</code>, named constants)</p>\n</blockquote>\n<p><strong>(You MUST set <code>TAURI_SIGNING_PRIVATE_KEY</code> as an environment variable at build time for updater artifacts -- never commit the private key)</strong></p>\n<p><strong>(You MUST configure code signing for macOS distribution -- unsigned apps are blocked by Gatekeeper)</strong></p>\n<p><strong>(You MUST use <code>bundle.identifier</code> as a valid reverse-domain string -- it is used for code signing, app data paths, and store submissions)</strong></p>\n<p><strong>(You MUST build platform-specific installers on their native OS -- cross-compilation is limited to NSIS via <code>cargo-xwin</code>)</strong></p>\n<p><strong>(You MUST set <code>createUpdaterArtifacts: true</code> in <code>bundle</code> to generate <code>.sig</code> files alongside installers)</strong></p>\n<p><strong>Failure to follow these rules will produce unsigned binaries, missing update signatures, or broken cross-platform builds.</strong></p>\n<p>&lt;/critical_reminders&gt;</p>\n","files":[{"path":"examples/ci-cd.md","sizeBytes":7845,"isText":true},{"path":"examples/code-signing.md","sizeBytes":6370,"isText":true},{"path":"examples/core.md","sizeBytes":9560,"isText":true},{"path":"examples/updater.md","sizeBytes":8589,"isText":true},{"path":"reference.md","sizeBytes":9257,"isText":true},{"path":"SKILL.md","sizeBytes":16920,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"notes-only","suspicious":0,"notes":12,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-29T15:30:01.08698Z","sha256":"2282E637577C1308917B8A6329203F27F2A28EED72E76075259C2C382E8B8629","sizeBytes":21792},"review":null,"source":{"repositoryUrl":"https://github.com/agents-inc/skills","path":"dist/plugins/desktop-packaging-tauri/skills/desktop-packaging-tauri","license":"MIT","commit":"3a51ef571e996b18294bf776d53dbdad26de0617","subtreeSha":"D3C8CE63017EBFC6079725DAAF74B165D31C56F31B398B6D904C287DC6CE1897","lastSyncedAt":"2026-09-29T15:27:48.914434Z"},"reviewedAt":"2026-09-29T15:34:27.058863Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/agents-inc/skills/tree/main/dist/plugins/desktop-packaging-tauri/skills/desktop-packaging-tauri"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install agents-inc-skills@llmmart"},{"target":"git","command":"git clone https://github.com/agents-inc/skills.git"}]}