Agent skill

Tauri Updater

by luochang212 in luochang212/skill-zoo

A skill your agent uses when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable…

MITAuto-check passed

Install Tauri Updater

skills CLI
$ npx skills add luochang212/skill-zoo --skill tauri-updater -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install luochang212/skill-zoo tauri-updater --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/luochang212/skill-zoo.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tauri-updater .claude/skills/tauri-updater && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
tauri-updater
GitHub stars
117
Token cost
~2.7k tokens
SKILL.md length
715 words
Files
1
Skills in repo
4
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable…

  • Works in 5 steps: Generate Signing Key (one-time) → Rust Backend → Tauri Configuration → …
  • Adding software auto-update to a Tauri 2 desktop app
  • SKILL.md covers Overview, When to Use, Architecture and Implementation Steps, plus 2 more sections
  • Calls bun and cargo; reaches github.com and api.github.com; needs TAURI_SIGNING_PRIVATE_KEY and TAURI_SIGNING_PRIVATE_KEY_PASSWORD

What it does

Tauri Updater is an agent skill from luochang212/skill-zoo. Use when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable builds for updates, or generating update manifests for GitHub Releases.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Tauri, GitHub and Rust. The repository describes itself as: All-in-One Desktop Agent Skills Utility. Welcome to the Skill Zoo, where all your skills live! The licence is MIT.

When your agent uses it

  • Adding software auto-update to a Tauri 2 desktop app
  • Users ask about tauri-plugin-updater integration
  • App update checking
  • Distinguishing installer vs portable builds for updates

Example prompts

  • “/tauri-updater”

Requirements

  • A credential in TAURI_SIGNING_PRIVATE_KEY

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Generate Signing Key (one-time)
  2. Rust Backend
  3. Tauri Configuration
  4. Frontend
  5. CI Pipeline

What it can do on your machine

Read from SKILL.md and the folder at commit 1c7afa6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun
    • cargo

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • api.github.com
    • objects.githubusercontent.com
    • github-releases.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • TAURI_SIGNING_PRIVATE_KEY
    • TAURI_SIGNING_PRIVATE_KEY_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Tauri Updater loads about 2.7k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 715 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from luochang212/skill-zoo at commit 1c7afa6, republished under its MIT licence (© luochang212). 715 words, ~2,657 tokens.

Download SKILL.mdSave it as .claude/skills/tauri-updater/SKILL.md (or your agent's skills folder).
name
tauri-updater
description
Use when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable builds for updates, or generating update manifests for GitHub Releases.

Tauri Updater

Overview

Add self-update to a Tauri 2 desktop app using tauri-plugin-updater. Covers macOS DMG, Windows NSIS (auto-install), and Windows portable (manual download link). Uses a GitHub Releases-hosted latest.json manifest with signed artifacts.

When to Use

  • User asks to add "auto-update", "software update", "check for updates" to a Tauri app
  • User asks about tauri-plugin-updater integration
  • User wants to distinguish installer vs portable builds for update behavior
  • User needs to generate update manifests for CI

Don't use for:

  • Tauri 1.x apps (different updater API)
  • Mobile apps (different update mechanisms)
  • Apps distributed only via app stores (use store update mechanisms)

Architecture

Installer vs Portable

Tauri updater only works with installers (NSIS, MSI, DMG). Portable builds need a different path.

BuildUpdate methodImplementation
macOS DMGAuto-download + installtauri-plugin-updater full flow
Windows NSISAuto-download + installtauri-plugin-updater full flow
Windows PortableLink to GitHub ReleasesButton opens releases page

Detecting portable at runtime: Use a Cargo feature flag:

toml
# Cargo.toml
[features]
portable = []
rust
// Rust command
#[tauri::command]
pub fn is_portable_build() -> bool {
    cfg!(feature = "portable")
}

Normal build: cargo build --release Portable build: cargo build --release --features portable

In lib.rs, conditionally register the updater plugin — skip it when the portable feature is active:

rust
#[cfg(all(desktop, not(feature = "portable")))]
app.handle()
    .plugin(tauri_plugin_updater::Builder::new().build())
    .expect("Failed to register updater plugin");

When is_portable_build() returns true, the frontend shows a GitHub Releases link instead of the auto-update flow.

Implementation Steps

1. Generate Signing Key (one-time)
bash
bun tauri signer generate -w ~/.tauri/<app-name>.key

Hit enter twice for empty password. Produces:

  • ~/.tauri/<app-name>.key — private key → store as GitHub Secret TAURI_SIGNING_PRIVATE_KEY
  • ~/.tauri/<app-name>.key.pub — public key → paste into tauri.conf.json

Empty password is fine — the key lives in encrypted GitHub Secrets. Adding a password means also managing TAURI_SIGNING_PRIVATE_KEY_PASSWORD in CI.

2. Rust Backend

src-tauri/Cargo.toml:

toml
[features]
portable = []

[dependencies]
tauri-plugin-updater = "2"
tauri-plugin-process = "2"

src-tauri/src/lib.rs:

rust
// Always register process plugin (needed for relaunch after update)
.plugin(tauri_plugin_process::init())
.setup(|app| {
    // Skip updater for portable builds
    #[cfg(all(desktop, not(feature = "portable")))]
    app.handle()
        .plugin(tauri_plugin_updater::Builder::new().build())
        .expect("Failed to register updater plugin");

    Ok(())
})

Register is_portable_build as a Tauri command in the invoke handler.

Command file (e.g. commands/settings.rs):

rust
#[tauri::command]
pub fn is_portable_build() -> bool {
    cfg!(feature = "portable")
}
3. Tauri Configuration

src-tauri/tauri.conf.json:

json
{
  "bundle": {
    "createUpdaterArtifacts": true
  },
  "plugins": {
    "updater": {
      "pubkey": "<PUBLIC KEY FROM .pub FILE>",
      "endpoints": [
        "https://github.com/<owner>/<repo>/releases/latest/download/latest.json"
      ]
    }
  }
}

The releases/latest/download/ URL pattern uses GitHub's redirect to always serve the latest release's asset.

Update CSP connect-src to allow GitHub release asset domains:

connect-src 'self' ipc: http://ipc.localhost https://api.github.com https://github.com https://objects.githubusercontent.com https://github-releases.githubusercontent.com

src-tauri/capabilities/default.json — add permissions:

json
{
  "permissions": [
    "updater:default",
    "process:default",
    "process:allow-restart"
  ]
}
4. Frontend

Install:

bash
bun add @tauri-apps/plugin-updater@^2 @tauri-apps/plugin-process@^2

State machine:

idle → checking → up-to-date
                → downloading → ready-to-restart
                → available (download retry) → downloading → ready-to-restart
                → error → idle (retry)

Portable: always shows "GitHub Releases" link button
StateUIAction
idle"Check for Updates" buttoncheck()
checkingSpinner, disabled buttonWait
up-to-date"Up to date"None
downloadingVersion number + cumulative byte progressWait
availableVersion number + "Download & Install"Retry downloadAndInstall() after a download failure
ready-to-restart"Restart Now" buttonrelaunch()
errorFriendly message + Retrycheck()

Key API details:

  • check() returns null when up-to-date (not an error)
  • check() throws on network failure or 404 (manifest doesn't exist yet) — show friendly message, not raw error
  • downloadAndInstall() progress callback: use event.data.chunkLength (not position/length). Track cumulative bytes with a state updater.
  • Store the Update object in a useRef to avoid stale closure in the progress callback.

Error handling pattern — never expose raw errors:

tsx
try {
  const result = await check();
  if (result) { /* downloadAndInstall() immediately */ }
  else { /* up-to-date */ }
} catch {
  // Network error, 404, rate limit, etc.
  setStatus("error");  // shows friendly t("updater.error") message
}
Show full SKILL.md (304 more words)Show less
5. CI Pipeline

Build job — pass signing key:

yaml
- name: Tauri build
  uses: tauri-apps/tauri-action@v0
  env:
    TAURI_SIGNING_PRIVATE_KEY: ${{ secrets.TAURI_SIGNING_PRIVATE_KEY }}
  with:
    args: --target ${{ matrix.target }}

Rename updater artifacts (after build, before upload):

yaml
- name: Rename updater artifacts
  shell: bash
  run: |
    case "${{ matrix.target }}" in
      universal-apple-darwin)
        TAR=$(find "$BUNDLE/macos" -name "*.app.tar.gz" | head -1)
        [ -n "$TAR" ] && mv "$TAR" "$BUNDLE/<App>-${VERSION}-macOS.app.tar.gz"
        [ -f "${TAR}.sig" ] && mv "${TAR}.sig" "$BUNDLE/<App>-${VERSION}-macOS.app.tar.gz.sig"
        ;;
      x86_64-pc-windows-msvc)
        EXE_SIG=$(find "$BUNDLE/nsis" -name "*.exe.sig" | head -1)
        [ -f "$EXE_SIG" ] && mv "$EXE_SIG" "$BUNDLE/<App>-${VERSION}-Windows.exe.sig"
        ;;
    esac

Windows portable rebuild:

yaml
- name: Create portable zip (Windows)
  if: matrix.target == 'x86_64-pc-windows-msvc'
  shell: pwsh
  run: |
    cargo build --release --manifest-path src-tauri/Cargo.toml --target ${{ matrix.target }} --features portable
    # ... package the portable binary as before

The --features portable flag compiles a binary where is_portable_build() returns true and the updater plugin is not registered.

Generate latest.json (in release job, after all artifacts are available):

yaml
- name: Generate updater manifest
  run: |
    MACOS_SIG=$(cat artifacts/macos/*.app.tar.gz.sig 2>/dev/null || echo "")
    WINDOWS_SIG=$(cat artifacts/windows/*.exe.sig 2>/dev/null || echo "")

    jq -n \
      --arg version "$VERSION" \
      --arg pub_date "$(date -u +"%Y-%m-%dT%H:%M:%SZ")" \
      --arg macos_sig "$MACOS_SIG" \
      --arg macos_url "https://github.com/<owner>/<repo>/releases/download/${VERSION}/<App>-${VERSION}-macOS.app.tar.gz" \
      --arg windows_sig "$WINDOWS_SIG" \
      --arg windows_url "https://github.com/<owner>/<repo>/releases/download/${VERSION}/<App>-${VERSION}-Windows.exe" \
      '{
        version: $version,
        notes: "",
        pub_date: $pub_date,
        platforms: {
          "darwin-x86_64": { signature: $macos_sig, url: $macos_url },
          "darwin-aarch64": { signature: $macos_sig, url: $macos_url },
          "windows-x86_64": { signature: $windows_sig, url: $windows_url }
        }
      }' > latest.json

- name: Upload manifest
  run: gh release upload "$TAG_NAME" latest.json

macOS universal binary: Both darwin-x86_64 and darwin-aarch64 point to the same .app.tar.gz with the same signature.

Platform Artifacts Summary
BuildStandard outputUpdater artifactUpdater uses?
macOS universal<App>-*.dmg<App>-*.app.tar.gz + .sigYes (tar.gz)
Windows NSIS<App>-*.exe<App>-*.exe + .sigYes (exe re-used)
Windows Portable<App>-*-Portable.zipN/ANo (releases link)

Common Mistakes

MistakeFix
Pushing tag before mainAlways push main first. Tag on unpushed commit won't trigger CI on correct SHA
Forgetting createUpdaterArtifactsNo .app.tar.gz or .sig files will be generated
CSP blocking downloadAdd objects.githubusercontent.com and github-releases.githubusercontent.com to connect-src
Missing process:allow-restartrelaunch() fails silently
Showing raw errors to userCatch and show friendly message. The first release won't have latest.json yet — that's a 404, not a bug
Wrong progress event fieldsTauri 2 uses event.data.chunkLength, not position/length
Treating check() null as errornull = no update available, it's a success case
Stale closure in download callbackStore Update in useRef, not just useState
Manifest URL case mismatchlatest.json in endpoints must match the uploaded filename exactly
Not cleaning up unused i18n keysWhen replacing a manual releases button with updater UI, remove old translation keys

Post-Release Notes

  • First release: Existing users won't have the updater code — they must download this release manually. After that, updates are automatic.
  • Homebrew: The .app.tar.gz and .sig are separate from the DMG. Homebrew cask formulas are unaffected.
  • Signature errors: If the updater reports signature verification failure, the pubkey in tauri.conf.json likely doesn't match the private key used in CI. Regenerate and redeploy.
  • Testing: Build a newer version to test the full download-and-install flow end-to-end.

© luochang212, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tauri-updater of luochang212/skill-zoo.

Open the folder on GitHubat commit 1c7afa6

Compare with similar skills

Tauri Updater next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Tauri Updater compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Tauri Updater this skillluochang212/skill-zoo117—~2.7kAutomated safety check: PassMIT
Resolve PR Reviewshencangsheng/easydb_app590—~2.4kAutomated safety check: PassMIT
Release VersionGOODBOY008/r-shell153—~4kAutomated safety check: PassMIT
Bump Versionflyxl/datazen114—~392Automated safety check: PassGPL-3.0
Git Workflowbkywksj/knowledge-base330—~1.1kAutomated safety check: PassCustom licence
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • Resolve PR Review

    shencangsheng/easydb_app

    Resolve pull request code review comments end-to-end. An agent skill from shencangsheng/easydb_app.

    590 GitHub stars~2.4k tokensUpdated 1 mo ago
    DevelopmentAuto-check passed
  • Release Version

    GOODBOY008/r-shell

    Release a new r-shell version and create a published GitHub release with contributor credits.

    153 GitHub stars~4k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Bump Version

    flyxl/datazen

    Update the DataZen application version number across all files and trigger a GitHub release rebuild.

    114 GitHub stars~392 tokensUpdated today
    DatabasesAuto-check passed
  • Git Workflow

    bkywksj/knowledge-base

    Git 工作流与版本管理技能,规范分支策略、提交信息和发布流程. An agent skill from bkywksj/knowledge-base.

    330 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Yaak Changelog

    mountain-loop/yaak

    Create or edit Yaak changelogs. An agent skill from mountain-loop/yaak.

    19k GitHub stars~1.6k tokensUpdated 3 days ago
    DevelopmentAuto-check passed

More from luochang212/skill-zoo

  • App Release

    luochang212/skill-zoo

    A skill your agent uses when the user asks to release a new version, ship a build, or publish a Skill Zoo release.

    117 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed
  • npm Release

    luochang212/skill-zoo

    A skill your agent uses when publishing or preparing to publish an npm package from this repository, especially the Skill Zoo CLI package under packages/cli.

    117 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check: warnings
  • Worth Fix

    luochang212/skill-zoo

    分析和判断任何论断、报告、想法或需求的真实性、价值与做法。当用户说"这个 bug 是真的吗"、"分析一下这个问题/这个报告/这个说法"、"这个修复值得做吗"、"帮我看下这个建议靠不靠谱",或用户给出一个待评估的 bug 报告、文章摘录、设计提案时使用。先核验、复现、定级、讲清原理、判断是否值得做,而不是直接相信或直接动手改代码。也适用于评估"要不要重构"。

    117 GitHub stars~751 tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Tauri Updater

What does Tauri Updater do?

A skill your agent uses when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable…. Tauri Updater is an agent skill from luochang212/skill-zoo. Use when adding software auto-update to a Tauri 2 desktop app, or when users ask about tauri-plugin-updater integration, app update checking, distinguishing installer vs portable builds for updates, or generating update manifests for GitHub Releases.

When should I use Tauri Updater?

Tauri Updater fits situations like: adding software auto-update to a Tauri 2 desktop app; users ask about tauri-plugin-updater integration; app update checking; distinguishing installer vs portable builds for updates.

How do I install Tauri Updater in Claude Code?

Run `npx skills add luochang212/skill-zoo --skill tauri-updater -a claude-code`. Or copy the skill folder (skills/tauri-updater in luochang212/skill-zoo) into .claude/skills/tauri-updater in your project. Claude Code loads it when a task matches its description.

How do I install Tauri Updater in Codex?

Run `npx skills add luochang212/skill-zoo --skill tauri-updater -a codex`. Or copy the skill folder (skills/tauri-updater in luochang212/skill-zoo) into .agents/skills/tauri-updater in your project. Codex loads it when a task matches its description.

Can I use Tauri Updater in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add luochang212/skill-zoo --skill tauri-updater -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/tauri-updater, .gemini/skills/tauri-updater, .github/skills/tauri-updater and .opencode/skills/tauri-updater in your project.

What does Tauri Updater need to run?

Going by SKILL.md and its folder, Tauri Updater needs the command-line tools its instructions call (bun and cargo) and credentials named TAURI_SIGNING_PRIVATE_KEY and TAURI_SIGNING_PRIVATE_KEY_PASSWORD. Our summary lists: A credential in TAURI_SIGNING_PRIVATE_KEY.

Does Tauri Updater access the network?

SKILL.md names 4 domains. In commands or code: github.com, api.github.com, objects.githubusercontent.com and github-releases.githubusercontent.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Tauri Updater safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Tauri Updater use?

Tauri Updater is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Tauri Updater use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Tauri Updater?

Skills that share tags, products or a category with Tauri Updater: Resolve PR Review (shencangsheng/easydb_app, 590 stars), Release Version (GOODBOY008/r-shell, 153 stars), Bump Version (flyxl/datazen, 114 stars) and Git Workflow (bkywksj/knowledge-base, 330 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Tauri Updater?

luochang212 (a GitHub user) maintains it in luochang212/skill-zoo, which has 117 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on October 9, 2026.

Source: luochang212/skill-zoo on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.