ci: fix tauri updater signing by removing invalid TAURI_UPDATER_* env - #5
Merged
Merged
Conversation
Co-authored-by: traeagent <traeagent@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
背景
tauri-action 构建在最后给 updater 产物签名时报错:
构建/打包本身都成功了,只在签名 updater 产物(
cursor-pool.app.tar.gz等)这步失败。改动
删除
.github/workflows/release.yml中两处无效的 env:TAURI_UPDATER_PRIVATE_KEYTAURI_UPDATER_PRIVATE_KEY_PASSWORDTauri v2 只认
TAURI_SIGNING_PRIVATE_KEY/TAURI_SIGNING_PRIVATE_KEY_PASSWORD,TAURI_UPDATER_*这两个变量名不是 Tauri 读取的标准变量,留着只会让人误以为有备用机制。注意:仅改 workflow 不够,根本原因是 Secret 内容格式
签名失败的根因是 GitHub Secret
TAURI_SIGNING_PRIVATE_KEY的内容格式不正确——缺少 minisign 要求的untrusted comment:注释行。合并本 PR 后还需在仓库 Settings → Secrets and variables → Actions 更新该 Secret:pnpm tauri signer generate -w ~/.tauri/cursor-pool.key.key文件内容(含首行untrusted comment: ...和所有换行)作为TAURI_SIGNING_PRIVATE_KEY的值TAURI_SIGNING_PRIVATE_KEY_PASSWORDTAURI_UPDATER_PUBKEYSecret 和tauri.conf.json中的pubkey,保证公私钥配对验证
合并后重新触发 Release workflow,确认 macOS/Windows 各平台 updater 产物签名成功,不再出现
Missing comment in secret key。