NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4958 most downloaded on npm
Last release 8 days ago
26 Sep 2026
Release timing varies
gaps range from 8 days to 5 months
Most releases are documented
notes for 38 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
9 years old
125 releases · first in 2017
Feat(security): signed update manifests (Ed25519) with trust lists and multi-signature manifests _`#9877` `d45536f` @mmaietta_
Feat(security): signed update manifests (Ed25519) with trust lists and multi-signature manifests #9877 d45536f @mmaietta
Optional Ed25519 signing of auto-update manifests (latest*.yml). When signing keys are configured
(updateManifest.signingKey/signingKeyFile in config, or ELECTRON_BUILDER_UPDATE_SIGN_KEY/ELECTRON_BUILDER_UPDATE_SIGN_KEY_FILE
env vars), each manifest is signed over its integrity-critical fields and the matching public keys are
embedded into app-update.yml (both resolved from the same keys on the platform packager, so signing and
embedding cannot disagree). electron-updater verifies the signature before downloading and refuses to
update on tamper/missing-signature (fail-closed). Opt-in: when no public key is configured, verification is
skipped with a one-time warning. New CLI: electron-builder create-update-key (prints the public key and its key id).
Key rotation without a flag day: an install trusts a list of public keys (updateManifestPublicKey is a
string or an array; updateManifest.publicKey, signingKey and signingKeyFile accept arrays, a PEM value may
hold several concatenated keys, and ELECTRON_BUILDER_UPDATE_SIGN_KEY_FILE accepts several paths joined with
the OS path delimiter), and a manifest may carry several signatures (signatures: [{ keyId, signature }],
one per signing key, next to the legacy signature of the first key). A manifest is accepted when any trusted
key validates any of its signatures, so a release signed with [old, new] verifies on installs that trust
either. AppUpdater.updateManifestPublicKey accepts a string or an array. A build-time warning flags an
explicit publicKey list that contains none of the signing keys.
Gating of the Linux package-manager signature-bypass flags landed separately as
AppUpdater.allowUnverifiedLinuxPackages (#9990).
#10123 6ab9a8c @OskarEichlerOne column per quarter.
Docs: fix broken electron.build documentation links in readmes, TSDoc comments, and error messages — point auto-update, code-signing, and multi-platfo
/docs/features/ locations, repair the electron.build./ domain typo, and replace anchors that no longer exist (#10107) #10111 cf39086 @claudeSecurity hardening and a migrate-schema fix: _`#10036` `b87a0b7` @mmaietta_
#10036 b87a0b7 @mmaietta
builder-util removePassword: redact single-letter/URI secret flags (security … -k <password>, osslsigncode -key <pkcs11-uri?pin-value=…>) and whitespace-containing secrets in debug logs, and make the /b … /c block-redaction regex ReDoS-safe.builder-util-runtime httpExecutor: fix the non-functional maxRedirects guard (the redirect counter was never advanced), so a redirect loop from a malicious feed/mirror no longer hangs the updater.electron-updater GitLabProvider: only forward the GitLab token to the channel-file request when its URL is same-origin as the API host, so an off-host/http:// direct_asset_url in the release JSON cannot exfiltrate the token.app-builder-lib: defense-in-depth hardening — validate executableName before interpolating it into the generated Flatpak launcher, contain custom-toolset extraction within the cache dir, and XML-escape MSI file-association ext/description.electron-builder migrate-schema: auto-remove the removed linux.syncDesktopName flag.BREAKING CHANGE: The legacy top-level UpdateInfo.path / UpdateInfo.sha512 fields are now written to latest*.yml only when the declared electronUpdater…
Feat(updater): gate legacy top-level manifest path/sha512 behind electronUpdaterCompatibility #9992 2c10f1f @mmaietta
BREAKING CHANGE: The legacy top-level UpdateInfo.path / UpdateInfo.sha512 fields are now written to latest*.yml only when the declared electronUpdaterCompatibility semver range intersects electron-updater versions <2.16.0 (previously they were written unconditionally), mirroring how the Windows sha2 field is gated; the legacy latest-mac.json is likewise emitted only when the range intersects <2.0.0. The default electronUpdaterCompatibility is now >=2.16 (previously >=2.15), so none of the legacy fields are emitted by default. Both fields are now optional on the UpdateInfo type. Modern clients (electron-updater >=2.16) read the files[] array and are unaffected. If you still ship apps that embed electron-updater 1.x – 2.15, set electronUpdaterCompatibility to a range that includes them (e.g. >=1.0.0) so the legacy descriptor keeps being emitted.
#9773 a086ef3 @kyletayloredFix(updater): detect legacy hex sha512 manifest values strictly and deprecate them for removal in v28 #9990 65f0403 @mmaietta
The updater previously used a fuzzy heuristic (looking for +, /, Z, or = characters) to decide whether a manifest sha512 was hex- or base64-encoded. It now uses a strict check: a value that is exactly 128 hexadecimal characters is treated as legacy hex; anything else is decoded as base64, which is what electron-builder has emitted since 19.x (2017). The two forms cannot collide — base64-encoded sha512 is always 88 characters ending in == — and a wrong pick can only fail closed with a checksum mismatch.
Hex-encoded sha512 values (from pre-19.x manifests or hand-rolled manifests built from raw sha512sum output) remain accepted in v27 but are deprecated: support will be removed in v28. Emit base64 instead, e.g. sha512sum file.ext | cut -d' ' -f1 | xxd -r -p | base64 -w0.
SHA-256 (sha2) update checksums are unchanged here — they remain accepted in v27 under the existing v28-removal grace period.
Chore(refactor): reducing duplicate code and extracting helper functions _`#9947` `8f3d9fa` @mmaietta_
Introduce xml escaping for publisher, publisherDisplayName, displayName, description in appxmanifest.xml to avoid issues with xml preserverd character
Fix: declare the missing electron-publish dependency on electron-builder, and switch type-checking to nodenext module resolution so the compiler model
Fix: resolve runtime ESM/CJS interop for namespace imports of CJS-only packages (sax, which, mime) _`#9884` `7674e60` @mmaietta_
Chore(refactor): remove deprecated snap config property and all remaining deprecated APIs. Hard-deletes 14 deprecated features accumulated across the…
snap config property and all remaining deprecated APIs. Hard-deletes 14 deprecated features accumulated across the codebase. No migration shims remain. (BREAKING) #9873 9d755c6 @mmaietta#9544 a5121de @mmaiettaChore: replace app-builder-bin node-dep-tree and rebuild-node-modules with pure-TS equivalents; nativeRebuilder: "legacy" now routes to @electron/rebu
Chore: stabilize flaky CI tests (electron zip ENOENT, 5xx retries, snap timeouts) _`#9795` `59efef1` @mmaietta_
Fix: harden generated-file output, argument construction, and download validation _`#9778` `d6a5aee` @mmaietta_
Chore(docs): documentation updates and docusaurus migration _`#9744` `d846315` @mmaietta_
Feat: pass release notes to GitHub/GitLab release body via releaseBody and releaseName options _`#9581` `b7df0bc` @asamofal_
Chore: bumping version packages of all packages to trigger Trusted Signing provedance release _`#9362` `030269b` @mmaietta_
### Minor Changes - #9209 `6fd391d9e8390c00c8b0674d8ac3a5b7b6f0f19f` Thanks @daihere1993! - feat: Support gitlab publisher
6fd391d9e8390c00c8b0674d8ac3a5b7b6f0f19f Thanks @daihere1993! - feat: Support gitlab publisherReplace hardcoded service-specific hostname checks with sophisticated cross-origin redirect detection that matches industry standards from Python requ
#9211 7c7fd6ca Thanks @FringeNet! - fix: implement industry-standard cross-origin redirect auth handling
Replace hardcoded service-specific hostname checks with sophisticated cross-origin redirect detection that matches industry standards from Python requests library and Apache HttpClient.
Key improvements:
Fixes GitHub issue #9207: GitHub release asset downloads failing with 403 Forbidden when redirected from api.github.com to release-assets.githubusercontent.com (Azure backend) or other cloud storage services that don't accept GitHub tokens.
The implementation now handles all cross-origin redirect scenarios while maintaining compatibility with legitimate same-origin redirects and industry-standard HTTP→HTTPS upgrades.
44b28997 Thanks @taylorhadden! - feat(github): Add tagNamePrefix option and deprecate vPrefixedTagName### Patch Changes - #9186 `1a6ea016` Thanks @daihere1993! - feat(electron-updater): add GitLab provider support - #9177 `35f5f6e5` Thanks @mmaietta! -
### Patch Changes - #9018 `a2f7f735` Thanks @gtluszcz! - Add information how to use electron-publish s3 with credentials stored in ~/.aws/config file.
### Patch Changes - #8815 `8e7811d1` Thanks @mmaietta! - chore: "organize imports" + change ObjectMap => Record for non-external properties (i.e. thin
#8815 8e7811d1 Thanks @mmaietta! - chore: "organize imports" + change ObjectMap => Record for non-external properties (i.e. things that don't get processed for scheme.json)
#8813 07429661 Thanks @mmaietta! - chore: extract common undefined | null to reuse current (unexported) type Nullish. Expose FileMatcher instead of @internal flag
### Minor Changes - #8741 `eacbbf59` Thanks @0xlau! - Add forcePathStyle option to S3Options - #8711 `6f0fb8e4` Thanks @hrueger! - Add host property t
### Minor Changes - #8741 `eacbbf59` Thanks @0xlau! - Add forcePathStyle option to S3Options - #8711 `6f0fb8e4` Thanks @hrueger! - Add host property t
### Patch Changes - #8545 `fc3a78e4e61f916058fca9b15fc16f076c3fabd1` Thanks @mmaietta! - chore(deps): update devDependencies, including typescript
fc3a78e4e61f916058fca9b15fc16f076c3fabd1 Thanks @mmaietta! - chore(deps): update devDependencies, including typescript### Patch Changes - #8516 `d1cb6bdb` Thanks @mmaietta! - fix(chore): upgrading typescript and fixing compiler errors
### Patch Changes - #8491 `178a3c40` Thanks @mmaietta! - chore: migrating to typedoc and updating/improving type+interface definitions
### Patch Changes - #8486 `d56cd274` Thanks @mmaietta! - fix(deploy): redeploy all packages to sync semver ranges
### Patch Changes - #8437 `be625e06` Thanks @juwonjung-hdj! - fix: retry renaming update file when EBUSY error occurs due to file lock
be625e06 Thanks @juwonjung-hdj! - fix: retry renaming update file when EBUSY error occurs due to file lock### Patch Changes - #8108 `3d4cc7ae` Thanks @beyondkmp! - feat: add minimumSystemVersion in electron updater - #8304 `1ac86c9e` Thanks @mmaietta! - ch
#8108 3d4cc7ae Thanks @beyondkmp! - feat: add minimumSystemVersion in electron updater
#8304 1ac86c9e Thanks @mmaietta! - chore: update pnpm to 9.4.0
#8291 ad668ae1 Thanks @IsaacAderogba! - fix: add MemoLazy to fix codeSigningInfo not responding to changed args
#8126 445911a7 Thanks @mmaietta! - chore(docs): update Bitbucket Options token doc
#8251 140e2f0e Thanks @m59peacemaker! - Refactored to resolve circular dependency, eliminating warnings from tools such as Rollup
#8110 fa7982f1 Thanks @mmaietta! - chore: entering alpha release stage
### Patch Changes - #8304 `1ac86c9e` Thanks @mmaietta! - chore: update pnpm to 9.4.0 - #8291 `ad668ae1` Thanks @IsaacAderogba! - fix: add MemoLazy to
### Patch Changes - #8251 `140e2f0e` Thanks @m59peacemaker! - Refactored to resolve circular dependency, eliminating warnings from tools such as Rollu
140e2f0e Thanks @m59peacemaker! - Refactored to resolve circular dependency, eliminating warnings from tools such as Rollup### Patch Changes - #8126 `445911a7` Thanks @mmaietta! - chore(docs): update Bitbucket Options token doc
### Patch Changes - #8108 `3d4cc7ae` Thanks @beyondkmp! - feat: add minimumSystemVersion in electron updater
3d4cc7ae Thanks @beyondkmp! - feat: add minimumSystemVersion in electron updater### Patch Changes - #8110 `fa7982f1` Thanks @mmaietta! - chore: entering alpha release stage
### Patch Changes - #8057 `ccbb80de` Thanks @mmaietta! - chore: upgrading connected dependencies (typescript requires higher eslint version)
### Patch Changes - #7806 `db424e8e` Thanks @AviVahl! - fix: update @types/node for compat with newest @types/node - #7806 `db424e8e` Thanks @AviVahl!
### Patch Changes - #7814 `549d07b0` Thanks @jgresham! - minor addition to docs for snap publishing. add snapcraft link to local and cd auth options
### Patch Changes - #7544 `dab3aeba` Thanks @NoahAndrews! - Fix differential downloads when the server compresses the blockmap file HTTP response
dab3aeba Thanks @NoahAndrews! - Fix differential downloads when the server compresses the blockmap file HTTP response### Minor Changes - #7314 `cc1ddabd` Thanks @lbestftr! - added the accelerate option to handle accelerated s3 buckets ### Patch Changes - #7362 `93930
### Patch Changes - #7362 `93930cf0` Thanks @onucsecu2! - docs: replaced 'access token' with 'app password' from BitbucketOptions
93930cf0 Thanks @onucsecu2! - docs: replaced 'access token' with 'app password' from BitbucketOptions### Minor Changes - #7314 `cc1ddabd` Thanks @lbestftr! - added the accelerate option to handle accelerated s3 buckets
### Patch Changes - #7306 `01c67910` Thanks @mmaietta! - chore: Update dependencies per audit/outdated
### Patch Changes - #7214 `53327d51` Thanks @mmaietta! - chore(dep): upgrading typescript and eslint dependencies
### Patch Changes - #7094 `1023a93e` Thanks @HppZ! - fix: close file stream when error
### Minor Changes - #7028 `e7179b57` Thanks @mmaietta! - feat: Adding timeout to publisher config for api requests and uploads
### Patch Changes - #6983 `adeaa347` Thanks @mmaietta! - fix: regenerate schema.json for x64ArchFiles in mac universal options
### Patch Changes - #6813 `7af4c226` Thanks @mmaietta! - chore: Update dependencies and audit
snap support, desktop integration attempt #509
<a name="9.0.0"></a>
<a name="8.7.0"></a>
<a name="8.6.0"></a>
<a name="8.5.3"></a>
Fixes: fix(nsis): Adding --INPUTCHARSET to makensis. (#4898 #6232 #6259)
#6556 a138a86f Thanks @mmaietta! - Breaking changes
Removing Bintray support since it was sunset. Ref: https://jfrog.com/blog/into-the-sunset-bintray-jcenter-gocenter-and-chartcenter/
Fail-fast for windows signature verification failures. Adding -LiteralPath to update file path to disregard injected wildcards
Force strip path separators for backslashes on Windows during update process
Force authentication for local mac squirrel update server
Fixes: fix(nsis): Adding --INPUTCHARSET to makensis. (#4898 #6232 #6259)
Adding additional details to error console logging
Fixes: fix(nsis): Adding --INPUTCHARSET to makensis. (#4898 #6232 #6259)
#6556 a138a86f Thanks @mmaietta! - Breaking changes
Removing Bintray support since it was sunset. Ref: https://jfrog.com/blog/into-the-sunset-bintray-jcenter-gocenter-and-chartcenter/
Fail-fast for windows signature verification failures. Adding -LiteralPath to update file path to disregard injected wildcards
Force strip path separators for backslashes on Windows during update process
Force authentication for local mac squirrel update server
Fixes: fix(nsis): Adding --INPUTCHARSET to makensis. (#4898 #6232 #6259)
Adding additional details to error console logging
### Patch Changes - #6400 `66ca625f` Thanks @jbool24! - refactor: update Bitbucket publisher to have optional config options for Token and Username (B
### Patch Changes - #6333 `54ee4e72` Thanks @lutzroeder! - fix: SnapStoreOptions required properties
54ee4e72 Thanks @lutzroeder! - fix: SnapStoreOptions required properties (#6327)### Minor Changes - #6228 `a9453216` Thanks @mmaietta! - feat: adding Bitbucket publisher and autoupdater
### Patch Changes - #6193 `7f933d00` Thanks @mmaietta! - fix: adding snapStore to AllPublishOptions so that it properly is generated via pnpm generate
### Minor Changes - #6167 `f45110cb` Thanks @mmaietta! - feat: Adding Keygen as an official publisher/updater for electron-builder
a4eae34f: Synchronizing CLI and package.json versions. Updating auto-publish values + changeset generation to be more frictionless
878671d0: Updating patch number as many deps were updated as parted of RenovateBot integration
1272afc5: Initial introduction of changset config
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →