NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #3633 most downloaded on pub.dev
Sparkle-style auto-updates for Flutter desktop apps with verified releases, release CLI, built-in UI, and Windows/macOS/Linux support.
Last release 5 days ago
03 Oct 2026
Ships unpredictably
gaps range from 8 days to 8 months
Nearly every release is documented
notes for 41 of 43 stable releases
5 versions withdrawn
withdrawn after publishing
2 years old
54 releases · first in 2025
This release hardens update recovery, downloads, release publishing, and the built-in updater UI across macOS, Windows, and Linux.
This release hardens update recovery, downloads, release publishing, and the built-in updater UI across macOS, Windows, and Linux.
releases/<channel>/<version>/<build-N|no-build>/<platform>/ paths; reuse of an existing release identity is rejected.http dependency is now ^1.5.0 for abortable request support.Full changelog comparison: v3.2.0...v3.2.1.
http dependency to 1.5.0 for abortable requests.One column per month.
Fixed duplicate macOS Dock tiles after updates by relaunching app bundles through LaunchServices. Thanks to @hobleyd (David Hobley) for the fix in #75
This release includes incompatible changes for Windows Inno users:
privilegesRequired: admin, requiresElevation: always, and Authenticode verification against an explicit certificate SHA-256 allowlist. Unsupported silent arguments and unsafe paths are rejected.ReleaseInnoInstall now requires installedExecutableRelativePath and installedExecutableSha256. The release publisher records these values automatically. Manually authored descriptors and direct constructor calls must supply them.See the Windows Inno installer guide for the required configuration.
Full changelog: v3.1.6...v3.2.0
requiresElevation: always, and Authenticode verification against an explicit
certificate SHA-256 allowlist. Unsupported silent arguments and unsafe paths
are rejected.ReleaseInnoInstall requires
installedExecutableRelativePath and installedExecutableSha256. The release
publisher records these values automatically; manually authored descriptors
and direct constructor calls must supply them.Hardened cross-platform release publishing with strict hosted-artifact validation, bounded transport behavior, and release-surface contract tests.
general-notary profile is available in the user's global keychain searchThanks to @Nicoeevee for the production findings and detailed reports that
informed this work. We'd love to keep developing these improvements together
in the upstream repository; maintaining a separate fork is not necessary for
future fixes, and pull requests are always welcome.
Validated with the merged PR's full CI run and a credentialed local macOS
notarized publish smoke using the existing Developer ID identity and
general-notary profile.
Release desktop_updater 3.1.5
Release desktop_updater 3.1.5
RNTO, while replacing the raw rename
failure with actionable diagnostics.release doctor guidance and documented Apache FtpServer's native
overwrite limitation, the required server-side atomic replacement boundary,
and safe SFTP, S3-compatible, or server-backed custom command alternatives.STOR, DELE plus RNTO, and multi-command backup shuffles. Thanks to
@Nicoeevee for reporting the production Apache FtpServer behavior in PR #71.Release desktop_updater 3.1.4
Release desktop_updater 3.1.4
app-archive.json indexes,
including hosted revision checks before and after the temporary upload and a
server-side rename before validating the published bytes.Release desktop_updater 3.1.3
Release desktop_updater 3.1.3
Release desktop_updater 3.1.2
Release desktop_updater 3.1.2
installUpdate handoff reported by
@Nicoeevee in PR #67 through a real Flutter macOS application update.general-notary signed/notarized/stapled app, DMG, standard PKG, privileged
PKG, background approval OFF/ON, forced recovery, and diagnostics lanes were
exercised locally with the consumer application updating from 1.0.0+100 to
1.1.0+110.Release desktop_updater 3.1.1
Release desktop_updater 3.1.1
installUpdate MethodChannel handoff to send the canonical
five-key payload required by the native plugin. A real Flutter macOS smoke
app update from 1.0.0+100 to 1.1.0+110 passed with signed, notarized, and
stapled artifacts.Breaking: remove the 3.0 direct environment/file release-signing command path. release publish, release sign, and release validate now use only the fe
Breaking: remove the 3.0 direct environment/file release-signing command
path. release publish, release sign, and release validate now use only
the feed-bound desktop_updater.keys.json profile or --key-profile.
Breaking: make standalone verify profile-backed and remove its direct
public-key environment input.
Breaking: make keys adopt migration-only. It accepts one strict JSON
input, preserves the existing key ID, writes a profile, and exports an
encrypted bundle; plaintext adoption input must be deleted afterward.
Add the 3.0 to 3.1 release-key guide.
Added automatic Ed25519 release-key profiles with fingerprint-derived key IDs
and idempotent release keygen setup.
Added protected local-key storage on macOS/Linux and Windows DPAPI storage without plaintext Windows fallback.
Added encrypted key export/import, public-only export, existing 3.0 key adoption, and two-phase pending-key rotation.
Added profile-backed publish, sign, and validate flows; the direct environment/file signing contract from 3.0 was removed in 3.1.0.
Breaking: require signed release metadata, pinned public keys, expected package identity, and an app-owned durable recovery store.
desktop_updater:migrate --from 1|2 command.Added production macOS DMG and PKG artifact publishing, validation, and local smoke evidence flows while preserving direct .app.zip whole-bundle updat
.app.zip whole-bundle update
behavior..app, and hands off to the existing whole-bundle replacement helper.Nothing published for this version
Preserved Inno Setup uninstall artifacts named unins###.exe, unins###.dat, and unins###.msg during Windows direct zip wholeDirectoryReplace updates.
unins###.exe,
unins###.dat, and unins###.msg during Windows direct zip
wholeDirectoryReplace updates.desktop_updater_stage_* directories
before creating a new staging directory..exe installers.Fixed macOS release publish metadata so release.json preserves the top-level .app bundle name while generated artifact zip filenames keep the existing
release publish metadata so release.json preserves the
top-level .app bundle name while generated artifact zip filenames keep the
existing extension-stripped format.Previewed a Windows protected-directory install fix that treats C:\Program Files and C:\Program Files (x86) app directories as requiring UAC elevation
C:\Program Files and C:\Program Files (x86) app directories as requiring
UAC elevation when the app is launched by a non-admin user, even if a simple
write probe can create a temporary file there.desktop_updater as a Sparkle-style updater for Flutter desktop apps.Nothing published for this version
Extended requestHeadersProvider to hosted release notes loaded through releaseNotesUrl, so private update hosts can use the same runtime-owned headers
requestHeadersProvider to hosted release notes loaded through
releaseNotesUrl, so private update hosts can use the same runtime-owned
headers for update metadata, artifacts, and release notes.Added customizable support-policy date formatting for localized ready-made UI, with a default YYYY-MM-DD HH:mm UTC display.
YYYY-MM-DD HH:mm UTC display.tr_TR, including bundled locale
fallback and app-owned date formatting overrides.Added ready-made updater UI localization loading from bundled package JSON, app-owned JSON assets, direct string overrides, and app-owned resolver cal
Added release publish additionalFiles support for packaging app-owned manuals, language packs, and other external files before platform signing, notar
release publish additionalFiles support for packaging app-owned
manuals, language packs, and other external files before platform signing,
notarization, pre-package hooks, and zip descriptor generation.Exported DesktopUpdaterController and core public update result/version types from package:desktop_updater/desktop_updater.dart so README quick start
DesktopUpdaterController and core public update result/version
types from package:desktop_updater/desktop_updater.dart so README quick
start examples work with a single package import.Added requestHeadersProvider so apps can attach runtime-owned HTTP headers to private update host requests for app-archive.json, release.json, and upd
requestHeadersProvider so apps can attach runtime-owned HTTP headers
to private update host requests for app-archive.json, release.json, and
update artifact downloads.Added MandatoryReadyToInstallBehavior for dialog-based mandatory update flows so apps can choose the default Save first prompt or restart without an e
MandatoryReadyToInstallBehavior for dialog-based mandatory update
flows so apps can choose the default Save first prompt or restart without an
extra confirmation.UpdateDialogListener mandatory Save first handling so it dismisses
the modal update flow and lets the user return to the app to save work.Nothing published for this version
Added mandatory ready-to-install UX that preserves mandatory state after staging and shows Save first plus Restart.
Save first plus Restart.supportPolicy for minimum supported app versions with warning-before-deadline and blocking-after-deadline ready-made UI.freshInstall metadata, ready-made fresh-install UI, external download launching, and release publish flags.release publish help and validation for support-policy and fresh-install flags.Nothing published for this version
Fixed Linux zip staging so Unix permission bits are restored from the update archive, preserving executable bundle files before native relaunch.
release publish.Added release publish --dart-define support so build-time Dart environment values are forwarded to flutter build.
release publish --dart-define support so build-time Dart environment
values are forwarded to flutter build.Added optional release notes support for update UIs through releaseNotesUrl, releaseNotesLoader, releaseNotesState, and loadReleaseNotes().
releaseNotesUrl, releaseNotesLoader, releaseNotesState, and loadReleaseNotes().{ "data": [{ "type", "message" }] } format supported while allowing richer sections, summaries, and item metadata.Added opt-in update diagnostics sinks with redacted log formatting for app-owned lifecycle logs.
Added release publish --mandatory so generated app-archive.json items can mark updates as mandatory while keeping the default optional.
release publish --mandatory so generated app-archive.json items can mark updates as mandatory while keeping the default optional.Fixed Windows release publish builds so the CLI invokes flutter build windows --release through shell-aware process resolution.
release publish builds so the CLI invokes flutter build windows --release through shell-aware process resolution.Fixed notarized macOS release publish so nested Flutter frameworks are signed before the outer .app, then verified through notary, stapler, and Gateke
release publish so nested Flutter frameworks are signed before the outer .app, then verified through notary, stapler, and Gatekeeper before packaging.release publish smoke coverage for Windows, Linux, and opt-in notarized macOS CI so release smoke tests exercise the same publish command users run.Hardened update selection so app-archive.json entries must match the downloaded release.json version, build number, platform, and channel.
app-archive.json entries must match the downloaded release.json version, build number, platform, and channel.release validate to reject hosted descriptor identity mismatches before accepting a published update..app symlinks and rechecked the staged app inside the native install helper before replacement.Added the high-level dart run desktop_updater:release publish flow for building, packaging, manifest generation, manual upload packages, provider uplo
dart run desktop_updater:release publish flow for building, packaging, manifest generation, manual upload packages, provider upload, and hosted validation.dart run desktop_updater:release validate to simulate an older installed version, select an update, fetch release.json, download the artifact, and verify length and SHA-256.release publish --platform macos --notarize and macos.notarize: true.Adds dart run desktop_updater:migrate for 1.x to 2.0 migration previews, safe edits, CI check mode, and manual findings. Documents the automated migra
Adds dart run desktop_updater:migrate for 1.x to 2.0 migration previews, safe edits, CI check mode, and manual findings. Documents the automated migration flow in the README and migration guide.
dart run desktop_updater:migrate to preview and apply safe 1.x to 2.0 migration edits, plus manual findings for typed state, old CLI commands, low-level APIs, and platform publishing work.Promoted the zip-first 2.0 release contract: app-archive.json points to release.json, and release.json points to one verified zip artifact.
app-archive.json points to release.json, and release.json points to one verified zip artifact.buildNumber metadata optional in release indexes, release descriptors, and the zip-first package CLI.Fixed version comparison so archive build metadata is not treated as newer when the installed app does not expose a build number.
allowUnsignedMacOSUpdates opt-out for owners who need unsigned macOS Release update mechanics while keeping signed, notarized, stapled updates as the default production-trusted path.buildNumber metadata optional in release indexes, release descriptors, and the zip-first package CLI.Kept skipCheckVersion as a deprecated alias for the same behavior.
skipInitialVersionCheck to DesktopUpdaterController so apps can initialize the controller without immediately checking for updates.skipCheckVersion as a deprecated alias for the same behavior.Added support for Flutter versions without build metadata in update checks and release tooling.
shortVersion is omitted.1.2.3 no longer throw, while malformed values like 1.2.3+ still fail.Added macOS release manifests, content-addressed gzip payloads, and ditto full ZIP fallback archives for .app bundles.
ditto full ZIP fallback archives for .app bundles..app trees or ZIP-only updates.Nothing published for this version
Nothing published for this version
Nothing published for this version
Revert fix macOS issues, sorry for the inconvenience, do not use 1.2.0 for macOS
Fix macOS issues (thanks to @TheFilyng)
Fix download and skip this version localization and add colors
Fix alert dialog skip condition
* Add alert dialog option
Add custom direct widget for theme colors
* Fix mandotory skip issue
Lower macOS platform requirement to 10.14
Add repository link to pubspec.yaml
* First version of plugin
Your coding agent can read these notes before it upgrades. Set up the MCP server →