I'm just getting started with Electron, so forgive me if this is a stupid question, but how is that different from the updates endpoint getting compromised (for apps with auto update enabled)?
That's an excellent question! The auto updater requires your packages to be code-signed, meaning that someone would have to compromise the endpoint _and_ also be able to sign code with your root-trusted certificate.