Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm just getting started with Electron, so forgive me if this is a stupid question, but how is that different from the updates endpoint getting compromised (for apps with auto update enabled)?


That's an excellent question! The auto updater requires your packages to be code-signed, meaning that someone would have to compromise the endpoint _and_ also be able to sign code with your root-trusted certificate.


Oh neat! That makes sense, but I didn't realize it was set up for code signing. Good to know :)


The auto-updater really isn't ready for prime time, sadly. I'd suggest waiting until https://github.com/electron/electron/issues/8106 is resolved before using it in your project.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: