Function: loadUpdateSigningKeys()
loadUpdateSigningKeys(
config?,baseDir?):string[]
Resolves the Ed25519 signing private key(s) (PEM) from, in precedence order:
- explicit
signingKeyconfig value (PEM literal, or an array of them) signingKeyFileconfig value (path to a PEM file, or an array of paths; relative paths are resolved againstbaseDir— the project directory — when given, like every other path in the build configuration)ELECTRON_BUILDER_UPDATE_SIGN_KEYenv (PEM literal — preferred for CI secrets)ELECTRON_BUILDER_UPDATE_SIGN_KEY_FILEenv (path to a PEM file; several paths may be joined withpath.delimiter, i.e.:on POSIX and;on Windows) The first source that is set wins, but that source may yield several keys: a PEM value (config, env, or file contents) may contain several concatenated-----BEGIN PRIVATE KEY-----blocks, and the array/list forms hold one key each. Every key is validated (Ed25519, no duplicates) and returned in configured order — the first key is the one written to the legacy singlesignaturefield. Returns an empty array when nothing is set, meaning manifest signing is disabled.baseDironly affects configsigningKeyFileentries; anELECTRON_BUILDER_UPDATE_SIGN_KEY_FILEpath keeps the usual environment-variable semantics and is resolved against the current working directory.
Parameters
config?
UpdateSigningKeySources | null
baseDir?
string | null
Returns
string[]