Skip to main content

Function: loadUpdateSigningKeys()

loadUpdateSigningKeys(config?, baseDir?): string[]

Resolves the Ed25519 signing private key(s) (PEM) from, in precedence order:

  1. explicit signingKey config value (PEM literal, or an array of them)
  2. signingKeyFile config value (path to a PEM file, or an array of paths; relative paths are resolved against baseDir — the project directory — when given, like every other path in the build configuration)
  3. ELECTRON_BUILDER_UPDATE_SIGN_KEY env (PEM literal — preferred for CI secrets)
  4. ELECTRON_BUILDER_UPDATE_SIGN_KEY_FILE env (path to a PEM file; several paths may be joined with path.delimiter, i.e. : on POSIX and ; on Windows) The first source that is set wins, but that source may yield several keys: a PEM value (config, env, or file contents) may contain several concatenated -----BEGIN PRIVATE KEY----- blocks, and the array/list forms hold one key each. Every key is validated (Ed25519, no duplicates) and returned in configured order — the first key is the one written to the legacy single signature field. Returns an empty array when nothing is set, meaning manifest signing is disabled. baseDir only affects config signingKeyFile entries; an ELECTRON_BUILDER_UPDATE_SIGN_KEY_FILE path keeps the usual environment-variable semantics and is resolved against the current working directory.

Parameters​

config?​

UpdateSigningKeySources | null

baseDir?​

string | null

Returns​

string[]