Skip to main content

Class: PacmanUpdater

Extends

  • LinuxUpdater

Constructors

Constructor

new PacmanUpdater(options?, app?): PacmanUpdater

Parameters

options?

AllPublishOptions | null

app?

AppAdapter

Returns

PacmanUpdater

Overrides

LinuxUpdater.constructor

Properties

_isUpdateSupported

protected _isUpdateSupported: VerifyUpdateSupport

Inherited from

LinuxUpdater._isUpdateSupported


_isUserWithinRollout

protected _isUserWithinRollout: VerifyUpdateSupport

Inherited from

LinuxUpdater._isUserWithinRollout


_logger

protected _logger: Logger = console

Inherited from

LinuxUpdater._logger


allowDowngrade

allowDowngrade: boolean = false

Whether to allow version downgrade (when a user from the beta channel wants to go back to the stable channel).

Taken in account only if channel differs (pre-release version component in terms of semantic versioning).

Default

false

Inherited from

LinuxUpdater.allowDowngrade


allowPrerelease

allowPrerelease: boolean = false

GitHub provider only. Whether to allow update to pre-release versions. Defaults to true if application version contains prerelease components (e.g. 0.12.1-alpha.1, here alpha is a prerelease component), otherwise false.

If true, downgrade will be allowed (allowDowngrade will be set to true).

Inherited from

LinuxUpdater.allowPrerelease


allowUnverifiedLinuxPackages

allowUnverifiedLinuxPackages: boolean = true

Linux only. Whether to allow installing unverified (unsigned / failing-GPG) .deb and .rpm packages during auto-update.

electron-builder does not sign Linux packages, so this defaults to true to preserve working auto-updates: the package manager's signature/GPG checks are bypassed where a bypass flag exists (--allow-unauthenticated for the apt fallback, --allow-unsigned-rpm for zypper, --nogpgcheck for dnf/yum), which is the historical behavior.

What false enforces depends on the package manager used on the target system:

  • dpkg (the default for .deb): no effect — dpkg performs no signature verification (a warning is logged); enforcing .deb signatures requires a debsig-verify/debsigs policy on the target system.
  • apt (.deb fallback): --allow-unauthenticated is omitted.
  • zypper: enforced — unsigned/untrusted packages fail to install.
  • dnf/yum: enforced via --setopt=localpkg_gpgcheck=1 (local package files are not GPG-checked by default).
  • bare rpm (fallback): cannot be enforced via the CLI (a warning is logged); admins must configure %_pkgverify_level signature on the target system.

pacman and AppImage targets are not affected by this option: pacman -U has no per-invocation bypass flag (local-file policy is LocalFileSigLevel in pacman.conf), and AppImage updates are verified only via the update-manifest checksum.

Default

true

Inherited from

LinuxUpdater.allowUnverifiedLinuxPackages


app

protected readonly app: AppAdapter

Inherited from

LinuxUpdater.app


autoDownload

autoDownload: boolean = true

Whether to automatically download an update when it is found.

Default

true

Inherited from

AppImageUpdater.autoDownload


autoInstallEvent

autoInstallEvent: AutoInstallEvent = "onQuit"

When a downloaded update is automatically installed (if quitAndInstall was not called before).

  • "onQuit" (default) — install on app quit by spawning the installer while the app exits.
  • "onNextLaunch" — defer the install: any app quit persists an install-on-next-launch marker for the downloaded update; on the next launch the updater re-validates the cached installer against freshly fetched update info and installs it (see installPendingUpdateIfAvailable). This avoids the class of failures where the on-quit installer process is killed by the OS before it finishes — most notably Windows terminating the detached NSIS installer during session end (log off / shutdown / restart), which can leave the app uninstalled but not re-installed (see https://github.com/electron-userland/electron-builder/issues/7807). The automatic install at startup only runs for targets that can install without an elevation prompt: NSIS (per-user, isAdminRightsRequired === false) and AppImage. Linux package targets (deb, rpm, pacman) always elevate via pkexec/sudo, and NSIS per-machine installs trigger a UAC prompt, so for those the pending update is kept and installPendingUpdateIfAvailable() must be called explicitly at a moment the app controls.
  • "manual" — never auto-install; the downloaded update stays cached until an explicit quitAndInstall().

"onNextLaunch" is planned to become the DEFAULT in v28 to resolve this class of bug once and for all.

Default

"onQuit"

Inherited from

LinuxUpdater.autoInstallEvent


autoRunAppAfterInstall

autoRunAppAfterInstall: boolean = true

Whether to run the app after finish install when run the installer is NOT in silent mode.

Default

true

Inherited from

LinuxUpdater.autoRunAppAfterInstall


currentVersion

readonly currentVersion: SemVer

The current application version.

Inherited from

LinuxUpdater.currentVersion


disableDifferentialDownload

disableDifferentialDownload: boolean = false

NSIS only Disable differential downloads and always perform full download of installer.

Default

false

Inherited from

AppImageUpdater.disableDifferentialDownload


downloadedUpdateHelper

protected downloadedUpdateHelper: DownloadedUpdateHelper | null = null

Inherited from

LinuxUpdater.downloadedUpdateHelper


forceDevUpdateConfig

forceDevUpdateConfig: boolean = false

Allows developer to force the updater to work in "dev" mode, looking for "dev-app-update.yml" instead of "app-update.yml" Dev: path.join(this.app.getAppPath(), "dev-app-update.yml") Prod: path.join(process.resourcesPath!, "app-update.yml")

Default

false

Inherited from

AppImageUpdater.forceDevUpdateConfig


fullChangelog

fullChangelog: boolean = false

GitHub provider only. Get all release notes (from current version to latest), not just the latest.

Default

false

Inherited from

LinuxUpdater.fullChangelog


previousBlockmapBaseUrlOverride

previousBlockmapBaseUrlOverride: string | null = null

The base URL of the old block map file.

When null, the updater will use the base URL of the update file to download the update. When set, the updater will use this string as the base URL of the old block map file. Some servers like github cannot download the old block map file from latest release, so you need to compute the old block map file base URL manually.

Default

null

Inherited from

AppImageUpdater.previousBlockmapBaseUrlOverride


quitAndInstallCalled

protected quitAndInstallCalled: boolean = false

Inherited from

LinuxUpdater.quitAndInstallCalled


requestHeaders

requestHeaders: OutgoingHttpHeaders | null = null

The request headers.

Inherited from

LinuxUpdater.requestHeaders


signals

readonly signals: UpdaterSignal

For type safety you can use signals, e.g. autoUpdater.signals.updateDownloaded(() => {}) instead of autoUpdater.on('update-available', () => {})

Inherited from

AppImageUpdater.signals


stagingUserIdPromise

protected readonly stagingUserIdPromise: Lazy<string>

Inherited from

AppImageUpdater.stagingUserIdPromise


updateInfoAndProvider

protected updateInfoAndProvider: UpdateInfoAndProvider | null = null

Inherited from

LinuxUpdater.updateInfoAndProvider

Accessors

channel

Get Signature

get channel(): string | null

Get the update channel. Doesn't return channel from the update configuration, only if was previously set.

Returns

string | null

Set Signature

set channel(value): void

Set the update channel. Overrides channel in the update configuration.

allowDowngrade will be automatically set to true. If this behavior is not suitable for you, simple set allowDowngrade explicitly after.

Parameters
value

string | null

Returns

void

Inherited from

LinuxUpdater.channel


disableWebInstaller

Get Signature

get disableWebInstaller(): boolean

Whether to block NSIS web-installer packages. Web installer files might not have signature verification, so they are disabled by default as of v27.

v27 grace period: apps that do not explicitly set this property will warn (but still download) if a web-installer update is received. In v28 the warning becomes an error and the download is blocked (ERR_UPDATER_WEB_INSTALLER_DISABLED). Apps that explicitly set this to true throw immediately. Set it to false only if you intentionally publish and rely on NSIS web-installer packages.

Default
true
Returns

boolean

Set Signature

set disableWebInstaller(value): void

Parameters
value

boolean

Returns

void

Inherited from

AppImageUpdater.disableWebInstaller


installerPath

Get Signature

get protected installerPath(): string | null

Sanitizes the installer path for use with shell:true spawn calls. Backslash-escapes metacharacters that have special meaning in POSIX shell. Note: paths containing single-quotes (') are not supported.

Returns

string | null

Inherited from

LinuxUpdater.installerPath


isAutoInstallOnNextLaunchSupported

Get Signature

get protected isAutoInstallOnNextLaunchSupported(): boolean

Whether this target supports the automatic autoInstallEvent: "onNextLaunch" install at startup. Targets whose install always requires elevation (deb/rpm/pacman via pkexec/sudo) must not show an authentication prompt at app launch, so they keep the pending update for an explicit installPendingUpdateIfAvailable() call instead.

Returns

boolean

Inherited from

LinuxUpdater.isAutoInstallOnNextLaunchSupported


isUpdateSupported

Get Signature

get isUpdateSupported(): VerifyUpdateSupport

Allows developer to override default logic for determining if an update is supported. The default logic compares the UpdateInfo minimum system version against the os.release() with semver package

Returns

VerifyUpdateSupport

Set Signature

set isUpdateSupported(value): void

Parameters
value

VerifyUpdateSupport

Returns

void

Inherited from

LinuxUpdater.isUpdateSupported


isUserWithinRollout

Get Signature

get isUserWithinRollout(): VerifyUpdateSupport

Allows developer to override default logic for determining if the user is below the rollout threshold. The default logic compares the staging percentage with numerical representation of user ID. An override can define custom logic, or bypass it if needed.

Returns

VerifyUpdateSupport

Set Signature

set isUserWithinRollout(value): void

Parameters
value

VerifyUpdateSupport

Returns

void

Inherited from

LinuxUpdater.isUserWithinRollout


logger

Get Signature

get logger(): Logger | null

The logger. You can pass electron-log, winston or another logger with the following interface: { info(), warn(), error() }. Set it to null if you would like to disable a logging feature.

Returns

Logger | null

Set Signature

set logger(value): void

Parameters
value

Logger | null

Returns

void

Inherited from

LinuxUpdater.logger


netSession

Get Signature

get netSession(): Session

Returns

Session

Inherited from

LinuxUpdater.netSession

Methods

addAuthHeader()

addAuthHeader(token): void

Shortcut for explicitly adding auth tokens to request headers

Parameters

token

string

Returns

void

Inherited from

LinuxUpdater.addAuthHeader


addListener()

addListener<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.addListener


addQuitHandler()

protected addQuitHandler(): void

Returns

void

Inherited from

LinuxUpdater.addQuitHandler


checkForUpdates()

checkForUpdates(): Promise<UpdateCheckResult | null>

Asks the server whether there is an update.

Returns

Promise<UpdateCheckResult | null>

null if the updater is disabled, otherwise info about the latest version

Inherited from

LinuxUpdater.checkForUpdates


checkForUpdatesAndNotify()

checkForUpdatesAndNotify(downloadNotification?): Promise<UpdateCheckResult | null>

Parameters

downloadNotification?

DownloadNotification

Returns

Promise<UpdateCheckResult | null>

Inherited from

LinuxUpdater.checkForUpdatesAndNotify


detectPackageManager()

protected detectPackageManager(pms): string

Detects the package manager to use based on the available commands. Allows overriding the default behavior by setting the ELECTRON_BUILDER_LINUX_PACKAGE_MANAGER environment variable. If the environment variable is set, it will be used directly. (This is useful for testing each package manager logic path.) Otherwise, it checks for the presence of the specified package manager commands in the order provided.

Parameters

pms

string[]

An array of package manager commands to check for, in priority order.

Returns

string

The detected package manager command or "unknown" if none are found.

Inherited from

LinuxUpdater.detectPackageManager


determineSudoCommand()

protected determineSudoCommand(): string

Returns

string

Inherited from

LinuxUpdater.determineSudoCommand


differentialDownloadInstaller()

protected differentialDownloadInstaller(fileInfo, downloadUpdateOptions, installerPath, provider, oldInstallerFileName): Promise<boolean>

Parameters

fileInfo

ResolvedUpdateFileInfo

downloadUpdateOptions

DownloadUpdateOptions

installerPath

string

provider

Provider<any>

oldInstallerFileName

string

Returns

Promise<boolean>

Inherited from

LinuxUpdater.differentialDownloadInstaller


dispatchError()

protected dispatchError(e): void

Parameters

e

Error

Returns

void

Inherited from

LinuxUpdater.dispatchError


dispatchUpdateDownloaded()

protected dispatchUpdateDownloaded(event): void

Parameters

event

UpdateDownloadedEvent

Returns

void

Inherited from

LinuxUpdater.dispatchUpdateDownloaded


doInstall()

protected doInstall(options): boolean

Parameters

options

InstallOptions

Returns

boolean

Overrides

LinuxUpdater.doInstall


downloadUpdate()

downloadUpdate(cancellationToken?): Promise<string[]>

Start downloading update manually. You can use this method if autoDownload option is set to false.

Parameters

cancellationToken?

CancellationToken = ...

Returns

Promise<string[]>

Paths to downloaded files.

Inherited from

LinuxUpdater.downloadUpdate


emit()

emit<U>(event, ...args): boolean

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

args

...Parameters<AppUpdaterEvents[U]>

Returns

boolean

Inherited from

LinuxUpdater.emit


eventNames()

eventNames<U>(): U[]

Type Parameters

U

U extends keyof AppUpdaterEvents

Returns

U[]

Inherited from

LinuxUpdater.eventNames


executeDownload()

protected executeDownload(taskOptions): Promise<string[]>

Parameters

taskOptions

DownloadExecutorTask

Returns

Promise<string[]>

Inherited from

LinuxUpdater.executeDownload


getFeedURL()

getFeedURL(): string | null | undefined

Returns

string | null | undefined

Inherited from

LinuxUpdater.getFeedURL


getMaxListeners()

getMaxListeners(): number

Returns

number

Inherited from

LinuxUpdater.getMaxListeners


getOrCreateDownloadHelper()

protected getOrCreateDownloadHelper(): Promise<DownloadedUpdateHelper>

Returns

Promise<DownloadedUpdateHelper>

Inherited from

LinuxUpdater.getOrCreateDownloadHelper


getUpdateInfoAndProvider()

protected getUpdateInfoAndProvider(): Promise<UpdateInfoAndProvider>

Returns

Promise<UpdateInfoAndProvider>

Inherited from

LinuxUpdater.getUpdateInfoAndProvider


hasCommand()

protected hasCommand(cmd): boolean

Parameters

cmd

string

Returns

boolean

Inherited from

LinuxUpdater.hasCommand


install()

install(isSilent?, isForceRunAfter?): boolean

Parameters

isSilent?

boolean = false

isForceRunAfter?

boolean = false

Returns

boolean

Inherited from

LinuxUpdater.install


installPendingUpdateIfAvailable()

installPendingUpdateIfAvailable(): Promise<boolean>

Installs an update that a previous launch marked as pending (see autoInstallEvent: "onNextLaunch" and quitAndInstall({ waitUntilNextLaunch: true })), then quits the app.

The cached installer is never trusted blindly: a fresh update-info fetch is performed first and the cached file is validated against it (checksum, and code signature where applicable). The pending update is only installed when its version is an installable change from the running app — newer, or older when allowDowngrade is set (a loop guard, mirroring isUpdateAvailable); otherwise the pending state is cleared.

Unlike the automatic startup install, an explicit call is also allowed for targets whose install requires elevation: NSIS per-machine installations (isAdminRightsRequired === true) and Linux package targets (deb, rpm, pacman — installed via pkexec/sudo).

On macOS this resolves to false: Squirrel.Mac already stages downloaded updates natively and applies them when the app is relaunched after quit, so there is no pending-install state managed by electron-updater.

Returns

Promise<boolean>

true if a pending update was validated and its installation was initiated (the app will quit).

Inherited from

LinuxUpdater.installPendingUpdateIfAvailable


isRunningAsRoot()

protected isRunningAsRoot(): boolean

Returns true if the current process is running as root.

Returns

boolean

Inherited from

LinuxUpdater.isRunningAsRoot


isUpdaterActive()

isUpdaterActive(): boolean

Returns

boolean

Inherited from

LinuxUpdater.isUpdaterActive


listenerCount()

listenerCount(type): number

Parameters

type

keyof AppUpdaterEvents

Returns

number

Inherited from

LinuxUpdater.listenerCount


listeners()

listeners<U>(type): AppUpdaterEvents[U][]

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

type

U

Returns

AppUpdaterEvents[U][]

Inherited from

LinuxUpdater.listeners


off()

off<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.off


on()

on<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.on


once()

once<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.once


onUpdateAvailable()

protected onUpdateAvailable(updateInfo): void

Parameters

updateInfo

UpdateInfo

Returns

void

Inherited from

LinuxUpdater.onUpdateAvailable


prependListener()

prependListener<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.prependListener


prependOnceListener()

prependOnceListener<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.prependOnceListener


quitAndInstall()

quitAndInstall(options?): void

Restarts the app and installs the update after it has been downloaded. It should only be called after update-downloaded has been emitted.

Note: autoUpdater.quitAndInstall() will close all application windows first and only emit before-quit event on app after that. This is different from the normal quit event sequence.

Parameters

options?

QuitAndInstallOptions = {}

See QuitAndInstallOptions. When omitted, the installer runs non-silent and the deferred install-on-next-launch flow is not used (same behavior as before the options object was introduced).

Returns

void

Inherited from

LinuxUpdater.quitAndInstall


rawListeners()

rawListeners<U>(type): AppUpdaterEvents[U][]

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

type

U

Returns

AppUpdaterEvents[U][]

Inherited from

LinuxUpdater.rawListeners


removeAllListeners()

removeAllListeners(event?): this

Parameters

event?

keyof AppUpdaterEvents

Returns

this

Inherited from

LinuxUpdater.removeAllListeners


removeListener()

removeListener<U>(event, listener): this

Type Parameters

U

U extends keyof AppUpdaterEvents

Parameters

event

U

listener

AppUpdaterEvents[U]

Returns

this

Inherited from

LinuxUpdater.removeListener


runCommandWithSudoIfNeeded()

protected runCommandWithSudoIfNeeded(commandWithArgs): string

Parameters

commandWithArgs

string[]

Returns

string

Inherited from

LinuxUpdater.runCommandWithSudoIfNeeded


sanitizeEnvPath()

protected sanitizeEnvPath(envPath): string

Strips relative-path entries from a PATH string. Prevents PATH-poisoning where a writable directory earlier in PATH shadows a trusted package manager binary.

Parameters

envPath

string

Returns

string

Inherited from

LinuxUpdater.sanitizeEnvPath


setFeedURL()

setFeedURL(options): void

Configure update provider. If value is string, GenericServerOptions will be set with value as url.

Parameters

options

PublishConfiguration | AllPublishOptions

If you want to override configuration in the app-update.yml.

Returns

void

Inherited from

LinuxUpdater.setFeedURL


setMaxListeners()

setMaxListeners(n): this

Parameters

n

number

Returns

this

Inherited from

LinuxUpdater.setMaxListeners


spawnLog()

protected spawnLog(cmd, args?, env?, stdio?): Promise<boolean>

This handles both node 8 and node 10 way of emitting error when spawning a process

  • node 8: Throws the error
  • node 10: Emit the error(Need to listen with on)

Parameters

cmd

string

args?

string[] = []

env?

any = undefined

stdio?

StdioOptions = "ignore"

Returns

Promise<boolean>

Inherited from

LinuxUpdater.spawnLog


spawnSyncLog()

protected spawnSyncLog(cmd, args?, env?): string

Parameters

cmd

string

args?

string[] = []

env?

Returns

string

Inherited from

LinuxUpdater.spawnSyncLog


sudoWithArgs()

protected sudoWithArgs(installComment): string[]

Parameters

installComment

string

Returns

string[]

Inherited from

LinuxUpdater.sudoWithArgs


verifyInstallerSignatureOnLaunch()

protected verifyInstallerSignatureOnLaunch(_installerPath): Promise<string | null>

Re-verification of the cached installer's code signature before an install-on-next-launch is executed. Platforms without installer signature verification resolve to null (no error).

Parameters

_installerPath

string

Returns

Promise<string | null>

Inherited from

LinuxUpdater.verifyInstallerSignatureOnLaunch


installWithCommandRunner()

static installWithCommandRunner(installerPath, commandRunner, logger): void

Parameters

installerPath

string

commandRunner

(commandWithArgs) => void

logger

Logger

Returns

void