Updater artifacts
Generate an ECDSA P-256 key pair once:
carbon signer generate --output carbon-updater.keyCommit or distribute the public key. Never commit the private key.
{ "bundle": { "updater": { "active": true, "createArtifacts": true, "endpoints": [ "https://updates.example.com/{{target}}/{{version}}/{{artifact}}" ], "publicKey": "BASE64_SUBJECT_PUBLIC_KEY_INFO" } }}Provide the private PEM or its path through CARBON_UPDATER_PRIVATE_KEY, then bundle:
carbon bundle desktop --updater-artifactsCarbon emits signatures and update JSON beside the package. Metadata includes version, target, artifact name, URL, byte size, SHA-256, algorithm, public key, and ECDSA signature. The build fails if the private key does not match the configured public key.
Upload the package, signature, and manifest without modifying them. The Updater plugin checks both the digest and signature before launching an installer.
