Updater
carbon add plugin UpdaterConfigure endpoints and the public signing key under bundle.updater, then grant updater:*.
import { updater } from '@dotcarbon/plugin-updater'
const update = await updater.check()if (update.available) { const download = await updater.download() console.log(download.signatureVerified, download.path) await updater.installAndRestart({ path: download.path })}Downloads are checked against the manifest SHA-256 and ECDSA signature before installation. The private key belongs only in CI; applications embed the public key used for verification.
See Updater artifacts for release-side signing and manifest generation.
