You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
f6c1eb253 (#15401) Added bundle.windows.bundleVCRuntime to copy the Visual C++ runtime DLLs into Windows MSI and NSIS installers. The bundler locates the runtime through VCTOOLS_REDIST_DIR or the bundled vswhere.exe.
f76b1d3ae (#15644) The bundler now prints the size of each generated bundle next to its path in the Finished N bundles at: output (directories such as macOS .app bundles are measured recursively).
af465eae1 (#15619) Add a --no-binary-patching flag to tauri build and tauri bundle. When set, the bundler skips patching the main executable with bundle type information (and the subsequent re-signing), leaving an already-signed binary untouched. Patching is only required when shipping multiple bundle types per platform that should each update with their own installer format.
0646cc162 (#15620) Add a --fit option to tauri icon to accept non-square source images. --fit cover center-crops the source to a square (clipping the longer side) and --fit contain pads the shorter side with transparency. Non-square sources without --fit keep erroring, now with a hint pointing to the flag.
f6c1eb253 (#15401) Added build.windows.staticVCRuntime to control MSVC static runtime linking. The STATIC_VCRUNTIME environment variable is now deprecated and emits a migration warning when used.
f45ec0dcf Record the app version in the trusted comment of updater signatures, so a signed artifact is bound to the version it was released as.
An update endpoint response is not signed, and the signature only covers the downloaded artifact, so the announced version on its own does not prove which release the url and signature point at. minisign covers the trusted comment with its global signature, which lets the updater plugin compare the two and reject a response that pairs a version number with a different release. Enable requireSignedVersion in the updater plugin configuration to enforce this.
tauri build fills the version in automatically, and tauri plugin add updater now enables requireSignedVersion for the project it is adding the plugin to. tauri signer sign gains an --app-version flag for signing updater artifacts by hand, and warns when it is omitted.
Enhancements
e19121427 (#15993) Don't always rewrite Cargo.toml file from CRLF line endings to LF
aebf38c84 (#15694) Migrate the Android Gradle scripts from the deprecated kotlinOptions DSL to compilerOptions, which is accepted by both Kotlin Gradle Plugin 1.9.x and 2.x. This lets projects move to Kotlin 2.x without hitting the hard error that 2.3+ raises on the old DSL.
This increased the minimum supported Gradle version to 8.13, if your gradle is on an earlier version, delete src-tauri/gen/android/gradle/wrapper/gradle-wrapper.properties and re-run tauri android init to update it.
d89d8fa62 (#15780) Warn during Android commands (init/dev/build) when the active Java version is too new for the Gradle version the project uses (e.g. Java 27 against the Gradle 9.6.1 the template ships, or Java 25 against a project still on Gradle 8.14), instead of letting the build fail later with a cryptic error. The warning points to the Gradle/Java compatibility matrix and suggests a supported JDK.
c3d21bd60 (#15730) Use Theme.Material3.DayNight.NoActionBar instead of Theme.MaterialComponents.DayNight.NoActionBar when running tauri android init
cdaf7eab6 (#15765) Clarify that the tauri init frontend commands run before tauri dev and tauri build, and can be left empty when they are not needed.
d0f38df06 (#15997) When stdin is not a terminal, tauri init now automatically skips prompts, avoiding IO errors in CI and scripts. This eliminates the need to pass --ci explicitly in non-interactive environments.
ca160ad48 (#15895) tauri build now warns when productName is still set to the default tauri-app, since it names the generated bundles and is written into install paths and metadata that are expected to be unique to your application. The config documentation for productName now lists what the field controls on each platform, and identifier's documentation notes that the default value is rejected.
010f06bae (#15737) Document the TAURI_SIGNING_PRIVATE_KEY_PATH environment variable and clarify that TAURI_SIGNING_PRIVATE_KEY accepts a string or a path for the build and bundle command but must be the literal key string for the signer sign command, both in ENVIRONMENT_VARIABLES.md and in the signer generate command output.
Bug Fixes
9bad06b9f (#16096) tauri capability new and tauri permission new now accept an --out path to a file that does not exist yet, trim comma-separated prompt answers (so fs:default, core:default works), report invalid permissions as errors instead of panicking, and reject identifiers that are not valid file names (such as ../../x), which previously let them write outside of the capabilities or permissions directory.
9642b3087 (#16117) tauri add now honors --tag, --rev and --branch for official plugins instead of silently installing the registry version, and rejects passing more than one of them. With npm, the JS package requirement is now ~<version> like the other package managers, instead of >=<version> which allowed a later major version.
cada1cd4f (#16105) Fix Android dev server port forwarding: adb reverse --list is now matched on the exact port (so tcp:80 no longer matches tcp:8080), stale forwards on other connected devices are actually removed, and the forward verification gives up with a warning after a few attempts instead of retrying forever.
d5bd04658 (#16111) Fix bundle > android > debugApplicationIdSuffix being written to the signingConfigs debug block instead of the buildTypes one, and keep the existing content of single-line debug blocks such as getByName("debug") { isDebuggable = true } instead of dropping it.
ba17da2e5 (#16101) tauri icon now generates 72x72 Android hdpi launcher icons (previously 49x49) and writes the Android launcher background color in #RRGGBB/#AARRGGBB notation instead of the raw CSS color string, which Android rejected or misread. Invalid SVG sources and --png 0 now return an error instead of panicking.
272842a57 (#16128) Fix error messages that printed placeholders such as {t} literally instead of the value, e.g. "Could not find an Android device matching {t}".
10ad4e54e (#16127) The Bash completions generated by tauri completions no longer replace the completions of cargo, npm, pnpm, yarn, bun and deno. They now define a _tauri_cli function registered only for the tauri and cargo-tauri commands. Generating completions when running the cargo-tauri binary directly no longer panics.
0e4ded72a (#16107) Fix binaries in src/bin and src/main.rs being left out of bundles when Cargo.toml declares a [[bin]] target without a path.
8e0fa2e2f (#16097) Fix the bundler using the host target triple when --target is not passed but build.target is set in .cargo/config.toml. The CLI now also accepts build.target as an array and honors the CARGO_BUILD_TARGET environment variable.
7bb0a5421 (#16120) Fix the Cargo.toml feature rewrite corrupting a string dependency version that has a trailing comment or uses single quotes (e.g. tauri = "2" # pin became "2#pin"). The version value is now kept as-is and the comment is preserved.
e4630258e (#16114) Fix the CLI's working directory being left changed to the config directory when the Tauri configuration fails to parse, for example when tauri dev reloads an invalid config.
1b91b7b7b (#16102) tauri info now logs a warning when it cannot check the latest crate version on crates.io instead of silently ignoring the failure, and no longer panics if crates.io returns a version it cannot parse.
1b91b7b7b (#16102) tauri info now lists every locked version of a Rust crate when Cargo.lock contains more than one, and no longer panics when the crates.io response cannot be parsed.
6507d0b8b (#16124) tauri dev now reports an error instead of panicking when the beforeDevCommand cannot be spawned or the devUrl host cannot be resolved, and no longer risks stopping the beforeDevCommand process tree twice when Ctrl+C and the app exit race.
c1ea96ad6 (#16110) Fix tauri dev not reacting to the app exiting when a process spawned by the app kept its stderr open, and stop keeping the whole app stderr output in memory. Also fix command output capture that could return empty output when the command finished before its output was read.
d61fbdc3e (#16109) Fix Cargo.toml feature injection and the v1 migration only updating either [dependencies] or [target.'cfg(..)'.dependencies], whichever came first in the file. Both the main and all target-specific dependency tables are now updated.
5d995ed35 (#16017) Normalize gen/android/gradlew CRLF line endings to LF on all host platforms, not only Unix. A gradlew checked out with CRLF broke sh ./gradlew on Windows hosts using Git Bash. The rewrite only runs when a CRLF is actually present. A failure to rewrite aborts on Unix, where the script is executed directly; on Windows the CLI invokes gradlew.bat, so failures there only warn.
6d943c420 (#16065) Fix the tauri capability new command description, which said "Create a new permission file", and the --skip-stapling help text on tauri build and tauri bundle, whose first line described the opposite of what the flag does.
b8be924d3 (#16106) tauri init no longer panics when the app name, window title, frontend dist, dev URL or before dev/build commands contain quotes or backslashes (e.g. -D ..\dist or vite --host "0.0.0.0"); the values are now JSON-escaped in the generated tauri.conf.json.
b9b32a259 (#16108) Fix PRODUCT_BUNDLE_IDENTIFIER in the iOS Xcode project being set to the raw identifier (with underscores) instead of the sanitized iOS bundle identifier used by the Xcode project template and the export options provisioning profiles.
4f51a2f06 (#16115) Fix tauri ios run --features being ignored, and tauri ios dev --release still building the app in debug mode.
59e077457 (#16075) tauri ios build for a simulator target no longer fails with "failed to rename app: Directory not empty" when the output .app from a previous build exists.
fe1aa30d2 (#16113) Quote the Tauri CLI path and the Xcode variables in the iOS "Build Rust Code" build phase, fixing builds when Xcode or the CLI is installed in a path containing spaces (requires regenerating the Xcode project with tauri ios init). Also fixes CXXFLAGS not being set for iOS targets in tauri ios xcode-script.
aa0a801c3 (#16116) Fix Java version detection for the Android Java/Gradle compatibility warning when JAVA_HOME is not set: the java binary on PATH is now resolved through symlinks (e.g. Linux alternatives and Homebrew), and on macOS the /usr/bin/java stub falls back to /usr/libexec/java_home.
1aafaa4e3 (#16103) When rewriting a localhost devUrl to the network address for mobile development, the query string and fragment are now preserved, and the IPv6 loopback ([::1]) and unspecified ([::]) addresses are now treated as localhost.
022932dd5 (#16123) Fix iOS Xcode project synchronization corrupting project.pbxproj when several build settings were added to the same configuration, when an added setting was changed again, or when a multi-line setting was overwritten. Product names, signing identities and other values written to the project are now properly escaped.
a4099d819 (#16098) tauri permission add (and tauri add) no longer overwrites an existing capabilities/desktop.json or capabilities/mobile.json when adding a desktop-only or mobile-only plugin permission and no platform-restricted capability exists; the new capability now gets an unused file name and identifier (e.g. desktop-2.json). An explicitly passed capability is now used even if its platforms do not match the plugin, with a warning, instead of being silently ignored.
e49d1b474 (#16100) tauri permission rm <plugin>:* and tauri remove no longer strip unrelated permissions whose identifier merely contains the plugin name (e.g. tauri remove os removing positioner:default). Local permission files are now looked up in the Tauri directory, like tauri permission new, and an unparsable permission file is skipped with a warning instead of aborting the command.
efa82f5ed (#16125) Fix plugin scaffolding for names like my-plugin: the default Android package ID now uses a snake_case segment (com.plugin.my_plugin) and user-provided IDs are validated, iOS Xcode folders use the same kebab-case name as the project file, and the plugin ios init/plugin android init code snippets now match the generated bindings and the setup(|app, api| ..) API. plugin init into a non-empty directory no longer creates a permissions folder after skipping the template.
db6804d80 (#16126) Fix --release being added to the cargo command when a custom profile is passed as --profile=<name>, which made cargo reject the build.
8310461f6 (#16104) Fix tauri init and tauri info detecting SvelteKit projects as plain Svelte; tauri init suggested the wrong dev server URL and frontend dist directory.
eaf96690d (#15804) On Linux, do not bundle xdg-open and xdg-utils in the AppImage anymore. This rarely worked and usually requires host system support anyway.
2b7c1f8b6 (#16003) Fix tauri add / tauri remove installing npm plugin packages into src-tauri instead of the frontend directory.
c735ba32b (#15241) Fix broken child window icons in Task Manager, you'll need to re-run tauri icon to generate the fixed icons
adf5acf6f (#15651) Fix MSI bundling when an external binary filename starts with a digit.
59e077457 (#16075) Detect pnpm from npm_config_user_agent when generating the mobile projects. pnpm's native binary (pnpm 11+) runs package scripts without setting PNPM_PACKAGE_NAME, and when installed through corepack the binary is named pnpm-native, so tauri android init recorded pnpm-native as the command for Gradle to run and the Android build failed with "A problem occurred starting process 'command 'pnpm-native''".
6a298ee12 (#15713) Fix tauri info reporting the Rust-only plugins (localhost, persisted-scope and single-instance) as missing their @tauri-apps/plugin-* JavaScript package, which is never published for those plugins.
33b3ea582 The bundled vswhere.exe is now written to a new, uniquely named temporary file on each use and removed afterwards, instead of running any existing %TEMP%\vswhere.exe.
What's Changed
2e6e33c85 (#16029) Moved to edition 2024 for the tauri init/tauri plugin init templates
ce3f13b91 (#15887) Lock unstable tauri crates to minor versions.
Security fixes
98918df64 (#16112) tauri add no longer installs the npm package tauri-plugin-<name>-api for community plugins. npm and crates.io are separate namespaces, so that package may be unowned or squatted; the CLI now asks you to install the plugin's JavaScript bindings yourself. tauri remove only removes the plugin's JS package when package.json lists it, and a failure there no longer skips the capability cleanup.
cc9d522c6 (#16095) The built-in dev server now rejects requests whose Host header is not the address it serves on, which blocks DNS rebinding attacks, and rejects cross-site Origins on its reload WebSocket. The index.html fallback now goes through the same path scope check as other files, and the reload WebSocket no longer closes when the client sends a message.
dacddfe9f (#16094) The CLI no longer writes its default ignore rules to shared files in the system temporary directory (.gitignore and .tauri/.gitignore) and reads them back, which let other local users change which files the project lookup and the dev watcher skip. The rules are now applied in memory. TAURI_CLI_WATCHER_IGNORE_FILENAME is now consistently treated as an ignore file name looked up in each directory, as documented.
fdd56da19 (#16099) Secure the local server that tauri android|ios dev|build uses to pass options to the Android Studio and Xcode build scripts: requests now need a random per-session token, WebSocket connections from web pages (with an Origin header) are rejected, and variables whose name contains TOKEN, PASSWORD, SECRET or CREDENTIAL are no longer sent. The connection details are now written with owner-only permissions to gen/<android|apple>/.tauri/cli-options-server.json (instead of the shared temp directory) and removed when the command exits. The IDE build scripts now report a clear error when the Tauri CLI command is not running.
ff7cd8d86 (#16118) tauri signer generate --write-keys now creates the private key with owner-only permissions (0600) on Unix and refuses to overwrite either the private or the public key file without --force. Updater signing now rejects file names containing tabs or newlines (which would corrupt the signature's trusted comment) and assumes an empty password instead of prompting when no password is given and stdin is not a terminal. tauri signer reports errors instead of panicking.
51aa20388 (#16119) On Windows, package manager commands (npm, pnpm, yarn, bun, deno, node) are now executed directly instead of through cmd /c, so arguments such as @tauri-apps/plugin-fs@>=2 are escaped properly and can no longer be interpreted as shell redirections or command separators.
Dependencies
Upgraded to tauri-cli@2.12.0
e2e585ad1 (#15828) On Android, fix missing consumer-rules.pro file in the template.
IMPORTANT: For plugin authors, update your build.gradle.kts file to remove the
section and rename your proguard-rules.pro to consumer-rules.pro to match the consumerProguardFiles("consumer-rules.pro") in the template.
e2e585ad1 (#15828) On Android, updated the template to use Gradle v9.6.1 (com.android.tools.build:gradle v9.3.1) and Kotlin v2.2. Use tauri android init to apply the change.
9e9a54dea (#15890) Update the generated iOS Xcode project to build with Xcode 27. The scenes lifecycle is not enabled by default: to opt in, add the UIApplicationSceneManifest key to your src-tauri/Info.ios.plist.
b6660a041 (#15954) Update typescript to v7 in tauri plugin init template. Also fixes the default rootDir in the template tsconfig.json
9e9a54dea (#15890) Update cargo-mobile2 and change the default minimum iOS version to 15.0 to support Xcode 27.
5a87bab12 Record the app version in the trusted comment of updater signatures, so a signed artifact is bound to the version it was released as.
An update endpoint response is not signed, and the signature only covers the downloaded artifact, so the announced version on its own does not prove which release the url and signature point at. minisign covers the trusted comment with its global signature, which lets the updater plugin compare the two and reject a response that pairs a version number with a different release. Enable requireSignedVersion in the updater plugin configuration to enforce this.
tauri build fills the version in automatically, and tauri plugin add updater now enables requireSignedVersion for the project it is adding the plugin to. tauri signer sign gains an --app-version flag for signing updater artifacts by hand, and warns when it is omitted.
67ffa192a (#15596 by @FabianLars) Fixed an issue in the AppImage bundler that caused the /.desktop and .DirIcon files to be absolute symlinks instead of relative symlinks which caused problems with AppImage installers like AppManager.
fca4a31f9 (#15454 by @fallintoplace) Fix tauri migrate generating invalid namespace imports for aliased pluginified imports from @tauri-apps/api.
Inputs like import { cli as superCli } from "@tauri-apps/api" now migrate to import * as superCli from "@tauri-apps/plugin-cli" instead of producing invalid ESM syntax. The migration tests also reparse migrated JS, Svelte, and Vue output so syntax regressions are caught directly.
926a57bb0 (#15201) Added uninstaller icon and uninstaller header image support for NSIS installer.
Notes:
For tauri-bundler lib users, the NsisSettings now has 2 new fields uninstaller_icon and uninstaller_header_image which can be a breaking change
When bundling with NSIS, users can add uninstallerIcon and uninstallerHeaderImage under bundle > windows > nsis to configure them.
764b9139a (#14313) Prompt to restart the Android emulator if it is not connected to adb.
5dc2cee60 (#14793) Added support for minimumWebview2Version option support for the MSI (Wix) installer, the old bundle > windows > nsis > minimumWebview2Version is now deprecated in favor of bundle > windows > minimumWebview2Version
Notes:
For anyone relying on the WVRTINSTALLEDProperty tag in main.wxs, it is now renamed to INSTALLED_WEBVIEW2_VERSION
For tauri-bundler lib users, the WindowsSettings now has a new field minimum_webview2_version which can be a breaking change
Enhancements
be0e4bd2d (#15218) Added Vietnamese translations for the NSIS installer
8718d0816 (#15033) Show the context before prompting for updater signing key password
Bug Fixes
fcb702ec4 (#14954) Fix build --bundles to allow nsis arg in linux+macOS
80c1425af (#14921) Fix iOS build failure when Metal Toolchain is installed by using explicit $(DEVELOPER_DIR)/Toolchains/XcodeDefault.xctoolchain path instead of $(TOOLCHAIN_DIR) for Swift library search paths.
33754ae5e (#15022 by @Legend-Master) Fix updater signing private keys generated using tauri signer generate with empty password can't be used (The keys generated during tauri were broken between v2.9.3 and v2.10.0, you'll need to regenerate them)
a2abe2e6b (#14607 by @sftse) Simplified internal representation of features: Option<Vec<String>> with Vec<String>, no user facing changes
84b04c4a8 (#14759 by @amrbashir) Added new environment variables for tauri signer sign command, to align with existing environment variables used in tauri build, tauri bundle and tauri signer generate
TAURI_SIGNING_PRIVATE_KEY
TAURI_SIGNING_PRIVATE_KEY_PATH
TAURI_SIGNING_PRIVATE_KEY_PASSWORD
The old environment variables are deprecated and will be removed in a future release.
Use an alternative method CreateProcessWithTokenW to run programs as user, this fixed a problem that the program launched with the previous method can't query its own handle
53611c4d7 (#14747 by @Legend-Master) Only watch dependent workspace members when running tauri dev instead of watching on all members
0575dd287 (#14521 by @kandrelczyk) Change the way bundle type information is added to binary files. Instead of looking up the value of a variable we simply look for the default value.
7f7d9aac2 (#14668 by @sftse) Refactored internal use of static on config and directory resolvings, no user facing changes, please report any regressions if you encounter any
3b4fac201 (#14194) Add tauri.conf.json > bundle > android > autoIncrementVersionCode config option to automatically increment the Android version code.
673867aa0 (#14094) Try to detect ANDROID_HOME and NDK_HOME environment variables from default system locations and install them if needed using the Android Studio command line tools.
3d6868d09 (#14128) Added support to defining the content type of the declared file association on macOS (maps to LSItemContentTypes property).
3d6868d09 (#14128) Added support to defining the metadata for custom types declared in tauri.conf.json > bundle > fileAssociations > exportedType via the UTExportedTypeDeclarations Info.plist property.
f70b28529 (#14093 by @lucasfernog) Ensure Rust targets for mobile are installed when running the dev and build commands (previously only checked on init).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.6.3→2.12.01.6.2→2.0.01.5.1→2.0.0Release Notes
tauri-apps/tauri (@tauri-apps/cli)
v2.12.0: @tauri-apps/cli v2.12.0Compare Source
[2.12.0]
New Features
f6c1eb253(#15401) Addedbundle.windows.bundleVCRuntimeto copy the Visual C++ runtime DLLs into Windows MSI and NSIS installers. The bundler locates the runtime throughVCTOOLS_REDIST_DIRor the bundledvswhere.exe.f76b1d3ae(#15644) The bundler now prints the size of each generated bundle next to its path in theFinished N bundles at:output (directories such as macOS.appbundles are measured recursively).af465eae1(#15619) Add a--no-binary-patchingflag totauri buildandtauri bundle. When set, the bundler skips patching the main executable with bundle type information (and the subsequent re-signing), leaving an already-signed binary untouched. Patching is only required when shipping multiple bundle types per platform that should each update with their own installer format.0646cc162(#15620) Add a--fitoption totauri iconto accept non-square source images.--fit covercenter-crops the source to a square (clipping the longer side) and--fit containpads the shorter side with transparency. Non-square sources without--fitkeep erroring, now with a hint pointing to the flag.f6c1eb253(#15401) Addedbuild.windows.staticVCRuntimeto control MSVC static runtime linking. TheSTATIC_VCRUNTIMEenvironment variable is now deprecated and emits a migration warning when used.f45ec0dcfRecord the app version in the trusted comment of updater signatures, so a signed artifact is bound to the version it was released as.An update endpoint response is not signed, and the signature only covers the downloaded artifact, so the announced
versionon its own does not prove which release theurlandsignaturepoint at. minisign covers the trusted comment with its global signature, which lets the updater plugin compare the two and reject a response that pairs a version number with a different release. EnablerequireSignedVersionin the updater plugin configuration to enforce this.tauri buildfills the version in automatically, andtauri plugin add updaternow enablesrequireSignedVersionfor the project it is adding the plugin to.tauri signer signgains an--app-versionflag for signing updater artifacts by hand, and warns when it is omitted.Enhancements
e19121427(#15993) Don't always rewriteCargo.tomlfile from CRLF line endings to LFaebf38c84(#15694) Migrate the Android Gradle scripts from the deprecatedkotlinOptionsDSL tocompilerOptions, which is accepted by both Kotlin Gradle Plugin 1.9.x and 2.x. This lets projects move to Kotlin 2.x without hitting the hard error that 2.3+ raises on the old DSL.This increased the minimum supported Gradle version to 8.13, if your
gradleis on an earlier version, deletesrc-tauri/gen/android/gradle/wrapper/gradle-wrapper.propertiesand re-runtauri android initto update it.d89d8fa62(#15780) Warn during Android commands (init/dev/build) when the active Java version is too new for the Gradle version the project uses (e.g. Java 27 against the Gradle 9.6.1 the template ships, or Java 25 against a project still on Gradle 8.14), instead of letting the build fail later with a cryptic error. The warning points to the Gradle/Java compatibility matrix and suggests a supported JDK.c3d21bd60(#15730) UseTheme.Material3.DayNight.NoActionBarinstead ofTheme.MaterialComponents.DayNight.NoActionBarwhen runningtauri android initf654f470c(#15862) Update template to usetargetSdk = 37cdaf7eab6(#15765) Clarify that thetauri initfrontend commands run beforetauri devandtauri build, and can be left empty when they are not needed.d0f38df06(#15997) When stdin is not a terminal,tauri initnow automatically skips prompts, avoiding IO errors in CI and scripts. This eliminates the need to pass--ciexplicitly in non-interactive environments.ca160ad48(#15895)tauri buildnow warns whenproductNameis still set to the defaulttauri-app, since it names the generated bundles and is written into install paths and metadata that are expected to be unique to your application. The config documentation forproductNamenow lists what the field controls on each platform, andidentifier's documentation notes that the default value is rejected.010f06bae(#15737) Document theTAURI_SIGNING_PRIVATE_KEY_PATHenvironment variable and clarify thatTAURI_SIGNING_PRIVATE_KEYaccepts a string or a path for thebuildandbundlecommand but must be the literal key string for thesigner signcommand, both inENVIRONMENT_VARIABLES.mdand in thesigner generatecommand output.Bug Fixes
9bad06b9f(#16096)tauri capability newandtauri permission newnow accept an--outpath to a file that does not exist yet, trim comma-separated prompt answers (sofs:default, core:defaultworks), report invalid permissions as errors instead of panicking, and reject identifiers that are not valid file names (such as../../x), which previously let them write outside of the capabilities or permissions directory.9642b3087(#16117)tauri addnow honors--tag,--revand--branchfor official plugins instead of silently installing the registry version, and rejects passing more than one of them. With npm, the JS package requirement is now~<version>like the other package managers, instead of>=<version>which allowed a later major version.cada1cd4f(#16105) Fix Android dev server port forwarding:adb reverse --listis now matched on the exact port (sotcp:80no longer matchestcp:8080), stale forwards on other connected devices are actually removed, and the forward verification gives up with a warning after a few attempts instead of retrying forever.d5bd04658(#16111) Fixbundle > android > debugApplicationIdSuffixbeing written to thesigningConfigsdebug block instead of thebuildTypesone, and keep the existing content of single-line debug blocks such asgetByName("debug") { isDebuggable = true }instead of dropping it.ba17da2e5(#16101)tauri iconnow generates 72x72 Androidhdpilauncher icons (previously 49x49) and writes the Android launcher background color in#RRGGBB/#AARRGGBBnotation instead of the raw CSS color string, which Android rejected or misread. Invalid SVG sources and--png 0now return an error instead of panicking.272842a57(#16128) Fix error messages that printed placeholders such as{t}literally instead of the value, e.g. "Could not find an Android device matching {t}".10ad4e54e(#16127) The Bash completions generated bytauri completionsno longer replace the completions ofcargo,npm,pnpm,yarn,bunanddeno. They now define a_tauri_clifunction registered only for thetauriandcargo-tauricommands. Generating completions when running thecargo-tauribinary directly no longer panics.0e4ded72a(#16107) Fix binaries insrc/binandsrc/main.rsbeing left out of bundles whenCargo.tomldeclares a[[bin]]target without apath.8e0fa2e2f(#16097) Fix the bundler using the host target triple when--targetis not passed butbuild.targetis set in.cargo/config.toml. The CLI now also acceptsbuild.targetas an array and honors theCARGO_BUILD_TARGETenvironment variable.7bb0a5421(#16120) Fix the Cargo.toml feature rewrite corrupting a string dependency version that has a trailing comment or uses single quotes (e.g.tauri = "2" # pinbecame"2#pin"). The version value is now kept as-is and the comment is preserved.e4630258e(#16114) Fix the CLI's working directory being left changed to the config directory when the Tauri configuration fails to parse, for example whentauri devreloads an invalid config.1b91b7b7b(#16102)tauri infonow logs a warning when it cannot check the latest crate version on crates.io instead of silently ignoring the failure, and no longer panics if crates.io returns a version it cannot parse.1b91b7b7b(#16102)tauri infonow lists every locked version of a Rust crate whenCargo.lockcontains more than one, and no longer panics when the crates.io response cannot be parsed.6507d0b8b(#16124)tauri devnow reports an error instead of panicking when thebeforeDevCommandcannot be spawned or thedevUrlhost cannot be resolved, and no longer risks stopping thebeforeDevCommandprocess tree twice when Ctrl+C and the app exit race.c1ea96ad6(#16110) Fixtauri devnot reacting to the app exiting when a process spawned by the app kept its stderr open, and stop keeping the whole app stderr output in memory. Also fix command output capture that could return empty output when the command finished before its output was read.d61fbdc3e(#16109) Fix Cargo.toml feature injection and the v1 migration only updating either[dependencies]or[target.'cfg(..)'.dependencies], whichever came first in the file. Both the main and all target-specific dependency tables are now updated.5d995ed35(#16017) Normalizegen/android/gradlewCRLF line endings to LF on all host platforms, not only Unix. Agradlewchecked out with CRLF brokesh ./gradlewon Windows hosts using Git Bash. The rewrite only runs when a CRLF is actually present. A failure to rewrite aborts on Unix, where the script is executed directly; on Windows the CLI invokesgradlew.bat, so failures there only warn.6d943c420(#16065) Fix thetauri capability newcommand description, which said "Create a new permission file", and the--skip-staplinghelp text ontauri buildandtauri bundle, whose first line described the opposite of what the flag does.b8be924d3(#16106)tauri initno longer panics when the app name, window title, frontend dist, dev URL or before dev/build commands contain quotes or backslashes (e.g.-D ..\distorvite --host "0.0.0.0"); the values are now JSON-escaped in the generatedtauri.conf.json.b9b32a259(#16108) FixPRODUCT_BUNDLE_IDENTIFIERin the iOS Xcode project being set to the rawidentifier(with underscores) instead of the sanitized iOS bundle identifier used by the Xcode project template and the export options provisioning profiles.4f51a2f06(#16115) Fixtauri ios run --featuresbeing ignored, andtauri ios dev --releasestill building the app in debug mode.59e077457(#16075)tauri ios buildfor a simulator target no longer fails with "failed to rename app: Directory not empty" when the output.appfrom a previous build exists.fe1aa30d2(#16113) Quote the Tauri CLI path and the Xcode variables in the iOS "Build Rust Code" build phase, fixing builds when Xcode or the CLI is installed in a path containing spaces (requires regenerating the Xcode project withtauri ios init). Also fixesCXXFLAGSnot being set for iOS targets intauri ios xcode-script.aa0a801c3(#16116) Fix Java version detection for the Android Java/Gradle compatibility warning whenJAVA_HOMEis not set: thejavabinary onPATHis now resolved through symlinks (e.g. Linux alternatives and Homebrew), and on macOS the/usr/bin/javastub falls back to/usr/libexec/java_home.1aafaa4e3(#16103) When rewriting a localhostdevUrlto the network address for mobile development, the query string and fragment are now preserved, and the IPv6 loopback ([::1]) and unspecified ([::]) addresses are now treated as localhost.022932dd5(#16123) Fix iOS Xcode project synchronization corruptingproject.pbxprojwhen several build settings were added to the same configuration, when an added setting was changed again, or when a multi-line setting was overwritten. Product names, signing identities and other values written to the project are now properly escaped.a4099d819(#16098)tauri permission add(andtauri add) no longer overwrites an existingcapabilities/desktop.jsonorcapabilities/mobile.jsonwhen adding a desktop-only or mobile-only plugin permission and no platform-restricted capability exists; the new capability now gets an unused file name and identifier (e.g.desktop-2.json). An explicitly passed capability is now used even if its platforms do not match the plugin, with a warning, instead of being silently ignored.e49d1b474(#16100)tauri permission rm <plugin>:*andtauri removeno longer strip unrelated permissions whose identifier merely contains the plugin name (e.g.tauri remove osremovingpositioner:default). Local permission files are now looked up in the Tauri directory, liketauri permission new, and an unparsable permission file is skipped with a warning instead of aborting the command.efa82f5ed(#16125) Fix plugin scaffolding for names likemy-plugin: the default Android package ID now uses a snake_case segment (com.plugin.my_plugin) and user-provided IDs are validated, iOS Xcode folders use the same kebab-case name as the project file, and theplugin ios init/plugin android initcode snippets now match the generated bindings and thesetup(|app, api| ..)API.plugin initinto a non-empty directory no longer creates apermissionsfolder after skipping the template.db6804d80(#16126) Fix--releasebeing added to the cargo command when a custom profile is passed as--profile=<name>, which made cargo reject the build.8310461f6(#16104) Fixtauri initandtauri infodetecting SvelteKit projects as plain Svelte;tauri initsuggested the wrong dev server URL and frontend dist directory.eaf96690d(#15804) On Linux, do not bundle xdg-open and xdg-utils in the AppImage anymore. This rarely worked and usually requires host system support anyway.2b7c1f8b6(#16003) Fixtauri add/tauri removeinstalling npm plugin packages intosrc-tauriinstead of the frontend directory.c735ba32b(#15241) Fix broken child window icons in Task Manager, you'll need to re-runtauri iconto generate the fixed iconsadf5acf6f(#15651) Fix MSI bundling when an external binary filename starts with a digit.11012a13f(#15681) Fix WiX bundler doesn't respect the resource's target file name.59e077457(#16075) Detect pnpm fromnpm_config_user_agentwhen generating the mobile projects. pnpm's native binary (pnpm 11+) runs package scripts without settingPNPM_PACKAGE_NAME, and when installed through corepack the binary is namedpnpm-native, sotauri android initrecordedpnpm-nativeas the command for Gradle to run and the Android build failed with "A problem occurred starting process 'command 'pnpm-native''".6a298ee12(#15713) Fixtauri inforeporting the Rust-only plugins (localhost,persisted-scopeandsingle-instance) as missing their@tauri-apps/plugin-*JavaScript package, which is never published for those plugins.33b3ea582The bundledvswhere.exeis now written to a new, uniquely named temporary file on each use and removed afterwards, instead of running any existing%TEMP%\vswhere.exe.What's Changed
2e6e33c85(#16029) Moved to edition 2024 for thetauri init/tauri plugin inittemplatesce3f13b91(#15887) Lock unstable tauri crates to minor versions.Security fixes
98918df64(#16112)tauri addno longer installs the npm packagetauri-plugin-<name>-apifor community plugins. npm and crates.io are separate namespaces, so that package may be unowned or squatted; the CLI now asks you to install the plugin's JavaScript bindings yourself.tauri removeonly removes the plugin's JS package whenpackage.jsonlists it, and a failure there no longer skips the capability cleanup.cc9d522c6(#16095) The built-in dev server now rejects requests whoseHostheader is not the address it serves on, which blocks DNS rebinding attacks, and rejects cross-siteOrigins on its reload WebSocket. Theindex.htmlfallback now goes through the same path scope check as other files, and the reload WebSocket no longer closes when the client sends a message.dacddfe9f(#16094) The CLI no longer writes its default ignore rules to shared files in the system temporary directory (.gitignoreand.tauri/.gitignore) and reads them back, which let other local users change which files the project lookup and the dev watcher skip. The rules are now applied in memory.TAURI_CLI_WATCHER_IGNORE_FILENAMEis now consistently treated as an ignore file name looked up in each directory, as documented.fdd56da19(#16099) Secure the local server thattauri android|ios dev|builduses to pass options to the Android Studio and Xcode build scripts: requests now need a random per-session token, WebSocket connections from web pages (with anOriginheader) are rejected, and variables whose name containsTOKEN,PASSWORD,SECRETorCREDENTIALare no longer sent. The connection details are now written with owner-only permissions togen/<android|apple>/.tauri/cli-options-server.json(instead of the shared temp directory) and removed when the command exits. The IDE build scripts now report a clear error when the Tauri CLI command is not running.ff7cd8d86(#16118)tauri signer generate --write-keysnow creates the private key with owner-only permissions (0600) on Unix and refuses to overwrite either the private or the public key file without--force. Updater signing now rejects file names containing tabs or newlines (which would corrupt the signature's trusted comment) and assumes an empty password instead of prompting when no password is given and stdin is not a terminal.tauri signerreports errors instead of panicking.51aa20388(#16119) On Windows, package manager commands (npm,pnpm,yarn,bun,deno,node) are now executed directly instead of throughcmd /c, so arguments such as@tauri-apps/plugin-fs@>=2are escaped properly and can no longer be interpreted as shell redirections or command separators.Dependencies
Upgraded to
tauri-cli@2.12.0e2e585ad1(#15828) On Android, fix missingconsumer-rules.profile in the template.IMPORTANT: For plugin authors, update your
build.gradle.ktsfile to remove thebuildTypes { release { isMinifyEnabled = false proguardFiles( getDefaultProguardFile("proguard-android-optimize.txt"), "proguard-rules.pro" ) } }section and rename your
proguard-rules.protoconsumer-rules.proto match theconsumerProguardFiles("consumer-rules.pro")in the template.e2e585ad1(#15828) On Android, updated the template to use Gradle v9.6.1 (com.android.tools.build:gradlev9.3.1) and Kotlin v2.2. Usetauri android initto apply the change.9e9a54dea(#15890) Update the generated iOS Xcode project to build with Xcode 27. The scenes lifecycle is not enabled by default: to opt in, add theUIApplicationSceneManifestkey to yoursrc-tauri/Info.ios.plist.b6660a041(#15954) Update typescript to v7 intauri plugin inittemplate. Also fixes the defaultrootDirin the templatetsconfig.json9e9a54dea(#15890) Update cargo-mobile2 and change the default minimum iOS version to 15.0 to support Xcode 27.v2.11.5: @tauri-apps/cli v2.11.5Compare Source
[2.11.5]
Security fixes
5a87bab12Record the app version in the trusted comment of updater signatures, so a signed artifact is bound to the version it was released as.An update endpoint response is not signed, and the signature only covers the downloaded artifact, so the announced
versionon its own does not prove which release theurlandsignaturepoint at. minisign covers the trusted comment with its global signature, which lets the updater plugin compare the two and reject a response that pairs a version number with a different release. EnablerequireSignedVersionin the updater plugin configuration to enforce this.tauri buildfills the version in automatically, andtauri plugin add updaternow enablesrequireSignedVersionfor the project it is adding the plugin to.tauri signer signgains an--app-versionflag for signing updater artifacts by hand, and warns when it is omitted.Dependencies
tauri-cli@2.11.5v2.11.4: @tauri-apps/cli v2.11.4Compare Source
[2.11.4]
Bug Fixes
67ffa192a(#15596 by @FabianLars) Fixed an issue in the AppImage bundler that caused the/.desktopand.DirIconfiles to be absolute symlinks instead of relative symlinks which caused problems with AppImage installers likeAppManager.Dependencies
tauri-cli@2.11.4v2.11.3: @tauri-apps/cli v2.11.3Compare Source
[2.11.3]
Bug Fixes
50b0237ed(#15549 by @Legend-Master) Escape special characters inproductNamewhen generating Androidstrings.xml728c8d4a5(#15473 by @Legend-Master) Skip building bundles when usingtauri android runbe0cb0d43(#15344 by @raglady) Fix NDK_HOME environment variable not honored when seted8fd411f(#15552 by @Legend-Master) Makeureq_protoshow trace level logs only on-vvvinstead of-vvfca4a31f9(#15454 by @fallintoplace) Fixtauri migrategenerating invalid namespace imports for aliased pluginified imports from@tauri-apps/api.Inputs like
import { cli as superCli } from "@tauri-apps/api"now migrate toimport * as superCli from "@tauri-apps/plugin-cli"instead of producing invalid ESM syntax. The migration tests also reparse migrated JS, Svelte, and Vue output so syntax regressions are caught directly.Dependencies
tauri-cli@2.11.3v2.11.2: @tauri-apps/cli v2.11.2Compare Source
[2.11.2]
Dependencies
tauri-cli@2.11.2v2.11.1: @tauri-apps/cli v2.11.1Compare Source
[2.11.1]
Dependencies
tauri-cli@2.11.1v2.11.0: @tauri-apps/cli v2.11.0Compare Source
[2.11.0]
New Features
926a57bb0(#15201) Added uninstaller icon and uninstaller header image support for NSIS installer.Notes:
tauri-bundlerlib users, theNsisSettingsnow has 2 new fieldsuninstaller_iconanduninstaller_header_imagewhich can be a breaking changeuninstallerIconanduninstallerHeaderImageunderbundle > windows > nsisto configure them.764b9139a(#14313) Prompt to restart the Android emulator if it is not connected to adb.5dc2cee60(#14793) Added support forminimumWebview2Versionoption support for the MSI (Wix) installer, the oldbundle > windows > nsis > minimumWebview2Versionis now deprecated in favor ofbundle > windows > minimumWebview2VersionNotes:
WVRTINSTALLEDPropertytag inmain.wxs, it is now renamed toINSTALLED_WEBVIEW2_VERSIONtauri-bundlerlib users, theWindowsSettingsnow has a new fieldminimum_webview2_versionwhich can be a breaking changeEnhancements
be0e4bd2d(#15218) Added Vietnamese translations for the NSIS installer8718d0816(#15033) Show the context before prompting for updater signing key passwordBug Fixes
fcb702ec4(#14954) Fixbuild --bundlesto allownsisarg in linux+macOS80c1425af(#14921) Fix iOS build failure whenMetal Toolchainis installed by using explicit$(DEVELOPER_DIR)/Toolchains/XcodeDefault.xctoolchainpath instead of$(TOOLCHAIN_DIR)for Swift library search paths.What's Changed
9979cde1c(#15175) Update NSIS installer Italian translationsDependencies
tauri-cli@2.11.0v2.10.1: @tauri-apps/cli v2.10.1Compare Source
[2.10.1]
Bug Fixes
35c35f27a(#14931 by @lucasfernog) Support comma-separated list of Cargo features on all commands.0d1cb83ba(#14932 by @lucasfernog) Fix missing Cargo args when running mobile dev and build commands.33754ae5e(#15022 by @Legend-Master) Fix updater signing private keys generated usingtauri signer generatewith empty password can't be used (The keys generated during tauri were broken between v2.9.3 and v2.10.0, you'll need to regenerate them)What's Changed
7be58a1c6(#14894 by @Legend-Master) Log patching bundle type information againDependencies
tauri-cli@2.10.1v2.10.0: @tauri-apps/cli v2.10.0Compare Source
[2.10.0]
Enhancements
f82594410(#13253 by @Armaldio) Allow electron to run the CLI directlya2abe2e6b(#14607 by @sftse) Simplified internal representation offeatures: Option<Vec<String>>withVec<String>, no user facing changes84b04c4a8(#14759 by @amrbashir) Added new environment variables fortauri signer signcommand, to align with existing environment variables used intauri build,tauri bundleandtauri signer generateTAURI_SIGNING_PRIVATE_KEYTAURI_SIGNING_PRIVATE_KEY_PATHTAURI_SIGNING_PRIVATE_KEY_PASSWORDThe old environment variables are deprecated and will be removed in a future release.
TAURI_PRIVATE_KEYTAURI_PRIVATE_KEY_PATHTAURI_PRIVATE_KEY_PASSWORDBug Fixes
62aa13a12(#14629 by @lucasfernog) Fixandroid build's--aaband--apkflags requiring a value to be provided.eccff9758(#14779 by @lucasfernog) Fix empty associated-domains entitlements when domains are not configured for deep links.ea31b07f1(#14789 by @Legend-Master) Fixed the command description fortauri inspect7fca58230(#14830 by @Legend-Master) Updatednsis_tauri_utilsto 0.5.3:CreateProcessWithTokenWto run programs as user, this fixed a problem that the program launched with the previous method can't query its own handle53611c4d7(#14747 by @Legend-Master) Only watch dependent workspace members when runningtauri devinstead of watching on all members1b0e335d3(#14713 by @wasuaje)tauri signer signdoesn't work for files without an extensionWhat's Changed
e3fdcb500(#14836 by @sftse) Continued refactors of tauri-cli, fix too weak atomics.0575dd287(#14521 by @kandrelczyk) Change the way bundle type information is added to binary files. Instead of looking up the value of a variable we simply look for the default value.7f7d9aac2(#14668 by @sftse) Refactored internal use of static on config and directory resolvings, no user facing changes, please report any regressions if you encounter anyDependencies
tauri-cli@2.10.0v2.9.6: @tauri-apps/cli v2.9.6Compare Source
[2.9.6]
Dependencies
tauri-cli@2.9.6v2.9.5: @tauri-apps/cli v2.9.5Compare Source
[2.9.5]
Bug Fixes
f855caf8a(#14481 by @Legend-Master) Fixed the mismatched tauri package versions check didn't work for pnpmPerformance Improvements
ce98d87ce(#14474 by @Tunglies) refactor: remove needless collect. No user facing changes.Dependencies
tauri-cli@2.9.5v2.9.4: @tauri-apps/cli v2.9.4Compare Source
[2.9.4]
Bug Fixes
b586ecf1f(#14416 by @Legend-Master) Premultiply Alpha before Resizing which gets rid of the gray fringe around the icons for svg images.Dependencies
tauri-cli@2.9.4v2.9.3: @tauri-apps/cli v2.9.3Compare Source
[2.9.3]
Bug Fixes
fd8c30b4f(#14353 by @ChaseKnowlden) Premultiply Alpha before Resizing which gets rid of the gray fringe around the icons.Dependencies
tauri-cli@2.9.3v2.9.2: @tauri-apps/cli v2.9.2Compare Source
[2.9.2]
Dependencies
tauri-cli@2.9.2v2.9.1: @tauri-apps/cli v2.9.1Compare Source
[2.9.1]
Dependencies
tauri-cli@2.9.1v2.9.0: @tauri-apps/cli v2.9.0Compare Source
[2.9.0]
New Features
3b4fac201(#14194) Addtauri.conf.json > bundle > android > autoIncrementVersionCodeconfig option to automatically increment the Android version code.673867aa0(#14094) Try to detect ANDROID_HOME and NDK_HOME environment variables from default system locations and install them if needed using the Android Studio command line tools.3d6868d09(#14128) Added support to defining the content type of the declared file association on macOS (maps to LSItemContentTypes property).3d6868d09(#14128) Added support to defining the metadata for custom types declared intauri.conf.json > bundle > fileAssociations > exportedTypevia theUTExportedTypeDeclarationsInfo.plist property.ed7c9a410(#14108) Addedbundle > macOS > infoPlistandbundle > iOS > infoPlistconfigurations to allow defining custom Info.plist extensions.75082cc5b(#14120) Addedios runandandroid runcommands to run the app in production mode.cc8c0b531(#14031) Added support to universal app links on macOS with theplugins > deep-link > desktop > domainsconfiguration.Enhancements
b5aa01870(#14268) Update cargo-mobile2 to 0.21, enhancing error messages and opening Xcode when multiple apps are installed.55453e845(#14262) Check mismatched versions intauri info1a6627ee7(#14122) Set a default log level filter when runningtauri add log.b06b3bd09(#14126) Improve error messages with more context.f6622a3e3(#14129) Prompt to install the iOS platform if it isn't installed yet.6bbb530fd(#14105) Warn if productName is empty when initializing mobile project.Bug Fixes
19fb6f7cb(#14146) Strip Windows-only extensions from the binary path so an Android project initialized on Windows can be used on UNIX systems.19fb6f7cb(#14146) Enhance Android build script usage on Windows by attempting to run cmd, bat and exe formats.28a2f9bc5(#14101) Fix iOS CLI usage after modifying the package name.d2938486e(#14261) Replaced the non-standard nerd font character withⱼₛintarui info25e920e16(#14298) Wait for dev server to exit before exiting the CLI when the app is closed ontauri dev --no-watch.b0012424c(#14115) Resolve local IP address whentauri.conf.json > build > devUrlhost is0.0.0.0.abf7e8850(#14118) Fixes mobile project initialization when usingpnpxorpnpm dlx.Dependencies
tauri-cli@2.9.0v2.8.4: @tauri-apps/cli v2.8.4Compare Source
[2.8.4]
Enhancements
f70b28529(#14093 by @lucasfernog) Ensure Rust targets for mobile are installed when running the dev and build commands (previously only checked on init).a9b342125(#14114 by @lucasfernog) Fix iOS dev and build targeting the simulator on Intel machines.61b9b681e(#14111 by [@lucasfernog](https://www.github.com/tauri-appsConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about these updates again.
This PR was generated by Mend Renovate. View the repository job log.