Fetching documentation…
Status: future · Priority: medium
Note: This is a future plan, not a commitment. The syntax and API shown here are proposals — they can be completely different when actually implemented.
Shipping a real commercial app means more than a working binary — the OS has to trust it. Unsigned apps trigger warnings ("unidentified developer"), get blocked by SmartScreen/Gatekeeper, and can't update safely. This page covers everything needed to build, sign, and distribute a production-grade Morph app.
Signing is platform-specific — Morph wraps each OS tool so one command works everywhere:
| Platform | Mechanism | Notes |
|---|---|---|
| Windows | Authenticode — signtool.exe sign, EV or OV certificate, timestamp server |
SmartScreen reputation |
| macOS | codesign with a Developer ID certificate, then notarization (notarytool + stapler) |
notarization is mandatory for Gatekeeper |
| Linux | no mandatory signing; optional GPG signatures on packages (AppImage, DEB, RPM) | distro-specific |
| Target | Format | Notes |
|---|---|---|
| Windows | .msix / .exe installer |
MSIX for Microsoft Store + enterprise deployment |
| macOS | .app bundle inside .dmg |
notarized + stapled |
| Linux | AppImage / Flatpak / Snap / .deb / .rpm |
Flatpak gives the best sandbox |
| Any | winget manifest, Homebrew cask, GitHub Releases | auto-update source |
Updates are only as safe as their verification. Morph ships a signed update manifest:
const updater = new AutoUpdater({
feed: "https://updates.myapp.com",
publicKey: "ed25519:..." // Ed25519 — manifest + binary signatures
})
await updater.check() // fetch signed manifest, verify, download, swap, relaunchfetch maps to the native TLS stack; optional certificate pinning; no hardcoded secrets in the binarymorph sign # sign the built binary (auto-detects platform)
morph notarize # macOS notarization + staple
morph package # produce .msix / .app / .dmg / AppImage / .deb / .rpm
morph publish # upload release + sign the auto-update manifestmorph.config additions:
{
"signing": { "certificate": "…", "timestampServer": "…" },
"updates": { "server": "https://updates.myapp.com", "publicKey": "…", "channels": ["stable", "beta"] },
"publisher": { "name": "…", "id": "com.example.app" }
}| Piece | State |
|---|---|
Single native binary output (morph build) |
✅ Shipped |
| Windows / macOS support (prerequisite for signing & stores) | ✅ Shipped — see Platforms |
morph sign / morph notarize |
❌ Not built |
morph package (MSIX, DMG, AppImage, …) |
❌ Not built |
AutoUpdater with signed manifests |
❌ Not built |
| Secure storage / sandboxing / crash reporting | ❌ Not built |
appcast.xml for macOS)?morph sign (Windows Authenticode, macOS codesign) + morph notarizemorph package for the main formats (MSIX, DMG, AppImage)AutoUpdater — signed manifest, atomic swap, rollbackkeychain), crash reporting, morph publish