Skip to content
CAI
Software that uses CAICheck a score

tauri-apps/tauri

63.8

Adequate · 27 September 2026

102.7k

lines of production code

Rust

with TypeScript

4

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

This system is the Tauri framework, a toolkit for building cross-platform desktop and mobile applications using web technologies and Rust. It provides a comprehensive CLI for scaffolding, building, and bundling apps into native installers for Windows, macOS, Linux, Android, and iOS. The core runtime manages windowing, webviews, and inter-process communication with a focus on security through granular permission controls and isolation patterns.

How it got here

2019–2024 — Tauri v2 release and mobile support

128 changes.

This period covers the finalization and release of Tauri v2, introducing a comprehensive new permission system (ACL), a modular plugin architecture, and robust mobile support for Android and iOS. The work involved restructuring the core runtime, CLI, and bundler to support these features, alongside extensive updates to examples and documentation to guide developers through the migration.

2025–2026 — API expansion and configuration schema

7 changes.

This period focused on expanding the Tauri runtime and API surface by introducing new features such as monitor work area support, drag region handling, and post-exit logic examples. Significant infrastructure work included the introduction of the v1 configuration schema parser and the addition of a comprehensive end-to-end test suite for the @tauri-apps/api. Minor improvements included enhancing Windows error dialogs with hyperlink support and adding string search utilities for the bundler.

Features

Add Isolation example demonstrating security pattern

A new example application named 'Isolation' has been added to the examples directory. It demonstrates the use of the isolation security pattern, configured via \tauri.conf.json\ to use the \isolation\ strategy with a specific output directory (\isolation-dist\). The example includes a simple Rust backend with a \ping\ command and a standard Tauri configuration, runnable via \cargo run --example isolation --features isolation\.

examples/isolation · high confidence

Add Tauri plugin sample example with mobile support

The plugin sample example now includes a complete implementation demonstrating how to build a Tauri plugin that works on both desktop and mobile platforms. The example features a \ping\ command that sends events via channels, a \js\_values\ command specifically for mobile to resolve JavaScript objects and arrays from native code, and proper error handling for mobile plugin invocations. It showcases the new plugin API including \PluginApi\ for registering Android and iOS plugins, and demonstrates how to structure a plugin with separate desktop and mobile implementations.

examples/api/src-tauri/tauri-plugin-sample · high confidence

Add Tauri schema generator crate with documentation assets

A new \tauri-schema-generator\ crate has been introduced to host the schema for the Tauri configuration file. The implementation currently provides an empty main entry point, but includes configuration for HTML documentation assets, specifically setting the logo and favicon URLs for the generated docs.

crates/tauri-schema-generator/src · high confidence

Add commands example application

A new example application has been added to demonstrate the Tauri command API. It showcases various command patterns including simple and stateful commands, async execution, raw futures, result returns, and argument renaming (including snake\_case conversion). The example includes a web interface to invoke these commands and a Rust backend implementing the corresponding handlers.

examples/commands · high confidence

Add isolation-dist example demonstrating the isolation pattern

A new example located at examples/isolation/isolation-dist has been added to demonstrate the Tauri isolation pattern. This example includes an HTML entry point and a JavaScript file that defines the \window.\_\_TAURI\_ISOLATION\HOOK\\_\, allowing developers to see how to implement the required hook for secure IPC communication.

examples/isolation/isolation-dist · high confidence

Add monitor work area API for Linux, macOS, and Windows

This change introduces a new \work\_area\ method to the \MonitorExt\ trait, allowing applications to retrieve the usable screen area (excluding taskbars, docks, or menus) on Linux, macOS, and Windows. The implementation provides platform-specific logic: on Linux it uses GTK's \workarea\, on macOS it calculates the visible frame relative to the screen frame, and on Windows it queries the \MONITORINFO\ structure via Win32 APIs. This enables developers to position windows or UI elements within the actual usable screen space rather than the full monitor bounds.

crates/tauri-runtime-wry/src/monitor · high confidence

Add multi-window example demonstrating inter-window communication and dynamic window creation

The multi-window example now provides a complete demonstration of managing multiple windows in a Tauri application. It includes a frontend interface allowing users to send messages to specific windows by label and create new WebviewWindows dynamically. The Rust backend initializes a third window at startup, while the configuration defines two initial windows with specific tabbing identifiers and a Content Security Policy. The example also explicitly registers necessary event and webview commands in the runtime authority to support inter-window communication and window creation.

examples/multiwindow · high confidence

Add resources example demonstrating asset resolution

A new example application located in \examples/resources/src-tauri\ has been added to demonstrate how to access bundled resources. The example configures \tauri.conf.json\ to include assets via the \bundle.resources\ pattern and uses the \path::BaseDirectory::Resource\ API in the Rust backend to resolve and read the content of \assets/index.js\ at startup.

examples/resources/src-tauri · high confidence

Add resources example demonstrating bundled asset resolution

A new example application has been added to showcase Tauri's bundle resources functionality. It demonstrates how to include a JavaScript file as a bundled resource and access it at runtime using the \resolveResource\ path API and the \read\_to\_string\ command, displaying the resolved file path and content in the browser UI.

examples/resources · high confidence

Add splashscreen example

Added a new example demonstrating how to implement a splashscreen that displays while initialization code runs, and then closes to reveal the main application window.

examples/splashscreen · high confidence

Add splashscreen example with main and splash HTML pages

The examples/splashscreen/dist directory now includes index.html and splashscreen.html files that demonstrate the Tauri splashscreen feature. The main window (index.html) uses the Tauri core invoke API to call close\_splashscreen after a 2-second delay, while splashscreen.html provides a full-screen styled overlay with a centered icon image.

examples/splashscreen/dist · high confidence

Add state management example

A new example application demonstrating how to manage and share application state across Tauri commands using Rust's \State\ API. The example includes a counter UI with increment, decrement, and reset functionality, showing how state persists across reloads.

examples/state · high confidence

Add webview zoom, print, and devtools hotkey scripts

New JavaScript scripts are injected into webviews to enable native-like keyboard and mouse interactions. Users can now zoom in and out using Ctrl/Cmd with +/- keys or the mouse wheel, reset zoom with Ctrl/Cmd+0, trigger the print dialog via the window.print() API, and toggle developer tools using platform-specific hotkeys (Ctrl+Shift+I on Windows/Linux, Cmd+Alt+I on macOS).

crates/tauri/src/webview/scripts · high confidence

Add window effects support for macOS and Windows

This change introduces a new \vibrancy\ module that enables platform-specific window effects. On macOS, users can now apply the Liquid Glass effect (with regular or clear styles, optional tint color and radius) or fall back to standard Visual Effect materials (such as Dark, Light, Titlebar, etc.) with configurable state and radius. On Windows, the module supports Mica (including Dark and Light variants), Acrylic, Blur, and Tabbed effects (including Dark and Light variants). The implementation delegates to the \window\_vibrancy\ crate and provides a unified \set\_window\_effects\ API to apply or clear these effects on Tauri windows.

crates/tauri/src/vibrancy · high confidence

Android CLI commands now support JSON, JSON5, and TOML configuration files

The \tauri android dev\, \build\, \run\, and \init\ commands now accept the \--config\ flag pointing to \.toml\ or \.json5\ files in addition to JSON. This allows developers to use their preferred configuration format for platform-specific overrides and build-time merges, simplifying configuration management for Android projects.

crates/tauri-cli/src/mobile/android · high confidence

Android plugin infrastructure and lifecycle hooks

The Android module now includes a new TauriActivity base class that forwards standard Android lifecycle events (onCreate, onResume, onStop, onDestroy, onConfigurationChanged, etc.) to the PluginManager, enabling plugins to react to app state changes. Additionally, core plugin support files (Channel, Invoke) have been added to handle JSON-based command invocation and response handling within the Android environment.

android · high confidence

Android template adds standard build and configuration files

The Android mobile template now includes essential scaffolding files: an .editorconfig for consistent code formatting, a .gitignore that excludes build artifacts and sensitive files like keystore.properties, and the Gradle wrapper scripts (gradlew and gradlew.bat) to ensure reproducible builds. These additions standardize the project structure and improve security by preventing accidental commits of sensitive configuration.

crates/tauri-cli/templates/mobile/android · high confidence

App template now includes a log plugin for debug builds

The generated Tauri application template now automatically registers the \tauri\_plugin\_log\ plugin when running in debug mode. This means developers will see log output at the Info level during development, aiding in debugging, while the plugin is not included in release builds to keep the application lightweight.

crates/tauri-cli/templates/app/src-tauri/src · high confidence

Command macro supports renaming and unused command removal

The command macro now supports a \rename\ attribute to override the command name exposed to the frontend, and automatically removes commands that are not listed in the application's access control list (ACL) when the \TAURI\_REMOVE\_UNUSED\_COMMANDS\ environment variable is set, helping to reduce bundle size and improve security by ensuring only allowed commands are available.

crates/tauri-macros/src/command · high confidence

Expanded NSIS installer localization support

The Windows NSIS installer now includes built-in language packs for Arabic, Bulgarian, Dutch, Hebrew, Italian, Japanese, Korean, Norwegian, Persian, Portuguese (including Brazilian), Russian, Simplified Chinese, Spanish (including International variants), and Swedish. Users can now select their preferred language during installation, ensuring installer prompts and WebView2 status messages are displayed in their native language.

crates/tauri-bundler/src/bundle/windows/nsis/languages · high confidence

Initial Android plugin framework and core APIs

This change introduces the foundational Android plugin infrastructure for Tauri, including the \PluginManager\ and \Plugin\ base classes that handle lifecycle events, command dispatch, and activity result callbacks. It adds the \AppPlugin\ to expose the \process.exit\ command and emit a \back-button\ event, and the \PathPlugin\ to resolve standard directories (home, config, data, cache, etc.) and resolve file names from Android content URIs. The diff also includes supporting utilities for file system operations (\FsUtils\), permission state management (\PermissionHelper\, \PermissionState\), JSON serialization (\JSObject\, \JSArray\), and logging (\Logger\), along with the necessary Kotlin annotations and a basic instrumentation test.

crates/tauri/mobile/android/src · high confidence

Initial Android plugin template for the sample API

The Android portion of the \tauri-plugin-sample\ example has been added, providing a functional plugin structure for mobile developers. This includes an \ExamplePlugin\ class that exposes commands like \ping\ and \jsValues\, demonstrating how to parse typed arguments, handle events via channels, and serialize JS objects/arrays. The entry also includes the necessary \AndroidManifest.xml\, a core \Example\ implementation class, and baseline unit and instrumentation tests to verify the package setup.

examples/api/src-tauri/tauri-plugin-sample/android · high confidence

Initial bundler implementation in crates/tauri-bundler

The \crates/tauri-bundler\ crate has been introduced to handle application packaging, providing the core logic for generating macOS, iOS, Windows (MSI/NSIS), and Linux (DEB/RPM/AppImage) bundles. This change adds the \AppCategory\ enum to map application categories to macOS \LSApplicationCategoryType\ and Freedesktop standards, implements \PackageType\ definitions with build priorities, and includes platform detection utilities to determine the target triple via \rustc\. It also introduces the \UpdaterBundle\ module to create update archives (tar.gz/zip) for macOS, Linux, and Windows installers.

crates/tauri-bundler/src/bundle · high confidence

Initial iOS API library release

The \crates/tauri/mobile/ios-api\ crate is introduced as a new Swift package providing the core iOS runtime for Tauri. This library includes the \PluginManager\ for handling plugin lifecycle and command invocation (supporting both synchronous and async \completionHandler:\ patterns), the \Invoke\ class for managing command arguments and responses, and utilities for JSON serialization, type coercion, and logging. It also establishes the foundational \Channel\ mechanism for event listeners and includes a \StdoutRedirector\ to capture stdout/stderr into \os\_log\.

crates/tauri/mobile/ios-api · high confidence

Initial implementation of the Wry-based runtime

This change introduces the \tauri-runtime-wry\ crate, providing the core runtime implementation for Tauri applications using the Wry webview library. It establishes the foundational architecture for cross-platform window and webview management, including platform-specific handling for Windows (WebView2), macOS/iOS (WKWebView), Linux (WebKitGTK), and Android. The implementation covers essential features such as window creation, focus management, DPI awareness, undecorated resizing, and webview permissions, serving as the bridge between Tauri's core API and the underlying webview engines.

crates/tauri-runtime-wry/src · high confidence

Initial release of tauri-driver as a cross-platform WebDriver intermediary

The \tauri-driver\ crate is introduced as a new component that acts as a WebDriver intermediary node for Tauri applications. It wraps the native WebDriver servers (WebKitWebDriver on Linux, Microsoft Edge Driver on Windows) to provide a unified interface for test frameworks. The driver listens on two ports (defaulting to 4444 for the client and 4445 for the native server) and supports configuring the application path, arguments, and webview options via the \tauri:options\ capability.

crates/tauri-driver · high confidence

Initial release of tauri-utils changelog and license files

The \crates/tauri-utils\ crate now includes a comprehensive \CHANGELOG.md\ documenting the history of the utility library, including new features like navigation limits and VCRuntime bundling, behavioral changes such as the \WindowEffect\ enum becoming non-exhaustive, and various bug fixes. Additionally, the crate now explicitly ships with \LICENSE-APACHE-2.0\ and \LICENSE-MIT\ files to clarify its dual licensing terms, and a \README.md\ describing its role in providing common utilities for configuration parsing and asset management.

crates/tauri-utils · high confidence

Introduce Tauri Schema Worker for dynamic schema retrieval

A new background worker service has been added to serve Tauri configuration schemas dynamically. It exposes endpoints to fetch the latest stable schema, the latest pre-release (next) schema, and schemas for specific Tauri versions. The worker retrieves schema definitions from the Tauri repository, caches them for performance, and ensures responses are served with the correct JSON content type.

crates/tauri-schema-worker/src · high confidence

Introduce built-in development server with host validation

The Tauri CLI now includes a built-in development server (powered by Axum) that serves frontend assets and manages hot-reload via WebSocket. This server validates the Host and Origin headers on incoming requests to prevent DNS rebinding attacks, ensuring that only requests addressed to the local server are served. It automatically watches the project directory for file changes and triggers browser reloads, providing a secure, zero-configuration local development experience.

crates/tauri-cli/src/dev · high confidence

Introduce tauri-driver as a WebDriver intermediary for Tauri apps

A new \tauri-driver\ component is added to act as a WebDriver intermediary node, bridging standard WebDriver clients with the platform-specific native WebDriver servers (WebKitWebDriver on Linux, msedgedriver on Windows). This intermediary handles session capability translation, converting Tauri-specific options into native browser options (such as adding the \.exe\ extension for Windows binaries) and forwarding requests to the native driver. It manages the lifecycle of the native driver process, ensuring it does not inherit stdout to prevent output corruption, and supports configuration via command-line arguments for ports and driver paths.

crates/tauri-driver/src · high confidence

Introduction of the tauri-plugin crate for plugin development

A new \tauri-plugin\ crate has been added to provide the core interface for building Tauri plugins. This crate exposes a \build\ feature containing helpers for the plugin \build.rs\ script, including the \Builder\ for checking conventions, generating permissions, and linking mobile projects, as well as \plugin\_config\ for reading CLI configuration. It also includes a \mobile\ module to patch iOS \Info.plist\ and Android manifests. The \runtime\ feature is currently reserved and exports nothing, directing users to use \tauri::plugin\ for defining the plugin itself.

crates/tauri-plugin/src · high confidence

Introduction of v1 configuration schema and parser

The \crates/tauri-utils/src/config\_v1\ module has been added, introducing the \Config\ struct and associated types (such as \WindowUrl\ and \BundleType\) that define the structure of the Tauri configuration file (\tauri.conf.json\). This module also includes a parser (\parse.rs\) capable of reading configuration from JSON, JSON5, and TOML formats, including platform-specific overrides, and defines the error types for configuration loading failures.

_crates/tauri-utils/src/config\v1 · high confidence

Isolation pattern implementation for secure IPC

This change introduces the Isolation pattern, a security feature that encrypts IPC messages between the main frame and an isolation iframe using AES-GCM. The Rust module in \crates/tauri-utils/src/pattern\ provides the cryptographic key generation and encryption/decryption logic, while the injected \isolation.js\ script handles the secure payload transmission in the browser. This ensures that sensitive data passed via IPC is protected from interception or tampering by other scripts.

crates/tauri-utils/src/pattern · high confidence

MSI installer now includes an elevated background update task

The Windows MSI bundler now bundles PowerShell scripts and a scheduled task definition that allow the installer to perform silent, elevated updates in the background. When the \enable\_elevated\_update\_task\ option is active, the generated MSI installs a scheduled task that runs \msiexec\ to install the new package without requiring user interaction or UAC prompts, improving the update experience for end users.

crates/tauri-bundler/src/bundle/windows/msi · high confidence

Mobile CLI commands now support pnpm, npx, and Deno execution contexts

The mobile initialization and build commands in the CLI now automatically detect and adapt to various JavaScript/TypeScript package managers. When invoked via pnpm (including \pnpm dlx\), npm, npx, or Deno, the CLI correctly identifies the binary and constructs the appropriate execution arguments, ensuring that mobile project generation and IDE script execution work seamlessly within these environments.

crates/tauri-cli/src/mobile · high confidence

New App plugin exposing core app information and control commands

A new \app\ plugin has been introduced in the Tauri core, exposing a set of commands to JavaScript/TypeScript clients for retrieving app metadata (version, name, identifier, Tauri version, bundle type) and controlling app behavior (show/hide on macOS, exit with code, set app theme, toggle macOS dock visibility, and check multi-window support). It also provides platform-specific data store management for Apple targets (fetching and removing data store identifiers) and registers the Android plugin bridge. This centralizes access to fundamental app-level properties and lifecycle controls that were previously unavailable or scattered.

crates/tauri/src/app · high confidence

New CI scripts for change-tag validation, license checks, and macOS crash reporting

The repository introduces several new CI helper scripts in \.scripts/ci/\ to enforce quality and support debugging. \check-change-tags.js\ validates that change files contain valid, known tags for configured packages, failing the build if tags are missing or unknown. \check-license-header.js\ scans source files to ensure they contain the required copyright and license headers. \collect-macos-crash-reports.sh\ automates the collection and formatting of macOS crash reports after failed e2e runs to aid in debugging app crashes. Additional scripts include \has-diff.sh\ to verify a clean working directory, \pack-cli.sh\ to package the CLI binaries, and \sync-cli-metadata.js\ to update CLI version metadata during versioning.

.scripts · high confidence

New CLI command to create capability files with validation

The Tauri CLI now includes a \capability new\ command (aliased as \create\) that guides users through creating capability definition files. This command prompts for a capability identifier, description, target windows, and permissions, then writes the resulting configuration to a JSON or TOML file in the \capabilities\ directory. The implementation adds strict validation for capability identifiers (allowing only ASCII alphanumeric characters, hyphens, and underscores to prevent path traversal) and permission identifiers, ensuring that generated files are safe and correctly formatted before being written to disk.

crates/tauri-cli/src/acl/capability · high confidence

New CLI commands to manage permissions and capabilities

The \tauri permission\ subcommand is now available, providing four new operations: \new\ to create permission definition files (supporting JSON and TOML formats with allow/deny command lists), \add\ to attach permissions to existing capabilities (preventing duplicates and avoiding file overwrites), \rm\ to remove specific permissions from capability files and permission directories (including wildcard support for plugin prefixes), and \ls\ to list available permissions from the generated ACL manifests with optional plugin and identifier filtering.

crates/tauri-cli/src/acl/permission · high confidence

New CLI commands to scaffold and initialize Android and iOS projects for Tauri plugins

The Tauri CLI now includes dedicated \plugin android init\ and \plugin ios init\ subcommands, allowing developers to add native mobile scaffolding to an existing Tauri plugin project. These commands generate the necessary Android and iOS project structures, configure the appropriate build dependencies (such as \tauri-build\), and provide the specific initialization code required for \src/lib.rs\ to register the plugin on each platform. Additionally, the initial plugin creation command (\plugin new\) and the general initialization command (\plugin init\) have been updated to support these mobile targets via \--android\, \--ios\, and \--mobile\ flags, and allow users to choose between Swift Package Manager and Xcode projects for iOS.

crates/tauri-cli/src/plugin · high confidence

New Docker images for cross-compilation

Added Dockerfiles and build scripts in .docker/cross to enable cross-compilation for architectures such as aarch64, armv7, and others. The setup installs necessary toolchains, QEMU for emulation, and a custom runner to execute cross-compiled binaries within the container environment.

.docker · high confidence

New JavaScript runtime scripts for IPC, isolation, and API exposure

The \crates/tauri/scripts\ directory now contains the core JavaScript files that power the Tauri runtime in the browser. This includes \core.js\ for IPC invocation and callback management, \ipc.js\ and \ipc-protocol.js\ for handling message passing (including the new custom protocol fallback and isolation pattern support), \isolation.js\ for setting up the secure isolation iframe, and \bundle.global.js\ which exposes the full set of JavaScript APIs (App, Window, Webview, Menu, Tray, etc.) to the web content. These scripts replace the previous inline or bundled approach, providing a structured, modular foundation for the frontend-backend communication layer.

crates/tauri/scripts · high confidence

New JavaScript/TypeScript menu API implementation

The menu module in \packages/api/src/menu\ has been rewritten to provide a new JavaScript/TypeScript API for creating and managing application menus. This change introduces new classes for \Menu\, \Submenu\, \MenuItem\, \CheckMenuItem\, \IconMenuItem\, and \PredefinedMenuItem\, replacing the previous implementation. The new API supports creating menu items with icons (including native icons on macOS and custom images), predefined items like 'Bring All to Front' and 'About' (with customizable metadata), and action handlers. It also handles the transformation of image assets for icons and manages the lifecycle of menu items via resource IDs, ensuring proper integration with the underlying Rust backend.

packages/api/src/menu · high confidence

New NSIS installer templates and file association support

The NSIS bundler now ships with a complete set of installer templates, including a new \FileAssociation.nsh\ script that allows applications to register file type associations in the Windows registry. The installer template (\installer.nsi\) has been updated to support DPI awareness, custom header/sidebar images, and uninstaller icons, while the utility scripts (\utils.nsh\) now include macros for managing AppUserModelId shortcuts and using the Windows Restart Manager to handle running applications during installation.

crates/tauri-bundler/src/bundle/windows/nsis · high confidence

New Node.js bindings for Tauri CLI execution

The CLI package now exposes a new Rust library entry point (\lib.rs\) that provides Node.js bindings via NAPI. This allows Node.js consumers to invoke the Tauri CLI programmatically through a \run\ function, which executes the CLI in a separate thread to prevent blocking the Node.js event loop and communicates results back via a thread-safe callback. A companion \log\_error\ function is also exposed to allow Node.js code to capture CLI error logs.

packages/cli/src · high confidence

New Rust interface implementation for Tauri CLI

The CLI now includes a new Rust interface implementation located in \crates/tauri-cli/src/interface/rust\. This adds support for parsing Cargo configuration files (including \.cargo/config\ and \.toml\ variants) to resolve build targets, manages \Cargo.toml\ manifest features and dependencies, detects installed Rust targets via \rustc\, and handles the execution of the development server with improved stderr handling and exit reason detection.

crates/tauri-cli/src/interface/rust · high confidence

New Tauri v2 JavaScript/TypeScript API surface

The \packages/api/src\ directory now contains the complete v2 frontend API implementation, replacing the previous structure. This introduces a modular package with dedicated modules for application metadata (\app\), IPC and channels (\core\), DPI scaling (\dpi\), events (\event\), image handling (\image\), menus (\menu\), path resolution (\path\), tray icons (\tray\), and window/webview management (\window\, \webview\, \webviewWindow\). Key behavioral changes include a new \Channel\ class for streaming messages from Rust, a \SERIALIZE\_TO\_IPC\FN\ symbol for custom type serialization, and a \JsImage\ type for passing images to the backend. The \mocks\ module provides \mockIPC\ and \mockConvertFileSrc\ for testing without a backend, and the \global.d.ts\ file exposes the \window.\\TAURI\\_\ global for vanilla JS usage.

packages/api/src · high confidence

New builder API for menus and menu items

The \crates/tauri/src/menu/builders\ module introduces a new fluent builder API for constructing menus, submenus, and menu items. This includes \MenuBuilder\ and \SubmenuBuilder\ (which now supports setting icons via \submenu\_icon\ and \submenu\_native\_icon\), as well as dedicated builders for standard items (\MenuItemBuilder\), checkable items (\CheckMenuItemBuilder\), and icon items (\IconMenuItemBuilder\). This provides a more structured way to define menu structures and item properties in Rust.

crates/tauri/src/menu/builders · high confidence

New dedicated CLI commands for generating and signing updater keys

The Tauri CLI now includes a dedicated \signer\ subcommand with two new capabilities: \signer generate\ creates new signing keypairs (with options to save to files or output to console, and a warning for password-less keys in CI environments), and \signer sign\ signs arbitrary files using a private key (provided via string or file path, or environment variables like \TAURI\_SIGNING\_PRIVATE\_KEY\ and \TAURI\_SIGNING\_PRIVATE\_KEY\_PATH\). The signing command also supports binding signatures to a specific app version via \--app-version\ to ensure updater integrity, and includes backward compatibility warnings for deprecated environment variables (\TAURI\_PRIVATE\_KEY\, etc.).

crates/tauri-cli/src/signer · high confidence

New drag behavior example with QA test suite

Added a new \examples/drag\ example that demonstrates \data-tauri-drag-region\ attribute behaviors, including bare, deep, and false values, as well as interactions with clickable elements like buttons and inputs. The example includes a comprehensive HTML-based QA test suite to verify drag region handling across various UI scenarios.

examples/drag · high confidence

New example demonstrating \`App::run\_return\` for post-exit logic

An example application has been added that showcases the \App::run\_return\ method. This example illustrates how to capture the application's exit code and execute custom logic (such as printing a message) after the app window closes, before the process terminates.

examples/run-return · high confidence

New file-associations example app for Tauri

This change introduces a new example application demonstrating how to handle file associations and URL schemes in Tauri. The example configures the app to register specific file extensions (png, jpg, jpeg, gif, taurijson, taurid) with associated MIME types and ranks, and sets up URL scheme handlers (myapp, myscheme) via the macOS Info.plist. The Rust backend parses command-line arguments on Windows/Linux and listens for the RunEvent::Opened event on macOS/iOS/Android to receive opened file paths, which are then passed to the frontend via an initialization script. It also demonstrates security scope handling by allowing access to opened files via the asset protocol scope.

examples/file-associations/src-tauri · high confidence

New file-associations example demonstrating app-to-file-type linking

Added a new example in the \examples/file-associations\ directory that demonstrates how to associate the application with specific file types (PNG, JPG, JPEG, GIF, and custom \taurid\/\taurijson\ extensions). The example includes an HTML interface that displays files opened by the application and provides build instructions for the Rust backend, including macOS-specific exported type definitions.

examples/file-associations · high confidence

New iOS mobile commands (dev, build, run) and project generation

The Tauri CLI now includes dedicated commands for iOS development and distribution. Users can run \tauri ios dev\ for development with hot-reloading, \tauri ios build\ to generate release IPAs (with options to skip code signing via \--no-sign\ or archive only via \--archive-only\), and \tauri ios run\ for production-style execution. The CLI also handles iOS project generation (\tauri ios init\), ensuring Rust targets are installed and CocoaPods dependencies are resolved. These commands support custom configuration merging, cargo features, and device selection.

crates/tauri-cli/src/mobile/ios · high confidence

New image plugin for managing image resources

A new \image\ plugin has been added to Tauri, exposing commands to create, inspect, and retrieve image data. Users can now create images from raw RGBA buffers (\new\), load them from bytes or file paths (\from\_bytes\, \from\_path\), and query their dimensions or raw pixel data (\size\, \rgba\). These images are managed as resources within the webview's resource table, allowing for efficient handling of image assets in the application.

crates/tauri/src/image · high confidence

New internal benchmarking infrastructure for CI metrics

The \bench/src\ directory now contains the core Rust binaries and utilities that power the project's internal performance benchmarking on CI. This includes \build\_benchmark\_jsons.rs\ for aggregating and storing benchmark results, \run\_benchmark.rs\ for executing specific performance tests (such as binary size, memory usage via \mprof\, and syscall counts via \strace\), and \utils.rs\ providing shared helpers for path resolution, command execution, and data parsing. These changes establish the foundational tooling for tracking Tauri's internal metrics over time.

bench/src · high confidence

New macOS signing and notarization crate

A new \tauri-macos-sign\ crate has been introduced to handle macOS code signing and notarization workflows. It provides capabilities to generate self-signed certificates, manage temporary keychains for importing signing identities, and handle provisioning profiles. The crate also integrates with Apple's \notarytool\ to submit applications for notarization, supporting both waiting for completion and asynchronous submission modes.

crates/tauri-macos-sign/src · high confidence

New macOS signing identity listing capability

The \tauri-macos-sign\ crate now includes a new \identity.rs\ module that provides functionality to list available macOS signing identities (such as iOS Distribution, Apple Development, and Developer ID Application certificates) from the system keychain. This change introduces a \Team\ struct and a \list\ function that parses X.509 certificates to extract team names, certificate identifiers, and common names, enabling the signing process to automatically discover and select appropriate signing credentials.

crates/tauri-macos-sign/src/keychain · high confidence

New mobile build utilities and plugin configuration helpers

The \tauri-plugin\ crate now includes a \build\ module with mobile-specific utilities. On macOS hosts, developers can use \mobile::update\_entitlements\ to patch iOS entitlements (e.g., for push notifications) and \mobile::update\_info\_plist\ to modify the iOS \Info.plist\ (e.g., for usage descriptions) during the build process. Additionally, \mobile::update\_android\_manifest\ allows inserting XML content into the Android manifest. The module also provides a \Builder\ to configure plugin builds (including Android/iOS paths and global API scripts) and a \plugin\_config\ helper to read plugin settings from environment variables passed by the Tauri CLI.

crates/tauri-plugin/src/build · high confidence

New plugin templates and mobile build scripts

The Tauri CLI now includes new template files for generating plugins, providing a complete structure for both desktop (Rust) and mobile (iOS Swift Package Manager, Android) targets. This adds guest JavaScript bindings, Rust command and model definitions, and mobile-specific initialization code. Additionally, new helper scripts for process management and continuous testing, along with ProGuard rules for Android, have been added to support the development and build process.

(repo-wide) · high confidence

New streaming example demonstrating custom protocol video playback

Added a new streaming example that showcases how to stream video files using a custom protocol handler. The example includes a Rust backend (\main.rs\) that implements HTTP range requests to support video seeking and partial content delivery, and a frontend (\index.html\) that utilizes \convertFileSrc\ to load the video stream. It also provides a \tauri.conf.json\ configuration with specific Content Security Policy (CSP) settings for the custom \stream:\ protocol and asset protocol scoping, serving as a reference implementation for developers.

examples/streaming · high confidence

New tauri-schema-generator crate for JSON schema generation

A new crate, tauri-schema-generator, has been added to the repository to generate JSON schemas for Tauri configuration files. This component includes a build script that automatically produces schema files for capabilities, permissions, scopes, and the main Tauri config, ensuring that the CLI's config.schema.json is kept in sync with the current Tauri version.

crates/tauri-schema-generator · high confidence

New tauri-utils crate with core utilities and HTML manipulation

The \crates/tauri-utils/src\ directory now contains a new \tauri-utils\ crate that provides core utilities for Tauri applications. This includes asset management (\assets.rs\), configuration parsing (\config.rs\), platform detection (\platform.rs\), and MIME type handling (\mime\_type.rs\). A significant addition is the HTML manipulation module (\html.rs\ and \html2.rs\), which allows for injecting Content Security Policy (CSP) headers and nonce tokens into HTML documents, enhancing security for webviews. The crate also includes build script utilities (\build.rs\) for linking Apple libraries and updating Android manifests, as well as resource path handling (\resources.rs\).

crates/tauri-utils/src · high confidence

New window enable/disable and centering APIs

This change introduces platform-specific implementations for the \WindowExt\ trait in the Wry runtime, adding \set\_enabled\ and \is\_enabled\ methods to control window interactivity, and a \center\ method to reposition windows to the center of their monitor. On Linux, enabling/disabling uses GTK sensitivity; on macOS, it toggles a semi-transparent overlay sheet; and on Windows, it uses the native \EnableWindow\ API. The \center\ logic is also implemented across platforms, with Windows handling title bar height adjustments for accurate positioning.

crates/tauri-runtime-wry/src/window · high confidence

New window management plugin and API surface

This change introduces the core window management plugin and its associated Rust types, exposing a comprehensive set of commands for creating, configuring, and manipulating application windows from JavaScript. The diff adds the \Monitor\ descriptor and a \WindowBuilder\ (behind an unstable feature flag) for programmatic window creation, alongside a plugin module that registers IPC commands for window lifecycle (create, close, destroy), state queries (is\_focused, is\_visible, is\_enabled, is\_fullscreen), and property setters (set\_title, set\_size, set\_position, set\_theme, set\_effects, set\_badge\_count). It also includes platform-specific capabilities such as macOS simple fullscreen, Windows overlay icons, and badge labels, effectively establishing the public API surface for window control in this release.

crates/tauri/src/window · high confidence

Repository initialization with core configuration and documentation files

The repository has been initialized with essential configuration and documentation files. This includes an \.editorconfig\ for consistent code formatting, a \.gitignore\ covering common build artifacts and environment files, and \.prettierrc\/\.prettierignore\ to standardize JavaScript/TypeScript formatting. Documentation is established via \README.md\, \ARCHITECTURE.md\, and \SECURITY.md\. Licensing is clarified with \LICENSE-MIT\ (renamed from \LICENSE\) and \LICENSE-APACHE-2.0\, alongside a \LICENSE.spdx\ manifest. Automated dependency management is configured through \renovate.json\ and \dependabot.yml\, while \pnpm-workspace.yaml\ sets up the monorepo structure for packages like \api\, \cli\, and \schema-worker\. Finally, \rustfmt.toml\ enforces Rust code style.

(repo-wide) · high confidence

Support for platform-specific configuration files

Tauri now supports platform-specific configuration files (e.g., \tauri.macos.conf.json\, \Tauri.windows.toml\) that are automatically merged with the main configuration file using JSON Merge Patch (RFC 7396). This allows developers to override settings for specific targets like macOS, Windows, Linux, Android, or iOS without duplicating the entire configuration structure.

crates/tauri-utils/src/config · high confidence

Tauri Runtime v2.12.0 introduces navigation limits, permission handling, and monitor-specific fullscreen

The \tauri-runtime\ crate has been updated to version 2.12.0, bringing several new capabilities and breaking changes for application developers. Users can now restrict webview navigation to app-bound domains via \limit\_navigations\_to\_app\_bound\_domains\ and control macOS app activation behavior with \activate\_ignoring\_other\_apps\. A new \no\_redirection\_bitmap\ option is available for Windows windows, and the \wry\ permission handler API is exposed, supporting permissions like DisplayCapture, Midi, and LocalFonts. Additionally, windows can now be set to fullscreen on a specific monitor using \set\_fullscreen\_on\_monitor\. On the breaking changes side, \RuntimeHandle\ methods for monitor queries (\primary\_monitor\, \monitor\_from\_point\, \available\_monitors\) now return \Result\s instead of direct values, and the crate has moved to Rust edition 2024 with an MSRV of 1.90.

crates/tauri-runtime · high confidence

Tauri core and runtime updated to v2.12.0 with new windowing and permission features

The \crates/tauri\ and \crates/tauri-runtime-wry\ crates have been updated to version 2.12.0. This release introduces several new capabilities, including the ability to limit webview navigation to app-bound domains, override application directories for portable app support, and exit the app directly via the \@tauri-apps/api/app\ \exit\ function. Window management is enhanced with \set\_fullscreen\_on\_monitor\ for multi-monitor setups, \set\_simple\_fullscreen\ on macOS, and a new \no\_redirection\_bitmap\ option for Windows. Additionally, the runtime now exposes Wry permission handlers for system features like display capture, MIDI, and local fonts, and supports creating multiple windows on Android and iOS.

crates/tauri · high confidence

Vendored BLAKE3 reference implementation for code generation

The \tauri-codegen\ crate now includes a vendored copy of the BLAKE3 reference implementation (\blake3\_reference\) within its vendor module. This addition provides a self-contained, readable algorithm implementation used for testing and as a reference during code generation, ensuring the build process does not rely on external dependencies for this specific cryptographic logic.

crates/tauri-codegen/src/vendor · high confidence

Security

The platform utilities now include a new \StartingBinary\ module that caches the application's executable path at startup using the \ctor\ crate. This implementation adds a security check on macOS to detect and reject executable paths containing symlinks, preventing potential path traversal or injection attacks. The symlink check can be disabled via the \process-relaunch-dangerous-allow-symlink-macos\ feature flag for compatibility with existing workflows that rely on symlinked binaries.

crates/tauri-utils/src/platform · high confidence

Architecture

New internal event system implementation and specification

The event handling subsystem in \crates/tauri/src/event\ has been restructured with a new internal implementation. This includes a formal specification (\event-system-spec.md\) defining emitters (App, Window, Webview, etc.) and listener types, a new \EventName\ type that validates event names against a strict character set (alphanumeric, \-\, \/\, \:\, \\_), and a refactored \Listeners\ manager that handles Rust-side listener lifecycle and pending action queues. The JavaScript bridge (\init.js\) now exposes internal unlisten capabilities, and the plugin layer (\plugin.rs\) registers the core \listen\, \unlisten\, \emit\, and \emit\_to\` commands to coordinate these changes.

crates/tauri/src/event · high confidence

New internal runtime crate for window and webview management

The \tauri-runtime\ crate has been introduced as the internal abstraction layer between Tauri and the underlying webview runtime. This change adds new modules for handling DPI scaling (\dpi.rs\), monitor information (\monitor.rs\), window lifecycle and events (\window.rs\), and webview interactions (\webview.rs\), along with a comprehensive webview permission system (\webview\_permissions.rs\). For users, this represents a structural reorganization of the runtime internals to support more granular control over windows, webviews, and platform-specific features, though the public API stability is not guaranteed as this is an internal crate.

crates/tauri-runtime/src · high confidence

Restructure webview module into dedicated subdirectory

The webview implementation has been reorganized from the crate root into a dedicated \crates/tauri/src/webview/\ directory. This change introduces a new module structure containing \mod.rs\ (core types and re-exports), \plugin.rs\ (JS-exposed commands for window management), and \webview\_window.rs\ (the \WebviewWindow\ and \WebviewWindowBuilder\ implementations). For users, this is a structural refactor that maintains the existing public API surface while improving code organization; no functional behavior or public interfaces are changed by this move.

crates/tauri/src/webview · high confidence

Restructured CLI helper modules for improved organization

The \tauri-cli\ helper logic has been reorganized into a dedicated \helpers\ module, splitting functionality into distinct files such as \app\_paths.rs\ for directory resolution, \cargo.rs\ for dependency management, \config.rs\ for configuration merging, and \framework.rs\ for frontend framework detection. This change improves code maintainability and separation of concerns without altering the external behavior of the CLI tools.

crates/tauri-cli/src/helpers · high confidence

Restructured Tauri CLI source code into modular command files

The Tauri CLI source code has been reorganized from a monolithic structure into distinct modules for each command (add, build, bundle, completions, dev, error, icon, init, inspect, remove, etc.). This change improves code maintainability and readability by separating concerns, making it easier to locate and modify specific command logic without navigating a large single file.

crates/tauri-cli/src · high confidence

Restructured internal manager modules for cleaner architecture

The internal application manager has been reorganized into dedicated sub-modules (menu, tray, webview, window) within the manager crate. This change improves code maintainability and separation of concerns by isolating the logic for managing menus, tray icons, webviews, and windows into their own files, without altering the public API or user-facing behavior.

crates/tauri/src/manager · high confidence

Restructured protocol handlers into a dedicated module

The custom protocol handling logic has been reorganized into a new \crates/tauri/src/protocol\ module, separating concerns into distinct files: \asset.rs\ for static asset serving, \tauri.rs\ for the main application URL handling and mobile dev proxying, and \isolation.rs\ for the isolation scheme. This change introduces asynchronous file loading for assets, supports multi-range HTTP requests, and implements specific mobile development features such as HTTPS scheme support on Windows and Android, custom root certificate handling, and response caching for the dev server proxy.

crates/tauri/src/protocol · high confidence

Tauri build script is restructured into modular source files

The \tauri-build\ crate has been refactored from a single monolithic source file into a modular structure, introducing dedicated modules for Access Control List (ACL) handling (\acl.rs\), dependency manifest validation (\manifest.rs\), and mobile build generation (\mobile.rs\). This change also includes new support files for Windows application manifests and static Visual C++ runtime linking, providing a clearer separation of concerns for build-time logic.

crates/tauri-build/src · high confidence

Tauri core library source files restructured into new module layout

The \crates/tauri/src\ directory has been reorganized into a new modular structure, introducing dedicated source files for core application logic (\app.rs\), asynchronous runtime handling (\async\_runtime.rs\), error definitions (\error.rs\), plugin management (\plugin.rs\), process control (\process.rs\), and state management (\state.rs\). This change also includes platform-specific bindings for iOS (\ios.rs\) and the isolation pattern implementation (\pattern.rs\), establishing the foundational codebase for the Tauri application lifecycle, IPC, and plugin system.

crates/tauri/src · high confidence

Behavioural changes

7 commits (3 fixes) modifying examples/.icons

A change to existing behaviour in examples/.icons — 7 commits (3 fixs), 19 files.

examples/.icons · medium confidence · unverified

API example app migrated to Svelte 5 with dynamic theming

The API example application has been rewritten in Svelte 5, introducing a modern UI that supports dynamic theme switching (light, dark, and auto) via the \setTheme\ API and respects system preferences. The app now features a responsive layout with a collapsible sidebar for mobile devices, a resizable console for viewing IPC messages, and dedicated views for demonstrating Window, Menu, Tray, and WebRTC capabilities.

examples/api/src · high confidence

API example app rewritten in Svelte 5

The API example application has been completely rewritten using Svelte 5, replacing the previous implementation. This update introduces Svelte 5's new component model, including the use of \$props()\ for reactive props, \$state()\ for reactive state, and \$derived()\ for computed values. The UI now leverages Svelte 5's syntax for reactivity and lifecycle management, providing a modernized developer experience and demonstrating the framework's latest capabilities within the Tauri ecosystem.

examples/api/src/views · high confidence

API example migrated to Svelte with new permission and isolation setup

The API example application has been rebuilt using Svelte and Vite, replacing the previous framework. This update introduces a comprehensive permission model using the new \capabilities\ system (with \main.json\ and \run-app.json\ defining granular access for core, window, and webview APIs) and a sample plugin (\tauri-plugin-sample\) demonstrating scoped permissions and cross-platform glue code. Additionally, the example now configures the Isolation Pattern for enhanced security, sets up mobile-specific configurations (including an \Info.plist\ for iOS), and includes a cross-compilation setup script for Linux.

examples/api · high confidence

API example restructured with new Rust backend and plugin architecture

The \examples/api/src-tauri\ directory has been completely rewritten to demonstrate modern Tauri patterns. The Rust backend now uses a modular structure with separate files for commands (\cmd.rs\), the application entry point (\lib.rs\), and platform-specific features like system tray (\tray.rs\) and custom menu handling (\menu\_plugin.rs\). Key behavioral changes include the introduction of a custom \tauri\_plugin\_sample\ for demonstrating plugin state and channel communication, explicit permission scoping via \CommandScope\ in the \log\_operation\ command, and the use of \WebviewWindowBuilder\ for advanced window configuration (such as handling new window requests and document title changes). The example also showcases runtime system tray creation with dynamic menu switching and icon updates, replacing the previous implementation.

examples/api/src-tauri · high confidence

AppImage bundler refactored to use bundled linuxdeploy plugins

The AppImage bundling logic in \crates/tauri-bundler/src/bundle/linux/appimage\ has been restructured to inline the \linuxdeploy-plugin-gtk\ and \linuxdeploy-plugin-gstreamer\ scripts directly into the Rust crate. This change replaces external plugin dependencies with self-contained shell scripts that handle GTK and GStreamer resource bundling, ensuring the bundler works reliably without requiring pre-installed linuxdeploy plugins on the host system.

crates/tauri-bundler/src/bundle/linux/appimage · high confidence

Automated migration from Tauri v1 to v2

The \tauri migrate\ command now automatically upgrades projects from Tauri v1 to v2. This process updates the \Cargo.toml\ manifest to use v2 dependencies and features, migrates the \tauri.conf.json\ configuration to the new schema, and rewrites frontend JavaScript/TypeScript imports to use the new pluginified module structure (e.g., \@tauri-apps/api/fs\ becomes \@tauri-apps/plugin-fs\). It also handles the installation of new npm packages and the removal of obsolete ones, while ensuring that capability permissions are correctly migrated.

crates/tauri-cli/src/migrate · high confidence

Comprehensive restructuring of the \`tauri info\` diagnostic output

The \tauri info\ command has been completely rewritten to provide a more structured and detailed diagnostic report. The new implementation organizes output into distinct sections: it now detects the build type (bundle vs. build) and displays the Content Security Policy (CSP) setting; it infers the frontend framework and bundler from \package.json\; it checks for outdated Node.js versions against the CLI's target version; it verifies the installation and versions of Rust toolchain components (rustc, cargo, rustup); it detects Windows-specific dependencies like Visual Studio build tools and WebView2; it lists installed Node.js package managers (npm, pnpm, yarn, bun, deno) and checks for outdated Tauri NPM packages; it lists Rust dependencies (tauri, wry, tao) and checks for outdated versions; and it validates that Tauri plugins have matching major/minor versions between their Rust and NPM packages, flagging mismatches as errors.

crates/tauri-cli/src/info · high confidence

DMG bundler now skips self-signing the disk image

The macOS DMG bundling process has been updated to stop automatically code-signing the generated \.dmg\ file. This change prevents the bundler from self-signing the disk image, addressing issues where self-signed DMGs caused problems during installation or verification. Users relying on the bundler for macOS distribution will now receive unsigned DMGs, which may require manual signing or notarization steps if required by their distribution channel.

crates/tauri-bundler/src/bundle/macos/dmg · high confidence

Enhanced drag-region behavior with deep and disabled modes

The window drag script now supports three modes for the \data-tauri-drag-region\ attribute: standard (drag only on direct clicks), \deep\ (drag on any click within the element's subtree), and \false\ (explicitly disables dragging for the element and its ancestors). This allows developers to create complex interactive areas where specific child elements can either trigger window dragging or remain fully interactive without blocking the drag gesture, while also fixing macOS double-click maximization to cancel if the mouse moves.

crates/tauri/src/window/scripts · high confidence

Hello World example updated to use new configuration and API structure

The Hello World example has been refreshed to align with the latest Tauri architecture. It now uses the new \tauri.conf.json\ schema, featuring a \frontendDist\ array for specifying the frontend source and a \security.csp\ block for Content Security Policy configuration. The Rust entry point (\main.rs\) has been updated to use the modern \tauri::Builder\ pattern with \invoke\handler\, and the frontend (\index.html\) now imports the \core\ module from \window.\\TAURI\\_\ to invoke commands, reflecting the shift to the new IPC and API surface.

examples/helloworld · high confidence

Improved icon selection and deterministic asset code generation

The codegen now selects the largest and highest-quality entry from ICO files instead of the first, ensuring better resolution for app icons. Additionally, asset embedding and configuration serialization are now deterministic, and the generated context code is wrapped in a function to improve performance.

crates/tauri-codegen/src · high confidence

Internal restructuring of the codegen module

The \tauri-build\ crate has reorganized its internal code generation logic by extracting the \CodegenContext\ builder into a new \codegen/context.rs\ module. This change moves the compile-time context generation logic into a dedicated file, improving code organization without altering the public API or build behavior for users.

crates/tauri-build/src/codegen · high confidence

Isolation pattern example now uses the core API and exposes the pattern identifier

The isolation example's distribution files have been updated to demonstrate the correct usage of the Tauri Isolation pattern. The main HTML file now imports the \invoke\ function from \window.\_\TAURI\\.core\ instead of the legacy global, ensuring compatibility with the current API surface. Additionally, a new \linked.js\ script has been added to the distribution, which logs the \\\_TAURI\PATTERN\\\ identifier from \window.\\_TAURI\INTERNALS\\_\ to verify that the isolation context is correctly established.

examples/isolation/dist · high confidence

Linux bundler now generates desktop entries with quoted Exec paths and proper icon handling

The Linux bundler now correctly generates \.desktop\ files for freedesktop-compliant environments. The \Exec\ field is automatically wrapped in quotes if the application binary name contains spaces, preventing launch failures. Additionally, the bundler now properly processes PNG icons, placing them in the standard \hicolor\ icon hierarchy based on their dimensions and density, and generates the corresponding desktop entry file with support for categories, comments, and MIME type associations.

crates/tauri-bundler/src/bundle/linux/freedesktop · high confidence

Linux bundling restructured into modular Debian and RPM implementations

The Linux bundling logic has been reorganized into distinct modules for Debian (.deb) and RPM packages, introducing specific behaviors for each format. For Debian packages, the bundler now supports generating changelog files and allows configuring the maintainer field by falling back to the publisher if authors are not specified. For RPM packages, users can now configure compression algorithms (Gzip, Zstd, Xz, Bzip2), specify release and epoch values, and define package dependencies including recommends, conflicts, and obsoletes. Both formats now explicitly support the RISC-V 64 architecture alongside existing x86 and ARM variants.

crates/tauri-bundler/src/bundle/linux · high confidence

The menu implementation has been restructured into distinct modules for different item types, introducing dedicated \CheckMenuItem\ and \IconMenuItem\ types alongside the existing \MenuItem\ and \Submenu\. This change adds the ability to display icons on submenus and icon menu items, supports native icons on macOS, and includes a new \BringAllToFront\ predefined menu item. The refactoring also ensures proper cleanup of menu channels to prevent resource leaks and fixes issues with submenu creation via object arguments.

crates/tauri/src/menu · high confidence

New ACL system for fine-grained permission control

Tauri introduces a new Access Control List (ACL) system to replace the legacy permission model, allowing developers to define precise, granular permissions for IPC commands via capability files. This change restructures the \tauri-utils\ crate with new modules for handling identifiers, manifests, and schema generation, and introduces a build-time resolution process that compiles permissions into the binary. Users will now configure access using capability definitions that map specific permissions to windows or webviews, with support for scoped arguments and JSON5 configuration files.

crates/tauri-utils/src/acl · high confidence

New filesystem and HTTP utility modules for bundler tools

The bundler now includes dedicated \fs\_utils\ and \http\_utils\ modules to handle file operations and tool downloads. The HTTP utilities ensure that requests to fetch build tools include a proper User-Agent header and support GitHub mirror redirection via environment variables, improving reliability in restricted network environments. Additionally, the HTTP module introduces a \platform-certs\ feature flag that allows the bundler to use the system's root certificates for TLS verification, enhancing security and compatibility on systems with custom CA setups.

crates/tauri-bundler/src/utils · high confidence

New macOS bundler implementation with code signing and notarization

The macOS bundling logic in \crates/tauri-bundler/src/bundle/macos\ has been replaced with a new implementation that constructs \.app\ bundles, generates \Info.plist\ and icon files, and handles code signing and notarization. This change introduces support for custom \CFBundleVersion\ on macOS and iOS, allows skipping code signing via a \--no-sign\ flag, and adds the ability to skip the stapling step during notarization. It also supports Liquid Glass icons and includes fixes for file association metadata and unnecessary entitlements on frameworks.

crates/tauri-bundler/src/bundle/macos · high confidence

New mobile plugin infrastructure with deadlock-avoidance patterns

The \crates/tauri/src/plugin/mobile.rs\ module introduces the core glue code for handling plugin commands and channels on Android and iOS. It implements a pending-call handler system that explicitly drops mutex locks before invoking callbacks that communicate with the webview, preventing deadlocks that could occur if the UI thread blocked while holding the lock. It also provides specific JNI integration functions (\handle\_android\_plugin\_response\, \send\_channel\_data\) to bridge Rust and Kotlin, and includes an iOS plugin registration path that waits for the native side to initialize before returning.

crates/tauri/src/plugin · high confidence

New resource management plugin with fallback close behavior

A new \resources\ plugin has been added to expose resource management capabilities to the application. This includes a \close\ command that attempts to close a resource by its ID, specifically implementing a fallback mechanism that checks the Webview, Window, and AppHandle resource tables in sequence if the initial close attempt fails. This ensures resources can be properly cleaned up even if they were registered in a different scope than the one initially queried.

crates/tauri/src/resources · high confidence

Restructured CLI interface with new Rust app abstraction

The Tauri CLI has been restructured to introduce a new \interface\ module that abstracts platform-specific build logic. This change adds a \Rust\ struct and \AppSettings\ trait to centralize configuration handling, bundler settings, and binary discovery for Rust-based projects. Users will benefit from improved error handling, better support for custom main binary names, and more robust management of build targets and features through this new internal architecture.

crates/tauri-cli/src/interface · medium confidence

Restructured IPC module with new runtime authority and capability builder

The IPC subsystem has been reorganized into dedicated source files (\authority.rs\, \capability\_builder.rs\, \channel.rs\, \command.rs\, \format\_callback.rs\, \protocol.rs\) to improve modularity. This change introduces a new \RuntimeAuthority\ struct that centralizes Access Control List (ACL) enforcement, command resolution, and scope management, replacing the previous inline logic. A new \CapabilityBuilder\ API is exposed (behind the \dynamic-acl\ feature) to allow runtime construction of capabilities. Additionally, the \Channel\ implementation has been refined to handle webview lifecycle events more robustly, ensuring pending payloads are not queued for closed webviews and callbacks are properly cleaned up.

crates/tauri/src/ipc · high confidence

Restructured filesystem scope implementation and API

The filesystem scope logic has been moved into a dedicated \fs\ module and re-implemented to improve pattern handling and reliability. This change introduces a new \Scope::is\_forbidden\ capability, fixes deadlocks in scope event handling, and resolves issues with canonicalizing root paths on Windows. Users can now manage asset protocol scopes via the \Scopes\ manager API, which exposes methods to allow or forbid specific files and directories at runtime.

crates/tauri/src/scope · high confidence

Restructured path resolution into platform-specific modules with new Android support

The path resolution logic has been reorganized into separate platform-specific implementations: a new \android.rs\ module for Android devices and a \desktop.rs\ module for desktop platforms (Linux, macOS, Windows). This change introduces Android-specific path resolution via a mobile plugin, including support for resolving file names from Android content URIs in the \file\_name\ method. It also corrects the \video\_dir\ behavior on Android to point to the app-specific Movies directory instead of the external cache storage, requiring users to migrate any files previously stored in the cache location. Additionally, the \SafePathBuf\ type now derives \serde::Serialize\ and implements \FromStr\, and the \PathResolver\ is now \Clone\.

crates/tauri/src/path · high confidence

Reworked macro implementation and mobile entry point support

The \tauri-macros\ crate has been restructured to support new capabilities and improved stability. The \mobile\_entry\_point\ macro now supports \async\ functions, automatically wrapping them to block on the async runtime for mobile targets. A new \context.rs\ module handles the \generate\_context!\ macro, parsing configuration, capabilities, and assets to embed them into the binary. The \menu.rs\ module introduces a refined \DoMenuItemInput\ parser for handling menu item kinds with negation support, addressing previous panics in menu-related commands. Additionally, the \runtime.rs\ module provides a \default\_runtime\ attribute to set default generic parameters for runtime types based on feature flags.

crates/tauri-macros/src · high confidence

Runtime binary patching for bundle type detection

The bundler now embeds bundle type information directly into the main binary at build time by patching a placeholder token with the specific package type (e.g., NSIS, MSI, AppImage, Deb, RPM). This allows the application to detect its own bundle type at runtime, which is required for the updater plugin to correctly identify and update the package. The process is controlled by the \binary\_patching\ setting (defaulting to enabled), and on Windows, the main binary is re-signed after patching to ensure code signature verification passes.

crates/tauri-bundler/src · high confidence

Tauri API package restructured with new build and configuration files

The \packages/api\ directory has been restructured to support the current build process. A new \rollup.config.ts\ is now used to bundle the TypeScript sources into ESM, CJS, and IIFE formats, including a script bundle for the Tauri core. The \tsconfig.json\ has been updated to target ES2019, use the 'bundler' module resolution, and enable strict type checking. Additionally, an \eslint.config.js\ is introduced to enforce code quality and security rules, and a \.gitignore\ file is added to exclude the \/dist/\ build output.

packages/api · high confidence

Tauri CLI 2.12.0 release with security hardening and new bundler options

The Tauri CLI has been updated to version 2.12.0, introducing several security fixes and new configuration options. Security improvements include stricter validation for updater signatures to prevent version spoofing, protection against DNS rebinding attacks in the dev server, and secure handling of signing keys and temporary files. New features allow developers to bundle the Visual C++ runtime with Windows installers, skip binary patching during builds, and configure non-square image fitting for icons. The release also updates Android templates to use Gradle 9.6.1 and Kotlin 2.2, and improves the \tauri init\ experience with better CI support and warnings for default product names.

crates/tauri-cli · high confidence

Tauri CLI v2.12.0 release with security hardening and platform updates

The @tauri-apps/cli package has been updated to version 2.12.0, introducing several security fixes and platform improvements. Security enhancements include stricter validation for updater signatures to prevent version spoofing, protection against DNS rebinding attacks in the dev server, and secure handling of mobile build options via per-session tokens. The release also updates Android templates to use Gradle v9.6.1 and Kotlin v2.2, and iOS templates to support Xcode 27. New features include the ability to copy Visual C++ runtime DLLs into Windows installers, a \--no-binary-patching\ flag for \tauri build\, and support for non-square images in \tauri icon\.

packages/cli · high confidence

Tauri build and codegen crates restructured and updated to v2.7.0

The \tauri-build\ and \tauri-codegen\ crates have been restructured, promoting them to stable v2.7.0 and moving to Rust edition 2024 with a minimum supported Rust version (MSRV) of 1.90. This update introduces new build-script features, including \Attributes::config\_path\ to customize configuration paths and \WindowsAttributes::static\_vc\_runtime\ for controlling MSVC static runtime linking. Resource handling is improved by emitting \cargo:rerun-if-changed\ for resource directories, ensuring new files are copied without manual rebuilds, and fixing icon resolution relative to the config file. The codegen crate now loads the default window icon from embedded resources and ensures reproducible builds by sorting embedded assets. Additionally, dependencies like \tauri-utils\ and \tauri-codegen\ are upgraded, and Android templates are updated to use Gradle v9.6.1 and Kotlin v2.2.

crates/tauri-build · high confidence

Tray icon API restructured with tagged events and new configuration options

The tray icon module has been reorganized into \mod.rs\ and \plugin.rs\, introducing a tagged \TrayIconEvent\ enum (serialized with a \type\ field) that distinguishes between Click, DoubleClick, Enter, Move, and Leave events, replacing the previous untagged structure. The JavaScript API now supports configuring \showMenuOnLeftClick\ and \iconAsTemplate\ options during tray creation, and exposes commands to manage tray icons by ID (get, remove) and update their icon, menu, tooltip, title, and visibility dynamically.

crates/tauri/src/tray · high confidence

Updated Android app template with edge-to-edge display and Material 3 theming

The Android app initialization template now uses the \Theme.Material3.DayNight.NoActionBar\ parent theme for both light and dark modes, providing a modern Material Design 3 appearance. Additionally, the \MainActivity\ now calls \enableEdgeToEdge()\, ensuring the app content extends into the system bars for an immersive edge-to-edge experience on supported Android versions.

crates/tauri-cli/templates/mobile/android/app · high confidence

Updated Android plugin and mobile templates with new structure and ProGuard rules

The Android plugin template and mobile Android configuration have been restructured to include essential build artifacts and security configurations. The plugin template now provides a standard Android project layout with an AndroidManifest, example Kotlin source files for plugin commands, and corresponding unit and instrumentation tests. Additionally, the mobile Android template now includes a consumer-rules.pro file with specific ProGuard rules to preserve Tauri's JNI methods, plugin annotations, and JSON serialization classes, ensuring that minification does not break native interop.

crates/tauri-cli/templates/plugin/android, crates/tauri/mobile/android · high confidence

Updated Tauri app template to Rust edition 2024 and MSRV 1.90

The generated Tauri application template now targets Rust edition 2024 and requires a minimum supported Rust version (MSRV) of 1.90. This change updates the \Cargo.crate-manifest\ to reflect the new edition and MSRV, and includes the \tauri-plugin-log\ dependency. Users creating new projects will benefit from the latest Rust language features and tooling, but must ensure their development environment is updated to Rust 1.90 or later.

crates/tauri-cli/templates/app/src-tauri, crates/tauri-cli/templates/plugin · high confidence

Updated iOS plugin template to target iOS 15.0

The iOS Xcode project template for Tauri plugins now sets the minimum deployment target to iOS 15.0, aligning with the app template's SDK versions. This change ensures that newly generated plugin projects are compatible with modern iOS development standards and removes support for older iOS versions in the generated codebase.

crates/tauri-cli/templates/plugin/ios-xcode · high confidence

Updated plugin example templates to Rust edition 2024 and MSRV 1.90

The plugin example templates now require Rust 1.90 and use the 2024 edition, reflecting the latest stable Rust standards. The Svelte-based example has been updated to use Svelte 5 syntax, including the new $state reactive store and $state() macro, and includes VS Code extension recommendations for Svelte and Tauri development. The basic vanilla example also adopts the new edition and MSRV requirements.

crates/tauri-cli/templates/plugin/\\example-api · high confidence

Windows bundler module structure and code signing implementation

The Windows bundler module has been restructured into dedicated files for module organization, NSIS/MSI output paths, and code signing logic. The new sign.rs module implements the core code signing workflow, including automatic detection of the Signtool executable via the Windows Registry and environment variables, support for custom signing commands, and verification of existing signatures. The util.rs module provides utilities for downloading WebView2 installers and locating Visual C++ runtime DLLs for bundling, while the mod.rs file establishes the public API for the Windows bundler components.

crates/tauri-bundler/src/bundle/windows · high confidence

On Windows, the runtime's error dialog implementation has been updated to support clickable hyperlinks within error messages. When the \common-controls-v6\ feature is enabled, the dialog uses the modern Task Dialog API, which allows users to click links directly in the error message to open them. If the feature is disabled, the dialog falls back to a standard message box and automatically strips hyperlink markup from the text to ensure compatibility.

crates/tauri-runtime-wry/src/dialog · high confidence

Fixes

Add KMP string search utility for bundler

The Tauri bundler now includes a Knuth–Morris–Pratt (KMP) string matching implementation in the \kmp\ module. This adds a utility function to locate patterns within byte arrays, which supports internal string replacement logic used during the bundling process.

crates/tauri-bundler/src/bundle/kmp · medium confidence

Android template now uses Gradle 9.6.1

The Android project template has been updated to use Gradle version 9.6.1. This change ensures that new Android projects generated by Tauri will utilize the latest Gradle wrapper configuration, providing access to recent build tool improvements and compatibility updates out of the box.

crates/tauri-cli/templates/mobile/android/gradle · high confidence

Improved Windows executable detection for Tauri CLI in Android builds

The Android build template now includes a Kotlin-based Gradle plugin and build task that handle invoking the Tauri CLI binary. Specifically, on Windows, the build process will automatically retry with common executable extensions (.exe, .cmd, .bat) if the initial attempt to run the Tauri binary fails, resolving issues with tools like nvm4w that may not expose the executable with a standard extension.

crates/tauri-cli/templates/mobile/android/buildSrc · high confidence

Updated iOS project template with modern build configuration and assets

The iOS project template has been updated to include a dedicated LaunchScreen storyboard, a complete set of App Icon assets for iPhone and iPad, and an ExportOptions.plist configured for debugging. The project.yml configuration now explicitly sets the initial view controller for the launch screen, enforces arm64 and Metal device capabilities, and configures build settings to exclude static libraries from resources to prevent build collisions. Additionally, workspace settings have been added to optionally support the legacy build system, and a .gitignore file has been introduced to exclude Xcode user data and build artifacts.

crates/tauri-cli/templates/mobile/ios · high confidence

Test coverage

Added ACL test fixtures and snapshots for capability resolution; Added Tauri benchmark application for file transfer testing; Added benchmark test fixtures for CPU, file transfer, and hello world scenarios; Added benchmark test harnesses for CPU-intensive and hello-world scenarios; Added integration test for CLI project initialization and build; Added integration tests for process restart with symlinks; Added test fixtures for updater signature verification and isolation security patterns; Added test utilities for unit testing Tauri applications; Added tests for iOS pbxproj handling and non-interactive init; New end-to-end test suite for @tauri-apps/api.

Dependencies

Initial workspace configuration and dependency lockfile

The repository is initialized with a Cargo workspace manifest defining the project structure, including core crates, CLI, bundler, and examples, alongside a generated Cargo.lock file that pins all Rust dependencies. The workspace sets the Rust edition to 2024 and establishes a minimum supported Rust version (MSRV) of 1.90, while also configuring workspace-level dependency management and linting rules for the entire codebase.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.

Score

  • CAI 41 → 64 (+22.5)
  • Rubric changed (rubric-2026.08.15 → rubric-2026.09.15) — scores are not directly comparable.

Lenses

  • Code Health 71 → 69 (-2.3)
  • Architecture 86 → 87 (+0.7)
  • Maturity 58 → 68 (+10.4)
  • Readiness 17 → 66 (+49.0)
  • Security 63 → 80 (+16.9)
  • Event Sourcing 100 (new)
  • Accessibility 57 (new)

Resolved (95)

  • Coverage not measured — test suite did not build
  • Dimension evaluation failed
  • Duplicated block (29 lines × 2) (crates/tauri/mobile/android/src/main/java/app/tauri/plugin/JSObject.kt)
  • FileTooLong: cli/index.js (packages/cli/index.js)
  • High CVE: [GHSA redacted] (Cargo.lock)
  • High IaC: DS-0002 (.devcontainer/Dockerfile)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • High: security finding (details withheld)
  • …and 75 more

New (627)

  • (anonymous) (cognitive 18) (crates/tauri-utils/src/pattern/isolation.js)
  • (anonymous) (cyclomatic 18) (crates/tauri-utils/src/pattern/isolation.js)
  • Builder::build (cognitive 19) (crates/tauri/src/app.rs)
  • Change coupling: init.rs ↔ BuildTask.kt (crates/tauri-cli/src/mobile/init.rs)
  • Change coupling: lib.rs ↔ lib.rs (crates/tauri-build/src/lib.rs)
  • Change coupling: listener.rs ↔ plugin.rs (crates/tauri/src/event/listener.rs)
  • Change coupling: webview_window.rs ↔ plugin.rs (crates/tauri/src/webview/webview_window.rs)
  • ClassTooLong: Webview (crates/tauri/src/webview/mod.rs)
  • ClassTooLong: WebviewBuilder (crates/tauri/src/webview/mod.rs)
  • ClassTooLong: WebviewManager (crates/tauri/src/manager/webview.rs)
  • ClassTooLong: WebviewWindowBuilder (crates/tauri/src/webview/webview_window.rs)
  • ClassTooLong: Window (crates/tauri/src/window/mod.rs)
  • ClassTooLong: Window (packages/api/src/window.ts)
  • Config::load (cognitive 21) (crates/tauri-cli/src/interface/rust/cargo_config.rs)
  • Confusingly similar names: listen and listen_any have nearly identical signatures. The distinction (likely target scope) is not obvious from the name alone, leading to potential misuse.
  • ContextItems::parse (cognitive 26) (crates/tauri-macros/src/context.rs)
  • Coverage not measured — JavaScript/TypeScript suite
  • Dependency hygiene PARTLY measured — Maven/Gradle declarations read, no dependency graph resolved
  • Dependency source pinned to a moving git ref
  • Duplicate intent: Both methods appear to trigger an application restart. The naming convention is inconsistent ('restart' vs 'request_restart') and the return types differ significantly (one returns ! (never), the other returns Result), suggesting they might have different execution contexts or error handling, but the semantic overlap is confusing.
  • …and 607 more

Changes since last survey

  • 151 commits — 66 feature/other, 85 fixes

By area

  • crates/tauri-cli — 33 commits
  • crates/tauri — 25 commits
  • (root) — 18 commits
  • .github/workflows — 6 commits
  • packages/api — 6 commits
  • crates/tauri-build — 4 commits
  • crates/tauri-bundler — 4 commits
  • packages/api-e2e — 3 commits
  • crates/tauri-runtime-wry — 2 commits
  • (repo) — 1 commit
  • .changes/acl-deny-execution-context.md — 1 commit
  • .changes/additional-watch-folders-alias.md — 1 commit
  • .changes/allow-crlf-cargo-toml.md — 1 commit
  • .changes/android-plugin-manager-relaunch.md — 1 commit
  • .changes/android-target-sdk-37.md — 1 commit
  • .changes/asset-protocol-multi-range.md — 1 commit
  • .changes/asset-protocol-off-main-thread.md — 1 commit
  • .changes/bundler-updater-targets-deb-rpm.md — 1 commit
  • .changes/cli-add-git-options.md — 1 commit
  • .changes/cli-android-adb-reverse.md — 1 commit

Notable commits

  • fix: Fix doubled word in RELEASING.md (#15853)
  • fix: Revert "Add cleanup_before_exit plugin hook, CLI kills entire app tree (#14443)" (#16134)
  • fix: Revert "feat(core): add android activityEmbedding config (#15255)" (#16138)
  • fix: Revert "fix(core): proper unique identifier for menu items on channels store" (#16137)
  • fix: chore: fix clippy warnings
  • fix: chore: remove change file for unreleased fix (#16140)
  • fix: fix(acl): rebase runtime-resolved scope ids past baked ACL (#15291)
  • fix: fix(android): JSObject and JSArray serialization
  • fix: fix(android): register result launchers per activity (#15949)
  • fix: fix(android): update template to use gradle 9 (#15828)
  • fix: fix(api): pass the color argument to setBackgroundColor commands (#16067)
  • fix: fix(build): validate inline capabilities from the config file (#16074)
  • fix: fix(bundler): WiX resources must use BTreeMap for reproducible builds
  • fix: fix(bundler): recognize deb and rpm as self-contained updater targets (#16064)
  • fix: fix(bundler): update linuxdeploy and linuxdeploy-plugin-gtk (#16062)
  • fix: fix(bundler): write vswhere to a uniquely named temp file
  • fix: fix(ci): give audit permissions (#15970)
  • fix: fix(ci): pnpm publish should use "debug" loglevel instead of "silly"
  • fix: fix(ci): restore ndk symlinks on macos (#15870)
  • fix: fix(cli): apply default ignore rules in memory instead of shared temp files (#16094)
  • …and 131 more

Architecture

  • Containers 0 added · 0 removed · contexts 1 added · 0 removed · edges 0 added · 0 removed

Added bounded contexts (1)

  • android

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

tauri-apps/tauri was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 27 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 447fa9f3f993fe77724189e355078b38ce20baea — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-7c1cb6328e11.