palisadeDownload

Updates and releases

How Palisade updates itself, how releases are built and signed, and what each release contains.

Palisade updates itself. Each update is checked against the project's signing key before it is installed.

Self-update

  • Installed apps check for updates automatically.
  • An update is installed only if its signature matches the project's signing key.
  • A failed update check never blocks startup.

What a release contains

Each installable release includes these assets on GitHub:

AssetWho it is for
Signed updater archiveExisting installs, through self-update.
Updater signatureUsed to check the archive before install.
Notarized universal DMG, model includedFirst installs. Supports Apple Silicon and Intel Macs running macOS 11 or later.

Get the latest DMG from the releases page.

How a release is built

  1. A maintainer pushes a vX.Y.Z tag.
  2. The tag must match the version in package.json, src-tauri/tauri.conf.json, and src-tauri/Cargo.toml.
  3. The workflow runs its checks.
  4. It waits for a reviewer to approve it.
  5. Only the approved job can read release credentials and publish.

The workflow builds the pinned llama.cpp sidecar from source for Apple Silicon (Metal) and Intel (CPU only). It combines them into one universal binary. It verifies the model checksum before packaging.

After publication, the update service serves the new release to installed apps. A failed or unapproved workflow cannot change what installed apps receive.

Local builds

Building locally never publishes an update. ./package.sh builds and, unless you pass --no-install, installs the app on your Mac. It does not need or read updater credentials.