Updating NativeDev
NativeDev has one release channel: GitHub Releases on sayedsahin/nativedev.
Background check
When installed as a native package, NativeDev checks the public GitHub Releases API in the background at most once every 24 hours:
Application starts
|
check timestamp
|
>= 24h?
|
GitHub latest release API
|
compare version
|
show update dialogThis check is unprivileged, read-only, and does not run APT or open a Polkit prompt. If no release has been published yet, NativeDev simply records that the check happened and shows nothing. A newer vX.Y.Z release is only offered when it contains the exact expected Debian asset nativedev_X.Y.Z_all.deb and GitHub reports a SHA-256 digest for that asset — a release missing either is treated as not yet ready to offer.
Update flow
GitHub Release
|
nativedev_X.Y.Z_all.deb
|
download
|
verify SHA-256 digest
|
Polkit action
|
install package
|
restart NativeDevClicking Update crosses the privilege boundary as the fixed semantic application.update action — there is no client-controlled URL, path, package name, repository, or command involved. The root helper:
- Independently re-queries the same fixed GitHub repository (it does not trust a URL from the GUI process).
- Downloads only the expected NativeDev
.debasset. - Verifies GitHub's reported SHA-256 digest against the downloaded file.
- Verifies the
.deb's ownPackage,Version, andArchitecturefields. - Installs the verified local package with APT, using the same immediate dpkg-lock-failure semantics used everywhere else (see Security model).
After a successful install, NativeDev offers Restart NativeDev so the new application code and the new root-owned helper are loaded together — the two are always shipped and updated as a matched pair (see the protocol-versioning note in the Security model).
Distro independence
Release discovery itself is distro-independent. Debian/Ubuntu via APT is the currently implemented package installer backend; future RPM/DNF or Pacman backends can select their own release asset without changing the 24-hour check/update UI policy described above.
Manually checking for a release
If you don't want to wait for the periodic check, the GitHub Releases page for the repository always reflects the latest published .deb, if any has been published yet.