winui-packaging

bởi microsoft

Đóng gói MSIX, ký mã và phân phối cho ứng dụng WinUI 3 — xây dựng cho bản phát hành, tạo chứng chỉ (winapp cert generate), tin cậy chứng chỉ, mã…

npx skills add https://github.com/microsoft/win-dev-skills --skill winui-packaging

Quick Reference

TaskCommand
Build for release.\BuildAndRun.ps1 /p:Configuration=Release
Package + signwinapp package <dir> --cert devcert.pfx
Generate + sign + packagewinapp package <dir> --generate-cert --install-cert
Generate dev certificatewinapp cert generate
Trust certificate (admin)winapp cert install ./devcert.pfx
Sign existing filewinapp sign ./app.msix ./devcert.pfx
Self-contained deploymentwinapp package <dir> --cert devcert.pfx --self-contained

End-to-End Workflow

Step 1: Build for Release

Use the BuildAndRun.ps1 script from the winui-dev-workflow skill to build your app in Release configuration without launching it:

.\BuildAndRun.ps1 /p:Configuration=Release -SkipRun

Step 2: Generate Certificate (one-time)

winapp cert generate --manifest .

Creates devcert.pfx (default password: password). The --manifest flag auto-matches the Publisher field in Package.appxmanifest.

Step 3: Trust Certificate (one-time, requires admin)

winapp cert install ./devcert.pfx

Adds cert to machine Trusted Root store. Persists across reboots.

Step 4: Package and Sign

winapp package <build-output-dir> --cert ./devcert.pfx

This locates appxmanifest.xml, stages the layout, generates resources.pri, creates .msix, and signs it.

Step 5: Install or Distribute

# Local install
Add-AppxPackage ./MyApp.msix

# Or double-click the .msix file

Key Rules

  • Publisher must match between certificate and manifest Identity.Publisher — use winapp cert generate --manifest to auto-match
  • Prefer winapp package --cert over separate winapp sign — one step instead of two
  • cert install requires admin — run terminal as Administrator
  • Default PFX password is password — override with --password
  • --timestamp is critical for production — without it, signatures expire with the cert:
    winapp package <dir> --cert prod.pfx --timestamp http://timestamp.digicert.com
    
  • --self-contained bundles Windows App SDK runtime — larger but no runtime dependency

CI/CD with GitHub Actions

name: Build and Package
on: [push]
jobs:
  build:
    runs-on: windows-latest
    steps:
      - uses: actions/checkout@v4
      - uses: microsoft/setup-WinAppCli@v0.1

      - name: Build
        run: dotnet build -c Release -p:Platform=x64

      - name: Package
        run: |
          winapp cert generate --if-exists skip --quiet
          winapp package ./bin/x64/Release/ --cert ./devcert.pfx --quiet

      - name: Upload artifact
        uses: actions/upload-artifact@v4
        with:
          name: msix-package
          path: "*.msix"

CI/CD tips:

  • Use --quiet for clean output
  • Use --if-exists skip with cert generate to avoid failures on re-runs
  • Store production PFX as a repository secret

Store Submission

  1. Partner Center account — register at partner.microsoft.com
  2. Age ratings — complete the questionnaire in Partner Center
  3. Screenshots — capture at 1366x768 minimum resolution
  4. Privacy policy — required for apps that access internet or user data
  5. Submit: upload the signed .msix / .msixbundle produced by winapp package via Microsoft Partner Center — Apps and games → your app → Packages. Microsoft Store submission is browser-based; there is no first-party CLI submit command yet.

Troubleshooting

ErrorSolution
"Publisher mismatch"Run winapp cert generate --manifest to re-generate
"Certificate not trusted"Run winapp cert install ./devcert.pfx as admin
"Access denied"cert install needs admin elevation
"Certificate file already exists"Use --if-exists overwrite or --if-exists skip
"appxmanifest.xml not found"Run winapp init or pass --manifest <path>
"Package installation failed"Trust cert first; remove stale: Get-AppxPackage <name> | Remove-AppxPackage
Signature invalid after timeRe-sign with --timestamp

References

FileRead when...
references/sourcegen-patterns.mdSetting up AOT/trimming, JSON source generators, NativeAOT readiness, CsWin32

Thêm skills từ microsoft

oss-growth
microsoft
Cá tính tăng trưởng OSS
official
accessibility-aria-expert
microsoft
Phát hiện và sửa các vấn đề về khả năng tiếp cận trong giao diện web React/Fluent UI. Sử dụng khi xem xét mã để đảm bảo tương thích với trình đọc màn hình, sửa nhãn ARIA, đảm bảo…
official
generate-canvas-app
microsoft
[DEPRECATED — sử dụng canvas-app thay thế] Tạo một ứng dụng canvas Power Apps hoàn chỉnh.
official
django
microsoft
Các phương pháp tốt nhất cho phát triển web Django bao gồm models, views, templates và testing.
official
github-issue-creator
microsoft
Chuyển đổi ghi chú thô, nhật ký lỗi, ghi âm giọng nói hoặc ảnh chụp màn hình thành báo cáo vấn đề markdown sắc nét theo phong cách GitHub. Sử dụng khi người dùng dán thông tin lỗi, lỗi…
official
python-package-management
microsoft
Sử dụng uv để quản lý phụ thuộc và poethepoet để tự động hóa tác vụ.
official
runtime-validation
microsoft
Xác thực thời gian chạy cho các ứng dụng đã di chuyển — bao gồm chiến lược kiểm thử (giai đoạn lập kế hoạch) và thực thi kiểm thử (giai đoạn xác thực): xác minh khởi động,…
official
azure-postgres-ts
microsoft
Kết nối đến Azure Database for PostgreSQL Flexible Server bằng gói pg (node-postgres) với hỗ trợ xác thực mật khẩu và Microsoft Entra ID (không mật khẩu).
official