Skip to content

Updates and channels

Release builds of Querybara check GitHub Releases for new versions, download them in the background, and offer a restart when one is ready. You choose between a stable and a beta channel. Administrators can turn updates off, or pin the channel, for every user of a machine.

Querybara checks 30 seconds after it starts and every 4 hours. When an update has downloaded, a notice says that the new version is ready, with Restart now, Release notes and Later. Restarting to install an update does not ask about schedules that are on, as quitting otherwise does.

To check at once, choose Help → Check for Updates…, or run Check for Updates… from the command palette. On Windows and Linux the menu bar sits at the left of the window’s title bar. On macOS, Check for Updates… and About Querybara are in the Querybara menu.

The About box (Help → About Querybara, or About Querybara in the command palette) shows the update status and holds the settings:

Setting What it does
Update channel Stable or Beta
Check for updates automatically Turns the background checks on or off
Check for updates Checks now; becomes Restart to update when one is ready
Installed from How it updates
Windows NSIS installer Replaced by the app, on restart or when you quit
macOS DMG Replaced by the app, on restart or when you quit
AppImage Replaced by the app, on restart or when you quit
deb and rpm Replaced by the app on Restart now; your system asks for an administrator password
Windows MSI, Windows zip, unpacked Not by the app: install the new version

deb and rpm updates use the desktop’s graphical administrator prompt (polkit’s pkexec). Without one, the notice shows the error, and you install the new package by hand.

The About box says why when the updater is off:

  • Updates are off in development runs.
  • This is a test build, which does not update itself. Install a release to get updates.
  • Updates are turned off by your administrator.
  • This build is not code-signed, so it does not update itself. (Windows builds without a code-signing publisher.)
  • This installation (MSI, zip or unpacked folder) is updated by installing the new version, not by Querybara.

Every download is checked against the SHA-512 in the release’s metadata. On Windows, the installer’s Authenticode publisher must match the one the app was built with. On macOS, the new app must satisfy the running app’s code signature. Linux packages carry no signature the updater could check, so they rely on the hash, fetched over https from GitHub.

The updater runs in its own session, which may reach only GitHub, over https.

  • Stable follows GitHub’s latest release, which is never a pre-release.
  • Beta takes the newest release of either kind, so it gets new versions first.

Leaving the beta channel never downgrades: Querybara stays on its beta version until a newer stable version ships.

A release can go out to a percentage of installs first. Each install keeps a random id in its data folder (.updaterId) and takes the update only when the id falls within the percentage, so the same machines stay in as the percentage grows. Setting the percentage to 0 halts a rollout; installs that already updated keep the new version.

Administrators can turn updates off, and pin the channel, machine-wide:

Platform Where
Windows HKLM\SOFTWARE\Policies\Querybara: DisableUpdates (REG_DWORD, 1 = off), UpdateChannel (REG_SZ, stable or beta), for example from Group Policy or Intune
macOS A configuration profile for the preference domain com.querybara.desktop: DisableUpdates (boolean), UpdateChannel (string)
macOS The file /Library/Application Support/Querybara/policy.json
Linux The file /etc/querybara/policy.json
Every platform The environment variable QUERYBARA_DISABLE_UPDATES=1, set system-wide

The policy file is JSON:

{ "disableUpdates": true, "updateChannel": "stable" }

On Windows:

Terminal window
reg add HKLM\SOFTWARE\Policies\Querybara /v DisableUpdates /t REG_DWORD /d 1 /f

How the sources combine:

  • Any source that turns updates off wins.
  • A pinned channel greys out the user’s choice in the About box, with Set by your administrator.
  • A policy file that exists but cannot be read as a policy turns updates off.
  • Every source can only be written by an administrator, except the environment variable, which can only turn updates off.

Windows has no policy file: standard users can create folders under %ProgramData%, so a file there would let any user switch updates off for everyone. MSI deployments are not updated by the app in any case; the switch also covers NSIS installs and the other platforms.

Each release builds:

  • Windows: an NSIS installer holding x64 and arm64, an MSI and a zip for each architecture.
  • macOS: a universal DMG, and a zip for signed releases.
  • Linux: AppImage, deb and rpm for x64 and arm64.

The Windows arm64 NSIS install is not smoke-tested in CI. Flatpak is not built.

Releases are signed and notarised when the signing secrets are set. Test builds are not signed: macOS asks you to allow them in System Settings → Privacy & Security the first time they open. See Troubleshooting.

Each release carries, next to the installers:

  • SHA256SUMS.txt, the checksums of the installers;
  • a CycloneDX 1.6 software bill of materials, querybara-<version>.cdx.json, listing every package in the app’s dependency closure with its version, package URL, integrity hash, licence and dependency graph;
  • THIRD_PARTY_NOTICES.txt, with each shipped package’s licence and notice texts.

The About box’s Third-party licences tab lists the same packages. Chromium’s and Node.js’s licences ship next to the executable in LICENSES.chromium.html.

Every build fails when a package that ships in the app is licensed only under AGPL, GPL, LGPL or SSPL, or when its licence is unknown and nobody has reviewed it.

Documents Querybara 0.1.1 · built frombc9f5aa