Deferred for now. This records what the listing needs, so the research doesn't have to be redone.
Approach
Submit the existing MSI through Partner Center's MSI/EXE route, pointing at its versioned GitHub Release URL. The Store doesn't update MSI apps, but the in-app updater (#465) does, which is what makes this route workable. The Store listing would be for the desktop app only; the CLI is already on winget, Scoop and npm.
Blocker: every executable in the MSI must be signed
From Microsoft's MSI/EXE package requirements:
The binary and all of its Portable Executable (PE) files must be digitally signed with a code signing certificate that chains up to a certificate issued by a Certificate Authority (CA) that is part of the Microsoft Trusted Root Program.
The MSI is Authenticode-signed in sign-windows, but the app's .exe inside it isn't, so the current installer would fail certification.
Fix: set bundle.windows.signCommand in the Tauri config for the Windows release build, calling a small wrapper around ssign. The Tauri bundler calls signCommand on the app .exe before WiX packs it, and again on the finished .msi (tauri-bundler/src/bundle/windows/msi/mod.rs). ssign can't sign MSI yet, so the wrapper must sign PE files and skip .msi; sign-windows keeps signing the MSI with osslsigncode as it does now. The Windows gui leg is already in the release-signing environment, so the Certum secrets are available there. ssign publishes a Windows binary.
This is worth doing even without the Store. SmartScreen and antivirus look at the executable that actually runs, and today that file is unsigned.
Timing
The first submission can't be earlier than 0.3.4. 0.3.3's inner .exe is unsigned, and 0.3.3 has no updater, so a Store user who installed it could never update from inside the app.
Listing checklist
From Create an app submission (MSI/EXE):
Account and setup (the maintainer has to do these):
- A Partner Center developer account. Individual accounts are free and require government-ID and selfie verification.
- Reserve the name "NetsCLI".
- The age-rating (IARC) questionnaire.
- Accept the agreements, then submit.
Content to prepare:
- Description (required, up to 10,000 characters), short description, up to 20 features, up to 7 keywords.
- Screenshots: at least 1, 4 or more recommended, 10 at most.
- A 1:1 box-art Store logo (required) and 2:3 poster art (recommended).
- License terms (required). The app is MIT-licensed.
- Notes for certification, up to 2,000 characters. Worth saying plainly what a network scanner does, and that by default the MCP server only scans local networks.
- A privacy policy URL. It's required if the app accesses or transmits personal information. The honest answer is yes: the app reads IP addresses, MAC addresses and hostnames on the local network, and the update check contacts GitHub. netscli.com has no privacy page yet.
Package fields:
- The package URL, which must be versioned and immutable. GitHub Release asset URLs are both.
- Architecture: x64. App type: MSI. Language.
- Installer parameters. A silent install is required, and a UAC prompt is allowed. The MSI installs per machine.
Known risk: the WebView2 bootstrapper
bundle.windows.webviewInstallMode is embedBootstrapper, which downloads the WebView2 runtime at install time if it's missing. The Store requires a standalone installer that doesn't download anything during setup. WebView2 is present on effectively every current Windows 10 and 11 machine, so in practice the bootstrapper does nothing, but a reviewer could object. The fallback is offlineInstaller for the Store build, which adds about 130 MB.
Open decision
Whether each release is submitted automatically through the Store submission API. That needs a Microsoft Entra app registration (tenant ID, client ID and secret). The recommendation was to submit 0.3.4 by hand, and automate only once it has passed certification, since the first review is where surprises come up.
Deferred for now. This records what the listing needs, so the research doesn't have to be redone.
Approach
Submit the existing MSI through Partner Center's MSI/EXE route, pointing at its versioned GitHub Release URL. The Store doesn't update MSI apps, but the in-app updater (#465) does, which is what makes this route workable. The Store listing would be for the desktop app only; the CLI is already on winget, Scoop and npm.
Blocker: every executable in the MSI must be signed
From Microsoft's MSI/EXE package requirements:
The MSI is Authenticode-signed in
sign-windows, but the app's.exeinside it isn't, so the current installer would fail certification.Fix: set
bundle.windows.signCommandin the Tauri config for the Windows release build, calling a small wrapper aroundssign. The Tauri bundler callssignCommandon the app.exebefore WiX packs it, and again on the finished.msi(tauri-bundler/src/bundle/windows/msi/mod.rs).ssigncan't sign MSI yet, so the wrapper must sign PE files and skip.msi;sign-windowskeeps signing the MSI with osslsigncode as it does now. The Windowsguileg is already in therelease-signingenvironment, so the Certum secrets are available there.ssignpublishes a Windows binary.This is worth doing even without the Store. SmartScreen and antivirus look at the executable that actually runs, and today that file is unsigned.
Timing
The first submission can't be earlier than 0.3.4. 0.3.3's inner
.exeis unsigned, and 0.3.3 has no updater, so a Store user who installed it could never update from inside the app.Listing checklist
From Create an app submission (MSI/EXE):
Account and setup (the maintainer has to do these):
Content to prepare:
Package fields:
Known risk: the WebView2 bootstrapper
bundle.windows.webviewInstallModeisembedBootstrapper, which downloads the WebView2 runtime at install time if it's missing. The Store requires a standalone installer that doesn't download anything during setup. WebView2 is present on effectively every current Windows 10 and 11 machine, so in practice the bootstrapper does nothing, but a reviewer could object. The fallback isofflineInstallerfor the Store build, which adds about 130 MB.Open decision
Whether each release is submitted automatically through the Store submission API. That needs a Microsoft Entra app registration (tenant ID, client ID and secret). The recommendation was to submit 0.3.4 by hand, and automate only once it has passed certification, since the first review is where surprises come up.