skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
microsoft/win-dev-skills169 installs

winui-packaging

MSIX packaging, code signing, and distribution for WinUI 3 apps with WinApp CLI 0.7+ — SDK-native project packaging, Native AOT, certificates, self-contained deployment, CI/CD, and Microsoft Store handoff. Use when preparing for release, creating MSIX installers, managing certificates, setting up CI/CD packaging, or publishing to the Microsoft Store.

How do I install this agent skill?

npx skills add https://github.com/microsoft/win-dev-skills --skill winui-packaging
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill provides standard instructions for WinUI 3 application packaging and signing. It utilizes vendor-supported tools and follows established development workflows, such as certificate management and CI/CD integration. The documented requirements for administrative privileges during certificate installation are appropriate for the intended development tasks.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

What does this agent skill do?

Requires WinApp CLI 0.7+. For analyzer setup, see winui-dev-workflow.

Quick Reference

TaskCommand
Release package + signwinapp package .\MyApp.csproj --arch x64 --cert .\devcert.pfx
Unsigned multi-architecture bundlewinapp package .\MyApp.csproj --arch x64 --arch arm64 --no-sign
Generate dev certificatewinapp cert generate
Trust certificate (admin)winapp cert install ./devcert.pfx
Sign existing filewinapp sign ./app.msix ./devcert.pfx
Bundle Windows App SDK runtimewinapp package .\MyApp.csproj --arch x64 --cert .\devcert.pfx --self-contained

End-to-End Workflow

Step 1: Check the Project and Deployment Intent

  • Pass the explicit project file, not . or a guessed bin folder. WinUI project packaging uses SDK-native dotnet publish packaging, defaults to Release, and preserves project AOT settings.
  • Check manifest identity, target architectures, the SDK for the app's TFM, and release warnings.
  • For Native AOT, set <PublishAot>true</PublishAot> in the project and fix IL/CsWinRT warnings; there is no winapp package --aot. AOT also needs the MSVC C++ build tools. See source-generator patterns.
  • Project packaging rejects WindowsPackageType=None; restore the packaged setting first (see winui-dev-workflow Critical Rules).

Do not run/register/unregister a development package just to produce release artifacts. Project packaging builds without a development winapp run --no-launch step. For WinUI SDK-native packaging, do not pass layout overrides --manifest, --executable, or --skip-pri; fix the project/manifest instead.

Step 2: Generate Certificate (one-time)

winapp cert generate --manifest .\Package.appxmanifest

Creates a development devcert.pfx (default password: password). This certificate command's --manifest flag auto-matches the Publisher field in Package.appxmanifest. Keep PFX files/passwords out of source control; production signing needs the organization's signing policy.

Step 3: Trust on the Intended Test Machine (optional, admin)

winapp cert install ./devcert.pfx

Adds the cert to the machine trust store and persists across reboots. Do this only with approval on the intended test machine; it is not required just to build/package in CI.

Step 4: Package and Sign

winapp package .\MyApp.csproj --arch x64 --cert .\devcert.pfx
# Repeat --arch for a bundle
winapp package .\MyApp.csproj --arch x64 --arch arm64 --no-sign

Choose one signing policy: --cert takes a PFX file, not a certificate thumbprint; its subject must match the manifest's Identity.Publisher. --no-sign leaves an artifact for external signing. Use the artifact paths reported by the command, not a guessed output directory.

For timestamped production signing, create an unsigned package then sign the resulting artifact:

# Replace MyApp.msix with the package/bundle path returned above
winapp sign .\MyApp.msix .\prod.pfx --timestamp http://timestamp.digicert.com

--timestamp belongs to winapp sign, not winapp package. Use an approved timestamp service and protect the PFX/password.

Step 5: Install or Distribute

When installation/testing is part of the task, choose the target per winui-ui-testing Step 1, and get consent for certificate trust and dependency provisioning on that machine. Packaging alone is not permission to install an app.

Self-Contained Does Not Mean Single-File

winapp package --self-contained sets only WindowsAppSDKSelfContained=true, not .NET SelfContained=true. For a fully self-contained JIT .NET app, set both in the project:

<PropertyGroup>
  <SelfContained>true</SelfContained>
  <WindowsAppSDKSelfContained>true</WindowsAppSDKSelfContained>
</PropertyGroup>

Native AOT covers the .NET runtime but still needs the Windows App SDK choice. Native WinUI runtime files stay alongside the executable/in the package; do not promise a single-file WinUI EXE. Some APIs still require additional MSIX dependencies; see the deployment guidance.

CI/CD

On a Windows runner provisioned with CLI 0.7+, the app's .NET SDK, and (for AOT) the native C++ toolchain, the packaging step can be:

winapp package .\MyApp.csproj --arch x64 --arch arm64 --no-sign
  • Committed package references, including the analyzer, restore normally; no machine-local analyzer is needed.
  • Archive the reported .msix/.msixbundle outputs using the CI system's artifact step. No UI launch or development registration is needed.
  • Retrieve production signing material through approved secret storage and sign in a separate protected step. Never commit a PFX or install a development root certificate just to build.

Store Submission

Associate the app with its Partner Center identity and follow its current submission requirements (package validation, ratings, screenshots, privacy policy). Use the SDK/Visual Studio packaging workflow when Store-upload artifacts or resource-package splitting are required. winapp package produces package artifacts; it does not publish to the Store or replace that submission workflow.

Troubleshooting

ErrorSolution
"Publisher mismatch"Run winapp cert generate --manifest to re-generate
"Certificate not trusted"Run winapp cert install ./devcert.pfx as admin
"Access denied"cert install needs admin elevation
"Certificate file already exists"Use --if-exists overwrite or --if-exists skip
Manifest missing / layout override rejectedCheck the explicit project and its original manifest; do not use winapp init or layout overrides to bypass SDK packaging
"Package installation failed"Check signing/trust and the exact conflicting identity; remove a stale registration only if confirmed and authorized
Signature invalid after timeSign with an approved timestamp service via winapp sign --timestamp

References

FileRead when...
references/sourcegen-patterns.mdSetting up AOT/trimming, JSON source generators, Native AOT readiness, CsWin32

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/microsoft/win-dev-skills/winui-packaging">View winui-packaging on skillZs</a>