Version: Unity 6.5 (6000.5)
Language : English
Share your package
Introduction to package signatures

Package signatures

Package publishers can sign packages, and package consumers can check for those signatures to protect against tampered, malicious, or unmaintained code from entering a project.

Starting with Unity 6.3, the Package Manager checks for digital signatures on all tarball packages used in the Unity ecosystem. Package signatures are part of Unity Core Standards.

The recommended best practice is for all publishers to sign their packages and for all consumers to use only signed packages. Multiple signing methods are available, from visual workflows in the Unity Editor to standalone command-line tools ideal for continuous integration or continuous delivery (CI/CD) pipelines.

Topic Description
Introduction to package signatures Understand what package signatures are, how the Package Manager displays signature status, and what each status indicator means.
Methods for signing packages Get an overview of how package signing works, and learn about the methods you can use to sign packages that you create.
Sign packages with the Package Manager window Pack and sign a package with a visual interface directly in the Unity Editor.
Sign packages with the Editor CLI Pack and sign a package from the command line using Unity Editor batch mode. Useful in CI/CD pipelines.
Unity Package Manager command-line interface Learn about the standalone UPM CLI tool and the workflow you can use to pack and sign packages outside of the Unity Editor. Ideal for CI/CD pipelines.
Sign packages with the scripting API Pack and sign a package using the Client.Pack method in a C# script.

Additional resources

Share your package
Introduction to package signatures
Copyright © 2023 Unity Technologies
优美缔软件(上海)有限公司 版权所有
"Unity"、Unity 徽标及其他 Unity 商标是 Unity Technologies 或其附属机构在美国及其他地区的商标或注册商标。其他名称或品牌是其各自所有者的商标。
公安部备案号:
31010902002961