Skip to content

Windows Store distribution: MSIX from existing PyInstaller GUI (keep GitHub zip)

Matt Burnett edited this page Sep 22, 2026 · 1 revision

This Issue serves as archival material, describing the process required to publish the CIB Mango Tree to the Microsoft Windows Store.

Originally, it was Issue #391. It was moved to this wiki because it's more suited here.

TLDR: There are two parts / phases to completing this task:

  • Phase 1: Initial .msix file creation and creation of the initial Windows Store presence for the app. These are already done.
  • Phase 2: Subsequent release publication. This is done by the GitHub workflow automation when a new release is created.

Concepts

Term Meaning
Partner Center Portal for listings, uploads, certification
MSIX Store package; CI builds it from the Windows PyInstaller output
Zip CIBMangoTree_windows.zip on GitHub Releases—not the Store
Identity Name / Publisher / PublisherDisplayName—must match Partner Center exactly
Entra Microsoft-specific identity management / authorization platform.
Certification Submission → Pre-processing → Certification → Publishing (hours–days)
Live Published in the Store; required before CI Store updates

What we are doing, and why

We will provide Windows users with the ability to install CIB Mango Tree from the Microsoft Store, in addition to the existing GitHub Releases zip.

The GUI is already a PyInstaller onedir (CIBMangoTree.exe) built in .github/workflows/build_gui.yml. The Store does not take that zip. It takes an MSIX whose identity matches the product in Partner Center.

This work wraps the current Windows build with MSIX packaging and Store identity (packaging/msix/). Microsoft re-signs Store MSIX after certification—no .pfx is needed in CI for Partner Center upload.

Associated PR: #386

Things you need

Partner Center access

Tasks regarding the Windows Store require access to the CIB Mango Tree account on Windows Partner Center.

To access the Windows Partner Center, you will need:

  • Windows Partner Center url for CIB Mango Tree: https://partner.microsoft.com/en-us/dashboard/products/9NQQP9MB8HR4/overview
  • Windows Partner Center login info: For security reasons, login info is not provided here. You can get this information from the CIB team.
  • Alternative Newsweekly Foundation's CIB Mango Tree 2FA authentication account for the Partner Center, on the authentication app of your choosing. You will need to contact the CIB team for more info regarding this 2FA account.

Repository files

MSIX packaging

Path Role
packaging/msix/AppxManifest.xml Store identity + app entry
packaging/msix/Assets/StoreLogo.png Package logo
packaging/msix/Assets/Square150x150Logo.png App logo
packaging/msix/Assets/Square44x44Logo.png App logo

CI / release workflow

Path Role
.github/workflows/build_gui.yml Windows MakeAppx pack + zip / _msix artifacts
.github/workflows/release.yml Tag release; GitHub Release + publish_msix (Store upload on tags)

Optional — Microsoft Learn MCP

Optional for local development only: the microsoft-learn MCP server can look up Store/MSIX docs while you work. It is not required to publish. Contributors using AI tooling will follow the CIB Mango Tree AI Policy.

Phase 1 — Initial setup (reference)

Completed for CIB Mango Tree. Use this outline to recover context or repair a broken setup—not as the day-to-day update path.

  1. Org developer account in Partner Center (provided by ANF).
  2. Reserve MSIX/PWA name (e.g. “CIB Mango Tree”).
  3. Copy View product identity into packaging/msix/AppxManifest.xml (Name, Publisher, PublisherDisplayName).
  4. Build MSIX in CI.
  5. Submission: pricing, properties, age ratings, Packages, listing, options.
  6. Submit for certification; wait (no overlapping submissions).
  7. After publish → live → Phase 2.

First Windows app · Create submission

Identity reference

Source: Partner Center → app → View product identity (Product release / General). Copy from there; do not invent values.

Partner Center field Value
Package/Identity/Name AlternativeNewsweeklyFoun.CIBMangoTree
Package/Identity/Publisher CN=C14B7C4E-669C-42C0-8DC2-159FACF8C396
Package/Properties/PublisherDisplayName Alternative Newsweekly Foundation
Package Family Name (PFN) AlternativeNewsweeklyFoun.CIBMangoTree_z2bz8bc4mgppp
Package SID S-1-15-2-961512062-280380537-1495283227-2373385957-312483637-2504256684-770294701
Store ID 9NQQP9MB8HR4
Store deep link ms-windows-store://pdp/?productid=9NQQP9MB8HR4
Web Store URL https://apps.microsoft.com/detail/9NQQP9MB8HR4

Name, Publisher, and PublisherDisplayName must match AppxManifest.xml (CI checks every pack). Store ID → Actions variable STORE_PRODUCT_ID. PFN and Package SID are assigned by Partner Center—do not hand-edit them into the manifest.

Phase 2 — Subsequent publishing

When: each new pyproject.toml / release-tag version for the Store.

Need: app live; no submission In process.

Rule: new MSIX four-part version must be higher than Partner Center’s current package. CI stamps from pyproject.toml (0.12.0 → 0.12.0.0).

  1. Bump pyproject.toml (match v*.*.* tag for releases).
  2. Do not change Store identity in AppxManifest.xml unless Partner Center changed.
  3. Let build_gui produce CIBMangoTree_windows.msix; confirm version.
  4. Confirm Partner Center has no open certification.
  5. Publish package:
    • Manual: Start update → upload .msix → Submit for certification.
    • CI (default on stable tags): publish_msix in release.yml.
  6. Wait for certification; on failure, fix and retry with a newer version.

Certification always runs; CI automates upload and submission via msstore publish.

Code to push the MSIX file to the Store runs in .github/workflows/release.yml in the publish_msix job. On stable tags, it downloads the CI-built MSIX and submits it to Partner Center via msstore publish.

Entra secrets and STORE_PRODUCT_ID are configured in GitHub Actions settings—see the job env block in release.yml.

PLEASE NOTE:

  • Entra credentials are stored in Secrets -> Secrets and Variables -> Secrets
  • STORE_PRODUCT_ID is stored in Secrets -> Secrets and Variables -> Variables

Entra setup (one-time): link the Entra tenant, register the app, add it under Partner Center Microsoft Entra applications with the Manager role, and store credentials in GitHub Actions secrets. Only someone with Manager authorization in Partner Center can perform this setup.

References