Add Tor Browser as a Fleet-maintained app (#41551)

Adds Tor Browser as a Fleet-maintained app for macOS only.

## Changes

- **macOS**: Homebrew cask `tor-browser`, DMG installer, bundle
identifier `org.torproject.torbrowser`
- Icon sourced from the official Tor Project GitHub at 128x128
- Added to `apps.json` catalog in alphabetical order

**Note:** Windows support was dropped. Tor Browser for Windows uses a
portable installer that installs to `%LOCALAPPDATA%` (not `C:\Program
Files`), which is outside the scope of what Fleet's CI validator and
Windows install validation can detect. macOS-only is the correct scope
for this app.

## Test plan

- [ ] Verify `go run cmd/maintained-apps/main.go
--slug="tor-browser/darwin"` produces valid output
- [ ] Confirm icon renders correctly in the software catalog UI
- [ ] Confirm macOS install/uninstall scripts work on a test device
This commit is contained in:
Mitch Francese
2026-03-17 10:56:20 -05:00
committed by GitHub
parent 7df3ce25a2
commit bb091361d9
6 changed files with 52 additions and 0 deletions
@@ -0,0 +1,8 @@
{
"name": "Tor Browser",
"slug": "tor-browser/darwin",
"unique_identifier": "org.torproject.torbrowser",
"token": "tor-browser",
"installer_format": "dmg",
"default_categories": ["Browsers"]
}
+7
View File
@@ -1667,6 +1667,13 @@
"unique_identifier": "com.todoist.mac.Todoist",
"description": "Todoist is a to do list and a planning center for individuals and teams."
},
{
"name": "Tor Browser",
"slug": "tor-browser/darwin",
"platform": "darwin",
"unique_identifier": "org.torproject.torbrowser",
"description": "Tor Browser is a privacy-focused web browser that protects against tracking, surveillance, and censorship by routing traffic through the Tor network."
},
{
"name": "Tower",
"slug": "tower/darwin",
@@ -0,0 +1,21 @@
{
"versions": [
{
"version": "15.0.7",
"queries": {
"exists": "SELECT 1 FROM apps WHERE bundle_identifier = 'org.torproject.torbrowser';"
},
"installer_url": "https://www.torproject.org/dist/torbrowser/15.0.7/tor-browser-macos-15.0.7.dmg",
"install_script_ref": "4530bdac",
"uninstall_script_ref": "1d588638",
"sha256": "29852c4f3aa3b77bccdf359c5a22cf3ffa49ad1828b3967fb722134ffdc29e20",
"default_categories": [
"Browsers"
]
}
],
"refs": {
"1d588638": "#!/bin/sh\n\n# variables\nAPPDIR=\"/Applications/\"\nLOGGED_IN_USER=$(scutil <<< \"show State:/Users/ConsoleUser\" | awk '/Name :/ { print $3 }')\n# functions\n\ntrash() {\n local logged_in_user=\"$1\"\n local target_file=\"$2\"\n local timestamp=\"$(date +%Y-%m-%d-%s)\"\n local rand=\"$(jot -r 1 0 99999)\"\n\n # replace ~ with /Users/$logged_in_user\n if [[ \"$target_file\" == ~* ]]; then\n target_file=\"/Users/$logged_in_user${target_file:1}\"\n fi\n\n local trash=\"/Users/$logged_in_user/.Trash\"\n local file_name=\"$(basename \"${target_file}\")\"\n\n if [[ -e \"$target_file\" ]]; then\n echo \"removing $target_file.\"\n mv -f \"$target_file\" \"$trash/${file_name}_${timestamp}_${rand}\"\n else\n echo \"$target_file doesn't exist.\"\n fi\n}\n\nsudo rm -rf \"$APPDIR/Tor Browser.app\"\ntrash $LOGGED_IN_USER '~/Library/Application Support/com.apple.sharedfilelist/com.apple.LSSharedFileList.ApplicationRecentDocuments/org.mozilla.tor browser.sfl*'\ntrash $LOGGED_IN_USER '~/Library/Application Support/TorBrowser-Data'\ntrash $LOGGED_IN_USER '~/Library/Preferences/org.mozilla.tor browser.plist'\ntrash $LOGGED_IN_USER '~/Library/Preferences/org.torproject.torbrowser.plist'\ntrash $LOGGED_IN_USER '~/Library/Saved Application State/org.torproject.torbrowser.savedState'\n",
"4530bdac": "#!/bin/sh\n\n# variables\nAPPDIR=\"/Applications/\"\nTMPDIR=$(dirname \"$(realpath $INSTALLER_PATH)\")\n# functions\n\nquit_and_track_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local timeout_duration=10\n\n # check if the application is running\n if ! osascript -e \"application id \\\"$bundle_id\\\" is running\" 2>/dev/null; then\n eval \"export $var_name=0\"\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ $EUID -eq 0 && \"$console_user\" == \"root\" ]]; then\n echo \"Not logged into a non-root GUI; skipping quitting application ID '$bundle_id'.\"\n eval \"export $var_name=0\"\n return\n fi\n\n # App was running, mark it for relaunch\n eval \"export $var_name=1\"\n echo \"Application '$bundle_id' was running; will relaunch after installation.\"\n\n echo \"Quitting application '$bundle_id'...\"\n\n # try to quit the application within the timeout period\n local quit_success=false\n SECONDS=0\n while (( SECONDS < timeout_duration )); do\n if osascript -e \"tell application id \\\"$bundle_id\\\" to quit\" >/dev/null 2>&1; then\n if ! pgrep -f \"$bundle_id\" >/dev/null 2>&1; then\n echo \"Application '$bundle_id' quit successfully.\"\n quit_success=true\n break\n fi\n fi\n sleep 1\n done\n\n if [[ \"$quit_success\" = false ]]; then\n echo \"Application '$bundle_id' did not quit.\"\n fi\n}\n\n\nrelaunch_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local was_running\n\n # Check if the app was running before installation\n eval \"was_running=\\$$var_name\"\n if [[ \"$was_running\" != \"1\" ]]; then\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ $EUID -eq 0 && \"$console_user\" == \"root\" ]]; then\n echo \"Not logged into a non-root GUI; skipping relaunching application ID '$bundle_id'.\"\n return\n fi\n\n echo \"Relaunching application '$bundle_id'...\"\n\n # Try to launch the application\n if osascript -e \"tell application id \\\"$bundle_id\\\" to activate\" >/dev/null 2>&1; then\n echo \"Application '$bundle_id' relaunched successfully.\"\n else\n echo \"Failed to relaunch application '$bundle_id'.\"\n fi\n}\n\n\n# extract contents\nMOUNT_POINT=$(mktemp -d /tmp/dmg_mount_XXXXXX)\nhdiutil attach -plist -nobrowse -readonly -mountpoint \"$MOUNT_POINT\" \"$INSTALLER_PATH\"\nsudo cp -R \"$MOUNT_POINT\"/* \"$TMPDIR\"\nhdiutil detach \"$MOUNT_POINT\"\n# copy to the applications folder\nquit_and_track_application 'org.torproject.torbrowser'\nif [ -d \"$APPDIR/Tor Browser.app\" ]; then\n\tsudo mv \"$APPDIR/Tor Browser.app\" \"$TMPDIR/Tor Browser.app.bkp\"\nfi\nsudo cp -R \"$TMPDIR/Tor Browser.app\" \"$APPDIR\"\nrelaunch_application 'org.torproject.torbrowser'\n"
}
}
File diff suppressed because one or more lines are too long
@@ -214,6 +214,7 @@ import TextExpander from "./TextExpander";
import TheUnarchiver from "./TheUnarchiver";
import Thunderbird from "./Thunderbird";
import Todoist from "./Todoist";
import TorBrowser from "./TorBrowser";
import Tower from "./Tower";
import Transmit from "./Transmit";
import Tunnelblick from "./Tunnelblick";
@@ -470,6 +471,7 @@ export const SOFTWARE_NAME_TO_ICON_MAP = {
"the unarchiver": TheUnarchiver,
thunderbird: Thunderbird,
todoist: Todoist,
"tor browser": TorBrowser,
tower: Tower,
transmit: Transmit,
tunnelblick: Tunnelblick,
Binary file not shown.

After

Width:  |  Height:  |  Size: 8.8 KiB