Commit Graph
25324 Commits
Author SHA1 Message Date
Magnus Jensen 06b831c63a log as error in apple reconciler for mixed label modes (#47502) 2026-06-15 21:45:56 +02:00
Victor Lyuboslavsky c57e54c529 Filter OTEL by environment (#47574) 2026-06-15 20:44:05 +01:00
github-actions[bot]andlucasmrod 2f62b913df Update versions of fleetd components in Fleet's TUF [automated] (#47631)
Automated change from [GitHub
action](https://github.com/fleetdm/fleet/actions/workflows/fleetd-tuf.yml).

Co-authored-by: lucasmrod <lucasmrod@users.noreply.github.com>
2026-06-15 15:57:39 -03:00
Lucas Manuel Rodriguez bdd15d6305 Ignore openssl CVEs in fleetdm/bomutils and fleetdm/wix (#47587)
Fixes: 
- https://github.com/fleetdm/fleet/actions/runs/27533019044
- https://github.com/fleetdm/fleet/actions/runs/27531598289

Runs:
- https://github.com/fleetdm/fleet/actions/runs/27534679935
- https://github.com/fleetdm/fleet/actions/runs/27534673753

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Added VEX (Vulnerability Exploitability eXchange) security
declarations for CVE-2026-45447 across multiple products, marking the
vulnerability as not affecting specified versions with justification
that vulnerable code is not in the execution path.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 15:31:31 -03:00
Eric bbd7ad0f91 Website: add section to software-management page (#47616)
Closes: https://github.com/fleetdm/fleet/issues/47387

Changes:
 - Added a section to the /software-management page

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Added new page section titled "Customize their experience" showcasing
user experience management and customization options. Highlights include
app patching notifications, native notification delivery, calendar
integration support, and seamless compatibility with existing management
tools, emphasizing flexible notification strategies across multiple
communication channels.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 13:13:27 -05:00
RachelElysia 9e7f6d15ad Fleet UI: Fix dark mode switch flicker on data tables (#47541) 2026-06-15 13:38:28 -04:00
RachelElysia 13ff272e2e Fleet UI: Fix radix missing title/description logs (#47607) 2026-06-15 13:37:56 -04:00
Eric 7352b820c5 Website: Add CTA to article template (#47546)
Closes: https://github.com/fleetdm/fleet/issues/47406

Changes:
- Added a CTA to the article template page.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Call-To-Action sections to certain article pages with a "Read
case studies" link and a "Try it yourself" sign-up button for select
categories.

* **Style**
* Updated CTA styling and layout, including a new CTA container and
button row.
* Improved mobile behavior: buttons stack, center, and become full-width
on small screens.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 12:21:58 -05:00
Jonathan Katz 85bd8123de Fix TestIntegrationsEnterprise/TestFMAVersionRollback failing because of FMA update (#47601)
The FMA unique identifier (software title match) for Cloudflare WARP
changed recently to Cloudflare One Client. This test was using the input
file from `/ee/maintained-apps/inputs/winget/cloudflare-warp.json` so
the change actually affected it.

# Checklist for submitter

## Testing

- [x] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually
    - N/A

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Updated Cloudflare product identification test expectations to reflect
current software naming and version tracking behavior.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 13:10:00 -04:00
Allen Houchins 60cc186962 Add more Windows FMAs (#47560)
This pull request adds support for several new Windows applications to
the maintained apps catalog by introducing new JSON manifest files under
`ee/maintained-apps/inputs/winget/`. Each manifest specifies
installation details, categorization, and, where needed, custom
install/uninstall scripts. The additions cover a mix of productivity,
developer tools, and communication apps.

**New application manifests added:**

_Productivity apps:_
* Added manifests for `ActivityWatch`, `AirParrot`, `Bdash`, `Binance`,
`Biscuit`, `BreakTimer`, `darktable`, `Descript`, `DevToys`, `dupeGuru`,
`Dynalist`, `Electrum`, `GDevelop`, and `Gephi`, each with relevant
install/uninstall scripts and metadata.
[[1]](diffhunk://#diff-55387cfd17c8952a5a5fe56f9072156a285797be5316796f7a1bec6a190170b1R1-R12)
[[2]](diffhunk://#diff-b6391ec86660a9cbcbe90756daea60701eb69b6e0ebbde2b0d8c75dd1a31a126R1-R11)
[[3]](diffhunk://#diff-04b0ac58d3fd3d42504786f39d612dc89bde16512d954bbf1646547d15837c6fR1-R13)
[[4]](diffhunk://#diff-12047bbb053e94f70e18af209bc7b901c37df285ca753549c619cc409b3da361R1-R13)
[[5]](diffhunk://#diff-984aab5373578ee3278d33367fc48b7d67c3ddb59b35d257ef170bb8ee62aaf4R1-R13)
[[6]](diffhunk://#diff-4e06e7c7940663923b6210a19495dd13eeb605d368312718402136666edb2d23R1-R13)
[[7]](diffhunk://#diff-e4ec2c2ab61f6a9de45914b1ca8ee08ce4cde504e4e595341a776a5e69dd5862R1-R12)
[[8]](diffhunk://#diff-b7a6f3074314e4d52a9c5b8d104247ecdbf80e526791d7a02e1819e7a7148441R1-R15)
[[9]](diffhunk://#diff-096ca15b420e419a365d998af529e92e2adfb45a1d28738cfb3009afff48b3daR1-R12)
[[10]](diffhunk://#diff-0db89ec11e8da68b0eb4e894805ae3f71258bf4844aadfd1423fe0b671e58da8R1-R12)
[[11]](diffhunk://#diff-ad484bc36aa30653876aaf4665ad1e5366088a68121163ed94399fecaa17cb7cR1-R14)
[[12]](diffhunk://#diff-1516c2e3c532aecf16b7f81e7cf4488ad1aefca791cf58f5bab1f08c1d3d0becR1-R14)
[[13]](diffhunk://#diff-133f3702736e7cc29113b3faf59cd15fd631b853f21108f19a3428c8a1dac0f7R1-R12)
[[14]](diffhunk://#diff-7b356cca2e47651ce2cdbf7b99ddd89b410185ddddf7546daaefee1d14161d5dR1-R12)

_Developer tools:_
* Added manifests for `Cherry Studio`, `Dataflare`, `DbVisualizer`, and
`Geany`, categorized as developer tools and including install/uninstall
scripts.
[[1]](diffhunk://#diff-8c85cc5f00362d25db8bc87ecd1135e4038b5dbe29408cf6146ff144de02d477R1-R12)
[[2]](diffhunk://#diff-b4a1720d2b1d727613a311c4a2cfd0f1c2e0a6198c0c31605286b9ef20e30896R1-R12)
[[3]](diffhunk://#diff-7a4d41ce430b5a37d4d311c5c3ebaf3bbaef41da062db201fb496f6a2d6abb5fR1-R12)
[[4]](diffhunk://#diff-cb4abb01239b831cc4e82020821d457a018ba1ea109fbc4fe1660bc0b7839af9R1-R12)

_Communication apps:_
* Added manifests for `Fellow` and `Franz`, categorized as communication
tools with user-scope installers and scripts.
[[1]](diffhunk://#diff-284b2bdcf738397525f4e60f50da15c764c6306e8707e4f3196a9a4968a96c56R1-R12)
[[2]](diffhunk://#diff-c60796271608d278c88037acec46900c6da13731b73697b2ef08e4c3ddacd9c8R1-R12)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Release Notes

* **New Features**
* Added support for 30+ new Windows applications including productivity
tools (Bdash, Morgen, Fellow), utilities (dupeGuru, DevToys, Geany),
developer tools (Lapce, KNIME, GDevelop), and others (Binance, Electrum,
GOG Galaxy, Mullvad Browser, ImHex, and more).

* **Improvements**
  * Updated description formatting for existing app entries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 12:06:24 -05:00
Jonathan Katz 75a822fb91 Show Fleet Premium message when viewing install details modal on Fleet Free (#47551)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #44617
Screenshot:
<img width="1318" height="528" alt="image"
src="https://github.com/user-attachments/assets/4ec4bd85-8efb-4729-86ad-ea3059439b60"
/>

Note that the uninstall details modal is viewable without any errors on
Fleet Free, so maybe we should address that at some point.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* When accessing software install details without a Fleet Premium
license, the activity modal now displays a Fleet Premium upsell message
with a "Learn more" link instead of a generic error, providing clearer
guidance to upgrade.

* **Tests**
* Added test coverage for the Fleet Premium license requirement scenario
in the install details modal.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 12:33:16 -04:00
Magnus JensenandCopilot Autofix powered by AI 3350943e0f update applebmapi tool with command flag and ability to fetch ADUE service discovery (#47320)
Small tool update to support fetching the service discovery URL

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a `-command` flag to enable a new operation mode; when set to
`adue` the CLI performs the account-driven enrollment discovery flow,
otherwise it falls back to the existing account detail behavior.

* **Chores**
  * Simplified the server private key flag to `-key`.
* Strengthened input validation to require both `-key` and `-org-name`.
* Enforced mutual exclusivity among operation flags (`-profile-uuid`,
`-serial-number`, `-command`).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-15 18:29:41 +02:00
kilo-code-bot[bot]andkiloconnect[bot] d66f4048c7 Remove 'windows coming soon' from /software-management (#47556)
## Summary

- Removes the "*Windows coming soon" text from the
`/software-management` page on fleetdm.com.

## Why

Fleet already supports Windows software and OS management. The "coming
soon" caveat adds unnecessary FUD and confusion — it makes it seem like
Fleet doesn't support Windows, which it absolutely does. Removing this
text provides a clearer and more accurate representation of Fleet's
capabilities.

## Changes

- `website/views/pages/software-management.ejs`: Removed the `<span
purpose="feature-note">*Windows coming soon</span>` element from the
"App store management" feature section.

---

Built for [Mike
McNeil](https://fleetdm.slack.com/archives/D0AFASLRHNU/p1781314316685189?thread_ts=1780459268.285059&cid=D0AFASLRHNU)
by [Kilo for Slack](https://kilo.ai/slack)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-06-15 11:26:10 -05:00
Dan Gordon 96fa2d9b1b Dbg add jamf switch wp landing page (#47534) 2026-06-15 10:17:43 -05:00
fleet-releaseandallenhouchins 8a62c73a22 Update Fleet-maintained apps (#47596)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated version metadata and installer information for 26 applications
including Affinity, BoltAI, CodexBar, Cursor, DataFlare, DeepL, Deezer,
Docker Desktop, Dockside, Dropshare, FireAlpaca, HexFiend, Hive, Kitty,
Melodics, Mullvad VPN, NVIDIA GeForce Now, OpenCode, Pd, Postman, Stats,
Syncovery, TablePlus, Typora, WhatsApp, and Zettlr across macOS and
Windows platforms.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-15 09:54:31 -05:00
Jordan MontgomeryandCopilot Autofix powered by AI 3f6ce1e4bf Initial move of fleet desktop app (#47181)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #46937

Moves fleet desktop standalone app from
https://github.com/allenhouchins/fleet-desktop into the monorepo

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

No changes file. Do we want to create a new changes directory and
changelog for this? Unclear

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

Downloaded build from CI, tested locally and installed via Fleet on a
mac mini. Launched and tested there - all looks good
<img width="1485" height="544" alt="Screenshot 2026-06-09 at 4 27 59 PM"
src="https://github.com/user-attachments/assets/48611808-2265-43b7-a514-afc4f578a9f8"
/>



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Launched Fleet Desktop macOS app with web-based self-service UI.
* Added fleet:// URL handling to trigger in-app actions (refetch, update
all).
  * Dock badge shows failing policies count in real time.
* Built-in token refresh, retries, and navigation error handling for
reliability.
  * MDM configuration support for enterprise deployment.
* Automated macOS packaging with code signing, notarization, and
artifact upload.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-15 10:18:09 -04:00
Noah Talerman 19f0df6e3e Revise APNs certificate renewal instructions (#47353)
Context:
https://fleetdm.slack.com/archives/C03C41L5YEL/p1781116521861239
2026-06-15 09:28:42 -04:00
Noah Talerman 4f23a20192 Update enrollment instructions for ChromeOS hosts (#47226)
Clarified the purpose of the fleetd Chrome extension for ChromeOS
enrollment.
2026-06-15 09:28:30 -04:00
Noah Talerman 27c0c31164 GitOps mode is premium only (#47216)
- We forgot to tag "Premium only" in the guide
2026-06-15 09:28:19 -04:00
Noah Talerman bc4a1e3cab Seamless migration: Remove links for images (#46919)
- @noahtalerman: The link takes me to the same image so I think it's
redundant. Also the styles look strange (see arrow in the bottom left):
 
<img width="757" height="349" alt="Screenshot 2026-06-05 at 1 05 11 PM"
src="https://github.com/user-attachments/assets/ef4a6890-1392-4b52-bb09-6eadbec0dc14"
/>
2026-06-15 09:28:09 -04:00
Nico 5e27628266 GitOps: combined include/exclude policy label targeting + labels_exclude_all (#33441) (#47505)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #46584 

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.
(Already added in main.)

## Testing

- [x] Added/updated automated tests

- [x] QA'd all new/changed functionality manually

`generate-gitops`:



https://github.com/user-attachments/assets/d32e89c3-2ce7-4c57-9492-66deb0a3dfe8



`gitops`:



https://github.com/user-attachments/assets/ac0e3935-bc8d-4541-b3e5-f992109630d9




<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added `labels_exclude_all` field support for refining policy label
scopes (available with Fleet Premium license).

* **Bug Fixes**
* Enhanced validation of policy label scope configurations to prevent
invalid field combinations and enforce license requirements.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 08:55:05 -03:00
Lucas Manuel Rodriguez 6d997bdfda Add fleet-user creation check (#47566)
- [X] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
* Added test coverage to verify team administrator access controls and
boundary enforcement. The test ensures that team admins cannot create
users in other teams, validating this restriction across both standard
and API-only user creation endpoints. The test also confirms that users
can be successfully created within their authorized team scope.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 07:59:32 -03:00
Victor Lyuboslavsky 4fdd4bd3b4 Fixing Windows SCEP issues (#47255)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #47492 and Resolves #46982

- Fixed panic when uploading bad profile
- Added validation for SCEP challenge to exclude underscore (and other
non-printable characters).

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Prevented a server panic during Windows configuration profile
validation when SCEP and non-SCEP elements are mixed; such profiles are
now rejected with a clear validation error.

* **New Features**
* Enforced Windows-compatible printable characters for Custom SCEP proxy
challenge values; rejects disallowed characters while preserving legacy
values unless changed.

* **UI / Validation**
* Improved form validation feedback for the Custom SCEP challenge field,
showing errors and disabling submit for invalid input while allowing
masked/unchanged values.

* **Tests**
* Added regression and unit tests covering profile validation and
challenge character validation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-15 08:52:25 +01:00
Allen Houchins b1eb5153ba Remove orphaned Fleet-maintained app files (#47576)
**Related issue:** N/A — repo cleanup

## Summary

Removes orphaned files under `ee/maintained-apps/` that have no entry in
`outputs/apps.json` and are not referenced by any input, so they are
dead
weight (never surfaced in the product UI or on fleetdm.com):

- **22 macOS `darwin.json` outputs** with no `apps.json` entry and no
  corresponding `inputs/homebrew/*.json` (so nothing regenerates them):
  salesforce-cli, screaming-frog-seo-spider, servo, shureplus-motiv,
  silentknight, silhouette-studio, simpledemviewer, sketchup, skim,
sonos-s1-controller, sonos, studio-3t, subethaedit, sunsama, superlist,
  swift-quit, swift-shift, switch, synologyassistant, systhist,
  tableau-public, tresorit.
- **6 winget scripts** not referenced by any winget input's
  `install_script_path`/`uninstall_script_path`:
`google_chrome_{install,uninstall}.ps1`,
`msteams_{install,uninstall}.ps1`,
  `okta_verify_{install,uninstall}.ps1`.

No `apps.json` entries, inputs, or referenced files are touched. 28
files
removed, deletions only.

# Checklist for submitter

- [x] Changes file not required (no user-visible behavior change;
removes unused files only).

## Testing

- [x] Verified each removed `darwin.json` has no `apps.json` entry and
no `inputs/homebrew/*.json`.
- [x] Verified each removed script is referenced by 0 winget inputs.
- [x] Diff is deletions only (943 lines across 28 files); no
entries/inputs affected.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Removals**
* Removed installation and uninstallation scripts for Windows
applications: Chrome, MSTeams, and Okta Verify.
* Removed macOS application configurations for approximately 20
applications including Salesforce CLI, Sonos, Studio 3T, SketchUp,
Tableau Public, Tresorit, and others.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-14 21:58:51 -05:00
fleet-releaseandallenhouchins 7f4e0157e5 Update Fleet-maintained apps (#47570)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated application version metadata for 23 maintained apps across
Windows and macOS platforms, including Android Studio, Audacity, AWS
CLI, Bezel, Cursor, Dropbox, Mailspring, Microsoft Edge, Nextcloud Talk,
Telegram, and others. Version numbers, installer checksums, and download
URLs have been refreshed to reflect the latest available releases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-14 07:05:17 -05:00
Allen Houchins 268c918f92 Add 12 Windows FMAs (#47558)
Adds Windows Fleet-maintained apps for apps that already exist as macOS
FMAs and ship in winget as a machine-scope MSI/WiX installer:

Bitwig Studio, Clockify, CMake, eM Client, Epic Games Launcher, Mixxx,
NAPS2, PDFsam Basic, Topaz Gigapixel AI, Topaz Photo AI, Transmission,
Zulip.

Identity fields verified against the real MSI (msiinfo) per new-fma
rules:
- fuzzy_match_name for version-bearing DisplayNames (Bitwig,
Transmission)
- program_publisher overrides where registry Publisher != winget locale
(Clockify -> CAKE.com Inc., eM Client -> eM Client s.r.o.)
- eM Client is x86-only (no x64 in winget)
2026-06-12 22:25:19 -05:00
Allen HouchinsandCopilot Autofix powered by AI 48b45577ae Add macOS Fleet-maintained apps (N) (#47537)
Adds 25 Fleet-maintained app(s) whose cask token starts with 'N':
inputs, outputs, app icons (TSX + website PNG), and the matching
index.ts and apps.json entries.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for 24 new apps (Nagstamon, Name Mangler, NAPS2, NDI
Tools, NeoFinder, Netiquette, NetNewsWire, Netron, NetSpot, Nextcloud
Talk Desktop, Nightfall, Nitro PDF Pro, Nocturnal, NordLayer, NoSQL
Workbench, NotchNook, Notepad.exe, Notesnook, NotesOllama, Noun Project,
Novabench, Nucleo, Numi, NVIDIA GeForce NOW) with
install/uninstall/version metadata.
* **UI Changes**
* Added icons and name→icon mappings for the new applications and
expanded the software icon registry.
* **Updates**
* Expanded and reordered the maintained apps listing to include the new
entries.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-12 21:14:23 -05:00
fleet-releaseandallenhouchins c2a15a8d70 Update Fleet-maintained apps (#47555)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

# Release Notes

* **Chores**
* Updated installer metadata for 52+ applications to newer versions,
including Android Studio, Brave Browser, Google Chrome, Microsoft Edge,
Visual Studio Code, Postman, and many others across macOS and Windows
platforms.
* Updated version numbers, download URLs, and integrity checksums to
reflect latest application releases.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-12 21:14:04 -05:00
Eric f2e328e014 Website: Bring back homepage hero quote (#47554)
Changes:
- Moved the quote from Wes Whetstone on the homepage back to the page
hero.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
  * Refreshed homepage hero with updated headline and messaging
  * Revised hero CTAs to "Get a demo" and "Join a workshop"
* Improved responsive layout and typography across mobile and desktop
breakpoints
* **New Features**
* Embedded customer quote with author identity and larger profile image
  * Reordered content so statistics follow the updated hero section
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 18:36:01 -05:00
Victor Lyuboslavsky 207d41e995 Windows MDM reconciler cleanup and remaining fixes (#47493)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #45635 

- Refactored setup experience flow to use host-specific reconciler
methods
- Removed now unneeded reconciler methods

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.
  
## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Windows configuration profiles are now queued immediately when a host
enrolls in Windows MDM, so profile delivery happens during the same
check-in instead of waiting for the next reconciliation cycle.
* Windows MDM enrollment finalization now runs per-host reconciliation
and will block release until that reconciliation completes.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 22:30:58 +01:00
Allen Houchins 532c5d5e33 Add macOS Fleet-maintained apps (A) (#47536)
Adds 43 Fleet-maintained app(s) whose cask token starts with 'A':
inputs, outputs, app icons (TSX + website PNG), and the matching
index.ts and apps.json entries.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added support for 50+ macOS applications including Acorn, Affinity
Suite, AirDroid, Anytype, Audio Hijack, and more
* Applications now include automated installation and management
capabilities with version tracking

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 15:33:14 -05:00
RachelElysia d852e602cc Fleet UI: preserve raw software name for icon matching when display name overrides are set (#47355) 2026-06-12 16:19:46 -04:00
RachelElysia 4d0c6285f2 Fleet UI: Unreleased bug fixes to command palette (AB vs ABM, Controls on Fleet Free, emoji not italicized) (#47432) 2026-06-12 16:19:28 -04:00
Eric 7a1264154c Website: update testimonials on visibility and reporting page (#47542)
Changes:
- Updated the testimonials shown on the visibility and reporting page.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Updates**
* Modified the selection and order of testimonials displayed on the
Visibility and reporting page.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 15:05:00 -05:00
Tim Lee 9279a99a38 Add vuln-triage Claude skill (#44246) 2026-06-12 13:43:34 -06:00
Konstantin Sykulev 2ad76714ce Throttle requests to AMAPI during profile reconcilation (#47223)
**Related issue:** Resolves #41910

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.
- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added a configurable env var to limit Android MDM profile
reconciliation batch size (FLEET_MDM_ANDROID_PROFILES_BATCH_SIZE;
default 1000).
* Reconciliation now processes hosts in cursor-based, batched windows
and persists a reconciliation cursor to resume/advance work, reducing
peak API load and enabling pagination.
* **Tests**
* Added validation tests for the batch-size config and tests verifying
cursor-based pagination and processing.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 13:13:29 -05:00
cmagadia a3f07e3752 Update leadership.md (#47517) 2026-06-12 19:12:02 +01:00
Nico 32e534215c Policies: combine include/exclude label targeting + add labels_exclude_all (#33441) (#47444)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #46582

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.
(Already added as part of the frontend PRs which have been merged to
main.)

## Testing

- [x] Added/updated automated tests

- [x] QA'd all new/changed functionality manually



https://github.com/user-attachments/assets/696b8e41-6653-4be8-aae0-cf45dfa7a9b6



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Support for labels_exclude_all in policy targeting to exclude hosts
matching all specified labels.
* Allow combining include and exclude label scopes (e.g., include_any
with exclude_any or exclude_all).

* **Improvements**
* Distinct include vs. exclude conflict errors and explicit overlap
reporting.
  * Premium gating extended to include/exclude_all.
* Centralized label-overlap detection for consistent validation and
improved policy membership/exclusion behavior.

* **Tests**
* Expanded tests covering exclude_all semantics and label-scope
validation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 15:05:20 -03:00
f298ca12b2 Website: Add CIS benchmarks blog article (#47486)
Adds "Benchmarks without the burden: continuous CIS compliance" by Dhruv
Majumdar.

---------

Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
Co-authored-by: Dan Gordon <daniel@fleetdm.com>
2026-06-12 11:04:39 -07:00
Eric 934268bccb Website: update error handling in Github webhook (#47533)
Related to: https://github.com/fleetdm/fleet/issues/47391

Changes:
- Updated the receive-from-github webhook to log a warning and return a
200 response when a request to the GitHub GraphQL API to find issue
details fails.
2026-06-12 12:46:09 -05:00
Allen HouchinsandCopilot Autofix powered by AI a30298db83 Add macOS Fleet-maintained apps (L) (#47519)
Adds 23 Fleet-maintained app(s) whose cask token starts with 'L':
inputs, outputs, app icons (TSX + website PNG), and the matching
index.ts and apps.json entries.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added support for 24 new macOS applications (Lapce, Lasso, Last Window
Quits, Latest, LaunchBar, LightBurn, LinearMouse, Lingon X, lo‑rain,
Local, LocalSend, LocationSimulator, Logseq, LookAway, Loop, Loopback,
LosslessCut, Low Profile, Lunacy, Lunar, LunaSea, Lunatask, Lychee
Slicer).
* Added corresponding app icons and installer/management entries to the
software catalog for in‑app discovery and installation.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
2026-06-12 12:31:46 -05:00
Ashish Kuthiala 62f2170892 Create bridging-the-it-security-divide.md (#47487)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
2026-06-12 10:29:45 -07:00
Allen Houchins 350d208eab Unfreeze FMAs (#47525)
Remove stale "frozen" flags from several input manifests and update
metadata and scripts for multiple apps. Bump package versions, installer
URLs, checksums and script references for Adobe Acrobat Pro, Backblaze,
Cloudflare WARP (Windows) and FileMaker Pro; add improved
install/uninstall scripts and more robust quit/relaunch and uninstall
handling. Also adjust minor manifest fields (categories/paths) and
refactor several script refs for reliability.
2026-06-12 12:29:12 -05:00
lewisbarajas 095701268d Update go-to-market-operations.md - fixed a typo in the beginning of … (#47521)
…the sentence.

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2026-06-12 11:55:01 -05:00
Rachael Shaw a77e2bb642 Remove DRI for api_endpoints.yml from website config (#47529)
This didn't override the need for a @go codeowner review since they own
the directory it's in, so moved it to CODEOWNERS

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated internal development configuration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 11:48:11 -05:00
Gray Williams f756a95fe8 Remove macos_setup reference (#47497)
This part of the document still references `macos_setup`. Should this be
changed to `setup_experience`?

May break older references, which should be updated.
2026-06-12 11:47:00 -05:00
ab1148674f Add release QA issue template for fleetd (#47195)
## Summary

- Adds a new `release-qa-fleetd.md` GitHub issue template to split
`fleetd` agent QA out of the main release QA checklist into its own
dedicated issue
- Covers smoke tests for **fleetd** (enrollment, Fleet Desktop/My device
all sections, scripts, software, self-healing, auto-updates disabled),
**osquery** (version, live queries, tables, scheduled queries, packs),
and **Android** (app deployment, setup experience, Google Play software,
certificates, debug mode, unenrollment)
- Includes the existing `fleetd` testing gate (local TUF, auto-update
n+1, edge promotion) steps
- Uses a hybrid format: clickable `**Progress**` task lists (native
markdown, outside tables) for check-off + GitHub's "X of Y tasks"
progress bar, with full step/expected-result detail tables below each
list

---------

Co-authored-by: Reed Haynes <reed@fleetdm.com>
Co-authored-by: Andrey Kizimenko <87822796+AndreyKizimenko@users.noreply.github.com>
2026-06-12 11:02:51 -05:00
Lucas Manuel Rodriguez 213a7a5d1f Docs updates for the new flag for SSO login rate limiting (#47509)
Doc changes for the new flag being released in v4.86.2.
2026-06-12 12:57:07 -03:00
Rachael Shaw 2f0fa55292 Update /server/api_endpoints/api_endpoints.yml CODEOWNER (#47469)
Currently @go is the codeowner for this file because of its location,
but it's not really Go code: this file is a YAML list of all the API
endpoints available when creating an API-only user in the UI. If this
goes through the same review process as API design, then product
designers can help maintain the display names and make sure they're
up-to-date with the REST API docs.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated code ownership configuration for API endpoint-related files.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 10:50:54 -05:00
Jorge Falcon 0611f2b6de Bumping the loadtest/osquery-perf module version to utilize increased ulimits (#47471)
- Bump osquery-perf module version to v1.2.2
  - Increases ulimits from 9999 to 999999

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated performance testing infrastructure dependency to the latest
patch version.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-12 11:31:36 -04:00