Commit Graph
25575 Commits
Author SHA1 Message Date
RachelElysia 0e85fd238a Fleet UI: Stop query-param URL replace from dismissing newly-landed toasts (#48205) 2026-06-24 16:30:28 -04:00
RachelElysia b5847cdc2a Fleet UI: Browser Back no longer trapped on script batch progress page (#48200) 2026-06-24 16:30:02 -04:00
RachelElysia b0f55db56b Fleet UI: Add software progress bar stops jittering as percentage digits change (#48187) 2026-06-24 16:29:46 -04:00
RachelElysia 237742b14c Fleet UI: Prevent button label wrap globally on narrow viewports (#48176) 2026-06-24 16:29:27 -04:00
Luke Heath 89b57e420e Use full-depth checkout in snapshot image build for correct build-info version (#48206) 2026-06-24 12:55:16 -07:00
Jonathan Katz 1d816a0fc2 Update claude rules to allow server/ptr non deprecated functions (#48199)
Updates the claude backend rules to still allow some functions from the
server/ptr package. The constructor functions are deprecated but not all
the functions in the package are. For example: UintOrNilIfZero, Equal
and ValOrZero are still fine.
2026-06-24 15:00:21 -04:00
Dan Gordon 30e5ee0a8a Modify healthcheck for TLS support in docker-compose (#46960)
Updated healthcheck command to support TLS configuration. accompanying
env.example sets FLEET_SERVER_TLS=true by default but our default test
in docker-compose.yml tests to http. Causes test to fail.

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Closes https://github.com/fleetdm/fleet/issues/46927


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated service health monitoring to correctly probe the health
endpoint over HTTPS when TLS is enabled, and over HTTP when it is not.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-24 14:55:29 -04:00
faff41e41d Fix My device page software sorting by display name (#45836)
**Related issue:** Closes #43673 (remaining issue reported by @getvictor
after PR #44873)

## Changes

The "My device" page / host details software tab sorts software by
`software_titles.name` (often an installer filename) instead of the
custom display name. PR #44873 fixed this for the global
`/software/titles` endpoint but missed the host-specific
`ListHostSoftware` query path.

**Fix:** Add a `LEFT JOIN software_title_display_names` to the outer
query wrapper in `ListHostSoftware`, and update
`hostSoftwareAllowedOrderKeys` to use
`COALESCE(NULLIF(stdn.display_name, ''), name)` so display names are
used for sorting when set.

**1 file changed:** `server/datastore/mysql/software.go`

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

---------

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: Dante Catalfamo <43040593+dantecatalfamo@users.noreply.github.com>
2026-06-24 14:16:57 -04:00
Allen Houchins 52c176f3ad Capitalize Kiro app name (#48194)
Update app name from 'kiro' to 'Kiro' in Homebrew input and generated
apps output to match proper app branding.

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #48182

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2026-06-24 13:06:35 -05:00
Allen Houchins d66242856f Disambiguate FMAs sharing macOS bundle IDs (#47951)
Fix handling of Fleet-maintained apps that share a macOS bundle
identifier (e.g. Firefox and Firefox ESR). Removed the blind rename from
UpsertMaintainedApp and added ReconcileMaintainedAppSoftwareNames: a
two-pass, idempotent reconciliation that (1) renames titles tied to a
single FMA via installer links and (2) heuristically renames by bundle
identifier only when the identifier maps to exactly one FMA name.
Updated team join logic to prefer matching by installer link and fall
back to bundle identifier, changed GetFMANamesByIdentifier to omit
ambiguous identifiers, added a call to reconcile during the
maintained-apps sync, and extended the datastore interface and mock
accordingly. Added tests and a manifest check for known shared
identifiers, plus a changelog entry.

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #42445

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Bug Fixes

* Fixed an issue where macOS apps sharing a bundle identifier (e.g.,
Firefox and Firefox ESR) would incorrectly report each other as already
installed and could have their software titles unexpectedly changed.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-24 13:05:53 -05:00
Dante Catalfamo 0e3bc85acb Fix My device software list appending macos_applications param on pagination (#48145)
**Related issue:** Resolves #39017
Related issue: Resolves #47846
2026-06-24 13:36:24 -04:00
Andrew Mellor dab5afaf4b 45641 Display ran_custom_mdm_command activities in host and global activity feeds (#47897)
**Related issue:** Resolves #45641

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information. In other subtask.

## Testing

- [x] Added/updated automated tests

- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Release Notes

* **New Features**
* Added support for tracking and displaying “ran custom MDM command”
activities across dashboard and host activity feeds.
* Added custom MDM command detail modals with status-aware messaging,
actor attribution, target host, and relative “time ago” updates.
* Improved command name rendering by shortening long request types for
cleaner display.
* **Bug Fixes**
* Enhanced command status handling for additional Apple and Windows
status formats so icons and verbs display correctly.
* **Tests**
* Added coverage for custom MDM command rendering and command-status
helper behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-24 18:34:20 +01:00
Scott Gress 20af889c56 Add regression test for #46604 (#46613) 2026-06-24 07:52:25 -07:00
Scott Gress 997a4097c4 Add docs for chart bounded context (#47877) 2026-06-24 07:51:49 -07:00
Scott Gress 6336443f37 Report mobile devices in "hosts online" (#47222) 2026-06-24 07:50:35 -07:00
Scott Gress 82f7405f19 Allow setting default vuln chart filters via GitOps (#47634) 2026-06-24 07:49:19 -07:00
Isabell ReedyandSam Pfluger 0668a5b9b5 Handbook update (#48118)
Co-authored-by: Sam Pfluger <108141731+Sampfluger88@users.noreply.github.com>
2026-06-24 09:29:50 -05:00
RachelElysia 0c4e7e6f0b Fleet UI: Cap policy/report name input at 255 + truncate long names with tooltip on details pages (#48154) 2026-06-24 10:20:18 -04:00
RachelElysia 7bac963f31 Fleet UI: Add CopyButton component, fix Copied! badge in dark mode (#48124) 2026-06-24 10:19:37 -04:00
Jonathan Katz b784de80b0 Cancel software install records instead of deleting when an installer is deleted (#48127)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #47348
Does two things:
- Removes the software_installers and software_titles joins. These could
be null, but we would still want to create software install records for
these installs even if the installer or title were deleted.
- Changes every case where a host_software_installs is deleted into
setting the canceled flag to 1 on that row.

It also updates some comments. `deletePendingSoftwareInstallsForPolicy`
had a comment that said it should be called _after_ deleting a policy,
but that seems wrong and was not actually reflected in the code even
when it was originally added. It should be called _before_ deleting the
policy so that the siua.policy_id column is still available before it
gets set to null by the FK constraint. Same for
`deletePendingHostScriptExecutionsForPolicy`.

Also removes the `NOTE(mna): ...` comment, because it seems like the
code works as intended and only the comments were wrong.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Prevented a 500 error when late software installation results are
reported after the related installer has been deleted.
* Pending software install entries are now preserved as **canceled**
(instead of being deleted) during installer, policy, and batch update
flows, keeping results consistent.
* Improved correctness of intermediate failure recording and
setup-experience deletion behavior, including distinguishing
**canceled** vs **removed** installs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-24 10:00:27 -04:00
Lucas Manuel Rodriguez 705f4db3a3 Fix data race in CVE tests (#48070)
Fixes: https://github.com/fleetdm/fleet/actions/runs/28003942578.

New run: https://github.com/fleetdm/fleet/actions/runs/28026451929.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Tests**
  * Improved test fixture logic for more reliable test execution.

**Note:** This release contains internal testing improvements with no
end-user-facing changes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-24 09:49:50 -03:00
Isabell Reedy 05f0c5e628 Update custom.js (#48111)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated GitHub review automation configuration, modifying approver
assignments for the handbook/marketing section and updating contributor
access for the website/views section.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-24 13:36:15 +01:00
Juan Fernandez 25973b3974 Authorize query read when creating a policy from query_id
When creating a fleet or global policy from an existing query (via
query_id) load the referenced query and authorize ActionRead on it
before its fields are copied, in both fleet policies and global
policies.
2026-06-24 08:27:53 -04:00
fleet-release 2e62d6ab7b Update Fleet-maintained apps (#48159) 2026-06-24 07:26:03 -05:00
fleet-releaseandallenhouchins 008818d7ab Update Fleet-maintained apps (#48155)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated Google Chrome macOS configuration to target version
`149.0.7827.197`, ensuring version checks and patched status indicators
align with the latest available build.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-23 22:30:40 -05:00
fleet-releaseandallenhouchins 3c8cfb6a16 Update Fleet-maintained apps (#48152)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Chores
* Updated MacPacker to version 0.15.4
* Updated REAPER (Windows) to version 7.75

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-23 22:21:35 -05:00
RachelElysia e0fc1e0e7a Fleet UI: Auto-dismiss success toasts after navigation (#48112) 2026-06-23 22:51:39 -04:00
fleet-releaseandallenhouchins ff105b31ef Update Fleet-maintained apps (#48151)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated version metadata, installer URLs, and checksums for 24 managed
applications (including BetterTouchTool, Bruno, Claude, Cursor, Element,
Microsoft Office apps, PyCharm, Slack, and others) to support latest
releases and improve version detection accuracy.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-23 20:47:48 -05:00
Eric f5aff03f0d Website: update custom <ol> marker styles (#48140)
Changes:
- Updated the custom `<ol>` marker we use in Markdown content to not
break onto multiple lines.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Fixed list numbering display across multiple pages (articles,
webinars, whitepapers, case studies, documentation, handbooks, and legal
pages) to prevent counter text from wrapping.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 18:51:02 -05:00
Andrey Kizimenko a13cd2c373 Remove dead Wails-template scaffolding from tools/hangar (#48126)
**Related issue:** N/A — follow-up cleanup to #46406 (Add Hangar).

## What & why

Fleet Hangar is a macOS-only, GUI-only dev tool built natively, but the
Wails v3 project template left behind config for modes/platforms it
never uses. None of it was referenced by CI, scripts, or the documented
build flow (`dev` / `build` / `package` / `dist` / `sign`).

Removed:
- **Server-mode + Docker tasks** (`build:server`, `run:server`,
`build:docker`, `run:docker`, `setup:docker`) in the root and common
Taskfiles. They point at `build/docker/Dockerfile.{server,cross}`, which
don't exist, and there is no `server` build tag anywhere in the Go code.
- **Docker cross-compilation** in `build/darwin` (`build:docker`,
`CROSS_IMAGE`, the `build:universal` `lipo:go` fallback). `build:` and
`build:universal` now call the native macOS paths directly.
- **iOS tasks** (`ios:device:list`, `ios:run:device`) — no iOS project
exists.
- **`frontend:vendor:puppertino`** — fetched CSS into
`frontend/public/puppertino` and rewrote `index.html`; none of those
targets exist and no task called it.
- **`.gitignore`** lines for `build/linux` and `build/windows` (neither
dir exists).
- **`config.yml`** template placeholders (commented `ios` /
`fileAssociations` blocks, the `My Other Data` `other` entry).

The darwin signing vars (`SIGN_IDENTITY`, `KEYCHAIN_PROFILE`,
`ENTITLEMENTS`) are now declared as empty strings instead of comments,
so removing `CROSS_IMAGE` doesn't leave `vars:` as a null mapping (which
the Taskfile schema rejects). Behavior is unchanged — the `sign:`
preconditions still guard on non-empty values.

Net: **11 insertions, 280 deletions** across 5 files. No change to the
real build flow.

## Testing

- Verified with `task build` — exit 0, produces `bin/fleet-hangar`
(arm64 Mach-O).
- `task --list-all` parses all three Taskfiles with no schema errors and
no dangling task references.

## Checklist

- [x] QA'd manually (`task build`)

No changes file: `tools/hangar` is an internal dev tool, so this is not
a user-visible change.


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Simplified build configuration by removing Puppertino CSS integration
and server/Docker/iOS build tasks.
* Updated development task with improved process management to prevent
orphaned processes.
* Streamlined macOS build process to native-only implementation,
removing cross-compilation support.
  * Cleaned up build configuration files and project ignore patterns.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 17:27:13 -05:00
Matías Spinarolli 264036b262 Fix typo in README.md for restaurant spelling (#48075)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2026-06-23 17:08:52 -05:00
Konstantin Sykulev a93c61722d Android certs support all idp vars (#48100)
**Related issue:** Resolves #36774

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Certificate templates now support additional variables for subject
names and SANs, including host platform and identity-provider-derived
fields such as username (local part), groups, department, and full name.
* **Bug Fixes**
* Improved validation and error handling for missing host or
identity-provider data during template variable substitution.
* **Tests**
* Expanded coverage for supported/unsupported variables, correct
placeholder replacement, caching behavior, and RFC 4514 escaping in
DN-related values.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 16:58:40 -05:00
3900de5125 Update Fleet-maintained apps (#48089)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated managed-app versions and installer metadata across macOS and
Windows, including cmux (0.64.17), Firefox (152.0.2), Granola (7.356.2),
Lens (2026.6.231104-latest), Power Automate (2.69.00217.26166), PreForm
(3.60.2.639), and Workflowy (4.3.2606230837), with refreshed download
links and verification checksums.
  * Marked Adobe Acrobat Pro as frozen.
* **Bug Fixes**
* Improved Power Automate uninstall reliability by switching to the WiX
Burn bootstrapper-based uninstall flow.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
Co-authored-by: Allen Houchins <allenhouchins@mac.com>
2026-06-23 16:04:41 -05:00
Andrey KizimenkoandGeorge Karr 0f9af89a93 Add Hangar: Go/Wails desktop control panel for the Fleet dev environment (#46406)
## Summary

Adds `tools/hangar` — a macOS desktop control panel for working on Fleet
locally: branch management, `fleet serve` orchestration, log tail, dev
MySQL backup/restore, `fleetctl`, GitOps, and `osquery-perf`, all in one
window.

Built with **Go + [Wails 3](https://v3alpha.wails.io)** — the backend is
plain Go (`os/exec`, `syscall`, goroutines) so Fleet engineers can
contribute to it; only the desktop shell is Wails. The `internal/`
packages are pure and unit-tested.

### History note
Hangar started as a Rust/Tauri app. It was ported to Go, and **the Go
port is now the canonical `tools/hangar`**. The original Rust/Tauri
implementation has been removed from the monorepo (preserved in a
standalone repo) — so although this branch's earlier commits add and
then replace the Rust app, the net diff is just the Go app at
`tools/hangar`. The bundle identifier is `com.fleetdm.fleet-hangar`,
matching the original app so existing settings carry over.

# Checklist for submitter

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops

> No `changes/` file: `tools/` is contributor tooling, not a
user-visible Fleet change. No DB migrations, no Fleet config settings,
no fleetd/orbit changes.

## Testing

- [x] Added/updated automated tests (Go unit tests across `internal/`,
including a path-traversal regression for backup deletion)
- [x] QA'd all new/changed functionality manually

## Test plan
- [x] `cd tools/hangar && task dev` launches the app (live-reload)
- [x] `task build` produces `bin/fleet-hangar`; `go test ./...` is green
- [x] First-run gate discovers a local Fleet clone and runs dep checks
- [x] Server tab can run the build chain and start `fleet serve`
- [x] Git tab branch search finds an older branch (e.g. a stale `qa-*`)
by name


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Introduced Fleet Hangar, a comprehensive desktop application for Fleet
development workflows, providing unified controls for server/database
management, git operations, configuration, logging, and troubleshooting.
  * Added database backup management with metadata tracking.
* Integrated process orchestration for development services (Docker,
ngrok, Python).
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: George Karr <georgekarrv@users.noreply.github.com>
2026-06-23 15:45:23 -05:00
Eric 4ca43f9ff2 Website: update logos on partners page (#48096)
Changes:
- Updated the partners page to display partners' logos in a grid on
larger screens (under 575px, the logo carousel is shown to users)
2026-06-23 15:31:13 -05:00
Steven Palmesano 1a68f206bd Improve software page tooltips (#46839)
Resolves #46921.

Before and after screens below.
Correct wording for scripts:

<img width="343" height="148" alt="Screenshot 2026-06-04 at 11 52 36"
src="https://github.com/user-attachments/assets/2f56dc01-0eb5-4fdd-9d9a-c4055b823bc9"
/>
<img width="309" height="129" alt="Screenshot 2026-06-04 at 11 55 07"
src="https://github.com/user-attachments/assets/99347a18-1304-451a-9d0d-d12a64acb9a7"
/>

Prefer human-readable software names:

<img width="659" height="146" alt="Screenshot 2026-06-04 at 09 41 03"
src="https://github.com/user-attachments/assets/f12a4f2b-a3d3-4860-a98d-8e0bd6145131"
/>
<img width="645" height="145" alt="Screenshot 2026-06-04 at 09 41 12"
src="https://github.com/user-attachments/assets/638cfef0-afb5-41a8-a37f-a412b055d76c"
/>

<img width="614" height="133" alt="Screenshot 2026-06-04 at 11 50 51"
src="https://github.com/user-attachments/assets/24c016c2-693e-4256-b7d2-bef057df16f3"
/>
<img width="622" height="114" alt="Screenshot 2026-06-04 at 11 55 32"
src="https://github.com/user-attachments/assets/8a06f0f1-01fa-498b-908d-2e8a81f03e9f"
/>


# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Bug Fixes**
* Improved host software empty-state tooltips with human-friendly
software/package naming (preferring display name) and context-specific
messaging.
* Corrected script vs non-script action wording: “Run” for script
packages and “Install” for non-scripts, including matching CTA and verb
text.
* Updated App Store self-service tooltip phrasing to include the app
name when available.

* **Tests**
* Adjusted tooltip expectations to match the updated placeholder and App
Store text.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 15:04:49 -05:00
Noah Talerman 3049194d2c 4.87 release article: Fix hyperlinks (#48072) 2026-06-23 12:44:06 -07:00
Eric 1844947194 Update vulnerability dashboard readme (#48104)
Changes:
- Updated the vulnerability dashboard's readme to trigger the
deploy-vulnerability-dashboard workflow.
2026-06-23 14:10:54 -05:00
Lucas Manuel Rodriguez a2940ecd31 Revert "Initial pass on TPM-backed disk encryption support (#46457)" (#48101)
This reverts commit 19ba1ed787. (PR:
https://github.com/fleetdm/fleet/pull/46457.)

# Checklist for submitter

## Testing

- [x] QA'd all new/changed functionality manually

## fleetd/orbit/Fleet Desktop

- [x] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [x] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [x] Verified that fleetd runs on macOS, Linux and Windows
- [x] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Changes**
* Unified the disk encryption prompt on TPM-backed Linux hosts to
display standard passphrase entry dialogs consistently, removing
specialized messaging previously shown for recovery key scenarios.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 16:08:22 -03:00
Sharon Katz 81f2edec65 Improve fleet scope validation for software title lookups (#48034)
## Summary

Ensures that `SoftwareTitleByID` validates fleet scope for all non-nil
`team_id` values, including zero. Previously the scope check was only
applied when `team_id > 0`.

## Reproduction

Added a unit test (`TestSoftwareTitleByIDTeamIDZero`) that sets up a
fleet-scoped user on fleet 1, then calls `SoftwareTitleByID` with
`team_id=0`. Before this change, the call succeeded. After, it correctly
returns 403.

Also confirmed that a global admin calling with `team_id=0` still
succeeds, and that all existing `TestServiceSoftwareTitlesAuth` subtests
continue to pass.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests

- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Improvements**
* Enhanced fleet scope validation for software title lookups, including
correct handling when a team scope value is set to `0`.

* **Tests**
* Added unit test coverage for software title retrieval authorization
behavior when the team scope value is `0`.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 14:28:15 -04:00
Allen Houchins b55d45806c Align software category name comparison with DB (#47983)
Normalize category name comparisons to match MySQL's utf8mb4_unicode_ci
collation (case-insensitive and ignoring Unicode variation selectors) to
avoid duplicate-entry errors. Add normalizeSoftwareCategoryName and
SoftwareCategoryNamesEqual (server/fleet/software.go) and use them where
categories are deduped (ee/server/service/software_installers.go). Make
batch insert idempotent by using ON DUPLICATE KEY UPDATE in the MySQL
batch insert (server/datastore/mysql/software.go). Add tests for
name-equality behavior and idempotent batch inserts
(server/fleet/software_test.go,
server/datastore/mysql/software_test.go). This prevents collisions
between visually identical emoji forms (e.g. with/without U+FE0F) and
tolerates concurrent/default category inserts.

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #47981

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed GitOps runs failing due to software category duplicate-entry
errors when names contain certain Unicode characters (e.g., emoji
variation selectors).

* **Improvements**
* Enhanced software category deduplication to properly handle
Unicode-equivalent names.
* Made batch category insertion operations idempotent to prevent
duplicate-key errors.

* **Tests**
* Added tests for software category idempotency and Unicode character
handling.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 12:38:58 -05:00
e32bcd594a Update self service docs (#47994)
Related to:

- #39018

---------

Co-authored-by: Noah Talerman <47070608+noahtalerman@users.noreply.github.com>
Co-authored-by: Rachael Shaw <r@rachael.wtf>
2026-06-23 12:34:18 -05:00
Lucas Manuel Rodriguez 8e94d5e820 Remove unused migration tests (#48074)
This is just removing tests that are never run (always skipped), see:

https://github.com/fleetdm/fleet/blob/7fa7e8f26d108c9421ed7b8e83ffde4468dab6ba/server/datastore/mysql/migrations/tables/migration_test.go#L101-L110

- [X] QA'd all new/changed functionality manually
2026-06-23 13:43:10 -03:00
Harrison RavazzoloandIrena Reedy 7d259d1d77 typo fix, link fix (#48079)
Co-authored-by: Irena Reedy <irena@fleetdm.com>
2026-06-23 08:59:27 -07:00
fleet-releaseandallenhouchins 6b9ee7e3d8 Update Fleet-maintained apps (#48071)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **Chores**
* Updated metadata for 24 applications to their latest available
versions, including Adobe Acrobat Pro, AWS CLI, AWS VPN Client,
BetterTouchTool, Cursor, Deezer, Grammarly Desktop, Linear, Notion,
Postman, and others, ensuring current versions are available for
deployment.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-23 10:41:27 -05:00
Noah TalermanandEric 000b2835c6 Rename guide: "Query" => "Report" (#48020)
And add redirects

Part of the following issue:
- https://github.com/fleetdm/fleet/issues/41419


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Chores**
* Updated legacy documentation redirects so older `/docs/using-fleet/*`
and `/guides/*` URLs now point to the correct current guide and report
destinations (301), including fixes for Fleet UI, learn-how-to-use, and
report/library links.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2026-06-23 11:30:06 -04:00
Allen Houchins a972ca21b0 Add "Support" default software category (#47923)
**Related issue:** Resolves #48064

Adds a new default self-service software category, rendered as **🛟
Support**, alongside the existing six defaults (Browsers, Communication,
Developer tools, Productivity, Security, Utilities).

## What changed

**Backend (Go)**
- `server/fleet/software.go` — added `🛟 Support` to
`DefaultSelfServiceCategoryNames` (seeds new fleets) and `"Support": "🛟
Support"` to `LegacySoftwareCategoryNames` (so GitOps/FMA manifests can
reference the non-emoji `Support`).
- New migration `20260619120000_AddSupportSoftwareCategory` — inserts
the global default (`team_id=0`) and backfills every existing fleet.
Timestamps pinned for deterministic schema dumps; `INSERT IGNORE` guards
the `(team_id, name)` unique key.
- `schema.sql` regenerated via `tools/dbutils`.
- `cmd/maintained-apps/main.go` — added `Support` to the FMA validator
allowlist.

**Frontend**
- `frontend/interfaces/software.ts` — added `"Support"` to the
`SoftwareCategory` union.
- `frontend/pages/hosts/details/cards/Software/SelfService/helpers.ts` —
added `{ label: "🛟 Support", value: "Support" }` to the fallback list.

**Docs**
- `docs/Configuration/yaml-files.md` — documented `Support` as a
supported GitOps category.

## Note on sort order
`ListSoftwareCategories` does `ORDER BY name` under
`utf8mb4_unicode_ci`, which sorts by the word after the (ignorable)
emoji. `🛟 Support` is therefore placed between `🔐 Security` and `🛠️
Utilities`.

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

Verified against a dockerized MySQL:
- Migration test `TestUp_20260619120000`
- `TestSoftware/SoftwareCategoryCRUD` (order-sensitive assertion)
- `TestSelfServiceCategoriesCRUD` + `TestDeviceSelfServiceCategories`
integration tests
- `cmd/maintained-apps` tests, ee categories test, `go vet`, `make
lint-go-incremental` (0 issues)
- `tools/dbutils` schema regeneration matches

## Database migrations

- [x] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [x] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [x] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [x] Verified the setting is documented (GitOps `categories` supported
values in `docs/Configuration/yaml-files.md`).


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Introduced the "🛟 Support" category as a new self-service software
classification option. Users can now better organize support-related
applications within their software catalog. The category is available
globally across all teams, providing improved organization and discovery
capabilities for support applications alongside utilities and other
existing software categories.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-23 09:41:08 -05:00
Juan Fernandez eb48eb37f8 Made team label membership checks more robust
When creating a manual label, make the checks around manual host more
robust.
2026-06-23 10:01:23 -04:00
Nico 9e4627e889 Frontend: document spread-prop exceptions (#46348)
Modified patterns.md to document that we prefer to not spread props into
components. Included some exceptions as well as some specific cases
where we'd never want to spread (e.g. into an `img` tag).

## Testing

- [x] QA'd all new/changed functionality manually
2026-06-23 11:00:59 -03:00
Mason Buettner 7fa7e8f26d Update link for vulnerability processing documentation (#48031)
Updating a broken link and move link.
2026-06-23 09:47:38 -04:00