42ccc344d2f7d01a642a62c8f39bf331b8205da8
22967
Commits
| Author | SHA1 | Message | Date | |
|---|---|---|---|---|
|
|
42ccc344d2 |
Added Android cert activity logging (docs) (#42609)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #37546 |
||
|
|
16d62da6a4 |
use redis to block double profile work for apple devices setting up (#42421)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #34433 Part 2 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. Added by first PR - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Profiles now install during device enrollment setup * **Bug Fixes** * Enhanced Apple MDM profile synchronization to handle concurrent processing scenarios * Improved profile reconciliation to prevent conflicts when multiple workers process the same device simultaneously <!-- end of auto-generated comment: release notes by coderabbit.ai --> --------- Co-authored-by: Martin Angers <martin.n.angers@gmail.com> |
||
|
|
f0057976c4 |
Updating Event Execution Details (#42685)
Adding details to event execution - improving issue template |
||
|
|
fbb1573be9 |
Create default patch policy query in FMA manifest (#42559)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42492 Includes changes from running ingestions on all FMAs # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually |
||
|
|
e794906340 | Fleet UI: Fix info button hover muck (#42674) | ||
|
|
13f94af560 |
Update software title names on FMA sync and upload (#42647)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #41710 Updates (only) macOS software title names on FMA catalog sync. Updates software title names on installer upload for Windows FMAs with an upgrade code. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually |
||
|
|
8d63bf2bbe |
Prevent duplicate Android web-clip apps with the same name (#42664)
Fixes #42641. |
||
|
|
1765c13523 |
Return bad request instead of 413 when installer size is too big (#42676)
Resolves #42456. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: - [X] Confirmed that the fix is not expected to adversely impact load test results |
||
|
|
1aef37c75c |
Bump github.com/go-git/go-git/v5 from 5.16.5 to 5.17.1 (#42670)
Bumps [github.com/go-git/go-git/v5](https://github.com/go-git/go-git) from 5.16.5 to 5.17.1. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/go-git/go-git/releases">github.com/go-git/go-git/v5's releases</a>.</em></p> <blockquote> <h2>v5.17.1</h2> <h2>What's Changed</h2> <ul> <li>build: Update module github.com/cloudflare/circl to v1.6.3 [SECURITY] (releases/v5.x) by <a href="https://github.com/go-git-renovate"><code>@go-git-renovate</code></a>[bot] in <a href="https://redirect.github.com/go-git/go-git/pull/1930">go-git/go-git#1930</a></li> <li>[v5] plumbing: format/index, Improve v4 entry name validation by <a href="https://github.com/pjbgf"><code>@pjbgf</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1935">go-git/go-git#1935</a></li> <li>[v5] plumbing: format/idxfile, Fix version and fanout checks by <a href="https://github.com/pjbgf"><code>@pjbgf</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1937">go-git/go-git#1937</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/go-git/go-git/compare/v5.17.0...v5.17.1">https://github.com/go-git/go-git/compare/v5.17.0...v5.17.1</a></p> <h2>v5.17.0</h2> <h2>What's Changed</h2> <ul> <li>build: Update module github.com/go-git/go-git/v5 to v5.16.5 [SECURITY] (releases/v5.x) by <a href="https://github.com/go-git-renovate"><code>@go-git-renovate</code></a>[bot] in <a href="https://redirect.github.com/go-git/go-git/pull/1839">go-git/go-git#1839</a></li> <li>git: worktree, optimize infiles function for very large repos by <a href="https://github.com/k-anshul"><code>@k-anshul</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1853">go-git/go-git#1853</a></li> <li>git: Add strict checks for supported extensions by <a href="https://github.com/pjbgf"><code>@pjbgf</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1861">go-git/go-git#1861</a></li> <li>backport, git: Improve Status() speed with new index.ModTime check by <a href="https://github.com/cedric-appdirect"><code>@cedric-appdirect</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1862">go-git/go-git#1862</a></li> <li>storage: filesystem, Avoid overwriting loose obj files by <a href="https://github.com/pjbgf"><code>@pjbgf</code></a> in <a href="https://redirect.github.com/go-git/go-git/pull/1864">go-git/go-git#1864</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/go-git/go-git/compare/v5.16.5...v5.17.0">https://github.com/go-git/go-git/compare/v5.16.5...v5.17.0</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/go-git/go-git/commit/5e23dfd02db92644dc4a3358ceb297fce875b772"><code>5e23dfd</code></a> Merge pull request <a href="https://redirect.github.com/go-git/go-git/issues/1937">#1937</a> from pjbgf/idx-v5</li> <li><a href="https://github.com/go-git/go-git/commit/6b38a326816b80f64c20cc0e6113958b65c05a1c"><code>6b38a32</code></a> Merge pull request <a href="https://redirect.github.com/go-git/go-git/issues/1935">#1935</a> from pjbgf/index-v5</li> <li><a href="https://github.com/go-git/go-git/commit/cd757fcb856a2dcc5fff6c110320a8ff62e99513"><code>cd757fc</code></a> plumbing: format/idxfile, Fix version and fanout checks</li> <li><a href="https://github.com/go-git/go-git/commit/3ec0d70cb687ae1da5f4d18faa4229bd971a8710"><code>3ec0d70</code></a> plumbing: format/index, Fix tree extension invalidated entry parsing</li> <li><a href="https://github.com/go-git/go-git/commit/dbe10b6b425a2a4ea92a9d98e20cd68e15aede01"><code>dbe10b6</code></a> plumbing: format/index, Align V2/V3 long name and V4 prefix encoding with Git</li> <li><a href="https://github.com/go-git/go-git/commit/e9b65df44cb97faeba148b47523a362beaecddf9"><code>e9b65df</code></a> plumbing: format/index, Improve v4 entry name validation</li> <li><a href="https://github.com/go-git/go-git/commit/adad18daabddee04c5a889f0230035e74bca32c0"><code>adad18d</code></a> Merge pull request <a href="https://redirect.github.com/go-git/go-git/issues/1930">#1930</a> from go-git/renovate/releases/v5.x-go-github.com-clo...</li> <li><a href="https://github.com/go-git/go-git/commit/29470bd1d862c6e902996b8e8ff8eb7a0515a9be"><code>29470bd</code></a> build: Update module github.com/cloudflare/circl to v1.6.3 [SECURITY]</li> <li><a href="https://github.com/go-git/go-git/commit/bdf06885bdaa3631cf6a2017108086c6f53dcf69"><code>bdf0688</code></a> Merge pull request <a href="https://redirect.github.com/go-git/go-git/issues/1864">#1864</a> from pjbgf/v5-issue-55</li> <li><a href="https://github.com/go-git/go-git/commit/5290e521c8cf651bf3e8d3e37f517c7cf7aa0b19"><code>5290e52</code></a> storage: filesystem, Avoid overwriting loose obj files. Fixes <a href="https://redirect.github.com/go-git/go-git/issues/55">#55</a></li> <li>Additional commits viewable in <a href="https://github.com/go-git/go-git/compare/v5.16.5...v5.17.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fleetdm/fleet/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
f57ec7f737 |
Adding testifylint as incremental linter. (#42658)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42657 |
||
|
|
d39578eb16 | Adding changes for Fleet v4.82.2 (#42417) | ||
|
|
4d64837453 |
Update Fleet-maintained apps (#42656)
Automated ingestion of latest Fleet-maintained app data. Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com> |
||
|
|
2b4b96bf50 |
fixing shallow clone boundary error (#42662)
Related issue: Resolves https://github.com/fleetdm/fleet/issues/41571 It appears that there is some sort of error with shallow cloning. ``` Run echo "=== Generating OSV Artifacts for Ubuntu ===" === Generating OSV Artifacts for Ubuntu === === OSV Repository Sync === Repository exists, updating with rolling window... fatal: error processing shallow info: 4 Error: Process completed with exit code 128. ``` Since we are only keeping a limited history of the repository via cache before re-clone, fall back to doing a regular `git pull`. This avoids the complicated shallow cloning / Git having to reconcile the overlapping but different shallow boundaries, which can cause "error processing shallow info: 4". ## Testing - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Refactor** * Modified repository synchronization to use full fetches instead of rolling-window shallow fetches. * Updated sync status messaging for clarity. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e98b0f480d | Use FMA names for macOS software (#42221) | ||
|
|
32f1c2026c |
Bump golang.org/x/image from 0.18.0 to 0.38.0 (#42661)
Bumps [golang.org/x/image](https://github.com/golang/image) from 0.18.0 to 0.38.0. <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/golang/image/commit/23ae9ed61c1d3343fb95015810f62dcbf444976e"><code>23ae9ed</code></a> tiff: cap buffer growth to prevent OOM from malicious IFD offset</li> <li><a href="https://github.com/golang/image/commit/e589e60f29d0bbbf6400e250e024f93cbc4961ee"><code>e589e60</code></a> webp: allow VP8L + VP8X(with alpha)</li> <li><a href="https://github.com/golang/image/commit/fe7d73de74b8a1ad508c93cfcb245d44579163ff"><code>fe7d73d</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/image/commit/e3d762b1d37ed96e757e3bc0bfb44f7455589df3"><code>e3d762b</code></a> all: upgrade go directive to at least 1.25.0 [generated]</li> <li><a href="https://github.com/golang/image/commit/833c6ed987962feaa3ec2624d8655421b25e2e0e"><code>833c6ed</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/image/commit/bc7fe0b43a01586e7ca7c087a2e8a625e8397dcb"><code>bc7fe0b</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/image/commit/c53c97f4ed88d55fafe963ee6e93cb357663d650"><code>c53c97f</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/image/commit/9032ff7c7b86f42b9bebdf6133191648224aecc0"><code>9032ff7</code></a> all: eliminate vet diagnostics</li> <li><a href="https://github.com/golang/image/commit/9c9d08c65c08567c997eccc8bde52fcc9369bea6"><code>9c9d08c</code></a> go.mod: update golang.org/x dependencies</li> <li><a href="https://github.com/golang/image/commit/742b1b756d98a0c48b1fcf464a0c63fa50e1aa6b"><code>742b1b7</code></a> all: fix some comments</li> <li>Additional commits viewable in <a href="https://github.com/golang/image/compare/v0.18.0...v0.38.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fleetdm/fleet/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
07a8378a68 |
Implement FMA software policy automation (#42533)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #36751 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually - [X] Verified that `fleetctl generate-gitops` correctly outputs policies with `install_software.fleet_maintained_app_slug` populated when the policies have FMA automation - [X] Verified that running `fleetctl gitops` using files with `install_software.fleet_maintained_app_slug` creates/updates FMA policy automation correctly - [X] Verified no changes to the above for custom packages or VPP apps - [X] Verified that when software is excepted from GitOps, FMA policy automations still work (correctly validates FMAs exist before applying) ## New Fleet configuration settings - [ ] Setting(s) is/are explicitly excluded from GitOps If you didn't check the box above, follow this checklist for GitOps-enabled settings: - [X] Verified that the setting is exported via `fleetctl generate-gitops` - [ ] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) checking on this - [X] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - [X] Verified that any relevant UI is disabled when GitOps mode is enabled |
||
|
|
ec35465d1f |
Bump jsrsasign from 11.1.0 to 11.1.1 in /website (#42634)
Bumps [jsrsasign](https://github.com/kjur/jsrsasign) from 11.1.0 to 11.1.1. <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/kjur/jsrsasign/blob/master/ChangeLog.txt">jsrsasign's changelog</a>.</em></p> <blockquote> <p>ChangeLog for jsrsasign</p> <ul> <li>Changes from 11.1.0 to 11.1.1 (2026-Feb-20) <ul> <li>security fix for DSA and BigInteger <ul> <li>PR <a href="https://redirect.github.com/kjur/jsrsasign/issues/651">#651</a>, <a href="https://redirect.github.com/kjur/jsrsasign/issues/650">#650</a>, <a href="https://redirect.github.com/kjur/jsrsasign/issues/649">#649</a>, <a href="https://redirect.github.com/kjur/jsrsasign/issues/648">#648</a>, <a href="https://redirect.github.com/kjur/jsrsasign/issues/647">#647</a>, <a href="https://redirect.github.com/kjur/jsrsasign/issues/646">#646</a>, <a href="https://redirect.github.com/kjur/jsrsasign/issues/645">#645</a>. Thank you <a href="https://github.com/Kr0remer"><code>@Kr0remer</code></a></li> <li>After assigned CVE number reports will be added.</li> </ul> </li> <li>SECURITY.md added. Thank you <a href="https://github.com/njg7194"><code>@njg7194</code></a></li> </ul> </li> </ul> <p>restore KJUR.crypto.Cipher class without RSA/RSAOAEP support</p> <ul> <li>Changes from 11.0.0 to 11.1.0 (2024-Feb-01) <ul> <li>src/crypto.js <ul> <li>restore KJUR.crypto.Cipher class without RSA and RSAOAEP encryption/decryption support</li> </ul> </li> </ul> </li> </ul> <p>remove RSA and RSAOAEP encryption for Marvin attack</p> <ul> <li>Changes from 10.9.0 to 11.0.0 (2024-Jan-16) <ul> <li>remove RSA PKCS#1.5 end OAEP encryption/decryption for Marvin attack (<a href="https://redirect.github.com/kjur/jsrsasign/issues/598">#598</a>)</li> <li>src/crypto.js <ul> <li>remove KJUR.crypto.Cipher class for RSA and RSAOAEP encryption/decryption</li> </ul> </li> <li>ext/{rsa,rsa2}.js remove encrypt/decrypt/encryptOAEP/decryptOAEP for RSAKey class</li> </ul> </li> </ul> <p>enhanced support for encrypted PKCS8</p> <ul> <li>Changes from 10.8.6 to 10.9.0 (2023-Nov-27) <ul> <li>KEYUTIL.getPEM is updated not to use weak ciphers (<a href="https://redirect.github.com/kjur/jsrsasign/issues/599">#599</a>) <ul> <li>default encryptionScheme is changed from des-EDE3-CBC to aes256-CBC</li> <li>default prf is changed from hmacWithSHA1 to hmacWithSHA256</li> </ul> </li> <li>src/keyutil.js <ul> <li>more encrypted PKCS#8 private key support <ul> <li>KEYUTIL.getKey now supports encrypted PKCS#8 private key with aes128-CBC, aes256-CBC encrypted and using hmacWithSHA224/256/384/512 as psudorandom function.</li> <li>KEYUTIL.getPEM now supports such as above encrypted PKCS#8 PEM priavte key.</li> </ul> </li> </ul> </li> <li>src/crypto.js <ul> <li>Cipher.decrypt/encrypt now supports symmetric ciphers (des-EDE3-CBC,aes128-CBC,aes256-CBC)</li> </ul> </li> <li>src/base64x.js <ul> <li>function inttohex and twoscompl are added</li> </ul> </li> <li>src/asn1.js <ul> <li>ASN1Util.bigIntToMinTwosComplementsHex is now DEPRECATED. use twoscompl.</li> </ul> </li> <li>src/asn1x509.js <ul> <li>aes*-CBC and hmacWithSHA* OIDs are added</li> </ul> </li> <li>test/qunit-do-{base64x,crypto-cipher,keyutil-eprv,keyutil,keyutil-p8egen}.html <ul> <li>update and add some test cases for above</li> </ul> </li> <li>stop bower support (bower.json removed)</li> </ul> </li> </ul> <p>X509.getExtSubjectDirectoryAttributes another bugfix</p> <ul> <li>Changes from 10.8.5 to 10.8.6 (2023-Apr-26) <ul> <li>src/x509.js <ul> <li>another bugfix X509.getExtSubjectDirectoryAttributes method</li> </ul> </li> </ul> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/kjur/jsrsasign/commit/e2b136e9eab7d571cb4a680ec10361ddc70fd573"><code>e2b136e</code></a> 11.1.1 release</li> <li><a href="https://github.com/kjur/jsrsasign/commit/e2e417efacac7a12792b989af87d8dfc6e0ca5c9"><code>e2e417e</code></a> Merge pull request <a href="https://redirect.github.com/kjur/jsrsasign/issues/641">#641</a> from njg7194/add-security-policy</li> <li><a href="https://github.com/kjur/jsrsasign/commit/77f177673ef4577b119629d453d357606fb2501b"><code>77f1776</code></a> Merge pull request <a href="https://redirect.github.com/kjur/jsrsasign/issues/651">#651</a> from Kr0emer/fix/bug-007-isprobableprime-negative</li> <li><a href="https://github.com/kjur/jsrsasign/commit/5ea1c32bb2aa894b4bd29849839afe4f98728195"><code>5ea1c32</code></a> Merge pull request <a href="https://redirect.github.com/kjur/jsrsasign/issues/650">#650</a> from Kr0emer/fix/bug-006-modpow-negative-exponent</li> <li><a href="https://github.com/kjur/jsrsasign/commit/ee4b013478366cb16cea9a4bdfb218b6077f83b1"><code>ee4b013</code></a> Merge pull request <a href="https://redirect.github.com/kjur/jsrsasign/issues/647">#647</a> from Kr0emer/fix/bug-003-dsa-nonce-compareto</li> <li><a href="https://github.com/kjur/jsrsasign/commit/37b4c06b145c7bfd6bc2a6df5d0a12c56b15ef60"><code>37b4c06</code></a> Merge pull request <a href="https://redirect.github.com/kjur/jsrsasign/issues/646">#646</a> from Kr0emer/fix/bug-002-dsa-domain-params-validation</li> <li><a href="https://github.com/kjur/jsrsasign/commit/d89f0ec6d5ec89b726030ea04eaf204fdee826a9"><code>d89f0ec</code></a> fix(crypto): correct compareTo checks in BigInteger RNG helpers</li> <li><a href="https://github.com/kjur/jsrsasign/commit/02fa75d1db191653c7a0b0e9c3aca3c42927aea7"><code>02fa75d</code></a> fix(jsbn2): reject non-positive values in primality checks</li> <li><a href="https://github.com/kjur/jsrsasign/commit/f508dddf7e8cb0c4ff159884ad1eac91b516ed74"><code>f508ddd</code></a> Merge branch 'master' into fix/bug-002-dsa-domain-params-validation</li> <li><a href="https://github.com/kjur/jsrsasign/commit/ca5b027240287a1e71fe63019fc4400332594323"><code>ca5b027</code></a> Merge pull request <a href="https://redirect.github.com/kjur/jsrsasign/issues/648">#648</a> from Kr0emer/fix/bug-004-modinverse-dos</li> <li>Additional commits viewable in <a href="https://github.com/kjur/jsrsasign/compare/11.1.0...11.1.1">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fleetdm/fleet/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
6f9e4ce214 | Bump brace-expansion from 1.1.12 to 1.1.13 (#42557) | ||
|
|
1263ffc46b |
Update Claude desktop app policy versions to latest (#42659)
## Summary - Update the macOS "Claude up to date" policy minimum version from `1.1.5749` to `1.1.9493` (latest Homebrew cask version) - Update the Windows "Claude up to date" policy minimum version from `1.1.5368` to `1.1.9310` (latest winget version) These policies ensure all Workstations team hosts are running the latest version of the Claude desktop app (Anthropic). The policies, Fleet-maintained app entries (`claude/darwin`, `claude/windows`), and workstations team references were already in place — this PR only bumps the version numbers checked by the osquery queries. ## Changes | File | Change | |------|--------| | `it-and-security/lib/macos/policies/update-claude.yml` | `version_compare` threshold `1.1.5749` → `1.1.9493` | | `it-and-security/lib/windows/policies/update-claude.yml` | `version_compare` threshold `1.1.5368` → `1.1.9310` | Built for [Allen Houchins](https://fleetdm.slack.com/archives/D0AFASNBZMW/p1774884397872049) by [Kilo for Slack](https://kilo.ai/features/slack-integration) Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com> |
||
|
|
83318887c9 |
Add video link to 'Why wireframe first?' handbook section (#42654)
## Summary - Adds a relevant LinkedIn video link to the "Why do we use a wireframe-first approach?" section of the "Why this way?" handbook page - The video illustrates why, much like Pixar's storyboarding process, Fleet uses wireframes to inexpensively storyboard user journeys before locking in decisions that are prohibitively expensive to change post-production - Minimal change: one new bullet point matching existing formatting and link style Built for [mikermcneil](https://fleetdm.slack.com/archives/D0AFASLRHNU/p1774883979731019?thread_ts=1774883159.649239&cid=D0AFASLRHNU) by [Kilo for Slack](https://kilo.ai/features/slack-integration) --------- Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com> |
||
|
|
6557086c71 | FE 🧹✨: Remove purple banner code and default to grey (#42649) | ||
|
|
4c4aa1d4c5 |
Cleanup temp installer files after download (#42463)
Ensure downloaded installer files are removed after validation. Add cleanupInstaller to remove the installer file (ignoring missing files and logging failures). Propagate a downloaded installer path from DownloadMaintainedApp (signature now returns the TempFileReader, the saved file path, and error), write the installer into cfg.tmpDir and set INSTALLER_PATH in cfg.env. Call cleanupInstaller on error paths and after successful validation to avoid leftover temp files. |
||
|
|
9da1d79be9 |
Update Fleet-maintained apps (#42648)
Automated ingestion of latest Fleet-maintained app data. Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com> |
||
|
|
18c97abf5a |
Use display name when applicable for Android config change updates (#42626)
Resolves #42383. Re-roll of #42384 using the relevant helper function. # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [ ] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit ## Release Notes * **Bug Fixes** * Enhanced Android software configuration success notifications to dynamically display the actual software display name, replacing previously static messaging. This improvement provides users with more specific and personalized feedback when confirming successful software configurations, improving clarity and reducing potential confusion when managing multiple software installations or updates on their Android devices. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
028ff2adf6 |
add missing validation for scripts, tests (#42424)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #41500 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually |
||
|
|
d84beaa43f |
Windows profile delete fixes (#42495)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42452 - Editing a Windows profile to remove LocURIs now deletes those LocURIs - Removing a shared LocURI from one profile would NOT delete it even though another profile still uses it. - Loadtest fixes (batching, etc.) - Ordering commands by created to make sure a new profile AFTER a delete doesn't get deleted. # Checklist for submitter ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Added profile change detection to identify and remove LocURIs when Windows profiles are edited. * **Bug Fixes** * Improved error logging when profile payload operations fail. * Enhanced pending command ordering for consistent processing. * Optimized profile deletion to prevent orphaned configurations across multiple profiles. * **Tests** * Added integration tests validating Windows profile edits with multi-part removals and shared LocURI protection. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
e54ea7b3ad |
Add GitOps exceptions UI to Change Management settings (#42348)
**Related issue:** Resolves #42182 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See <a href="https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files">Changes files</a> for more information. will add to last PR ## Testing - [X] Added/updated automated tests - [X] Added `ChangeManagement.tests.tsx` with unit/integration tests covering: - Exceptions checkboxes render correctly from config for new install (only Enroll secrets checked) and migrated instances (Labels and Enroll secrets checked) - Form save sends the correct `gitops.exceptions` payload via `configAPI.update` - Form validation shows error when GitOps mode is enabled but no repo URL is provided - Non-premium tier renders the premium feature message - [X] QA'd all new/changed functionality manually - [X] verified that Labels and Secrets are checked for pre-existing (migrated) instance - [X] verified that only Secrets is checked for new instance - [X] verified that changing the settings in the UI and saving persists the `gitops.exceptions` config as expected <img src="https://github.com/user-attachments/assets/095c538c-68aa-4179-b4b1-fd5878c0a2b0"> ## Summary by CodeRabbit * **New Features** * Added GitOps exceptions configuration in Change Management settings with toggles for Labels, Software, and Enroll Secrets, enabling granular control over exception flags. <!-- START COPILOT CODING AGENT TIPS --> --- ✨ Let Copilot coding agent [set things up for you](https://github.com/fleetdm/fleet/issues/new?title=✨+Set+up+Copilot+instructions&body=Configure%20instructions%20for%20this%20repository%20as%20documented%20in%20%5BBest%20practices%20for%20Copilot%20coding%20agent%20in%20your%20repository%5D%28https://gh.io/copilot-coding-agent-tips%29%2E%0A%0A%3COnboard%20this%20repo%3E&assignees=copilot) — coding agent works faster and does higher quality work when set up for your repo. --------- Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: sgress454 <553428+sgress454@users.noreply.github.com> |
||
|
|
f1bad72003 |
Use new multiplatform keys on the front end (#41763)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #41601 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Details This PR updates the front end to use the following renamed API keys: * bootstrap_package -> macos_bootstrap_package * manual_agent_install -> macos_manual_agent_install * enable_release_device_manually -> apple_ enable_release_device_manually * script -> macos_script * macos_setup -> setup_experience * macos_settings -> apple_settings * custom_settings -> configuration_profiles * macos_setup_assistant -> apple_setup_assistant It also ensures that consumers of the "get fleet config" API pull from the `.fleet` property rather than `.team`, so that they can use all of the newly renamed response fields. ## Summary by CodeRabbit * **Refactor** * Restructured Mobile Device Management configuration for Apple devices, reorganizing setup experience, bootstrap package, and device configuration field organization. * Updated filter terminology and query parameters throughout device management interfaces, improving how users filter and navigate Apple device settings. * Enhanced configuration field naming conventions for better clarity and maintainability across device management features. <!-- end of auto-generated comment: release notes by coderabbit.ai --> # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually --- Manual Test Plan Prerequisites - Fleet server with MDM enabled (macOS at minimum) - At least one macOS host enrolled in Fleet MDM - A team configured with setup experience settings --- 1. Manage Hosts — Filters - [X] macOS settings filter: - Go to Hosts > Manage Hosts - Filter by macOS settings status (e.g. Pending, Verified, Failed) - Verify the filter applies and hosts list updates - Check that the URL contains apple_settings=<status> - Copy the URL, paste it in a new tab — verify the filter is still applied - Manually edit the URL to use macos_settings=<status> instead — verify it still works (backward compat) - Clear the filter pill — verify both apple_settings and macos_settings are removed from the URL - [X] Bootstrap package filter: - Filter by bootstrap package status - Verify the URL contains macos_bootstrap_package=<status> - Manually edit the URL to use bootstrap_package=<status> — verify it still works - Clear the filter pill — verify both params are removed --- 2. Setup Experience (Controls Page) - [X] Bootstrap package: - Go to Controls > Setup experience for a team - Upload a bootstrap package — verify it appears in the table - Toggle the "manual agent install" advanced option on/off — verify it saves - Delete the bootstrap package — verify it's removed - In the bootstrap package table, click "View all hosts" link for a status row — verify it navigates to Manage Hosts with macos_bootstrap_package in the URL - [X] End user authentication: - Toggle end user authentication on/off for a team and for "No team" - Verify the toggle reflects the saved state after page reload - [X] Setup assistant: - Upload a setup assistant profile - Verify the "release device manually" toggle works for both a team and "No team" - [X] Install software: - Verify the "require all software" checkbox reflects the correct saved state for both team and "No team" |
||
|
|
82c3983939 |
Bump github.com/antchfx/xpath from 1.2.2 to 1.3.6 (#42633)
Bumps [github.com/antchfx/xpath](https://github.com/antchfx/xpath) from 1.2.2 to 1.3.6. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/antchfx/xpath/releases">github.com/antchfx/xpath's releases</a>.</em></p> <blockquote> <h2>v1.3.6</h2> <p>Merged PR:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/120">#120</a>(<a href="https://github.com/mislav"><code>@mislav</code></a>) - Fix <code>last()</code> predicate on grouped expr.</li> </ul> <p>Fixed:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/121">#121</a></li> </ul> <h2>Release v1.3.5</h2> <p>Merged PR:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/117">#117</a>(<a href="https://github.com/mislav"><code>@mislav</code></a>)- fix <code>ancestor::</code> axes with position predicate.</li> </ul> <p>Fixed:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/113">#113</a> - (fix <code>string()</code> function)</li> </ul> <h2>v1.3.4</h2> <p>Merged PR:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/107">#107</a>(<a href="https://github.com/Mrflatt"><code>@Mrflatt</code></a>) - supports Regexp feature in <code>replace()</code> function</li> <li><a href="https://redirect.github.com/antchfx/xpath/issues/111">#111</a>(<a href="https://github.com/wjc4"><code>@wjc4</code></a>) - Improve <code>getHashCode</code> performance</li> </ul> <p>Fixed:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/109">#109</a></li> </ul> <h2>v1.3.3</h2> <p>fix non-English predicate query <a href="https://redirect.github.com/antchfx/xpath/issues/106">#106</a></p> <h2>v1.3.2</h2> <p>New Features:</p> <ul> <li>Supports Unicode chars for Non-English (PR <a href="https://redirect.github.com/antchfx/xpath/issues/100">#100</a>)</li> </ul> <p>Bug Fixed:</p> <ul> <li><a href="https://redirect.github.com/antchfx/xpath/issues/101">#101</a></li> <li><a href="https://redirect.github.com/antchfx/xpath/issues/102">#102</a></li> <li><a href="https://redirect.github.com/antchfx/xpath/issues/104">#104</a></li> </ul> <h2>v1.3.1</h2> <ul> <li>Merged PR <a href="https://redirect.github.com/antchfx/xpath/issues/97">#97</a>.</li> <li>Allows node-set numeric operator <code>+</code>, <code>-</code>, <code>mod()</code>.<a href="https://github.com/antchfx/xpath/commit/4b4638b370e898a9d10709464b8cd460b7dcfd0c">https://github.com/antchfx/xpath/commit/4b4638b370e898a9d10709464b8cd460b7dcfd0c</a></li> <li><a href="https://redirect.github.com/antchfx/xpath/issues/98">#98</a>, Remove the duplicate element filter <a href="https://github.com/antchfx/xpath/commit/5481aef473ee298d297387f5b69e2768df09e0c4">https://github.com/antchfx/xpath/commit/5481aef473ee298d297387f5b69e2768df09e0c4</a></li> </ul> <h2>v1.3.0</h2> <ul> <li>fixes <a href="https://redirect.github.com/antchfx/xpath/issues/93">#93</a></li> </ul> <h3>New features:</h3> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/antchfx/xpath/commit/afd4762cc342af56345a3fb4002a59281fcab494"><code>afd4762</code></a> fix <a href="https://redirect.github.com/antchfx/xpath/issues/121">#121</a></li> <li><a href="https://github.com/antchfx/xpath/commit/a8ced8f559cd68fc4aedfc87f21599d1190c0852"><code>a8ced8f</code></a> Merge PR <a href="https://redirect.github.com/antchfx/xpath/issues/120">#120</a></li> <li><a href="https://github.com/antchfx/xpath/commit/c92c3ebebbdd67f715161810f97ecfbcaa47921e"><code>c92c3eb</code></a> Fix last() predicate on grouped expressions</li> <li><a href="https://github.com/antchfx/xpath/commit/3cbab9750ea36cbae6f967ebbf29b9eda0e841bf"><code>3cbab97</code></a> Merge PR <a href="https://redirect.github.com/antchfx/xpath/issues/119">#119</a></li> <li><a href="https://github.com/antchfx/xpath/commit/02c01b0b4051e7edd1bf40f3d595cc9143936aaa"><code>02c01b0</code></a> Fix chained predicates on ancestor axis</li> <li><a href="https://github.com/antchfx/xpath/commit/511abd57bc74e9644fe27f4e52b559065e686e92"><code>511abd5</code></a> Merge PR <a href="https://redirect.github.com/antchfx/xpath/issues/117">#117</a></li> <li><a href="https://github.com/antchfx/xpath/commit/060b15493444a0e6c5a232022516e434818f7391"><code>060b154</code></a> Fix positional predicate for the "ancestor" axis</li> <li><a href="https://github.com/antchfx/xpath/commit/8d50c252d867285812177ffd3ff0924104ffb1eb"><code>8d50c25</code></a> fix <a href="https://redirect.github.com/antchfx/xpath/issues/112">#112</a>,<a href="https://redirect.github.com/antchfx/xpath/issues/113">#113</a></li> <li><a href="https://github.com/antchfx/xpath/commit/b9e198da9fb170a229c9c7e27d52e1a350636f4c"><code>b9e198d</code></a> Merge PR <a href="https://redirect.github.com/antchfx/xpath/issues/111">#111</a></li> <li><a href="https://github.com/antchfx/xpath/commit/fcb882bece30fe7d4d8f5069fed13f95a726e62f"><code>fcb882b</code></a> improve getHashCode by removing fmt.Sprintf</li> <li>Additional commits viewable in <a href="https://github.com/antchfx/xpath/compare/v1.2.2...v1.3.6">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fleetdm/fleet/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
121625638f |
/enroll page: Update copy (#42602)
- We use "BYO mobile" instead of "corporate mobile": https://docs.google.com/document/d/1aVZ_eAiUjq1pdltR5ckwcbOXKB0DMzmboWZlegqJXDk/edit?tab=t.0 - Decided to just go with "mobile" because that's more familiar to end users - Context: https://fleetdm.slack.com/archives/C03C41L5YEL/p1774377975564699 |
||
|
|
c2a9b83510 |
Lock/wipe guide (#42601)
Fleet uses EACS |
||
|
|
c8cb7bfa2a |
Move renew abm token instructions to guide (#42589)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Related to https://github.com/fleetdm/fleet/issues/42512 --------- Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com> |
||
|
|
0b4e5cdc89 |
Fix copy/paste on schema (#42643)
Fixes a bug introduced in https://github.com/fleetdm/fleet/pull/42569/changes |
||
|
|
d8588ed790 |
Bump macadmins version and add macos_thermal_pressure and macos_soc_power tables (#42569)
**Related issue:** Resolves #42530 - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## fleetd/orbit/Fleet Desktop - [X] Verified compatibility with the latest released version of Fleet (see [Must rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md)) - [X] If the change applies to only one platform, confirmed that `runtime.GOOS` is used as needed to isolate changes - [X] Verified that fleetd runs on macOS, Linux and Windows - [X] Verified auto-update works from the released version of component to the new version (see [tools/tuf/test](../tools/tuf/test/README.md)) |
||
|
|
7db99c7801 |
Fix test-packaging.yml action (#42570)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42573 Fixes failing test by replacing no-longer-supported `--no-quarantine` option with manually turning off quarantine for Wine. Successful run here: https://github.com/fleetdm/fleet/actions/runs/23661332211 --------- Co-authored-by: Allen Houchins <allenhouchins@mac.com> |
||
|
|
3793777c8d |
Update Fleet-maintained apps (#42636)
Automated ingestion of latest Fleet-maintained app data. Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com> |
||
|
|
04471cef6a |
Update Fleet-maintained apps (#42627)
Automated ingestion of latest Fleet-maintained app data. Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com> |
||
|
|
fb975a7de7 |
Add warning banner for Android web apps requiring Google Chrome (#42598)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42047 # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [x] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: |
||
|
|
9bfef5dec3 |
Fleet UI: Remove incorrect copy (#42586)
## Issue Closes #40683 ## Description - Removed from 2 modals that were rendering it ## Testing - [x] Added/updated automated tests - [x] QA'd all new/changed functionality manually |
||
|
|
f4a2e3aac8 |
Update marketing handbook: remove middle initial from Irena Reedy's name (#42616)
## Summary - Remove middle initial "E." from Irena Reedy's name in the Marketing handbook Team table Built for [Irena Reedy](https://fleetdm.slack.com/archives/D0APYC9R9SL/p1774663433994189) by [Kilo for Slack](https://kilo.ai/features/slack-integration) Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com> |
||
|
|
1c9ba1a514 |
Bump path-to-regexp from 8.3.0 to 8.4.0 in /tools/fleet-slackbot (#42623)
Bumps [path-to-regexp](https://github.com/pillarjs/path-to-regexp) from 8.3.0 to 8.4.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/pillarjs/path-to-regexp/releases">path-to-regexp's releases</a>.</em></p> <blockquote> <h2>8.4.0</h2> <p><strong>Important</strong></p> <ul> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2026-4926">CVE-2026-4926</a> (<a href="https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-j3q9-mxjg-w52f">GHSA-j3q9-mxjg-w52f</a>)</li> <li>Fix <a href="https://www.cve.org/CVERecord?id=CVE-2026-4923">CVE-2026-4923</a> (<a href="https://github.com/pillarjs/path-to-regexp/security/advisories/GHSA-27v5-c462-wpq7">GHSA-27v5-c462-wpq7</a>)</li> </ul> <p><strong>Fixed</strong></p> <ul> <li>Restricts wildcard backtracking when using more than 1 in a path (<a href="https://redirect.github.com/pillarjs/path-to-regexp/pull/421">pillarjs/path-to-regexp#421</a>)</li> </ul> <p><strong>Changed</strong></p> <ul> <li>Dedupes regex prefixes (<a href="https://redirect.github.com/pillarjs/path-to-regexp/pull/422">pillarjs/path-to-regexp#422</a>) <ul> <li>This will result in shorter regular expressions for some cases using optional groups</li> </ul> </li> <li>Rejects large optional route combinations (<a href="https://redirect.github.com/pillarjs/path-to-regexp/pull/424">pillarjs/path-to-regexp#424</a>) <ul> <li>When using groups such as <code>/users{/delete}</code> it will restrict the number of generated combinations to < 256, equivalent to 8 top-level optional groups and unlikely to occur in a real world application, but avoids exploding the regex size for applications that accept user created routes</li> </ul> </li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/34cb451ddaeea4783a2fe60579ffb3e4ccfc73a7"><code>34cb451</code></a> 8.4.0</li> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/22a967901afc8b2b42eefe456faa7b6773dcc415"><code>22a9679</code></a> Reject large optional route combinations (<a href="https://redirect.github.com/pillarjs/path-to-regexp/issues/424">#424</a>)</li> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/8881a88930cf96ebaa00412a8e87cdd601bb3f3d"><code>8881a88</code></a> Byte optimization (<a href="https://redirect.github.com/pillarjs/path-to-regexp/issues/423">#423</a>)</li> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/43669ac637fe70fad33693d145a74d98179152ce"><code>43669ac</code></a> Dedupe regex prefixes (<a href="https://redirect.github.com/pillarjs/path-to-regexp/issues/422">#422</a>)</li> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/48646547da685c1ccb76a95fe23373975a91e200"><code>4864654</code></a> Restrict repeated wildcard backtracking (<a href="https://redirect.github.com/pillarjs/path-to-regexp/issues/421">#421</a>)</li> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/05a5a973702a863fb69415294503d13cb9d18b20"><code>05a5a97</code></a> Remove dependabot config (<a href="https://redirect.github.com/pillarjs/path-to-regexp/issues/404">#404</a>)</li> <li><a href="https://github.com/pillarjs/path-to-regexp/commit/5b635cd1bd1d6d7ed6023d8834ae6e6a1e22461f"><code>5b635cd</code></a> Remove <code>package-lock.json</code> (<a href="https://redirect.github.com/pillarjs/path-to-regexp/issues/407">#407</a>)</li> <li>See full diff in <a href="https://github.com/pillarjs/path-to-regexp/compare/v8.3.0...v8.4.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/fleetdm/fleet/network/alerts). </details> Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> |
||
|
|
181bc1b778 |
Update marketing handbook: remove middle initial from Irena Reedy (#42618)
## Summary Removes middle initial 'E.' from Irena Reedy's name in the marketing handbook Team table. Built for [Irena Reedy](https://fleetdm.slack.com/archives/D0APYC9R9SL/p1774664048458209) by [Kilo for Slack](https://kilo.ai/features/slack-integration) Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com> |
||
|
|
e728fd3d5e |
Add GCPW as a Windows FMA (#42619)
This pull request adds support for the "Google Credential Provider for Windows" application to the maintained apps system, including its metadata, installation logic, and user interface icon. The changes ensure that the app is properly recognized, categorized, and visually represented in the frontend. **New application support:** - Added metadata for "Google Credential Provider for Windows" in `winget` input, including identifiers, architecture, installer type, and default category. - Added output configuration for the app, specifying version, detection query, installer/uninstaller scripts, installer URL, and SHA256 hash. - Registered the app in the main `apps.json` output with a description and platform information. **Frontend/UI updates:** - Added a new React SVG icon component for "Google Credential Provider for Windows" in the software page. - Registered the new icon in the icons index and mapped the app name to the icon in the `SOFTWARE_NAME_TO_ICON_MAP`. [[1]](diffhunk://#diff-628095892e1d16090be1db6cc1a5c9cebc65248c32a8b1312385394818f2907bR13) [[2]](diffhunk://#diff-628095892e1d16090be1db6cc1a5c9cebc65248c32a8b1312385394818f2907bR317) |
||
|
|
302ad3df7a |
Insert hmwp and windows command entries at once (#42566)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42544 This inserts the commands into the windows command queue in batches along with the host_mdm_windows_profile entries. corresponding host profile entries are inserted in the same batch as the command queue entry so that if a host checks in very quickly after, its profile doesn't get overwritten by the reconciler during the "update" pass at the end. This isn't easily reproducible locally, but will run a loadtest as soon as possible # Checklist for submitter If some of the following don't apply, delete the relevant line. - [x] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [x] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [x] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [x] Added/updated automated tests - [x] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [x] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: - [x] Confirmed that the fix is not expected to adversely impact load test results - [x] Alerted the release DRI if additional load testing is needed <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **Chores** * Optimized Windows MDM device profile management with more efficient batch processing for command delivery and profile updates. <!-- end of auto-generated comment: release notes by coderabbit.ai --> |
||
|
|
579801bdfb |
GitOps docs: Clarify how to use labels_include_any with policies (#42612)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves https://github.com/fleetdm/fleet/issues/38113 |
||
|
|
0414f30d24 |
Website: Update case study links on customers page. (#42571)
Closes: https://github.com/fleetdm/fleet/issues/42043 Changes: - Updated the customers page to only show 12 case study links by default, and to include a "Load more" button that shows 12 more case study card links when clicked. - Renamed the files for the customers page (testimonials » customers) |
||
|
|
73d9c4f85a |
Typo Fix "Bug" to "Bugs" (#42460)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves # # Checklist for submitter If some of the following don't apply, delete the relevant line. - [ ] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. - [ ] Input data is properly validated, `SELECT *` is avoided, SQL injection is prevented (using placeholders for values in statements), JS inline code is prevented especially for url redirects, and untrusted data interpolated into shell scripts/commands is validated against shell metacharacters. - [ ] If paths of existing endpoints are modified without backwards compatibility, checked the frontend/CLI for any necessary changes ## Testing - [ ] Added/updated automated tests - [ ] Where appropriate, [automated tests simulate multiple hosts and test for host isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing) (updates to one hosts's records do not affect another) - [ ] QA'd all new/changed functionality manually For unreleased bug fixes in a release candidate, one of: - [ ] Confirmed that the fix is not expected to adversely impact load test results - [ ] Alerted the release DRI if additional load testing is needed ## Database migrations - [ ] Checked schema for all modified table for columns that will auto-update timestamps during migration. - [ ] Confirmed that updating the timestamps is acceptable, and will not cause unwanted side effects. - [ ] Ensured the correct collation is explicitly set for character columns (`COLLATE utf8mb4_unicode_ci`). ## New Fleet configuration settings - [ ] Setting(s) is/are explicitly excluded from GitOps If you didn't check the box above, follow this checklist for GitOps-enabled settings: - [ ] Verified that the setting is exported via `fleetctl generate-gitops` - [ ] Verified the setting is documented in a separate PR to [the GitOps documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485) - [ ] Verified that the setting is cleared on the server if it is not supplied in a YAML file (or that it is documented as being optional) - [ ] Verified that any relevant UI is disabled when GitOps mode is enabled ## fleetd/orbit/Fleet Desktop - [ ] Verified compatibility with the latest released version of Fleet (see [Must rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md)) - [ ] If the change applies to only one platform, confirmed that `runtime.GOOS` is used as needed to isolate changes - [ ] Verified that fleetd runs on macOS, Linux and Windows - [ ] Verified auto-update works from the released version of component to the new version (see [tools/tuf/test](../tools/tuf/test/README.md)) |
||
|
|
581cae309a |
Update how google drive fma version is created (#42270)
**Related issue:** Resolves #40751 |
||
|
|
f55eb085f0 |
make sure to reset fleet challenge when resending android cert (#42550)
**Related issue:** Resolves #41542 |
||
|
|
6598b608b7 |
Enforce GitOps exceptions (#42191)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or remove if NA --> **Related issue:** Resolves #42180 <!-- This is an auto-generated comment: release notes by coderabbit.ai --> ## Summary by CodeRabbit * **New Features** * Enhanced GitOps exception handling for labels, secrets, and software with clearer enforcement and omission semantics. * Server-side prefetch of team software so omitted team software can preserve existing installers during validation. * Presence flags track whether top-level keys (labels, secrets, software) were provided versus omitted. * **Behavior Changes** * Omitted vs empty sections are now distinguished: omission can mean “no-op” or “delete-all” depending on exception settings. * GitOps YAML can define and manage labels directly; validations now reject YAML that includes keys marked as excepted. <!-- end of auto-generated comment: release notes by coderabbit.ai --> # Checklist for submitter If some of the following don't apply, delete the relevant line. - [X] Changes file added for user-visible changes in `changes/`, `orbit/changes/` or `ee/fleetd-chrome/changes`. See [Changes files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files) for more information. ## Testing - [X] Added/updated automated tests - [X] QA'd all new/changed functionality manually * **Labels** - [ ] Validated that with label exceptions off, omitting `labels:` key from default.yml clears all global labels - [ ] Validated that with label exceptions off, omitting `labels:` key from a fleet .yml clears all labels for that fleet - [ ] Validated that with label exceptions off, setting empty `labels:` key from default.yml clears all global labels - [ ] Validated that with label exceptions off, setting empty `labels:` key from a fleet .yml clears all labels for that fleet - [ ] Validated that with label exceptions on, omitting `labels:` key from default .yml leaves existing global labels as-is - [ ] Validated that with label exceptions on, omitting `labels:` key from a fleet .yml leaves existing labels as-is - [ ] Validated that with label exceptions on, setting `labels:` key on default .yml generates an error - [ ] Validated that with label exceptions on, setting `labels:` key on a fleet .yml generates an error - [ ] Validated that with label exceptions on, a policy using `labels_include_any` referencing an existing label succeeds without `labels:` key - [ ] Validated that with label exceptions on, a query using `labels_include_any` referencing an existing label succeeds without `labels:` key - [ ] Validated that with label exceptions on, an MDM profile using `labels_include_any` referencing an existing label succeeds without `labels:` key - [ ] Validated that with label exceptions on, a software package using `labels_include_any` referencing an existing label succeeds without `labels:` key (requires software exceptions off) - [ ] Validated that with label exceptions on, an app store app using `labels_include_any` referencing an existing label succeeds without `labels:` key (requires software exceptions off) - [ ] Validated that with label exceptions on, a fleet maintained app using `labels_include_any` referencing an existing label succeeds without `labels:` key (requires software exceptions off) * **Secrets** - [ ] Validated that with secrets exceptions off, omitting `secrets:` key from default.yml clears all global secrets - [ ] Validated that with secrets exceptions off, omitting `secrets:` key from a fleet .yml clears all secrets for that fleet - [ ] Validated that with secrets exceptions on, omitting `secrets:` key from default .yml leaves existing global secrets as-is - [ ] Validated that with secrets exceptions on, omitting `secrets:` key from a fleet .yml leaves existing secrets as-is - [ ] Validated that with secrets exceptions on, setting `secrets:` key on default .yml generates an error - [ ] Validated that with secrets exceptions on, setting `secrets:` key on a fleet .yml generates an error * **Software** - [ ] Validated that with software exceptions off, omitting `software:` key from no-team.yml/unassigned.yml clears all software for "no team" - [ ] Validated that with software exceptions off, omitting `software:` key from a fleet .yml clears all software for that fleet - [ ] Validated that with software exceptions off, setting empty `software:` key on a fleet .yml clears all software for that fleet - [ ] Validated that with software exceptions off, setting empty `software:` key on no-team.yml/unassigned.yml clears all software for "no team - [ ] Validated that with software exceptions on, omitting `software:` key from a fleet .yml leaves existing software as-is - [ ] Validated that with software exceptions on, setting `software:` key on a fleet .yml generates an error - [ ] Validated that with software exceptions on, omitting `software:` key from no-team.yml/unassigned.yml leaves existing software as-is for "no team" - [ ] Validated that with software exceptions on, setting `software:` key on no-team.yml/unassigned.yml generates an error - [ ] Validated that with software exceptions on, a policy using `install_software.hash_sha256` referencing an existing package succeeds without `software:` key - [ ] Validated that with software exceptions on, a policy using `install_software.app_store_id` referencing an existing VPP app succeeds without `software:` key - [ ] Validated that with software exceptions on, a patch policy using `fleet_maintained_app_slug` referencing an existing FMA succeeds without `software:` key - [ ] Validated that with software exceptions on, `setup_experience.software` referencing existing software succeeds without `software:` key (server-side validation fallback) - [ ] Validated that with software exceptions on, omitting `software:` from no-team.yml/unassigned.yml preserves existing no-team software - [ ] Validated that with software exceptions on, a policy in no-team.yml/unassigned.yml using `install_software.hash_sha256` referencing existing no-team software succeeds without `software:` key For unreleased bug fixes in a release candidate, one of: - [X] Confirmed that the fix is not expected to adversely impact load test results I don't think so. There is a bit of overhead when this feature is used since we have to fetch software from the server, but it would be done in a specific test, so even if there is an impact it should affect existing load testing, only new, specific tests. |