Commit Graph
25686 Commits
Author SHA1 Message Date
fleet-releaseandallenhouchins 49876736ec Update Fleet-maintained apps (#48383)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated macOS installer metadata for Antigravity, ChatGPT Desktop,
DevKnife, jamovi, Marked, Netron, OpenAudible, and Workflowy to newer
versions.
* Refreshed download links and checksums so installs and updates use the
latest available release files.
* Improved ChatGPT Desktop cleanup behavior during removal for a more
complete uninstall.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-27 22:00:36 -05:00
fleet-releaseandallenhouchins 5b09386b7e Update Fleet-maintained apps (#48377)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Updated installer metadata for multiple maintained apps on macOS and
Windows, including Claude, Clop, Codex, LookAway, Ocenaudio, Ollama,
Shotcut, Spyder, Teleport Connect, Teleport Suite, and Zen Browser.
* Added newer release versions for several apps, so package listings now
reflect the latest available downloads.

* **Bug Fixes**
* Refreshed download links and checksum values to match the updated
installer packages.
* Improved version checks so installed apps are compared against the
correct current release.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-27 07:34:25 -05:00
Allen Houchins 1b4fd9132e Add allenhouchins as an articles maintainer (#48361) 2026-06-26 23:46:37 -04:00
kitzy 79052c442f Add article: AI isn't just replacing jobs, it's rewriting the job description (#48372)
Context:
https://fleetdm.slack.com/archives/C01ALP02RB5/p1782267841317159
2026-06-26 22:15:58 -04:00
Allen Houchins 8d9c0e4fd2 Style inline article CTA button links (#48364)
Add targeted styling for `p a[purpose='cta-button']` in basic article
pages so markdown-authored CTA links render as branded Fleet buttons. It
reuses the existing `.cta-button()` mixin while overriding layout
details (inline-flex, fit-content width, padding, spacing, and hover
text decoration) so the button sizes to its label and fits article flow.



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Improved the appearance of inline “Green Fleet” call-to-action links
in article content.
* Buttons now display inline, size more naturally with the text, and
have updated spacing for better readability.
* Hover behavior has been kept clean by preventing unwanted text
decoration.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 20:36:14 -05:00
fleet-releaseandallenhouchins 59dc95596d Update Fleet-maintained apps (#48371)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated maintained app definitions so installs and update checks
recognize the latest releases for Arc, Brave, Claude, Dockside, eM
Client, Fantastical, Figma, Funter, Gather, Microsoft Edge, Ocenaudio,
Ollama, P4V, Quip, R for Windows, Tuple, and Warp.
* Refreshed download links and package checksums to match the newest
installers, improving update reliability across macOS and Windows.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-26 20:33:00 -05:00
Irena Reedy d0e05ffd76 Update medical-research-institution.md (#44779) 2026-06-26 17:42:44 -07:00
Irena Reedy 523ddd05e1 Update digital-bank.md (#44780) 2026-06-26 17:42:31 -07:00
Irena Reedy 8aa00831c1 Update cloud-infrastructure-company.md (#44782) 2026-06-26 17:42:10 -07:00
Irena Reedy 158b501a9f Update it-platform-provider.md (#44783) 2026-06-26 17:42:02 -07:00
Irena ReedyandMike Thomas 226aa35713 Update computational-research-company.md (#44784)
Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
2026-06-26 17:41:50 -07:00
29c57d8f25 Create schnellere-schwachstellenbehebung-verlangt-enge-zusammenarbeit… (#45675)
German version

---------

Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
Co-authored-by: Henry Stamerjohann <headmin@users.noreply.github.com>
Co-authored-by: Eric <eashaw@sailsjs.com>
2026-06-26 17:41:11 -07:00
Irena Reedy 2a6cdeadda Update financial-services-platform.md (#44786) 2026-06-26 17:33:39 -07:00
Eric adef9c7c6c Website: Update error handling in android proxy endpoints (#48240)
Related to https://github.com/fleetdm/fleet/issues/48114
Related to https://github.com/fleetdm/fleet/issues/47386

Changes:
- Added a new exit to seven Android proxy endpoints `managementApiError`
that is used when the Android management API responds with a transient
5xx error (502, 503, and 504).

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved handling of temporary Android Management API failures by
returning a dedicated, retry-friendly error outcome for transient 5xx
responses (502/503/504).
* Updated enrollment, web app creation, device deletion/modification,
command issuance, policy changes, and enterprise app policy updates to
surface clearer, more specific failure messages instead of generic
errors.
  * Makes it easier to identify issues that may resolve on retry.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 17:26:22 -05:00
Luke Heath a3d638ba9e Fix dogfood-deploy DOCKER_IMAGE guidance (tags + digest) and make geolite2 tag digest-safe (#48233) 2026-06-26 15:14:26 -07:00
Andrew Mellor 529a592ad6 Clarify NO_PROXY usage in proxy configuration (#48359)
Added after support request looking for clarity on proxy configuration.

- [x] QA'd all new/changed functionality manually
2026-06-26 17:11:53 -05:00
fleet-releaseandallenhouchins 07147a14f8 Update Fleet-maintained apps (#48365)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated installer metadata for Brave Browser on macOS, Granola on
Windows, Linear on Windows, and Remote Desktop Manager on Windows.
* Refreshed version checks, download links, and package checksums so the
latest releases are detected and installed correctly.
  * Kept existing install/uninstall behavior unchanged.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-26 16:21:21 -05:00
Allen Houchins 404e65525c Remove duplicate text from managed migration article (#48363)
Removed unnecessary text from the article.
2026-06-26 16:20:22 -05:00
Victor Lyuboslavsky a019cfb8f4 Compress windows_mdm_responses envelopes on the Windows MDM hot path (#48320)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #44188 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [x] Added/updated automated tests

- [x] QA'd all new/changed functionality manually

## Database migrations

- [x] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [x] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Windows MDM check-in response payloads are now stored gzip-compressed
in the database to reduce write pressure for large SyncML data.
* When fetching results, responses are automatically decompressed so the
original content is returned to clients.
* Empty payloads are preserved, and stored data is validated to ensure
only valid gzip content is accepted.
* **Database / Migration**
* Added a migration and backfill to move existing records from
uncompressed storage to the new compressed column format.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 22:03:01 +01:00
Allen Houchins 2c1396a141 Refine Managed Migration Assistant description (#48360)
Updated text for clarity and conciseness regarding Managed Migration
Assistant in macOS 26.4.
2026-06-26 15:24:08 -05:00
Jordan Montgomery b438893bc2 Do not block further wipe commands on inactive existing entry (#48358)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #45931

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved device lock handling so only active pending lock commands are
treated as valid.
* Fixed stale lock state cases where an old lock reference no longer
blocks a new lock request.
* When a prior lock command is no longer deliverable, a new lock command
is now issued and tracked correctly.
* Updated coverage to verify lock status transitions and replacement
behavior in these edge cases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 15:58:42 -04:00
Jordan Montgomery a764e5d595 Parse both date formats while parsing macos profiles for verification (#48328)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #45947

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

We do not know how to repro the customer issue and I spent about 6 hours
across a couple of days throwing everything I could at it so testing was
limited to macos profile verification smoke testing and unit tests to
confirm the time we see from customer logs and queries is now supported

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed an issue where macOS configuration profiles could get stuck in
“Verifying” when the reported install date uses a 12-hour time format.
* Improved parsing of locale-formatted install dates, including handling
of special spacing characters found on newer macOS versions.
* Enhanced validation so unsupported or empty install date formats
return clearer error messages.


<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 15:58:31 -04:00
George Karr 0f439f9593 Auto-update, pin, and rollback Fleet-maintained apps via UI and GitOps (#48293)
**Related issue:** Resolves #38504

  **Constituent PRs (merged into this feature branch):**

- #47682 — Fleet UI: APRF Software title details page Library/Inventory
layout
- #47808 — Extend update software installer API to support FMA version
pinning
  - #47944 — Fleet UI: APRF library item accordion component
  - #48081 — Versions modal, multi-row Library, pinned state
  - #48098 — Add `pinned_version` to `edited_software` activity
  - #48123 — Auto-update FMA cron
  - #48144 — Download a newly-published FMA version when pinned to it

  # Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or
`ee/fleetd-chrome/changes`. See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

  ## Testing

  - [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates
  to one hosts's records do not affect another)

  - [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added Fleet-maintained app version pinning (Latest, exact, and major)
via a new Versions modal.
* Introduced premium auto-updates for maintained apps with pin-aware
promotion and rollback-safe caching.
  * Added expandable library version rows and a Policies modal.
* **Bug Fixes**
* Improved pin handling, cache/manifest hydration, and safer update
behavior on per-app failures and deduplication.
* **UI/UX**
* Refreshed the Software title details experience with new
accordion/list patterns, redesigned details widget/tooltips, and updated
installer presentation.
* **Documentation**
* Expanded Storybook component/page coverage and adjusted Storybook
canvas padding.
* **Tests**
* Added/updated unit and integration tests for pinning, auto-update
flows, and new modal/UI behavior.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 14:42:23 -05:00
fleet-releaseandallenhouchins 1e689710fb Update Fleet-maintained apps (#48357)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Updated macOS installer details for Vimcal to the latest available
release, including version info, download link, and checksum.
* Adjusted WhatsApp’s patched eligibility check to recognize the newer
app version.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-26 14:04:17 -05:00
fleet-releaseandallenhouchins 7b833d4eff Update Fleet-maintained apps (#48353)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Updates**
* Refreshed macOS package metadata for Linear, Memory Cleaner, and
NetNewsWire to their latest available versions.
* Updated installer links and checksum values so the correct app builds
are delivered.
  * Adjusted version checks to match the newer releases.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-26 13:40:11 -05:00
Carlo ce1f85b9b8 Use active custom script if available (#48350)
**Related issue:** Resolves #48301

When the auto-update cron downloads a new Fleet-maintained app version,
it now carries forward the previously-active install/uninstall scripts
when they were customized (e.g. via GitOps), instead of overwriting them
with the manifest defaults. Customization is detected per-script by
comparing the active scripts against the manifest (the uninstall script
is compared against the manifest template substituted with the active
version's package IDs, since it's version-specific). When the active
scripts match the manifest, the new version's manifest scripts are used
as before.

  # Checklist for submitter

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

  ## Testing

  - [x] Added/updated automated tests
  - [x] QA'd all new/changed functionality manually
2026-06-26 14:38:42 -04:00
Eric 8cd9f395ef Website: update position of homepage hero background (#48354)
Changes:
- Updated the position of the homepage hero background to prevent issues
with text flowing outside of the clouds in the image on large screens

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Adjusted the homepage hero background alignment on desktop for a
better visual layout.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 13:34:12 -05:00
Luke Heath 2b50257de9 Bump golang.org/x/image to v0.42.0 (CVE-2026-33813) (#48345) 2026-06-26 11:24:16 -07:00
Andrew Mellor 5d58c5f5ff fix: remove as a custom MDM command text from MDM command list view (#48307)
**Related issue:** Resolves #48297

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [x] QA'd all new/changed functionality manually





<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Corrected MDM command labeling in host details so only commands run
through the custom MDM command API appear as “custom MDM command.”
* Improved command details display for MDM items to show the appropriate
label instead of applying the custom label broadly.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 19:13:50 +01:00
Andrey Kizimenko 54c598ecad Left-align Advanced options toggle in vuln exposure chart filter (#48348)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Visual polish for the unreleased Vulnerability
Exposure chart filter (part of #47674 / #44746)

Left-aligns the "Advanced options" reveal toggle in the chart filter
modal's Software tab so it matches the design. Previously the toggle
stretched to the full width of the column-flex container and its content
was centered; this adds `align-self: flex-start` so it hugs the left
edge.

## Before / After
- **Before:** "Advanced options" toggle centered in the panel.
<img width="400" alt="image"
src="https://github.com/user-attachments/assets/b4cbe5fc-832e-415b-af31-bfd3ca14085d"
/>

- **After:** Left-aligned, matching the Figma design.
<img width="400" alt="CleanShot 2026-06-26 at 12 20 50@2x"
src="https://github.com/user-attachments/assets/6204bc50-eb1a-4abc-bee6-45f6bb161bb2"
/>

# Checklist for submitter

- [x] QA'd all new/changed functionality manually

<!-- Frontend-only CSS alignment fix on an unreleased feature —
DB/config/orbit/changes-file sections below are N/A and removed per
template instructions. -->


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Adjusted the alignment of the “Advanced options” toggle in the
software filters panel for a cleaner layout.
* **Bug Fixes**
* Improved the positioning of the toggle button so it aligns
consistently within the filter section.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 13:06:44 -05:00
kitzy 0410131e11 Remove unnecessary nested folder (#48331) 2026-06-26 13:01:42 -05:00
fleet-releaseandallenhouchins 17f60996e1 Update Fleet-maintained apps (#48352)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated the Chatwise macOS app entry to version 26.6.0.
* Refreshed the download package and checksum to match the latest
installer.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-26 13:00:23 -05:00
0f6b60ef02 Update Fleet-maintained apps (#48347)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Updated version information, download links, and package checksums for
several managed apps, including Alcove, BetterTouchTool, draw.io,
Granola, Lens, Marked, Microsoft Edge, WeChat, and XnView MP.
* Added an update lock for VNC Viewer to keep its current package
version fixed.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
Co-authored-by: Allen Houchins <allenhouchins@mac.com>
2026-06-26 12:36:02 -05:00
Carlo d5afa45efd Pin-cleanup on FMA delete (#48333)
**Related issue:** Resolves #48309

Deleting a Fleet-maintained app from a team now also deletes its
`software_title_team_pins` row. Previously the pin survived the delete
(the FK cascades only on title deletion, and the title row outlives the
installer rows), so re-adding the app resurfaced a stale pin pointing at
a version no longer cached.

  # Checklist for submitter

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

  ## Testing

  - [x] Added/updated automated tests
  - [x] QA'd all new/changed functionality manually
2026-06-26 13:18:50 -04:00
Allen Houchins c672f68cc9 Enhance Managed Migration Assistant article with governance details (#48341)
Edit blog post
2026-06-26 12:06:28 -05:00
Juan Fernandez cbe36a217a Fix policy selection resetting pagination to first page
Fixes #47246

On the host details policies tab and the device user self-service
policies page, clicking a policy while on any page other than the first
reset the list back to page 1. To fix this, Memoize the data set so its
reference stays stable across re-renders that don't change the policies.
2026-06-26 13:03:40 -04:00
Carlo 0b6f8066db Return per-version filename in fleet_maintained_versions (#48335)
**Related issue:** Resolves #48334

The software title response now returns a per-version `filename` in
`fleet_maintained_versions`, and the Library version rows render each
version's own filename instead of the active installer's. Previously,
every cached-version row showed the active installer's filename because
the array didn't include one.

  # Checklist for submitter

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

  ## Testing

  - [x] Added/updated automated tests
  - [x] QA'd all new/changed functionality manually
2026-06-26 12:44:55 -04:00
Juan Fernandez 005bcdcf87 fleet-mcp: run multi-host live queries via ad-hoc campaign so observer_plus works
Resolves #46005 

Implement flow for ad-hoc distributed query campaign streamed over the
/api/v1/fleet/results/websocket endpoint, the same way the Fleet UI and
fleetctl run live queries.
2026-06-26 12:07:13 -04:00
Konstantin Sykulev 19caa5ce8c Fixing android tests (#48336)
https://github.com/fleetdm/fleet/actions/runs/28218912241/job/83595668272

`cmd/fleetctl/fleetctl TestGitOpsAndroidCertificatesAdd`
`cmd/fleetctl/fleetctl TestGitOpsAndroidCertificatesChange`
`cmd/fleetctl/fleetctl TestGitOpsAndroidCertificatesDeleteOne`

Panic triggered due to missing mock
```
created by net/http.(*Server).Serve in goroutine 1296276
	/opt/hostedtoolcache/go/1.26.4/x64/src/net/http/server.go:3464 +0x88a
    gitops_test.go:6099: 
        	Error Trace:	/home/runner/work/fleet/fleet/cmd/fleetctl/fleetctl/gitops_test.go:6099
        	Error:      	Received unexpected error:
        	            	applying Android certificates: POST /api/latest/fleet/spec/certificates: do request: Post "http://127.0.0.1:39447/api/latest/fleet/spec/certificates": EOF (API time: 4ms)
        	Test:       	TestGitOpsAndroidCertificatesDeleteOne
```

  ## Testing

  - [x] Added/updated automated tests
  - [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

## Summary by CodeRabbit

* **Tests**
* Updated the test mocks used for GitOps and fleetctl scenarios to
support certificate template variable updates.
* Prevents failures when certificate template variable setting is
invoked during test runs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 12:48:46 -03:00
Allen Houchins f8974bd8a4 Add article on Managed Migration Assistant (#48332)
Adds a comprehensive article explaining Apple's Managed Migration
Assistant in macOS 26.4, covering how it transforms Mac-to-Mac migration
from an uncontrolled user choice into declarative organizational policy.
Discusses governance, compliance, operational benefits, and how Fleet
can operationalize migration policies through version-controlled YAML.
2026-06-26 10:31:45 -05:00
fleet-releaseandallenhouchins 8a24da28ee Update Fleet-maintained apps (#48329)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Refreshed installer metadata for multiple Windows and macOS apps to
newer releases, including version checks, download links, and package
checksums.
* Updated several app entries such as Chrome, Cursor, Postman,
Bitwarden, Calibre, Zulip, and others to help keep install and upgrade
detection accurate.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-06-26 10:30:03 -05:00
Juan Fernandez 194f0cfb8f Fix SSO callback URLs doubling the subpath under a URL prefix
Fixes #46641

When Fleet runs under a subpath, server_url already includes that
subpath, so appending url_prefix again produced a doubled ACS callback
path (e.g. https://host/subpath/subpath/api/v1/fleet/sso/callback),
breaking SAML authentication for both login and MDM end user
authentication.

Drop url_prefix from the callback URL construction so the path is
appended directly to server_url, which is the full external base URL.
Fixes the same flaw in all five ACS-construction sites: login SSO
initiate and callback, and MDM SSO initiate plus both callback branches.
2026-06-26 10:40:55 -04:00
Juan Fernandez 8b737cc87c Fix duplicated URL prefix in transactional email links for subpath deployments
Fixes #46642

When Fleet is deployed under a subpath, server_url already carries that
subpath, so the email link base was being built as server_url +
url_prefix, duplicating the path (e.g.
https://host/subpath/subpath/login/reset) and producing 404 links.

Use server_url directly as the link base, matching how the rest of the
codebase already treats server_url as the full external base URL.
2026-06-26 10:40:26 -04:00
Jordan Montgomery 657ba985c3 Fix returned values on MDM command results endpoint (#48296)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

Fix tagging of hostnames on returned MDM command results so all returned
results have a hostname

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed an issue where some MDM command results could return without
hostnames.
* Improved result visibility so only hosts the caller is allowed to see
are included.
* Ensured team-scoped users see only their permitted results, while
global admins continue to see all available results.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 10:34:26 -04:00
Sharon Katz 7a419d6c3a Add exponential backoff to orbit config polling loop (#46674)
Closes #45627

Part 2 of #45553 -- see there for the full behavioral contract and
Oracle.

## Changes

- Integrated the shared `orbit/pkg/backoff` package (shipped in #45624)
into orbit's `ExecuteConfigReceivers` loop
- On error (5xx, network failure): polling interval doubles each failure
(30s, 60s, 120s, ...) capped at 5 minutes
- On success: resets immediately to normal 30s polling
- The inner `retry.Do` in `GetConfig` (transient retry within a single
tick) is unchanged

## Manual testing

### Automated tests

```
go test ./orbit/pkg/backoff/ -race -count=1   # 17 tests, 0 failures
go test ./client/ -count=1 -short              # client tests pass
```

### Build verification

```
go build ./orbit/cmd/orbit/     # compiles clean
go build ./orbit/cmd/desktop/   # compiles clean
```

### Dev environment testing

Built orbit from this branch and swapped it into a local dev setup
(`/opt/orbit/bin/orbit/macos/stable/orbit`). Server-side logs confirmed
that after the restart with the new binary, `/api/fleet/orbit/config`
requests stopped arriving at the fixed 30s cadence (old behavior),
consistent with backoff engaging on error responses. The `device_token`
endpoint (not covered by this PR) continued at its normal interval,
confirming the backoff is scoped to the config polling loop only.

Full end-to-end verification of the log messages (`backing off`,
`next_retry`, `exiting backoff`) should be done by QA with `sudo tail -f
/var/log/orbit/orbit.stderr.log`.

### QA manual test plan (cc @xpkoala)

**Setup:** Local Fleet server + orbit built from this branch (see build
steps above). Orbit logs are at `/var/log/orbit/orbit.stderr.log`
(requires `sudo`).

**Test 1 -- Backoff on server failure:**
1. Start Fleet server, verify orbit connects (config requests every ~30s
in server log)
2. Stop the Fleet server (`kill` the process or `docker stop` the
container)
3. Watch orbit logs: `sudo tail -f /var/log/orbit/orbit.stderr.log`
4. **Expected:** Log lines with `"running config receivers, backing
off"` and `next_retry` values increasing: ~60s, ~120s, ~240s, then
capping at ~5m (values include up to 10% random jitter)

**Test 2 -- Recovery resets to normal:**
1. While orbit is in backoff (from Test 1), restart the Fleet server
2. Wait for the next backoff tick to fire
3. **Expected:** Log line `"config receivers succeeded, exiting
backoff"` with `backoff_duration` showing how long the backoff lasted,
then polling resumes at normal 30s

**Test 3 -- Normal operation unchanged:**
1. With both server and orbit running healthy, watch orbit logs for ~2
minutes
2. **Expected:** No backoff-related log lines. Config polling stays at
30s intervals.

---

# Checklist for submitter

- [x] Changes file added for user-visible changes in `orbit/changes/`.
- [x] Input data is properly validated, no SQL changes, no JS changes.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops (backoff caps at 5 min).
- [x] Added/updated automated tests (existing backoff package tests
cover the mechanism).
- [ ] QA'd all new/changed functionality manually.

## fleetd/orbit/Fleet Desktop

- [x] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes (backoff is
platform-agnostic).
- [ ] Verified that fleetd runs on macOS, Linux and Windows.
- [ ] Verified auto-update works from the released version of component
to the new version.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Improvements**
* Config polling now implements exponential backoff on network/server
failures, gradually increasing retry intervals up to a 5-minute maximum
instead of fixed intervals.
* After a successful config poll, the retry schedule automatically
resets back to the normal update interval.
* **Tests**
* Added unit tests to verify backoff increases after repeated failures
and resets promptly after recovery.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 10:09:42 -04:00
kitzyandHenry Stamerjohann 4cfa31b118 Add guide for Managed Migration Assistant: Mac-to-Mac migration with Fleet (#48318)
Co-authored-by: Henry Stamerjohann <headmin@users.noreply.github.com>
2026-06-26 09:37:05 -04:00
Nico 040cefde93 Enable refetchOnWindowFocus and set refetchInterval to 5s when no report results are available (#48268)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #48192

- Deleted `refetchOnWindowFocus: false` so that users get fresh data if
they navigate away and come back to the report results page (IMHO this
should be the behavior across all Fleet's UI).
- Set a refetch interval of 5s when no report results are available.

^ is gated to the report bringing back results (i.e. `discard_data =
false` and `logging = snapshot`).

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [x] QA'd all new/changed functionality manually



https://github.com/user-attachments/assets/13513f37-8634-4c22-95cc-c0b2e9128058



https://github.com/user-attachments/assets/ae30640a-d0cb-4d93-a0f3-058650895959



https://github.com/user-attachments/assets/54a46634-fbca-4a7a-a75e-36b73370c9a0





<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Report results now refresh automatically when you return to the
browser window.
* Empty report results are checked again every 5 seconds until data
appears.

* **Bug Fixes**
* Improved handling of report caching settings so refresh behavior is
skipped when caching is disabled.
* The empty-state view now stays in sync with whether report caching is
available.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-06-26 09:51:29 -03:00
Rahul Raghunathan bd95ad8d70 Fix typo in Handbook - Marketing README (#48276)
fix the typo of appropriate

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [ ] Timeouts are implemented and retries are limited to avoid infinite
loops
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2026-06-26 13:32:04 +01:00
Juan Fernandez 71696f1c91 Fix spacing around icons and add missing
Relates to #38670

Fix padding issue around automation icons and
add missing automation icons.
# Checklist for submitter

If some of the following don't apply, delete the relevant line.
2026-06-26 07:51:27 -04:00
Steven Palmesano ec04c9a582 Fix broken link for Tahoe migration info (#48228) 2026-06-26 05:57:44 -05:00