Commit Graph
22481 Commits
Author SHA1 Message Date
Irena ReedyandAshish Kuthiala 52bdd4f8ec Create technology-platform.md (#41714)
Co-authored-by: Ashish Kuthiala <53918208+akuthiala@users.noreply.github.com>
2026-03-14 16:08:21 -05:00
Irena Reedy c9c3b488d8 Create identity-platform.md (#41716) 2026-03-14 16:03:32 -05:00
Irena Reedy 935a47054f Create fintech-company.md (#41715) 2026-03-14 16:02:06 -05:00
Irena Reedy 5640de95f3 Create cybersecurity-company.md (#41713) 2026-03-14 15:55:47 -05:00
Noah Talerman da74b7cfae Why no YAML schema for GitOps? (#41694) 2026-03-14 12:30:01 -05:00
Victor Lyuboslavsky 8c81821d0f Reduced database contention during the vulnerability cron (#41667)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41664

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [x] Alerted the release DRI if additional load testing is needed

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Optimized database performance for vulnerability processing to reduce
contention during routine operations.
  * Improved query efficiency for software cleanup processes.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-03-14 09:31:58 -05:00
Mike McNeil 2733f8a196 Homepage: Change heading for new section ("you can just do things") (#41708) 2026-03-14 02:23:35 -05:00
Ashish Kuthiala 9675c2b0eb Update assets page - re-org (#41705)
Update assets page - re-org
2026-03-13 23:52:35 -05:00
b56484673b Remove 'Still want to contact the CEO?' sentence from CEO handbook (#41703)
## Summary
- Removes the "Still want to contact the CEO?" sentence from the CEO
handbook page (`handbook/ceo/README.md`), keeping the "Contact us"
section heading and surrounding content intact.

Built for
[mikermcneil](https://fleetdm.slack.com/archives/D0AFASLRHNU/p1773453994081899?thread_ts=1773453980.663789&cid=D0AFASLRHNU)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

---------

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: Mike McNeil <mikermcneil@users.noreply.github.com>
2026-03-13 21:33:35 -05:00
kilo-code-bot[bot]andkiloconnect[bot] df3912d252 Lowercase 'Blog' to 'blog' in website nav menu (#41702)
## Summary

- Changed "Resources / Blog" to "Resources / blog" in the website
navigation menu (both mobile and desktop variants) in
`website/views/layouts/layout.ejs`

This is a minimal text change — lowercasing "Blog" to "blog" in the nav
menu label, alt text, and data attributes across both mobile and desktop
navigation dropdowns.

Built for
[mikermcneil](https://fleetdm.slack.com/archives/D0AFASLRHNU/p1773453585867159)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-03-13 21:02:53 -05:00
kilo-code-bot[bot]andkiloconnect[bot] 80884d8278 Update CEO responsibilities in handbook (#41701)
## Summary

- Replace "signatures on all documents" with "signatures on many
documents"
- Replace "human resources" with "product vision"
- Remove "legal counsel" from CEO DRI responsibilities
- Replace "brand & product marketing (brandfronts, pitchfronts,
featurefronts, ICPs, personas, and targeting)" with "brand strategy"

Changes applied to both `handbook/ceo/README.md` and
`handbook/company/leadership.md`.

Built for
[mikermcneil](https://fleetdm.slack.com/archives/D0AFASLRHNU/p1773453403391289)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-03-13 21:00:50 -05:00
kilo-code-bot[bot]andkiloconnect[bot] bca6956596 Fix CEO handbook 'schedule time with the CEO' links to point to leadership page (#41700)
## Summary
- Updated two links in `handbook/ceo/README.md` that pointed to
`company/communications#schedule-time-with-the-ceo` to instead point to
`company/leadership#schedule-time-with-the-ceo`
- The `#schedule-time-with-the-ceo` section lives on the leadership
page, not the communications page, so these links were broken

## Changes
- `handbook/ceo/README.md` line 16 (Contact us section): updated link
target from `communications` to `leadership`
- `handbook/ceo/README.md` line 43 (Process the CEO's calendar section):
updated link target from `communications` to `leadership`

Built for
[mikermcneil](https://fleetdm.slack.com/archives/D0AFASLRHNU/p1773453157605119)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-03-13 20:57:29 -05:00
Mike Thomas b0516ab3c4 Update device-management.ejs (#41699)
Updated the caption in the "Modern device management" block
2026-03-14 09:28:59 +09:00
EricandMike Thomas c1ff1fcea1 Website: add section to homepage, update layout (#41697)
Changes:
- Added a "Modern change management" section to the homepage
- Updated the homepage layout to match the latest wireframes

---------

Co-authored-by: Mike Thomas <78363703+mike-j-thomas@users.noreply.github.com>
2026-03-14 09:19:21 +09:00
Sam Pfluger 8c0bba7824 Link report to resp (#41696)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [ ] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [ ] Confirmed that the fix is not expected to adversely impact load
test results
- [ ] Alerted the release DRI if additional load testing is needed

## Database migrations

- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

## New Fleet configuration settings

- [ ] Setting(s) is/are explicitly excluded from GitOps

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [ ] Verified that the setting is exported via `fleetctl
generate-gitops`
- [ ] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that the setting is cleared on the server if it is not
supplied in a YAML file (or that it is documented as being optional)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

## fleetd/orbit/Fleet Desktop

- [ ] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [ ] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [ ] Verified that fleetd runs on macOS, Linux and Windows
- [ ] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))
2026-03-13 18:37:39 -05:00
Nathanael Holliday 1be36c8f83 Update 📜 Fleet Privacy Policy.md (#41584)
Updated in connection to this issue:
https://github.com/orgs/fleetdm/projects/80/views/1?filterQuery=hollidayn&pane=issue&itemId=162655280&issue=fleetdm%7Cconfidential%7C14762
2026-03-13 17:54:19 -05:00
f990d85491 Add consultant offboarding process to handbook (#41453)
## Summary

- Adds a new "Offboard a consultant" process to the People department
handbook page (`handbook/people/README.md`) with steps for notification,
KPI retirement, and access removal.
- Adds guidance on the Leadership page
(`handbook/company/leadership.md`) in the Consultants section, prompting
project DRIs to notify the Head of People when offboarding a consultant.

## Changes

### `handbook/people/README.md`
- New `### Offboard a consultant` section under Responsibilities, placed
after "Change the DRI of a consultant" and before "Add an advisor".
- Three-step process: DRI notification → retire KPI column (links to
existing [Retire a
KPI](https://fleetdm.com/handbook/people#retire-a-kpi) section) →
offboarding issue.

### `handbook/company/leadership.md`
- New blockquote in the Consultants section directing project DRIs to
notify the Head of People when ending a consultant engagement, with a
link to the new offboarding process.

---

Built for [Isabell
Reedy](https://fleetdm.slack.com/archives/D0AEGJCGJR0/p1773242873045939)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

---------

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: Isabell Reedy <113355639+ireedy@users.noreply.github.com>
Co-authored-by: Mike McNeil <mikermcneil@users.noreply.github.com>
2026-03-13 17:38:54 -05:00
4b9867a212 Add weekly Primo CRO export ritual to Finance handbook (#41689)
## Summary
- Adds a new weekly ritual assigned to @sampfluger88 for sending an
export/email to Primo's CRO every Friday with a list of non-ICP contact
form visitors.
- Adds a corresponding responsibility section ("Send Primo CRO weekly
export") to the Finance handbook README.
- This is in addition to warm-intro's by the support team for any actual
inbound requests that are not Fleet ICP.

## Changes
- `handbook/finance/finance.rituals.yml`: New ritual entry with weekly
frequency, autoIssue enabled, starting 2026-03-13.
- `handbook/finance/README.md`: New responsibility section with
step-by-step process.

Built for [Sam
Pfluger](https://fleetdm.slack.com/archives/C04DNAYL1QF/p1773439214834899?thread_ts=1773078316.093639&cid=C04DNAYL1QF)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

---------

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: Sam Pfluger <108141731+Sampfluger88@users.noreply.github.com>
2026-03-13 17:13:50 -05:00
Jahziel Villasana-Espinoza ce5f1e050a fix issue with duplicate entries in setup experience for FMAs (#41685)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41663 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)
- [x] QA'd all new/changed functionality manually

The 2 first software entries are for FMAs that had multiple versions in
Fleet and had been rolled back. Note that there is 1 row for each.

<img width="2940" height="1912" alt="LWScreenShot 2026-03-13 at 2 53
50 PM"
src="https://github.com/user-attachments/assets/48464655-5728-4965-8fd4-4c4c0c550f35"
/>
2026-03-13 18:10:55 -04:00
Ashish Kuthiala 49a6598acd Update tables (#41692)
redesigned tables
2026-03-13 17:04:46 -05:00
Dan Gordon b27432cee5 Fix Dan Gordon github account (#41625)
Updated github account info on Marketing readme page.
2026-03-13 16:38:57 -05:00
kilo-code-bot[bot]andkiloconnect[bot] 796663a83c Add Slack update policy for macOS and Windows workstations (#41687)
## Summary

- Adds new Fleet policies (`update-slack.yml`) for macOS and Windows
that **fail** if a device has an outdated version of Slack installed
(below `4.48.100`).
- Follows the existing `update-*` policy pattern used by 1Password,
Claude, and Firefox.
- Registers both policies in `workstations.yml` under the appropriate OS
sections.

## Changes

| File | Description |
|---|---|
| `it-and-security/lib/macos/policies/update-slack.yml` | New macOS
policy: checks `apps` table for `Slack.app` version via
`version_compare` |
| `it-and-security/lib/windows/policies/update-slack.yml` | New Windows
policy: checks `programs` table for `Slack` version via
`version_compare` |
| `it-and-security/fleets/workstations.yml` | Adds both policy paths to
the workstations fleet |

## Policy behavior

The policy **passes** if Slack is not installed OR if the installed
version is >= `4.48.100`. The policy **fails** if Slack is installed but
at a version older than `4.48.100`.

---

Built for [Allen
Houchins](https://fleetdm.slack.com/archives/D0AFASNBZMW/p1773436302175049)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-03-13 16:19:38 -05:00
ea6c720615 Deploy Slack across all workstation platforms (#41684)
## Summary

- Adds Slack as managed software to the Workstations fleet for
**macOS**, **Windows**, and **Linux** so it is installed on all new and
existing devices and kept up to date automatically.
- Uses **Fleet-maintained apps** (`slack/darwin`, `slack/windows`) for
macOS and Windows to ensure the latest version is always deployed.
- References the existing `slack-deb.yml` and `slack-rpm.yml` package
definitions for Linux (Debian and RPM).
- All entries include `self_service: true` and `setup_experience: true`
to install on new devices during setup and allow self-service
reinstallation.
- Mobile devices (iOS, iPadOS, Android) already have Slack configured in
both company-owned and personal mobile device fleets — no changes needed
there.

## Changes

Only `it-and-security/fleets/workstations.yml` is modified:

| Platform | Method | Entry |
|----------|--------|-------|
| macOS | `fleet_maintained_apps` | `slack/darwin` (Apple Silicon) |
| Windows | `fleet_maintained_apps` | `slack/windows` (x86) |
| Linux (Debian) | `packages` | `slack-deb.yml` |
| Linux (RPM) | `packages` | `slack-rpm.yml` |

Built for [Allen
Houchins](https://fleetdm.slack.com/archives/D0AFASNBZMW/p1773435271021419)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

---------

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: Allen Houchins <32207388+allenhouchins@users.noreply.github.com>
2026-03-13 16:07:51 -05:00
Luke Heath 17a29f5485 Update release candidate creation date in README (#41681) 2026-03-13 15:55:44 -05:00
Allen Houchins e0dec78e61 Removing Slack to prep for demo (#41679)
This pull request removes Slack from the managed software and policy
lists for all platforms (macOS, Linux, and Windows) in the workstation
fleet configuration. The associated policy file for keeping Slack up to
date on macOS has also been deleted.

Key removals by theme:

Slack software and policy removal:

* Removed the `update-slack.yml` policy from the list of enforced macOS
policies in `workstations.yml`.
* Deleted the `update-slack.yml` policy file for macOS, which checked
that Slack was up to date.

Slack application removal from managed software:

* Removed Slack from the list of managed apps for macOS
(`slack/darwin`), Linux (`slack-deb.yml` and `slack-rpm.yml`), and
Windows (`slack/windows`) in the `workstations.yml` configuration.
[[1]](diffhunk://#diff-48e4b7825d0b94911c4b33cccbe16ac3698dfb4b3e365a86432b58f06294daaaL227-L242)
[[2]](diffhunk://#diff-48e4b7825d0b94911c4b33cccbe16ac3698dfb4b3e365a86432b58f06294daaaL287-L292)
[[3]](diffhunk://#diff-48e4b7825d0b94911c4b33cccbe16ac3698dfb4b3e365a86432b58f06294daaaL340-L345)
2026-03-13 15:50:40 -05:00
2abacc577e Feat/31914 patch policy (#41518)
Implements patch policies #31914 

- https://github.com/fleetdm/fleet/pull/40816
- https://github.com/fleetdm/fleet/pull/41248
- https://github.com/fleetdm/fleet/pull/41276
- https://github.com/fleetdm/fleet/pull/40948
- https://github.com/fleetdm/fleet/pull/40837
- https://github.com/fleetdm/fleet/pull/40956
- https://github.com/fleetdm/fleet/pull/41168
- https://github.com/fleetdm/fleet/pull/41171
- https://github.com/fleetdm/fleet/pull/40691
- https://github.com/fleetdm/fleet/pull/41524
- https://github.com/fleetdm/fleet/pull/41674

---------

Co-authored-by: Jonathan Katz <44128041+jkatz01@users.noreply.github.com>
Co-authored-by: jkatz01 <yehonatankatz@gmail.com>
Co-authored-by: RachelElysia <71795832+RachelElysia@users.noreply.github.com>
Co-authored-by: Jahziel Villasana-Espinoza <jahziel@fleetdm.com>
2026-03-13 16:47:09 -04:00
Victor Lyuboslavsky ca89b035ac Don't clear past lock/wipe (#41504)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41190 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Bug Fixes
* Improved audit log accuracy when canceling pending lock or wipe
commands. The original activity record is now preserved, with the
cancellation tracked as a separate follow-up entry for better
visibility.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-03-13 15:21:24 -05:00
Victor Lyuboslavsky 8f24773d2e Added per-IP rate limiting and response caching (#41516)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37092 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
  * Added per‑IP rate limiting to IdP metadata and SSO endpoints.
* Implemented TTL-backed in‑memory caching for IdP metadata responses to
reduce backend load.

* **Tests**
* Added tests covering metadata caching behavior, cache miss/error
handling, and content type preservation.
* Added tests validating rate limiting behavior across clients, bursts,
and proxy scenarios.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-03-13 15:21:16 -05:00
Scott Gress 759c95100a Add aliases for more multi-platform setup experience fields (#41599)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41091

# Details

Implements the following config key aliases:

- [x] Add a second name for `bootstrap_package`:
`macos_bootstrap_package`
  - Support `bootstrap_package` for backwards compatibility
- [x] Add a second name for `manual_agent_install`:
`macos_manual_agent_install`
  - Support `manual_agent_install` for backwards compatibility
- [x] Add a second name for `enable_release_device_manually `: `apple_
enable_release_device_manually `
  - Support `enable_release_device_manually` for backwards compatibility
- [x] Add a second name for `script`: `macos_script`
  - Support `script` for backwards compatibility

Also cleans up some error messages missed in previous alias PRs.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [X] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [X] Added/updated automated tests
- [X] QA'd all new/changed functionality manually
ran gitops successfully with new keys
2026-03-13 15:17:05 -05:00
jacobshandling ad6ddc44f1 Trim ARM suffixes from arch linux OS names (#41656)
_working on spinning up an ARM Arch Linux host to verify this fix_
**Related issue:** Resolves #33495 


- [x] Changes file added for user-visible changes in `changes/`
- [x] Added/updated automated tests
- [ ] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved OS name normalization for Arch Linux ARM hosts by removing
redundant system identifiers for cleaner display.

* **Tests**
* Added validation tests for Arch Linux ARM and standard Arch Linux host
configurations to ensure consistent OS naming and architecture mapping.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-03-13 12:14:22 -07:00
jacobshandling 35b1ea7e4d Ignore cvefeed dir - helpful for local dev of vuln repo processes (#41615) 2026-03-13 12:13:51 -07:00
Ashish Kuthiala 6f03c72f8e Revise deployment assets table with platform details (#41657)
Updated the deployment assets table to include platform information and
reorganized the layout for better clarity.
2026-03-13 13:44:18 -05:00
Jonathan Katz 4a16578b75 Followup #35528: Fix iOS app still changing platform when uploading macOS installer (#41648)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #35528
The existing migrations were bumped in #41624 so they should be good for
the 4.83 release

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.
- Changes file exists in main (`changes/35528-wrong-title-platform`) but
was reverted out of 4.82 release.

- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually
2026-03-13 14:32:07 -04:00
Victor Lyuboslavsky a6c15e8a5b Fixed false positive vulnerabilities for Mattermost Desktop. (#41619)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #40007 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] QA'd all new/changed functionality manually
2026-03-13 13:26:36 -05:00
Victor Lyuboslavsky fa30866e40 Fixed a bug where the fleetd executable_hashes table failed to compute hashes for app bundles with emoji characters in their names (#41638)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41328

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

## fleetd/orbit/Fleet Desktop

- [x] Verified compatibility with the latest released version of Fleet
(see [Must rule]
- [x] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [x] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Fixed an issue where executable hashes failed to compute for macOS app
bundles with emoji or other Unicode characters in executable names,
improving bundle detection and integrity checks.

* **Tests**
* Added comprehensive tests to ensure correct handling of Unicode escape
sequences and emoji in bundle names and executables.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-03-13 13:26:19 -05:00
Victor Lyuboslavsky fe1e4d295b Fixed error message when deleting a certificate authority (#41635)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41532

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved error messaging when deleting a certificate authority that is
referenced by certificate templates. Users now receive a clear,
user-friendly message instead of a generic database error.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-03-13 13:25:35 -05:00
Juan Fernandez 0a00d20969 Don't resend profiles if IdP values do not change (41239) (#41662)
Resolves #41239 

PUT /hosts/{id}/device_mapping should only trigger a resend of profiles
when the IdP value changes.
2026-03-13 14:16:07 -04:00
Juan Fernandez 067e5fb33f Made Host Results endpoint URL consistent (33714) (#41501)
Resolves #33714

Added alias `GET /api/v1/fleet/scripts/batch/abc-def/host_results` for
`GET /api/v1/fleet/scripts/batch/abc-def/host-results` for consistency
sake.
2026-03-13 14:00:26 -04:00
Lucas Manuel Rodriguez da34876029 Ignore vulnerabilities in fleetdm/fleetctl (#41647)
Fixes
https://github.com/fleetdm/fleet/actions/runs/23038854478/job/66912680981.

Run with this branch:
https://github.com/fleetdm/fleet/actions/runs/23058249026
2026-03-13 14:22:40 -03:00
Juan Fernandez fadac07aa0 Surface correct HTTP status on SCIM data constraint errors (40260) (#41530)
Made sure Scim errors are reported with the correct HTTP status code in
case a data constraint violation happens.
2026-03-13 13:22:10 -04:00
jacobshandling 9866e9f5bf Rlp fe follow ups to main (#41658)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
This PR contains identical frontend changes to those currently in
`recovery-pw-feature` - this allows separate frontend review of the code

- [x] QA'd all new/changed functionality manually
2026-03-13 09:43:20 -07:00
Noah Talerman 77f8a7c00b Update roadmap-preview-january-2026.md (#41150)
May or may not be working on signed, downloadable installers this
quarter. For article, leaning towards not.
2026-03-13 09:20:56 -07:00
Mike ThomasandEric 3ebbdbee76 Update device management landing page footer to match the hero (#41650)
Changes:

- Updated the footer to match the hero.

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2026-03-13 11:03:25 -05:00
jacobshandling 614b4bf8b2 Disallow manage hosts page header buttons from wrapping text (#41654)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41653 
<img width="810" height="597" alt="Screenshot 2026-03-13 at 8 44 23 AM"
src="https://github.com/user-attachments/assets/b5e7feff-e576-4c0d-a9ee-b2ef1a17a7ea"
/>


- [x] Changes file added for user-visible changes in `changes/`
- [x] QA'd all new/changed functionality manually
2026-03-13 09:02:40 -07:00
Mike McNeil 56782b4c81 fix trivial copy/paste issue + fixed the other apple_setup (#41655) 2026-03-13 10:56:43 -05:00
Mike McNeil 24465931f4 Fix prototype generator templates (#41651) 2026-03-13 10:49:46 -05:00
Mike ThomasandEric c0e5d7d1fd Update infrastructure-as-code.ejs (#41646)
Changes:

- Moved the quote higher up the page.
- Updated "configuration as code" to "infrastructure as code".

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2026-03-14 00:49:11 +09:00
Dante Catalfamo 03420675e2 Clarify Okta platform sso policy query (#40644) 2026-03-13 11:43:12 -04:00
Mike Thomas c95e696a3f Update device management landing page layout and narrative (#41626)
This PR updates the device management landing page to better reflect
Fleet’s positioning around high-agency device management and
infrastructure-as-code.

Changes

- Reordered sections to prioritize speed and agency
- Moved “Modern change management” to the top of the positioning
narrative to highlight Fleet’s ability to ship device management changes
quickly.
- Moved the comparison section further down the page so visitors first
understand the value proposition before evaluating alternatives.
- Updated the customer quote to better reflect the
infrastructure-as-code story and added the customer logo for stronger
social proof.
2026-03-14 00:38:06 +09:00
Mike Thomas d327e4c3bd Update homepage text (#41642)
Changes:

- Changed "Configuration as code" to "Infrastructure as code."
- Updated "UI, API, or infrastructure as code" feature block to not be
duplicative.
- Removed "agent" from the bottom ticker.
- Corrected typo on screenshot.
2026-03-13 10:36:22 -05:00