Commit Graph
14810 Commits
Author SHA1 Message Date
Ian Littman 57e979f0a4 Swap JetBrains EAP versions for maxed last major release for vuln check purposes (#24783)
For #22723.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
2024-12-16 14:01:38 -06:00
Konstantin Sykulev 7e1478589b Delete pending installs/scripts on policy delete (#24463)
When a policy is deleted clean up any pending software installs or
scripts generated from the policy

https://github.com/fleetdm/fleet/issues/23886

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
2024-12-16 11:47:34 -06:00
Ian Littman a86caed431 Replace CRLF with LF on script upload (#24760)
For #24166

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
2024-12-16 11:25:12 -06:00
Victor Lyuboslavsky 1e5da18963 Fixed potential deadlocks when deploying Apple configuration profiles. (#24777)
#24771

Fixing deadlocks found in loadtest:
https://docs.google.com/document/d/1-Q6qFTd7CDm-lh7MVRgpNlNNJijk6JZ4KO49R1fp80U/edit?tab=t.0
- added retries to statements prone to deadlocks

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
- [x] Manual QA for all new/changed functionality
2024-12-16 11:16:42 -06:00
Noah Talerman 6b6eb19bb0 Fleet server configuration docs: capitalize "S3" (#24794) 2024-12-16 10:42:20 -06:00
Robert Fairburn 20963421b9 Update terraform monitoring to fix a deprecation (#24698) 2024-12-16 10:38:11 -06:00
github-actions[bot]andlucasmrod d94f10f147 Update versions of fleetd components in Fleet's TUF [automated] (#24779)
Automated change from [GitHub
action](https://github.com/fleetdm/fleet/actions/workflows/fleetd-tuf.yml).

Co-authored-by: lucasmrod <lucasmrod@users.noreply.github.com>
2024-12-16 12:01:56 -03:00
Eric dc0dddffaf Website: update /app-library page (#24778)
Closes: #24259
Closes: https://github.com/fleetdm/confidential/issues/9070

Changes:
- Added a section about custom packages and app store apps to the
/app-library page.
- Updated the "Request an app" button to "Add an app" and updated it to
link to the maintained apps JSON.
2024-12-13 18:40:34 -06:00
Harrison RavazzoloandHarrison John 1d6a6c3224 Fix Typos in Windows CSP Article (#24775)
Co-authored-by: Harrison John <harrisonjohn@Harrisons-MacBook-Pro.local>
2024-12-13 16:38:04 -08:00
Lucas Manuel RodriguezandEric 9daa5a2950 Add docs for the nftables fleetd table (#24749)
#15651

We missed to add the docs in the original PR:
https://github.com/fleetdm/fleet/pull/23941

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2024-12-13 21:34:24 -03:00
Andrea Scarpino e3c87a2c79 List paths used by Fleet desktop (#23891)
We don't expose fleet publicly and we had to open these paths to make
Fleet Desktop work.
2024-12-13 17:47:50 -06:00
Mike ThomasandEric dc4f3026e6 add VM content (#24743)
- Add VM content to `vm` and `eo-security` personalization of
/software-management.

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2024-12-13 17:47:02 -06:00
Eric 395a6e261d MSP dashboard: Update readme to document all required config values (#24773)
Changes:
- Updated the MSP dashboard's readme to include a section about required
config values for software features.
- Added config values required for software features to the MSP
dashboard's docker-compose file.
- Added an uploads configuration file that lists the configuration
values required for software features.
2024-12-13 17:24:52 -06:00
Konstantin Sykulev 4503b2f334 Fixed bug when using without_vulnerability_details and vulnerability filters (#24769)
https://github.com/fleetdm/fleet/issues/24765

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Added/updated tests
2024-12-13 16:39:21 -06:00
Noah Talerman 7d7fc7b249 Update user story template: activity change (#24772)
- PR will be merged in when it's approved like API/YAML design PRs
- When we build the feature, the doc changes will get squished by auto
generated docs:
https://fleetdm.com/handbook/company/communications#audit-logs
2024-12-13 16:47:38 -05:00
Sam Pfluger 71ad7e3a8f Update communications.md (#24770) 2024-12-13 15:45:49 -06:00
Victor Lyuboslavsky 48e3654d75 Adding secret support to profiles via gitops. (#24675)
#24547

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
2024-12-13 15:41:23 -06:00
Drew Baker d23195911e Create foursquare-quickly-migrates-to-fleet.md (#24768) 2024-12-13 16:02:43 -05:00
Eric 02b0a97ac8 Website: add support for new usage statistics (#24511)
Changes:
- Updated the receive-usage-analytics webhook to support a new input:
`numQueries`
- Added a new attribute to the HistoricalUsageSnapshot model
`numQueries`
- Added a commented-out section to the
send-aggregated-metrics-to-datadog script.
2024-12-13 15:00:30 -06:00
dependabot[bot] 39e71cf5e0 Bump golang.org/x/crypto from 0.21.0 to 0.31.0 in /tools/terraform (#24715) 2024-12-13 14:59:19 -06:00
Noah Talerman 256bb67f95 Dogfood: enforce macOS 15.2 (#24753) 2024-12-13 14:57:07 -06:00
Allen Houchins 03d00cd995 Removing iOS and iPadOS apps from the 💻🐣 Workstations (canary) team (#24713) 2024-12-13 14:54:49 -06:00
Scott Gress ff63cdf904 Add flaky test guide to handbook (#24722) 2024-12-13 14:54:26 -06:00
Mike Thomas f56dea3f23 add new accordion items (#24741)
closes https://github.com/fleetdm/fleet/issues/24642
- Two new items were added to the top of the accordion.
- The numbers for accordion header and body IDs/targets were updated to
allow for the new items.
2024-12-13 14:24:15 -06:00
Lucas Manuel Rodriguez 7d0609341e Release fleetd 1.37.0 (#24752) 2024-12-13 17:08:36 -03:00
Mike ThomasandEric 82e000a758 Name change (Observability => Orchestration) (#24747)
- made the text changes to the page, page title, site navigation
---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2024-12-13 13:24:42 -06:00
jacobshandlingandJacob Shandling 7e5000cf52 UI - Redirect on invalid URL parameter to /software/add/fleet-maintained/:id (#24637)
## #24636

Redirect when NaN "foobar" provided as software id in url:

https://github.com/user-attachments/assets/e1b0ce3d-f494-447c-a452-285f0e6758af

- [x] Changes file added for user-visible changes in `changes/`,
- [x] Manual QA for all new/changed functionality

---------

Co-authored-by: Jacob Shandling <jacob@fleetdm.com>
2024-12-13 10:40:58 -08:00
Mike ThomasandEric fb118b6f35 add new section to observability (#24742)
- Added "Orchestrate anything."
- Renamed "Pulse check anything" to "On-demand data."
- Renamed "On-demand data" to "Deep context from your environment."

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2024-12-13 11:16:28 -06:00
Noah Talerman 36c6585f5f Setup experience guide: document current behavior (#24736)
- Document current behavior
2024-12-13 10:30:01 -05:00
RachelElysia 6c79c07441 Fleet UI: Dropdown always scrolled to view in userform (#24719) 2024-12-13 09:26:58 -05:00
Noah Talerman a5726399cb Creating Windows CSPs (#24737)
Great guide @harrisonravazzolo! Taking an opportunity to teach folks the
Fleet language: custom OS settings.

Also, "Fleet" instead of "FleetDM":
https://fleetdm.com/handbook/company/communications#capitalization-and-proper-nouns
2024-12-13 09:05:53 -05:00
Noah Talerman dab8cc9ab4 macOS 15 CIS Benchmarks: document missing items (#24645)
- Missing 2.6.3.5 and 2.7.2
2024-12-13 08:51:43 -05:00
Nathanael HollidayandSam Pfluger 5d51b6c06e Update sales.rituals.yml (#24296)
Edits correspond to these handbook edits: 
https://github.com/fleetdm/fleet/pull/24295

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

<!-- Note that API documentation changes are now addressed by the
product design team. -->

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [ ] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [ ] Added support on fleet's osquery simulator `cmd/osquery-perf` for
new osquery data ingestion features.
- [ ] Added/updated tests
- [ ] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes
- [ ] If database migrations are included, checked table schema to
confirm autoupdate
- For database migrations:
- [ ] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [ ] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [ ] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).
- [ ] Manual QA for all new/changed functionality
- For Orbit and Fleet Desktop changes:
- [ ] Orbit runs on macOS, Linux and Windows. Check if the orbit
feature/bugfix should only apply to one platform (`runtime.GOOS`).
- [ ] Manual QA must be performed in the three main OSs, macOS, Windows
and Linux.
- [ ] Auto-update manual QA, from released version of component to new
version (see [tools/tuf/test](../tools/tuf/test/README.md)).

---------

Co-authored-by: Sam Pfluger <108141731+Sampfluger88@users.noreply.github.com>
2024-12-13 01:43:26 -06:00
Mike McNeil fc828a56b5 Update testimonials.yml (#23993) 2024-12-12 17:09:10 -08:00
Mike McNeil 3b7ce275ec Update homepage.ejs (#24739) 2024-12-12 17:08:05 -08:00
Mike Thomas 3acb833d5d endpoint-security-case-study (#24738)
Publishing an endpoint security case study.
2024-12-12 19:06:52 -05:00
Mike ThomasandEric 4551d11b73 Q4 landing page update (#24694)
Closes https://github.com/fleetdm/confidential/issues/9117

Updated /software-management and /observability landing pages to align
with Fleet's positioning and narrative.

Next steps when Mike T returns from PTO:

- Find a home for the content we removed
https://github.com/fleetdm/fleet/issues/24701
- Improve the software management hero to focus on differentiators
https://github.com/fleetdm/fleet/issues/24700
- Remove marketing fluff from /observability for security engineers
https://github.com/fleetdm/fleet/issues/24640

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2024-12-13 08:54:17 +09:00
Ian Littman 42186b1ad9 Fix nil pointer dereference on CVEs when OS versions list hasn't been populated yet (#24735)
For #22523.

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
2024-12-12 17:23:27 -06:00
Victor Lyuboslavsky 3d671f110d Removed server error if no private IP was found by detail_query_network_interface (#24726)
#24725

# Checklist for submitter
- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality
2024-12-12 15:45:26 -06:00
Lucas Manuel Rodriguez d81f174ab9 Move orbit changes file (#24731) 2024-12-12 18:38:23 -03:00
Rebecca CowartandEric bf83f0309b Update windows_eventlog.yml (#24711)
Stray quotation in example query

---------

Co-authored-by: Eric <eashaw@sailsjs.com>
2024-12-12 15:31:32 -06:00
Harrison RavazzoloandHarrison John 52fe6dba14 Add win csp article - Updated category tag (#24730)
Adding article to site for crafting windows CSPs

---------

Co-authored-by: Harrison John <harrisonjohn@Harrisons-MacBook-Pro.local>
2024-12-12 13:31:07 -08:00
Eric 3c10fe0050 Website: fix failing deploy (#24728)
Changes:
- Updated the category meta tag value (`articles` » `guides`) of the
"Creating Windows CSPs" article to resolve a build script error.
- Wrapped an HTML tag in the article in backticks so it won't be seen as
an unregistered custom HTML element by the website
2024-12-12 15:22:13 -06:00
Harrison RavazzoloandHarrison John ef9927a53a Crafting Windows CSP article (#24727)
Article for website covering the building of Windows csps

Co-authored-by: Harrison John <harrisonjohn@Harrisons-MacBook-Pro.local>
2024-12-12 12:49:58 -08:00
Konstantin SykulevandRachael Shaw abeb16c087 Updated deprecated endpoint references with new endpoint (#24723)
[#23880](https://github.com/fleetdm/fleet/issues/23880)

---------

Co-authored-by: Rachael Shaw <r@rachael.wtf>
2024-12-12 13:55:49 -06:00
Konstantin SykulevandIan Littman 669e944f50 Team policy endpoint now accepts null to unset a script or software installer (#24658)
https://github.com/fleetdm/fleet/issues/23490

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/Committing-Changes.md#changes-files)
for more information.
- [x] Added/updated tests
- [x] Manual QA for all new/changed functionality

---------

Co-authored-by: Ian Littman <iansltx@gmail.com>
2024-12-12 13:33:19 -06:00
dependabot[bot] d45403f1ca Bump golang.org/x/crypto from 0.28.0 to 0.31.0 (#24717)
Bumps [golang.org/x/crypto](https://github.com/golang/crypto) from
0.28.0 to 0.31.0.
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/golang/crypto/commit/b4f1988a35dee11ec3e05d6bf3e90b695fbd8909"><code>b4f1988</code></a>
ssh: make the public key cache a 1-entry FIFO cache</li>
<li><a
href="https://github.com/golang/crypto/commit/7042ebcbe097f305ba3a93f9a22b4befa4b83d29"><code>7042ebc</code></a>
openpgp/clearsign: just use rand.Reader in tests</li>
<li><a
href="https://github.com/golang/crypto/commit/3e90321ac7bcee3d924ed63ed3ad97be2079cb56"><code>3e90321</code></a>
go.mod: update golang.org/x dependencies</li>
<li><a
href="https://github.com/golang/crypto/commit/8c4e668694ccbaa1be4785da7e7a40f2ef93152b"><code>8c4e668</code></a>
x509roots/fallback: update bundle</li>
<li><a
href="https://github.com/golang/crypto/commit/6018723c74059e3b91c84268b212c2f6cdab1f64"><code>6018723</code></a>
go.mod: update golang.org/x dependencies</li>
<li><a
href="https://github.com/golang/crypto/commit/71ed71b4faf97caafd1863fed003e9ac311f10ee"><code>71ed71b</code></a>
README: don't recommend go get</li>
<li><a
href="https://github.com/golang/crypto/commit/750a45fe5e473d5afa193e9088f3d135e64eca26"><code>750a45f</code></a>
sha3: add MarshalBinary, AppendBinary, and UnmarshalBinary</li>
<li><a
href="https://github.com/golang/crypto/commit/36b172546bd03a74c79e109ec84c599b672ea9e4"><code>36b1725</code></a>
sha3: avoid trailing permutation</li>
<li><a
href="https://github.com/golang/crypto/commit/80ea76eb17c0c52f5d5d04e833d6aeb6b062d81d"><code>80ea76e</code></a>
sha3: fix padding for long cSHAKE parameters</li>
<li><a
href="https://github.com/golang/crypto/commit/c17aa50fbd32393e5d52fa65ca51cbfff0a75aea"><code>c17aa50</code></a>
sha3: avoid buffer copy</li>
<li>Additional commits viewable in <a
href="https://github.com/golang/crypto/compare/v0.28.0...v0.31.0">compare
view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=golang.org/x/crypto&package-manager=go_modules&previous-version=0.28.0&new-version=0.31.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the
[Security Alerts page](https://github.com/fleetdm/fleet/network/alerts).

</details>

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-12 16:05:17 -03:00
Eugene 039ea91f9b Capitalization fix & added :id information (#24643)
Fixed capitalization of "Default response" and id information for
modiifying a package
2024-12-12 12:50:49 -06:00
Scott Gress cdae1749bf Fix flaky TestEnqueueMDMCommand test (#24697)
FYI this was diagnosed and fixed using the
[RandoKiller](https://github.com/fleetdm/fleet/pull/24696).

---

This PR fixes the TestEnqueueMDMCommand, which has been failing
intermittently
[here](https://github.com/fleetdm/fleet/blob/main/server/service/integration_mdm_test.go#L2922).
Most of the time the `/api/latest/fleet/mdm/apple/commands` API is
returning one result as expected, but occasionally it returns 2, for
example:

```
[
  {
    "device_id": "B11F1FC1-F176-48CF-88A4-CB7A3DFEF987",
    "command_uuid": "63bb4313-ccbf-4647-ac07-7d15df5f92d7",
    "updated_at": "2024-12-12T02:41:36Z",
    "request_type": "ProfileList",
    "status": "Acknowledged",
    "hostname": "test-host"
  },
  {
    "device_id": "B11F1FC1-F176-48CF-88A4-CB7A3DFEF987",
    "command_uuid": "7de9d712-7524-4443-a20a-7127e6064f6e",
    "updated_at": "2024-12-12T02:41:36.141498Z",
    "request_type": "InstallEnterpriseApplication",
    "status": "Pending",
    "hostname": "test-host"
  }
]
```

It seems that the second command is related to trying to install a
bootstrap package (uploaded by a previous test) to the newly-enrolled
host.

The fix in this PR is to filter the API response to only the command
we're verifying the presence of. It's a decent solve, but leaves open
the edge case of a bug that causes multiple commands to be sent
unexpectedly. The ideal solution would be to remove the interaction
between the two tests, perhaps by deleting any created bootstraps before
those tests complete, or by re-initializing the state in some other way.
I don't currently have enough context to easily implement a solution
like that (i.e. I know there's a "delete bootstrap" API, but not sure if
that's enough to solve this issue).
2024-12-12 12:30:42 -06:00
Victor Lyuboslavsky 5db90645a4 Added a check for active = 1 to CleanupHostMDMAppleProfiles (#24712)
#23816 

This catches the case when host re-enrolls in MDM with pending profiles.

Demo of the issue/fix: https://youtu.be/ol3xbJWw8HQ

# Checklist for submitter
- [x] Manual QA for all new/changed functionality
2024-12-12 12:04:17 -06:00