Commit Graph
20482 Commits
Author SHA1 Message Date
Ian LittmanandAllen Houchins 79cd166c85 🤖 Move child process to separate cgroup for Linux uninstall script (#37131)
For #36619. Zed + Opus 4.5, prompt was just "fix
https://github.com/fleetdm/fleet/issues/36619"

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

No changes file as this isn't in a Fleet release.

## Testing

- [ ] QA'd all new/changed functionality manually

---------

Co-authored-by: Allen Houchins <allenhouchins@mac.com>
2025-12-31 12:16:35 -06:00
Victor Lyuboslavsky a3cc31dac8 Validate certificate template names (#37765)
Fix for unreleased bug:
- Enforce validation rules for certificate template names (e.g., length,
allowed characters).
- Implement duplicate name error handling in MySQL datastore.

<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37761

# Checklist for submitter

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [x] Confirmed that the fix is not expected to adversely impact load
test results



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

## Release Notes

* **New Features**
* Certificate template naming now enforced with validation rules: no
empty or whitespace-only names, character restrictions, and maximum
length limits.
  * Validation occurs on both client and server sides.

* **Bug Fixes**
* Improved error handling and messaging for duplicate certificate
templates.
  * Corrected certificate validation error message text.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2025-12-31 09:18:31 -06:00
Victor Lyuboslavsky c88cc953fb Refactor endpoint_utils for modularization (#36484)
Resolves #37192

Separating generic endpoint_utils middleware logic from domain-specific
business logic. New bounded contexts would share the generic logic and
implement their own domain-specific logic. The two approaches used in
this PR are:
- Use common `platform` types
- Use interfaces

In the next PR we will move `endpointer_utils`, `authzcheck` and
`ratelimit` into `platform` directory.

# Checklist for submitter

- [x] Added changes file

## Testing

- [x] Added/updated tests
- [x] QA'd all new/changed functionality manually



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Restructured internal error handling and context management to support
bounded context architecture.
* Improved error context collection and telemetry observability through
a provider-based mechanism.
* Decoupled licensing and authentication concerns into interfaces for
better modularity.

* **Chores**
* Updated internal package dependencies to align with new architectural
boundaries.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2025-12-31 09:12:00 -06:00
RachelElysia 360a426224 Fleet UI: Update the read-only SQL editor to appear non-interactive (#37764) 2025-12-31 09:38:12 -05:00
RachelElysia e171c02a03 GitOps: Android config generated in team software directory (#37767) 2025-12-31 09:29:49 -05:00
Victor Lyuboslavsky fa9c868c6e Add uuid column to host_certificate_templates (#37763)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37580

This migration is needed for the larger unreleased bug PR: #37616

Doing the migration separately to merge quickly and minimize merge
conflicts.
2025-12-30 14:09:43 -06:00
Magnus Jensen 9c28ff3ac9 validate android profile JSON on upload (#37756)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #35567 

<img width="717" height="116" alt="image"
src="https://github.com/user-attachments/assets/98d77730-bab1-4e8d-a19f-0efafd5e2323"
/>


# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually
2025-12-30 12:10:06 -04:00
Ian Littman 405e10fe90 Clean up android app config data layer, fix no-team persist bug (#37740)
Resolves #37729. Unreleased, so no changes file.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)

## Testing

- [x] Added/updated automated tests

- [ ] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [x] Confirmed that the fix is not expected to adversely impact load
test results

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Refactored Android app configuration storage and retrieval to use
JSON-based format instead of structured objects.
* Updated configuration lookups to use team-based identification
consistently.
* Added new method for retrieving Android app configurations by app team
ID.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2025-12-30 09:35:41 -06:00
fleet-releaseandmostlikelee 1b8eaecf73 Update Fleet-maintained apps (#37754)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-30 08:55:59 -06:00
Lucas Manuel Rodriguez 61588a5ac1 Fix auto-update of .tar.gz components in orbit (#37741)
Resolves #37340.

These two issues are present on installations that used `fleetctl` (with
the `.sha512` caching optimization for `.tar.gz`) to generate the fleetd
installers.

I also recently hit this issue while releasing osqueryd to `edge` and
when releasing fleetd.

# Issue 1

First update of a `.tar.gz` component like Fleet Desktop on macOS/Linux
after installation doesn't work; second update after installation does
work:
1. Pushing a first update to TUF after the installation does the removal
of `.sha512` to `.tar.gz`, but contents are not extracted.
2. Pushing a second update to TUF after (1) does the `.tar.gz` update
and correctly updates.

How to reproduce locally:
```
# Create TUF repository
SYSTEMS="macos linux-arm64 windows-arm64" \
PKG_FLEET_URL=https://localhost:8080 \
PKG_TUF_URL=http://localhost:8081 \
DEB_FLEET_URL=https://host.docker.internal:8080 \
DEB_TUF_URL=http://host.docker.internal:8081 \
MSI_FLEET_URL=https://host.docker.internal:8080 \
MSI_TUF_URL=http://host.docker.internal:8081 \
GENERATE_PKG=1 \
GENERATE_DEB_ARM64=1 \
GENERATE_MSI_ARM64=1 \
ENROLL_SECRET=q6BjogOT6E04UmxrtZdXCE54fe89m35J \
FLEET_DESKTOP=1 \
USE_FLEET_SERVER_CERTIFICATE=1 \
DEBUG=1 \
./tools/tuf/test/main.sh

# Remove current installation in macOS.
sudo ./it-and-security/lib/macos/scripts/uninstall-fleetd-macos.sh remove

# Install the package
sudo installer -pkg fleet-osquery.pkg -target /

# Check version shown in Fleet Desktop icon (e.g. N)

# Update "Fleet Desktop" component to N+1.
source ./tools/tuf/test/load_orbit_version_vars.sh
echo $ORBIT_VERSION
FLEET_DESKTOP_VERSION=$ORBIT_VERSION make desktop-app-tar-gz
./tools/tuf/test/push_target.sh macos desktop desktop.app.tar.gz $ORBIT_VERSION

# Check version shown in Fleet Desktop icon, and it doesn't update (that's the bug).

# Update "Fleet Desktop" component to N+2.
source ./tools/tuf/test/load_orbit_version_vars.sh
echo $ORBIT_VERSION
FLEET_DESKTOP_VERSION=$ORBIT_VERSION make desktop-app-tar-gz
./tools/tuf/test/push_target.sh macos desktop desktop.app.tar.gz $ORBIT_VERSION

# Check version shown in Fleet Desktop icon, and now it updated to N+2.
```

# Issue 2

Installing on top of existing installation (re-install). Less likely to
happen but still an issue.
Re-installation of packages does not delete existing stuff at
`/opt/orbit/bin/`/`C:\Program Files\Orbit`.
So, e.g. `ls /opt/orbit/bin/desktop/macos/stable/` after a re-install
shows:
- desktop.app.tar.gz from before the installation.
- sha512 of the installed package.
- Fleet Desktop/ of the installed package..
It runs the version that came with the package, but not the updated
version.
This is fixed by a subsequent update after the re-install.

How to reproduce locally:

```
# Create TUF repository.
SYSTEMS="macos linux-arm64 windows-arm64" \
PKG_FLEET_URL=https://localhost:8080 \
PKG_TUF_URL=http://localhost:8081 \
DEB_FLEET_URL=https://host.docker.internal:8080 \
DEB_TUF_URL=http://host.docker.internal:8081 \
MSI_FLEET_URL=https://host.docker.internal:8080 \
MSI_TUF_URL=http://host.docker.internal:8081 \
GENERATE_PKG=1 \
GENERATE_DEB_ARM64=1 \
GENERATE_MSI_ARM64=1 \
ENROLL_SECRET=q6BjogOT6E04UmxrtZdXCE54fe89m35J \
FLEET_DESKTOP=1 \
USE_FLEET_SERVER_CERTIFICATE=1 \
DEBUG=1 \
./tools/tuf/test/main.sh

# Remove and install the package in macOS
sudo ./it-and-security/lib/macos/scripts/uninstall-fleetd-macos.sh remove
sudo installer -pkg fleet-osquery.pkg -target /

# Push a new update for "Fleet Desktop" (e.g. N+1).
source ./tools/tuf/test/load_orbit_version_vars.sh
echo $ORBIT_VERSION
FLEET_DESKTOP_VERSION=$ORBIT_VERSION make desktop-app-tar-gz
./tools/tuf/test/push_target.sh macos desktop desktop.app.tar.gz $ORBIT_VERSION

# Re-install the original installer
sudo installer -pkg fleet-osquery.pkg -target /

# Check version shown in Fleet Desktop icon, it says N instead of N+1 (that's the bug).

# A new push to TUF of N+2 fixes the issue.
```

# More info

Both issues happen also with `osqueryd` in macOS which comes bundled as
a `osqueryd.app.tar.gz`.

---

- [X] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [X] QA'd all new/changed functionality manually

## fleetd/orbit/Fleet Desktop

- [X] Verified compatibility with the latest released version of Fleet
(see [Must
rule](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/workflows/fleetd-development-and-release-strategy.md))
- [X] If the change applies to only one platform, confirmed that
`runtime.GOOS` is used as needed to isolate changes
- [X] Verified that fleetd runs on macOS, Linux and Windows
- [X] Verified auto-update works from the released version of component
to the new version (see [tools/tuf/test](../tools/tuf/test/README.md))


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed auto-update mechanism for .tar.gz components to properly manage
cached hashes and ensure stale extracted contents are cleaned up during
re-downloads following hash mismatches.

<sub>✏️ Tip: You can customize this high-level summary in your review
settings.</sub>

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2025-12-30 11:17:32 -03:00
Ian LittmanandJuan Fernandez 646a4b4159 Implement fleetctl generate-gitops for team labels, add team filtering to fleetctl get labels, don't show global labels when filtering labels spec endpoint to a specific team (#37750)
Implements #37749.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

## New Fleet configuration settings

If you didn't check the box above, follow this checklist for
GitOps-enabled settings:

- [x] Verified that the setting is exported via `fleetctl
generate-gitops`
- [x] Verified the setting is documented in a separate PR to [the GitOps
documentation](https://github.com/fleetdm/fleet/blob/main/docs/Configuration/yaml-files.md#L485)
- [ ] Verified that any relevant UI is disabled when GitOps mode is
enabled

---------

Co-authored-by: Juan Fernandez <juan@fleetdm.com>
2025-12-30 09:09:55 -04:00
Ian Littman 8284bac1ca Address backend review feedback from #37208 (#37742) 2025-12-30 08:48:55 -03:00
Allen Houchins 01907e5f8c Remove Microsoft Teams Windows app and related files (#37747)
Deleted Microsoft Teams Windows app definition and output files, and
removed its entry from the main apps.json. This cleans up legacy support
for the old Teams Windows package.
2025-12-29 22:59:06 -06:00
fleet-releaseandallenhouchins 8a2af6cb65 Update Fleet-maintained apps (#37743)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2025-12-29 22:11:00 -06:00
fleet-releaseandmostlikelee 1258a68ab8 Update Fleet-maintained apps (#37738)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-29 21:55:10 -06:00
Ian Littman 8e4e89f4e9 API + auth + UI changes for team labels (#37208)
Covers #36760, #36758.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [ ] QA'd all new/changed functionality manually
2025-12-29 21:28:45 -06:00
Lucas Manuel Rodriguez 04d2a98b50 Update osquery schema and flags to 5.20.0 (#37688) 2025-12-29 16:28:40 -03:00
Steven Palmesano 424ae271c8 Tines reorg (#37731)
Resolves #34967.
2025-12-29 13:04:49 -06:00
Steven Palmesano 239c1fd62b Solutions symlinks (#37732)
Documentation and one symlink created.

Also, moved an existing profile in the iOS directory and updated the
relevant article that links to it.
2025-12-29 12:42:56 -06:00
Jordan MontgomeryandMagnus Jensen 7535889de3 Skip bootstrap package install during migration (#37614)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #36010 and #37644

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements)
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

## Database migrations

- [x] Checked schema for all modified table for columns that will
auto-update timestamps during migration.
- [x] Confirmed that updating the timestamps is acceptable, and will not
cause unwanted side effects.
- [x] Ensured the correct collation is explicitly set for character
columns (`COLLATE utf8mb4_unicode_ci`).

---------

Co-authored-by: Magnus Jensen <magnus@fleetdm.com>
2025-12-29 12:00:24 -04:00
RachelElysia 058ede617c Fleet UI: Fix edit software/config for no teams bug (#37728) 2025-12-29 10:25:09 -05:00
Noah Talerman ef411a0259 Entra conditional access: Migration w/o end user action isn't supported (#37676)
- Update migration instructions now that we think migration w/o end user
action isn't supported
- More info in this bug: https://github.com/fleetdm/fleet/issues/34306
2025-12-29 10:33:31 -03:00
Noah Talerman 1535e9dba0 Okta conditional access: Instructions "coming soon" (#37675)
Add coming soon message so users/customers know instructions are coming
soon
2025-12-29 11:55:22 +01:00
fleet-releaseandmostlikelee a6dce92737 Update Fleet-maintained apps (#37721)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-28 16:57:39 -06:00
fleet-releaseandallenhouchins 5e20c58b4a Update Fleet-maintained apps (#37720)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2025-12-27 17:33:47 -06:00
fleet-releaseandmostlikelee c809266e19 Update Fleet-maintained apps (#37719)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-27 17:26:15 -06:00
fleet-release 5a3bf1da69 Update Fleet-maintained apps (#37718) 2025-12-27 08:08:55 -06:00
fleet-releaseandallenhouchins 99d313f347 Update Fleet-maintained apps (#37714)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2025-12-26 21:37:43 -06:00
fleet-releaseandmostlikelee 075815d03d Update Fleet-maintained apps (#37713)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-26 21:18:56 -06:00
Scott Gress 0c39fe4572 Allow disabling schedule with empty start/end time (#37709)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37599

# Details

Fixes an unreleased issue where if you clear the start/end time of a
software auto-update schedule and then attempt to disable and save the
schedule, the API returns an error due to the start/end time being
invalid. Now, the start/end time will be unchanged if the schedule is
disabled.

## Testing

- [X] Added/updated automated tests
- [X] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [X] Confirmed that the fix is not expected to adversely impact load
test results
- [X] Alerted the release DRI if additional load testing is needed
2025-12-26 17:46:45 -06:00
fleet-release cc1485cc46 Update Fleet-maintained apps (#37708) 2025-12-26 08:33:39 -06:00
fleet-releaseandAllen Houchins 1751673805 Update Fleet-maintained apps (#37685)
Automated ingestion of latest Fleet-maintained app data.

---------

Co-authored-by: Allen Houchins <allenhouchins@mac.com>
2025-12-25 20:34:17 -06:00
rhuddleston d2546673bb Fix for https://github.com/fleetdm/fleet/issues/37671 (#37679)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37671

added missing icon file
2025-12-25 19:33:01 -03:00
fleet-releaseandmostlikelee 3f4718a46b Update Fleet-maintained apps (#37683)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-25 11:42:42 -06:00
fleet-releaseandmostlikelee 10d8ab2329 Update Fleet-maintained apps (#37673)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-24 08:58:22 -06:00
RachelElysia 6edf96291f Fleet UI: Fix decoding mdm output (#37608) 2025-12-24 09:22:07 -05:00
fleet-releaseandmostlikelee 6cd44182a3 Update Fleet-maintained apps (#37659)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-24 00:27:58 -06:00
jacobshandling 9adfe73101 Update "add certs" naming (#37658)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves
#https://github.com/fleetdm/fleet/issues/30876#issuecomment-3687904875


<img width="1133" height="344" alt="Screenshot 2025-12-23 at 1 00 27 PM"
src="https://github.com/user-attachments/assets/ffeebbe2-1253-43a5-8a88-6b78d722f431"
/>
<img width="827" height="383" alt="Screenshot 2025-12-23 at 1 01 18 PM"
src="https://github.com/user-attachments/assets/ddbea202-d560-4486-b046-06fbadd1c4e2"
/>
<img width="807" height="639" alt="Screenshot 2025-12-23 at 1 01 29 PM"
src="https://github.com/user-attachments/assets/365b7da2-fd28-4b3d-965c-b25ec980c0d2"
/>


- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually
2025-12-23 13:23:16 -08:00
Noah Talerman c0c54ca1f8 API docs typo: Change labels and configuration fields to body (#37656) 2025-12-23 14:06:55 -06:00
Noah Talerman e1aded2e49 Use "array" instead of "string[]" (#37655)
To be consistent
2025-12-23 14:04:29 -06:00
Rachael Shaw 827023b541 #31909 Guide: Okta conditional access (#36816)
Note that there are still some TODOs (commented out for now). Will make
a separate issue to fill those in, so we can get the basic guide out
ASAP.

---
**Edit:** Bug report for missing info
[here](https://github.com/fleetdm/fleet/issues/37652)
2025-12-23 14:00:25 -06:00
fleet-releaseandmostlikelee 34ff25ec44 Update Fleet-maintained apps (#37636)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2025-12-23 13:42:12 -06:00
Noah Talerman a34c5b7040 Be more explicit in calendar events current issues (#37211)
Context:
https://github.com/fleetdm/fleet/issues/36975#issuecomment-3648138529
2025-12-23 14:11:39 -05:00
Carlo e99ff3e046 Fix FMAs on Render (#37557)
Fixes #33732

Base64-encodes the `install_script` and `uninstall_script` payloads for
add and edit software to prevent being blocked by WAF rules and allow
FMAs for Windows to be added/edited in Fleet instances running on
Render.


![fix-33732-fma-on-render](https://github.com/user-attachments/assets/8293fa30-0739-4769-bd21-09733a23dadc)
2025-12-23 13:01:32 -05:00
Ashish KuthialaandMike McNeil 2f57b35c95 Clarify approach to engaging with engineers and leaders (#36603)
Added emphasis on understanding the needs of IT and Security leaders to
better partner with them.

---------

Co-authored-by: Mike McNeil <mikermcneil@users.noreply.github.com>
2025-12-23 10:34:12 -06:00
Noah Talerman 6407cb6604 "Sprint" => Milestone (#37642)
- @noahtalerman: We decided to use the Milestone field in GitHub for the
"Release planning" project instead of the custom "Sprint" field. That
way, we only have one field to update when a user story is moved from
one release to another.
- @noahtalerman: I removed the "Sprint" field from the "Release
planning" project.
2025-12-23 11:19:45 -05:00
Rachael Shaw 21e6d60d68 Fix query & policy author styles (#37605)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37582 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing
- [x] QA'd all new/changed functionality manually

### Before
<img width="1624" height="1060" alt="Screenshot 2025-12-19 at 4 24
21 PM"
src="https://github.com/user-attachments/assets/e9bdaaaa-b6cc-4a8a-ade6-bc766128b34b"
/>

### After
<img width="1624" height="1060" alt="Screenshot 2025-12-19 at 4 24
31 PM"
src="https://github.com/user-attachments/assets/a96abfbe-b70a-4273-9324-88b4cf6d6d13"
/>
2025-12-23 10:03:27 -06:00
Nico c2f7c6b1fb Rename About to Vitals (#37634)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #37603

This is a follow-up of https://github.com/fleetdm/fleet/pull/37604 which
only renames the `About` directory and its files to `Vitals`.

## Testing

- [x] QA'd all new/changed functionality manually
2025-12-23 11:51:26 -03:00
fleet-release 0f0b9e8991 Update Fleet-maintained apps (#37631) 2025-12-23 07:51:48 -06:00
Allen Houchins 54f239826e Add Spotify as a Windows FMA (#37630)
This pull request adds full support for managing the installation and
uninstallation of Spotify on Windows via winget in the maintained apps
system. It introduces new configuration and script files, updates output
manifests, and ensures that both install and uninstall processes are
handled silently and robustly.

**Spotify Windows app integration:**

* Added a new manifest `spotify.json` in
`ee/maintained-apps/inputs/winget` to define Spotify's winget package
details, including references to custom install and uninstall scripts.
* Updated `ee/maintained-apps/outputs/apps.json` to register the Spotify
Windows app, enabling it to be discovered and managed by the platform.
* Added a new output manifest
`ee/maintained-apps/outputs/spotify/windows.json` specifying the
installer URL, version, install/uninstall script references, and
detection query for Spotify.

**Installation and uninstallation scripting:**

* Introduced a PowerShell install script `spotify_install.ps1` that
performs a silent installation of Spotify, handling exit codes and
errors gracefully.
* Added a PowerShell uninstall script `spotify_uninstall.ps1` that
locates Spotify's uninstaller via the registry, kills running processes,
and executes the uninstall silently, preserving existing arguments and
handling errors.
2025-12-22 22:19:39 -06:00