Files
Allen Houchins cbcc3a8855 Fix Portfolio Performance FMA ingestion after winget scope correction (#49538)
**Related issue:** N/A — fixes the nightly "Update Fleet-maintained
apps" workflow failure on 2026-07-19 (`panic: ingesting winget app:
failed to find installer for app`).

## Details

The `buchen.portfolio` 0.86.0 winget manifest (released 2026-07-16)
changed the top-level `Scope` from `machine` to `user`. Our input pinned
`installer_scope: machine`, so the ingester's installer-matching loop
found no candidate and panicked, killing the whole nightly
maintained-apps run.

The upstream change was a **correction**, not a mistake: the vendor's
NSIS installer script (`portfolio-product/installer/installer.nsi`)
installs to `$LOCALAPPDATA\Programs` and registers under HKCU, and is
byte-identical between 0.85.0 and 0.86.0 — the installer has been
user-scoped all along; prior winget manifests mislabeled it.

Changes:
- `ee/maintained-apps/inputs/winget/portfolioperformance.json`:
`installer_scope` → `user` (52 other winget inputs already use user
scope)
- `ee/maintained-apps/outputs/portfolioperformance/windows.json`:
regenerated via `go run ./cmd/maintained-apps -slug
portfolioperformance/windows` — version 0.85.0 → 0.86.0, installer URL
and sha256 updated (sha256 matches the manifest's declared
`InstallerSha256`)

No behavior change for hosts: the custom uninstall script already
searches HKCU first, osquery's `programs` table reads per-user (HKU)
uninstall keys so the exists/patched queries keep working, and the
ingester's MSI-only scope branches don't apply to this exe-type app with
custom scripts.

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [ ] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] QA'd all new/changed functionality manually — verified the 0.86.0
winget manifest and vendor NSIS script upstream, and regenerated the
output locally with the ingester (previously panicking, now succeeds).
2026-07-18 21:21:58 -05:00

13 lines
505 B
JSON

{
"name": "Portfolio Performance",
"slug": "portfolioperformance/windows",
"package_identifier": "buchen.portfolio",
"unique_identifier": "Portfolio Performance",
"installer_arch": "x64",
"installer_type": "exe",
"installer_scope": "user",
"install_script_path": "ee/maintained-apps/inputs/winget/scripts/portfolioperformance_install.ps1",
"uninstall_script_path": "ee/maintained-apps/inputs/winget/scripts/portfolioperformance_uninstall.ps1",
"default_categories": ["Productivity"]
}