Skip to content

Update Fleet-maintained apps - #47567

Closed
fleet-release wants to merge 1 commit into
mainfrom
fma-2606131626
Closed

Update Fleet-maintained apps#47567
fleet-release wants to merge 1 commit into
mainfrom
fma-2606131626

Conversation

@fleet-release

@fleet-release fleet-release commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Automated ingestion of latest Fleet-maintained app data.

Summary by CodeRabbit

  • Chores
    • Updated version metadata for 18 maintained applications across Windows and macOS platforms: Android Studio, Audacity, AWS CLI, Bezel, CoconutBattery, Codex, Dropbox, FireAlpaca, Marked, Microsoft Edge, Nextcloud Talk, Notesnook, NVIDIA GeForce NOW, SoundAnchor, Spotify, Syncovery, Typora, and Zen. Each update includes version bumps and corresponding installer checksums.

Generated automatically with cmd/maintained-apps.
@github-actions

Copy link
Copy Markdown
Contributor

Script Diff Results

ee/maintained-apps/outputs/android-studio/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/audacity/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/aws-cli/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/bezel/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/coconutbattery/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/codex-app/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/dropbox/windows.json

=== Install Script (no changes) ===
=== Uninstall // 1035e43a -> f9913fdb ===

--- /tmp/old.2EKTie	2026-06-13 16:32:14.463450828 +0000
+++ /tmp/new.MlX0Hi	2026-06-13 16:32:14.463450828 +0000
@@ -1,4 +1,4 @@
-$product_code = '{C1BD7420-DAD0-58F1-BAD3-C58354BEE1AB}'
+$product_code = '{6D846646-9AD7-5D6C-8BB0-04B336C8EC3A}'
 $timeoutSeconds = 300  # 5 minute timeout
 
 # Fleet uninstalls app using product code that's extracted on upload

ee/maintained-apps/outputs/firealpaca/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/marked-app/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/microsoft-edge/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/nextcloud-talk/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/notesnook/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/nvidia-geforce-now/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/soundanchor/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/spotify/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/syncovery/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/typora/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/zen/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

@coderabbitai

coderabbitai Bot commented Jun 13, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

This PR updates version metadata and installer checksums across 18 maintained third-party applications. Each update includes bumping the version string, adjusting SQL version-compare thresholds used by patch-detection queries, updating installer download URLs to point to new release artifacts, and replacing SHA-256 checksums for installer verification. Dropbox's update also includes a new MSI product-code GUID for the uninstall script. Typora's change corrects an installer URL hostname.

Possibly related PRs

  • fleetdm/fleet#47485: Overlapping Android Studio Windows version bump and matching version/query updates in the same configuration file.
  • fleetdm/fleet#46810: Direct overlap with AWS CLI Windows configuration updates including version-compare thresholds, installer URL, and SHA-256 changes.
  • fleetdm/fleet#46451: Concurrent Microsoft Edge Windows version bump with matching query and checksum updates.
🚥 Pre-merge checks | ✅ 3 | ❌ 2

❌ Failed checks (1 warning, 1 inconclusive)

Check name Status Explanation Resolution
Description check ⚠️ Warning The PR description is minimal and lacks required checklist items, related issue reference, and detailed change rationale expected by the repository template. Expand description with relevant checklist items (e.g., 'Changes file added'), add a related issue reference, and provide context about why these app versions were updated.
Title check ❓ Inconclusive The PR title 'Update Fleet-maintained apps' is generic and vague, lacking specific detail about which apps were updated or the nature of the changes. Consider a more specific title like 'Update Fleet-maintained app versions to latest releases' to better convey the changeset scope.
✅ Passed checks (3 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fma-2606131626

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Caution

Some comments are outside the diff and can’t be posted inline due to platform limitations.

⚠️ Outside diff range comments (1)
ee/maintained-apps/outputs/firealpaca/darwin.json (1)

9-12: ⚠️ Potential issue | 🟠 Major | ⚡ Quick win

FireAlpaca bypasses installer integrity verification.

The static download URL and "sha256": "no_check" setting mean no cryptographic verification of the downloaded installer. This weakens security posture against supply-chain attacks (MITM, compromised CDN).

While this pre-dates the current PR, consider whether FireAlpaca's release mechanism supports versioned URLs and checksums. If not, document this as accepted risk.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ee/maintained-apps/outputs/firealpaca/darwin.json` around lines 9 - 12, The
manifest in ee/maintained-apps/outputs/firealpaca/darwin.json currently uses a
static installer_url and "sha256": "no_check", which disables integrity
verification; update the manifest so installer_url points to a
versioned/release-specific download (not a generic download page) and replace
"sha256": "no_check" with the real SHA-256 checksum of the installer for that
specific release (maintain the matching
install_script_ref/uninstall_script_ref), or if no versioned URL/checksum is
published by FireAlpaca, add a clear comment in this file and project
documentation marking this as an accepted risk and why (citing lack of
publisher-provided checksums), so the security trade-off is recorded.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Outside diff comments:
In `@ee/maintained-apps/outputs/firealpaca/darwin.json`:
- Around line 9-12: The manifest in
ee/maintained-apps/outputs/firealpaca/darwin.json currently uses a static
installer_url and "sha256": "no_check", which disables integrity verification;
update the manifest so installer_url points to a versioned/release-specific
download (not a generic download page) and replace "sha256": "no_check" with the
real SHA-256 checksum of the installer for that specific release (maintain the
matching install_script_ref/uninstall_script_ref), or if no versioned
URL/checksum is published by FireAlpaca, add a clear comment in this file and
project documentation marking this as an accepted risk and why (citing lack of
publisher-provided checksums), so the security trade-off is recorded.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 6aadce89-a7d8-4ad1-b357-168a06e74341

📥 Commits

Reviewing files that changed from the base of the PR and between 268c918 and 1bd7d13.

📒 Files selected for processing (18)
  • ee/maintained-apps/outputs/android-studio/windows.json
  • ee/maintained-apps/outputs/audacity/windows.json
  • ee/maintained-apps/outputs/aws-cli/windows.json
  • ee/maintained-apps/outputs/bezel/darwin.json
  • ee/maintained-apps/outputs/coconutbattery/darwin.json
  • ee/maintained-apps/outputs/codex-app/darwin.json
  • ee/maintained-apps/outputs/dropbox/windows.json
  • ee/maintained-apps/outputs/firealpaca/darwin.json
  • ee/maintained-apps/outputs/marked-app/darwin.json
  • ee/maintained-apps/outputs/microsoft-edge/windows.json
  • ee/maintained-apps/outputs/nextcloud-talk/darwin.json
  • ee/maintained-apps/outputs/notesnook/darwin.json
  • ee/maintained-apps/outputs/nvidia-geforce-now/darwin.json
  • ee/maintained-apps/outputs/soundanchor/darwin.json
  • ee/maintained-apps/outputs/spotify/windows.json
  • ee/maintained-apps/outputs/syncovery/darwin.json
  • ee/maintained-apps/outputs/typora/darwin.json
  • ee/maintained-apps/outputs/zen/darwin.json

@github-actions

Copy link
Copy Markdown
Contributor

Closing in favor of #47568.

@github-actions github-actions Bot closed this Jun 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants