Skip to content

Update Fleet-maintained apps - #49763

Closed
fleet-release wants to merge 1 commit into
mainfrom
fma-2607221721
Closed

Update Fleet-maintained apps#49763
fleet-release wants to merge 1 commit into
mainfrom
fma-2607221721

Conversation

@fleet-release

@fleet-release fleet-release commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Automated ingestion of latest Fleet-maintained app data.

FMA installer verification report

Mode: report-only · Scope: changed vs. HEAD · 140 app(s) verified, 10 failure(s), 0 warning(s)

App Version Hash Signature Notarization Result
adlock/darwin 2.1.8.9 📝 no_check URL; observed 275749317e9f908a3406d2f12c1bba9fe4692c5a9174a7a83241360aa557875e ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
advanced-installer/windows 23.9 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Timestamp Server Signature verification: fa… ❌ FAIL
akiflow/darwin 2.78.15 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
amazon-corretto-11/windows 11.0.32.9 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
amazon-corretto-17/windows 17.0.20.8 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
amazon-corretto-21/windows 21.0.12.8 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
amazon-corretto-25/windows 25.0.4.7 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
amazon-corretto-26/windows 26.0.2.10 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
amazon-corretto-8/windows 1.8.0.502 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
amazon-corretto-jre-8/windows 1.8.0.502 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
anka-virtualization/darwin 3.9.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
aptakube/windows 1.18.6 ✅ recomputed hash matches manifest 📝 signed by [Zandar Labs SL] (no pin yet) ✅ PASS
aws-cli/windows 2.36.5 ✅ recomputed hash matches manifest 📝 signed by [Amazon Web Services, Inc.] (no pin yet) ✅ PASS
aws-vpn-client/darwin 5.4.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
aws-vpn-client/windows 5.4.2 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com Services LLC] (no pin yet) ✅ PASS
azul-zulu-25-jdk/windows 25.36.15 ✅ recomputed hash matches manifest 📝 signed by [Azul Systems, Inc.] (no pin yet) ✅ PASS
badgeify/darwin 1.14.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
bettertouchtool/darwin 6.651 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
betterzip/darwin 6.0 ❌ manifest claims 19e2bf96ca0d33be907528828b4e0d27edd6acfe8f3317431d784537ebc96723 but do… ⏭️ macOS signature verification requires a macOS host; deferred to validator ❌ FAIL
beyond-compare/darwin 5.2.4.32425 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
binance/darwin 2.4.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
chatgpt/darwin 26.715.72359 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
cisco-jabber/windows 15.3.0.61167 ✅ recomputed hash matches manifest 📝 signed by [CISCO SYSTEMS, INC.] (no pin yet) ✅ PASS
claude/darwin 1.24012.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
claude/windows 1.24012.0 ✅ recomputed hash matches manifest ⏭️ cannot verify .msix Authenticode at ingest; deferred to validator ✅ PASS
cleanmymac/darwin 5.5.7 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
cleanshot/darwin 4.8.10 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
clop/darwin 3.3.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
cloudflare-warp/darwin 2026.6.880.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
cloudflare-warp/windows 26.6.880.0 ✅ recomputed hash matches manifest 📝 signed by [Cloudflare, Inc.] (no pin yet) ✅ PASS
comet/windows 150.0.7871.230 ✅ recomputed hash matches manifest 📝 signed by [PERPLEXITY AI, INC.] (no pin yet) ✅ PASS
companion/darwin 5.0.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
crossover/darwin 26.3.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
cursor/darwin 3.12.30 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
dataflare/darwin 3.1.5 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
dbgate/darwin 7.2.3 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
devolutions-launcher/windows 2026.2.16.0 ✅ recomputed hash matches manifest 📝 signed by [Devolutions Inc] (no pin yet) ✅ PASS
discord/darwin 0.0.402 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
discord/windows 1.0.9249 ✅ recomputed hash matches manifest 📝 signed by [Discord Inc.] (no pin yet) ✅ PASS
displaylink/darwin 16.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
downie/darwin 4.12.11 ❌ downloading installer: performing request for URL https://software.charliemonroe.net/tr… ⏭️ installer download failed ❌ FAIL
drawio/darwin 30.4.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
dropbox/darwin 262.4.3183 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
element/darwin 1.12.24 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
emclient/darwin 10.4.5642 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
emclient/windows 10.4.5642 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Timestamp Server Signature verification: fa… ❌ FAIL
fantastical/darwin 4.1.17 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
figma/windows 126.7.8 ✅ recomputed hash matches manifest 📝 signed by [Figma, Inc.] (no pin yet) ✅ PASS
filen/darwin 3.0.53 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
firefox/darwin 153.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
firefox@esr/darwin 140.13.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
firefox@nightly/darwin 155.0a1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
firefox@nightly/windows 155.2607.2120.0 ✅ recomputed hash matches manifest ⏭️ cannot verify .msix Authenticode at ingest; deferred to validator ✅ PASS
flexoptix/darwin 5.66.0-latest ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
fontbase/darwin 2026.5.23 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
gitify/darwin 7.0.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
gitkraken/darwin 12.3.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
google-chrome/darwin 150.0.7871.182 📝 no_check URL; observed 7d0f07ca07504828e2f8fcc994e9f2c8459c0d98557c8f3573fdb30a208edb7b ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
google-chrome/windows 150.0.7871.182 📝 no_check URL; observed e6e60414ad1c5cd7b2c374002635e1d872e5c8059b7152cdec5b74c70c25a935 📝 signed by [Google LLC] (no pin yet) ✅ PASS
granola/darwin 7.427.9 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
granola/windows 7.427.9 ✅ recomputed hash matches manifest 📝 signed by [Granola Labs Ltd] (no pin yet) ✅ PASS
hive-app/darwin 1.2.20 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
i1profiler/darwin 3.8.7.19194 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
jami/darwin 2.41 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
jamovi/darwin 2.7.38.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
keyboard-maestro/darwin 11.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
kiro/darwin 1.0.198 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
kiro/windows 1.0.198 ✅ recomputed hash matches manifest 📝 signed by [Amazon.com, Inc.] (no pin yet) ✅ PASS
lookaway/darwin 2.3.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
loom/darwin 0.362.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
loom/windows 0.362.1 ✅ recomputed hash matches manifest 📝 signed by [Loom, Inc.] (no pin yet) ✅ PASS
macpacker/darwin 0.18.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
macwhisper/darwin 14.4.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
mailspring/darwin 1.23.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
megasync/darwin 6.5.0.2 📝 no_check URL; observed f76f01706c4d33b9ffd37def07547b73f3e3fa2e1e6a120547cc6ec9d5294f7e ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
megasync/windows 6.5.0.2 ✅ recomputed hash matches manifest 📝 signed by [Mega Limited] (no pin yet) ✅ PASS
microsoft-365-copilot/darwin 1.2607.1302 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
microsoft-excel/darwin 16.111.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
microsoft-onenote/darwin 16.111.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
microsoft-powerpoint/darwin 16.111.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
microsoft-teams/windows 26183.1903.4892.4448 ✅ recomputed hash matches manifest ⏭️ cannot verify .msix Authenticode at ingest; deferred to validator ✅ PASS
microsoft-word/darwin 16.111.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
milanote/darwin 3.18.116 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
miro/darwin 0.11.162 📝 no_check URL; observed 79cfc9c65a4e66250fbbbb5145249175ac2e291c0f01e736ec7b8a912bcfa93b ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
miro/windows 0.11.162 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Signature verification: failed ❌ FAIL
naps2/darwin 8.3.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
naps2/windows 8.3.1 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Signature verification: failed ❌ FAIL
nordpass/darwin 7.9.2 📝 no_check URL; observed 43b45373992603631b12c3774f79c6bec0597bdf355818746d806cee088c8514 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
notepadexe/darwin 1.5.5 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
notion/darwin 7.27.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
notion/windows 7.27.0 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Timestamp Server Signature verification: fa… ❌ FAIL
nova/darwin 14 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
okta-verify/darwin 9.67.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
opencode-desktop/darwin 1.18.4 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
origami-studio/darwin 224.0.0.0.0 📝 no_check URL; observed 024170e9472d5b1e2c9ab187c564e25343add97ff0cd90136f695dbf7e1fc860 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
postman/darwin 12.20.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
postman/windows 12.20.2 ✅ recomputed hash matches manifest 📝 signed by [Postman, Inc.] (no pin yet) ✅ PASS
power-bi/windows 2.156.951.0 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Signature verification: failed ❌ FAIL
powerphotos/darwin 3.4.2 📝 no_check URL; observed 555835ca35a350f1c757f5fdb4811bfd2c4372a368c7fbbe6e5b25a83dbb56a8 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
prisma-browser/windows 150.49.7.182 ✅ recomputed hash matches manifest 📝 signed by [Palo Alto Networks, Inc] (no pin yet) ✅ PASS
pritunl/windows 1.3.4696.56 ✅ recomputed hash matches manifest 📝 signed by [Pritunl Inc.] (no pin yet) ✅ PASS
proton-drive/windows 3.0.3 ✅ recomputed hash matches manifest 📝 signed by [Proton AG] (no pin yet) ✅ PASS
pycharm/darwin 2026.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
qlab/darwin 5.6.3 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
remote-desktop-manager/darwin 2026.2.3.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
remote-desktop-manager/windows 2026.2.16.0 ✅ recomputed hash matches manifest 📝 signed by [Devolutions Inc] (no pin yet) ✅ PASS
reqable/darwin 3.2.13 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
reqable/windows 3.2.13 ✅ recomputed hash matches manifest 📝 signed by [Shanghai Reqable Information Technology Co., Ltd.] (no pin yet) ✅ PASS
rive/darwin 0.8.5252 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
royal-tsx/windows 7.4.50721.0 ✅ recomputed hash matches manifest 📝 signed by [Royal Apps GmbH] (no pin yet) ✅ PASS
rstudio/windows 2026.07.1+147 ✅ recomputed hash matches manifest 📝 signed by [Posit Software, PBC] (no pin yet) ✅ PASS
rubymine/darwin 2026.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
rubymine/windows 2026.2 ✅ recomputed hash matches manifest 📝 signed by [JetBrains s.r.o.] (no pin yet) ✅ PASS
rustrover/darwin 2026.2 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
rustrover/windows 2026.2 ✅ recomputed hash matches manifest 📝 signed by [JetBrains s.r.o.] (no pin yet) ✅ PASS
setapp/darwin 3.54.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
slack/darwin 4.51.180 📝 no_check URL; observed 1c6e82dec528a714c383b46bd9ecf48d34fa9a521e7c9b76e2910427ecf484e0 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
slack/windows 4.51.180 ✅ recomputed hash matches manifest ⏭️ cannot verify .msix Authenticode at ingest; deferred to validator ✅ PASS
snagit/darwin 2026.3.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
soundsource/darwin 6.1.0 📝 no_check URL; observed 646c8be0b8debbbfd4cf4d630edc38da925dae7274c18215851147cdf56bbed2 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
spokenly/darwin 2.25.4 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
superwhisper/darwin 2.16.5 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
tableau-prep/darwin 2026.2.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
tableau/darwin 2026.2.1 ❌ downloading installer: validation failed: fleet_maintained_app.url Couldn't download ma… ⏭️ installer download failed ❌ FAIL
telegram/windows 7.0.4 ✅ recomputed hash matches manifest 📝 signed by [Telegram FZ-LLC] (no pin yet) ✅ PASS
teleport-connect/darwin 18.10.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
teleport-connect/windows 18.10.1 ✅ recomputed hash matches manifest ❌ Authenticode signature verification failed: Signature verification: failed ❌ FAIL
teleport-suite/darwin 18.10.1 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
thunderbird/darwin 153.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
tor-browser/darwin 15.0.19 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
tuple/darwin 3.1.3 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
typora/windows 1.14.7 ✅ recomputed hash matches manifest 📝 signed by [Qiyun (Shanghai) Technology Co., Ltd.] (no pin yet) ✅ PASS
virtualbox/darwin 7.2.14 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
vivaldi/darwin 8.1.4087.56 📝 no_check URL; observed c83c898a17eda61ac79a744fef90604cabe322c27fd1c46050c4e10377e1c343 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
webcatalog/darwin 77.5.0 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
webex/darwin 46.7.0.35472 📝 no_check URL; observed a0bfa017828054c20f4c3ff8ae3a5232cede9f0feab4926f65c09038003a35b6 ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
webex/windows 46.7.0.35472 ✅ recomputed hash matches manifest 📝 signed by [Cisco Systems, Inc.] (no pin yet) ✅ PASS
wechat/darwin 4.1.12.25 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
whatsapp/darwin 26.29.18 📝 no_check URL; observed f19d1467c04768c3b17edb83004d5c1e5fcdaad1ed4fbe64fb704d43f4ea5adf ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
wispr-flow/darwin 1.6.182 ✅ recomputed hash matches manifest ⏭️ macOS signature verification requires a macOS host; deferred to validator ✅ PASS
Failure and warning details

advanced-installer/windows (23.9)

  • ❌ Authenticode signature verification failed: Timestamp Server Signature verification: failed

betterzip/darwin (6.0)

  • ❌ SHA256 mismatch: manifest claims 19e2bf96ca0d33be907528828b4e0d27edd6acfe8f3317431d784537ebc96723, downloaded bytes hash to 10cef4dad336335fdd0c989ad4230f7850573c2bff139d168dc9ee704fd5e767

downie/darwin (4.12.11)

emclient/windows (10.4.5642)

  • ❌ Authenticode signature verification failed: Timestamp Server Signature verification: failed

miro/windows (0.11.162)

  • ❌ Authenticode signature verification failed: Signature verification: failed

naps2/windows (8.3.1)

  • ❌ Authenticode signature verification failed: Signature verification: failed

notion/windows (7.27.0)

  • ❌ Authenticode signature verification failed: Timestamp Server Signature verification: failed

power-bi/windows (2.156.951.0)

  • ❌ Authenticode signature verification failed: Signature verification: failed

tableau/darwin (2026.2.1)

teleport-connect/windows (18.10.1)

  • ❌ Authenticode signature verification failed: Signature verification: failed

Summary by CodeRabbit

  • Updates
    • Updated maintained app packages across Windows and macOS to their latest releases, including Installer, Akiflow, Cursor, Granola, Teams, RustRover, WhatsApp, and many others.
    • Refreshed download links, version detection, and package verification data for reliable installation and upgrade handling.
    • Updated Firefox Nightly and PowerPhotos release metadata.
  • Bug Fixes
    • Improved Setapp cleanup by removing additional background services and related application data during uninstall.

Generated automatically with cmd/maintained-apps.
@github-actions

Copy link
Copy Markdown
Contributor

Script Diff Results

ee/maintained-apps/outputs/advanced-installer/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/akiflow/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/beyond-compare/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/cleanmymac/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/clop/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/comet/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/cursor/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/dataflare/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/firefox@nightly/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/granola/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/granola/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/lookaway/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/macwhisper/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/megasync/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/microsoft-teams/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/powerphotos/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/prisma-browser/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/pritunl/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/rustrover/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/setapp/darwin.json

=== Install Script (no changes) ===
=== Uninstall // e23bd29d -> 9ef05eb6 ===

--- /tmp/old.y36rsS	2026-07-22 17:37:23.330978176 +0000
+++ /tmp/new.m4h0Ln	2026-07-22 17:37:23.330978176 +0000
@@ -5,6 +5,76 @@
 LOGGED_IN_USER=$(scutil <<< "show State:/Users/ConsoleUser" | awk '/Name :/ { print $3 }')
 # functions
 
+remove_launchctl_service() {
+  local service="$1"
+  local booleans=("true" "false")
+  local plist_status
+  local paths
+  local should_sudo
+
+  echo "Removing launchctl service ${service}"
+
+  # A wildcard label can't be used with launchctl or as a plist name, so expand
+  # it to the labels of currently loaded services that match the pattern.
+  local services=("$service")
+  if [[ "$service" == *"*"* ]]; then
+    local regex
+    # Escape regex metacharacters, turn '*' into '.*', and anchor the pattern so
+    # it matches a full label rather than a substring.
+    regex=$(printf '%s' "$service" | sed -e 's/[][(){}.^$+?|\\]/\\&/g' -e 's/\*/.*/g')
+    regex="^${regex}$"
+    services=()
+    local id
+    # Match every loaded job by label regardless of PID; launchctl list reports
+    # loaded-but-not-running jobs with a "-" in the PID column.
+    while read -r _ _ id; do
+      [[ "$id" =~ $regex ]] && services+=("$id")
+    done < <(launchctl list 2>/dev/null | tail -n +2)
+    if [[ ${#services[@]} -eq 0 ]]; then
+      echo "No loaded launchctl service matches ${service}"
+      return
+    fi
+  fi
+
+  local service_label
+  for service_label in "${services[@]}"; do
+    for should_sudo in "${booleans[@]}"; do
+      plist_status=$(launchctl list "${service_label}" 2>/dev/null)
+
+      if [[ $plist_status == \{* ]]; then
+        if [[ $should_sudo == "true" ]]; then
+          sudo launchctl remove "${service_label}"
+        else
+          launchctl remove "${service_label}"
+        fi
+        sleep 1
+      fi
+
+      paths=(
+        "/Library/LaunchAgents/${service_label}.plist"
+        "/Library/LaunchDaemons/${service_label}.plist"
+      )
+
+      # if not using sudo, prepend the home directory to the paths
+      if [[ $should_sudo == "false" ]]; then
+        for i in "${!paths[@]}"; do
+          paths[i]="${HOME}${paths[i]}"
+        done
+      fi
+
+      for path in "${paths[@]}"; do
+        if [[ -e "$path" ]]; then
+          if [[ $should_sudo == "true" ]]; then
+            sudo rm -f -- "$path"
+          else
+            rm -f -- "$path"
+          fi
+        fi
+      done
+    done
+  done
+}
+
 trash() {
   local logged_in_user="$1"
   local target_file="$2"
@@ -52,10 +122,19 @@
   fi
 }
 
+remove_launchctl_service 'com.setapp.DesktopClient.SetappAgent'
+remove_launchctl_service 'com.setapp.DesktopClient.SetappAssistant'
+remove_launchctl_service 'com.setapp.DesktopClient.SetappLauncher'
+remove_launchctl_service 'com.setapp.DesktopClient.SetappUpdater'
 sudo rm -rf "$APPDIR/Setapp.app"
 trash $LOGGED_IN_USER '~/Library/Application Scripts/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'
+trash $LOGGED_IN_USER '~/Library/Application Support/Setapp*'
 trash $LOGGED_IN_USER '~/Library/Caches/com.setapp.DesktopClient'
 trash $LOGGED_IN_USER '~/Library/Caches/com.setapp.DesktopClient.SetappAgent'
+trash $LOGGED_IN_USER '~/Library/Containers/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'
+trash $LOGGED_IN_USER '~/Library/HTTPStorages/com.setapp.DesktopClient*'
+trash $LOGGED_IN_USER '~/Library/LaunchAgents/com.setapp.DesktopClient.*plist'
 trash $LOGGED_IN_USER '~/Library/Logs/Setapp'
+trash $LOGGED_IN_USER '~/Library/Preferences/com.setapp.DesktopClient.plist'
 trash $LOGGED_IN_USER '~/Library/Preferences/com.setapp.DesktopClient.SetappAgent.plist'
 trash $LOGGED_IN_USER '~/Library/Saved Application State/com.setapp.DesktopClient.savedState'

ee/maintained-apps/outputs/typora/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/vivaldi/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/wechat/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/whatsapp/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

@coderabbitai

coderabbitai Bot commented Jul 22, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

Walkthrough

Updated 23 maintained-app JSON entries across Windows and macOS with newer versions, patched-query thresholds, installer URLs, and SHA-256 checksums. Existing detection and script references remain unchanged for most entries. Setapp also received a new uninstall script that removes related launchctl services and expands cleanup across user Library locations.

Possibly related PRs

  • fleetdm/fleet#49743 — Updates overlapping maintained-app entries with matching version, query, installer, and checksum changes.
  • fleetdm/fleet#49759 — Updates the same maintained-app manifest structure and several overlapping entries.
  • fleetdm/fleet#49719 — Updates the Typora manifest version and patched-query target.
🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 warning)

Check name Status Explanation Resolution
Description check ⚠️ Warning The description gives a summary and report, but it omits the required template sections and checklist items. Fill in the repository template: add the related issue, checklist items, testing details, database/migration sections, and any applicable notes.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title is concise and accurately summarizes the bulk update to Fleet-maintained apps.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fma-2607221721

Warning

There were issues while running some tools. Please review the errors and either fix the tool's configuration or disable the tool if it's a critical failure.

🔧 Checkov (3.3.8)
ee/maintained-apps/outputs/advanced-installer/windows.json

Traceback (most recent call last):
File "/usr/local/bin/checkov", line 2, in
from checkov.main import Checkov
ModuleNotFoundError: No module named 'checkov'

ee/maintained-apps/outputs/akiflow/darwin.json

Traceback (most recent call last):
File "/usr/local/bin/checkov", line 2, in
from checkov.main import Checkov
ModuleNotFoundError: No module named 'checkov'

ee/maintained-apps/outputs/beyond-compare/darwin.json

Traceback (most recent call last):
File "/usr/local/bin/checkov", line 2, in
from checkov.main import Checkov
ModuleNotFoundError: No module named 'checkov'

  • 21 others

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ee/maintained-apps/outputs/setapp/darwin.json`:
- Line 20: Update remove_launchctl_service to resolve the logged-in console
user’s UID and use launchctl asuser with the user’s gui/<uid> domain to boot out
each Setapp label, rather than calling launchctl list/remove in the
root/current-process domain. Keep removal of both user and system plist
locations as appropriate, but ensure the user LaunchAgents are resolved from
/Users/<logged-in-user> instead of root $HOME; preserve wildcard label matching
and the existing trash cleanup.
- Line 20: The cleanup script must handle cases where LOGGED_IN_USER is empty,
root, or loginwindow before invoking trash. Add validation after determining
LOGGED_IN_USER and skip the per-user trash calls when no valid GUI console user
exists; preserve system-wide cleanup such as launchctl removal and deleting
Setapp.app.
🪄 Autofix (Beta)

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro

Run ID: 2454856f-4c5e-4997-883a-ea86f2ded4be

📥 Commits

Reviewing files that changed from the base of the PR and between 940706c and 9af1e07.

📒 Files selected for processing (24)
  • ee/maintained-apps/outputs/advanced-installer/windows.json
  • ee/maintained-apps/outputs/akiflow/darwin.json
  • ee/maintained-apps/outputs/beyond-compare/darwin.json
  • ee/maintained-apps/outputs/cleanmymac/darwin.json
  • ee/maintained-apps/outputs/clop/darwin.json
  • ee/maintained-apps/outputs/comet/windows.json
  • ee/maintained-apps/outputs/cursor/darwin.json
  • ee/maintained-apps/outputs/dataflare/darwin.json
  • ee/maintained-apps/outputs/firefox@nightly/darwin.json
  • ee/maintained-apps/outputs/granola/darwin.json
  • ee/maintained-apps/outputs/granola/windows.json
  • ee/maintained-apps/outputs/lookaway/darwin.json
  • ee/maintained-apps/outputs/macwhisper/darwin.json
  • ee/maintained-apps/outputs/megasync/windows.json
  • ee/maintained-apps/outputs/microsoft-teams/windows.json
  • ee/maintained-apps/outputs/powerphotos/darwin.json
  • ee/maintained-apps/outputs/prisma-browser/windows.json
  • ee/maintained-apps/outputs/pritunl/windows.json
  • ee/maintained-apps/outputs/rustrover/windows.json
  • ee/maintained-apps/outputs/setapp/darwin.json
  • ee/maintained-apps/outputs/typora/windows.json
  • ee/maintained-apps/outputs/vivaldi/darwin.json
  • ee/maintained-apps/outputs/wechat/darwin.json
  • ee/maintained-apps/outputs/whatsapp/darwin.json

"refs": {
"1ba0fd31": "#!/bin/bash\n\n# variables\nAPPDIR=\"/Applications/\"\nTMPDIR=$(dirname \"$(realpath \"$INSTALLER_PATH\")\")\n# functions\n\nquit_and_track_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local timeout_duration=10\n\n # check if the application is running\n local app_running\n app_running=$(osascript -e \"application id \\\"$bundle_id\\\" is running\" 2>/dev/null)\n if [[ \"$app_running\" != \"true\" ]]; then\n eval \"export $var_name=0\"\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping quitting application ID '$bundle_id'.\"\n eval \"export $var_name=0\"\n return\n fi\n\n # App was running, mark it for relaunch\n eval \"export $var_name=1\"\n echo \"Application '$bundle_id' was running; will relaunch after installation.\"\n\n echo \"Quitting application '$bundle_id'...\"\n\n # try to quit the application within the timeout period\n local quit_success=false\n SECONDS=0\n while (( SECONDS < timeout_duration )); do\n if osascript -e \"tell application id \\\"$bundle_id\\\" to quit\" >/dev/null 2>&1; then\n if ! pgrep -f \"$bundle_id\" >/dev/null 2>&1; then\n echo \"Application '$bundle_id' quit successfully.\"\n quit_success=true\n break\n fi\n fi\n sleep 1\n done\n\n if [[ \"$quit_success\" = false ]]; then\n echo \"Application '$bundle_id' did not quit.\"\n fi\n}\n\n\nrelaunch_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local was_running\n\n # Check if the app was running before installation\n eval \"was_running=\\$$var_name\"\n if [[ \"$was_running\" != \"1\" ]]; then\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping relaunching application ID '$bundle_id'.\"\n return\n fi\n\n echo \"Relaunching application '$bundle_id'...\"\n\n # Launch the app in the logged-in user's GUI session. Apps launched by root\n # won't register with the user's Dock/GUI, so run 'open' as the console user.\n # Use 'launchctl asuser' to bootstrap into the console user's Mach namespace\n # and GUI session — 'sudo -u' alone doesn't do this, which can cause\n # LSOpenURLsWithRole() failures even when 'open' exits 0.\n local open_status=0\n if [[ $EUID -eq 0 ]]; then\n local console_uid\n console_uid=$(id -u \"$console_user\")\n /bin/launchctl asuser \"$console_uid\" sudo -u \"$console_user\" open -b \"$bundle_id\" >/dev/null 2>&1 || open_status=$?\n else\n open -b \"$bundle_id\" >/dev/null 2>&1 || open_status=$?\n fi\n\n if [[ $open_status -eq 0 ]]; then\n echo \"Application '$bundle_id' relaunched successfully.\"\n else\n echo \"Failed to relaunch application '$bundle_id'.\"\n fi\n}\n\n\n# extract contents\nunzip \"$INSTALLER_PATH\" -d \"$TMPDIR\"\n# copy to the applications folder\nquit_and_track_application 'com.setapp.DesktopClient.SetappAgent'\nif [ -d \"$APPDIR/Setapp.app\" ]; then\n\tsudo mv \"$APPDIR/Setapp.app\" \"$TMPDIR/Setapp.app.bkp\"\nfi\nsudo cp -R \"$TMPDIR/Setapp.app\" \"$APPDIR\"\nrelaunch_application 'com.setapp.DesktopClient.SetappAgent'\n",
"e23bd29d": "#!/bin/bash\n\n# variables\nAPPDIR=\"/Applications/\"\nLOGGED_IN_USER=$(scutil <<< \"show State:/Users/ConsoleUser\" | awk '/Name :/ { print $3 }')\n# functions\n\ntrash() {\n local logged_in_user=\"$1\"\n local target_file=\"$2\"\n local timestamp=\"$(date +%Y-%m-%d-%s)\"\n local rand=\"$(jot -r 1 0 99999)\"\n\n # replace ~ with /Users/$logged_in_user\n if [[ \"$target_file\" == ~* ]]; then\n target_file=\"/Users/$logged_in_user${target_file:1}\"\n fi\n\n local trash=\"/Users/$logged_in_user/.Trash\"\n\n # If the target contains glob characters, expand it and move each match.\n if [[ \"$target_file\" == *[*?[]* ]]; then\n local file file_name\n local matched=false\n local i=0\n # compgen -G expands the (quoted) pattern itself, so paths containing\n # spaces glob correctly; reading line by line keeps each match intact.\n while IFS= read -r file; do\n [[ -n \"$file\" ]] || continue\n [[ -e \"$file\" || -L \"$file\" ]] || continue\n matched=true\n i=$((i + 1))\n file_name=\"$(basename \"$file\")\"\n echo \"removing $file.\"\n # The per-match counter keeps matches that share a basename from\n # overwriting each other in the trash.\n mv -f \"$file\" \"$trash/${file_name}_${timestamp}_${rand}_${i}\"\n done < <(compgen -G \"$target_file\" 2>/dev/null)\n if [[ \"$matched\" == false ]]; then\n echo \"$target_file doesn't exist.\"\n fi\n return\n fi\n\n local file_name=\"$(basename \"${target_file}\")\"\n\n if [[ -e \"$target_file\" ]]; then\n echo \"removing $target_file.\"\n mv -f \"$target_file\" \"$trash/${file_name}_${timestamp}_${rand}\"\n else\n echo \"$target_file doesn't exist.\"\n fi\n}\n\nsudo rm -rf \"$APPDIR/Setapp.app\"\ntrash $LOGGED_IN_USER '~/Library/Application Scripts/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'\ntrash $LOGGED_IN_USER '~/Library/Caches/com.setapp.DesktopClient'\ntrash $LOGGED_IN_USER '~/Library/Caches/com.setapp.DesktopClient.SetappAgent'\ntrash $LOGGED_IN_USER '~/Library/Logs/Setapp'\ntrash $LOGGED_IN_USER '~/Library/Preferences/com.setapp.DesktopClient.SetappAgent.plist'\ntrash $LOGGED_IN_USER '~/Library/Saved Application State/com.setapp.DesktopClient.savedState'\n"
"9ef05eb6": "#!/bin/bash\n\n# variables\nAPPDIR=\"/Applications/\"\nLOGGED_IN_USER=$(scutil <<< \"show State:/Users/ConsoleUser\" | awk '/Name :/ { print $3 }')\n# functions\n\nremove_launchctl_service() {\n local service=\"$1\"\n local booleans=(\"true\" \"false\")\n local plist_status\n local paths\n local should_sudo\n\n echo \"Removing launchctl service ${service}\"\n\n # A wildcard label can't be used with launchctl or as a plist name, so expand\n # it to the labels of currently loaded services that match the pattern.\n local services=(\"$service\")\n if [[ \"$service\" == *\"*\"* ]]; then\n local regex\n # Escape regex metacharacters, turn '*' into '.*', and anchor the pattern so\n # it matches a full label rather than a substring.\n regex=$(printf '%s' \"$service\" | sed -e 's/[][(){}.^$+?|\\\\]/\\\\&/g' -e 's/\\*/.*/g')\n regex=\"^${regex}$\"\n services=()\n local id\n # Match every loaded job by label regardless of PID; launchctl list reports\n # loaded-but-not-running jobs with a \"-\" in the PID column.\n while read -r _ _ id; do\n [[ \"$id\" =~ $regex ]] && services+=(\"$id\")\n done < <(launchctl list 2>/dev/null | tail -n +2)\n if [[ ${#services[@]} -eq 0 ]]; then\n echo \"No loaded launchctl service matches ${service}\"\n return\n fi\n fi\n\n local service_label\n for service_label in \"${services[@]}\"; do\n for should_sudo in \"${booleans[@]}\"; do\n plist_status=$(launchctl list \"${service_label}\" 2>/dev/null)\n\n if [[ $plist_status == \\{* ]]; then\n if [[ $should_sudo == \"true\" ]]; then\n sudo launchctl remove \"${service_label}\"\n else\n launchctl remove \"${service_label}\"\n fi\n sleep 1\n fi\n\n paths=(\n \"/Library/LaunchAgents/${service_label}.plist\"\n \"/Library/LaunchDaemons/${service_label}.plist\"\n )\n\n # if not using sudo, prepend the home directory to the paths\n if [[ $should_sudo == \"false\" ]]; then\n for i in \"${!paths[@]}\"; do\n paths[i]=\"${HOME}${paths[i]}\"\n done\n fi\n\n for path in \"${paths[@]}\"; do\n if [[ -e \"$path\" ]]; then\n if [[ $should_sudo == \"true\" ]]; then\n sudo rm -f -- \"$path\"\n else\n rm -f -- \"$path\"\n fi\n fi\n done\n done\n done\n}\n\ntrash() {\n local logged_in_user=\"$1\"\n local target_file=\"$2\"\n local timestamp=\"$(date +%Y-%m-%d-%s)\"\n local rand=\"$(jot -r 1 0 99999)\"\n\n # replace ~ with /Users/$logged_in_user\n if [[ \"$target_file\" == ~* ]]; then\n target_file=\"/Users/$logged_in_user${target_file:1}\"\n fi\n\n local trash=\"/Users/$logged_in_user/.Trash\"\n\n # If the target contains glob characters, expand it and move each match.\n if [[ \"$target_file\" == *[*?[]* ]]; then\n local file file_name\n local matched=false\n local i=0\n # compgen -G expands the (quoted) pattern itself, so paths containing\n # spaces glob correctly; reading line by line keeps each match intact.\n while IFS= read -r file; do\n [[ -n \"$file\" ]] || continue\n [[ -e \"$file\" || -L \"$file\" ]] || continue\n matched=true\n i=$((i + 1))\n file_name=\"$(basename \"$file\")\"\n echo \"removing $file.\"\n # The per-match counter keeps matches that share a basename from\n # overwriting each other in the trash.\n mv -f \"$file\" \"$trash/${file_name}_${timestamp}_${rand}_${i}\"\n done < <(compgen -G \"$target_file\" 2>/dev/null)\n if [[ \"$matched\" == false ]]; then\n echo \"$target_file doesn't exist.\"\n fi\n return\n fi\n\n local file_name=\"$(basename \"${target_file}\")\"\n\n if [[ -e \"$target_file\" ]]; then\n echo \"removing $target_file.\"\n mv -f \"$target_file\" \"$trash/${file_name}_${timestamp}_${rand}\"\n else\n echo \"$target_file doesn't exist.\"\n fi\n}\n\nremove_launchctl_service 'com.setapp.DesktopClient.SetappAgent'\nremove_launchctl_service 'com.setapp.DesktopClient.SetappAssistant'\nremove_launchctl_service 'com.setapp.DesktopClient.SetappLauncher'\nremove_launchctl_service 'com.setapp.DesktopClient.SetappUpdater'\nsudo rm -rf \"$APPDIR/Setapp.app\"\ntrash $LOGGED_IN_USER '~/Library/Application Scripts/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'\ntrash $LOGGED_IN_USER '~/Library/Application Support/Setapp*'\ntrash $LOGGED_IN_USER '~/Library/Caches/com.setapp.DesktopClient'\ntrash $LOGGED_IN_USER '~/Library/Caches/com.setapp.DesktopClient.SetappAgent'\ntrash $LOGGED_IN_USER '~/Library/Containers/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'\ntrash $LOGGED_IN_USER '~/Library/HTTPStorages/com.setapp.DesktopClient*'\ntrash $LOGGED_IN_USER '~/Library/LaunchAgents/com.setapp.DesktopClient.*plist'\ntrash $LOGGED_IN_USER '~/Library/Logs/Setapp'\ntrash $LOGGED_IN_USER '~/Library/Preferences/com.setapp.DesktopClient.plist'\ntrash $LOGGED_IN_USER '~/Library/Preferences/com.setapp.DesktopClient.SetappAgent.plist'\ntrash $LOGGED_IN_USER '~/Library/Saved Application State/com.setapp.DesktopClient.savedState'\n"

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🩺 Stability & Availability | 🟠 Major | 🏗️ Heavy lift

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -u

echo "== file location =="
git ls-files | rg '(^|/)darwin\.json$' | sed -n '1,20p'

echo
echo "== target file relevant lines =="
cat -n ee/maintained-apps/outputs/setapp/darwin.json | sed -n '1,80p'

echo
echo "== find related scripts/settings =="
rg -n "export|LOGGED_IN_USER|launchctl list|launchctl remove|HomeDir|ConsoleUser|Setapp|LaunchAgents|LaunchDaemons|com.setapp" ee/maintained-apps -S

Repository: fleetdm/fleet

Length of output: 50370


🌐 Web query:

Apple launchctl list remove root gui UID bootout man page

💡 Result:

In modern macOS, the bootout command is the recommended method for removing or stopping services, replacing the older load and unload commands [1]. Core Commands and Usage: 1. bootout: Use this to remove a service from a domain or stop it. The syntax is: launchctl bootout [domain-target]/[service-identifier] [2][3][4] Example (GUI domain): launchctl bootout gui/501/com.example.service [1][5] Example (System domain): sudo launchctl bootout system/com.example.daemon [1][6][7] 2. list: Use this to view loaded services. The recommended alternative for modern use is the print subcommand, which provides more detailed output [3][8]. launchctl list [2][1] launchctl print [domain-target]/[service-identifier] [3][9] 3. Domain Specifiers: - gui/UID: Targets the graphical user interface domain for a specific user [4][9]. - system/: Targets the system-wide domain (requires root privileges for modifications) [2][9]. - user/UID: Targets the user domain (can exist independently of a GUI session) [4][9]. Important Considerations: - Remove vs. Bootout: While older versions of launchctl included a remove command [10][8], bootout is the current standard for managing the lifecycle of services in defined domains [1][7]. - Persistence: If you want to permanently disable a service so it does not restart after a reboot, you must remove or move its corresponding.plist file (e.g., from /Library/LaunchDaemons or ~/Library/LaunchAgents) [6]. Using bootout only stops the current instance [6][7]. - Disabling: You can also use the disable subcommand to prevent a service from loading in future sessions without deleting the file [3][5]. launchctl disable [domain-target]/[service-identifier] [5][11] Always verify the exact service identifier by using the list or print subcommands before attempting to bootout or disable a service [3][6][9].

Citations:


🏁 Script executed:

#!/bin/bash
set -u

echo "== setapp darwin.json =="
sed -n '1,90p' ee/maintained-apps/outputs/setapp/darwin.json

echo
echo "== setapp-related launchctl paths =="
rg -n "launchctl|asuser|BOOTSTRAP_DOMAIN|HomeDir|console|ConsoleUser|SetappAgent|SetappAssistant|SetappLauncher|SetappUpdater|LaunchAgents|LaunchDaemons" ee/maintained-apps/outputs/setapp ee/maintained-apps/outputs/busycontacts ee/maintained-apps/outputs/supportcompanion ee/maintained-apps/outputs/runjs ee/maintained-apps/outputs -S | sed -n '1,200p'

Repository: fleetdm/fleet

Length of output: 50370


Remove Setapp launches from the logged-in user’s launchctl domain.

launchctl list/remove here targets root’s/current-process domain, not the user’s gui/<uid>/user domain, so these per-user agents can stay loaded even after their ~/Library/LaunchAgents/* plists are deleted and later relaunch. Resolve the console UID and launchctl asuser into /bootout each Setapp label, then trash the corresponding user LaunchAgents without relying on root $HOME.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ee/maintained-apps/outputs/setapp/darwin.json` at line 20, Update
remove_launchctl_service to resolve the logged-in console user’s UID and use
launchctl asuser with the user’s gui/<uid> domain to boot out each Setapp label,
rather than calling launchctl list/remove in the root/current-process domain.
Keep removal of both user and system plist locations as appropriate, but ensure
the user LaunchAgents are resolved from /Users/<logged-in-user> instead of root
$HOME; preserve wildcard label matching and the existing trash cleanup.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '--- locate file ---'
git ls-files | grep -F 'ee/maintained-apps/outputs/setapp/darwin.json' || true

echo '--- read relevant file excerpt ---'
wc -l ee/maintained-apps/outputs/setapp/darwin.json || true
sed -n '1,180p' ee/maintained-apps/outputs/setapp/darwin.json | cat -n

echo '--- run shell behavior probe for the exact command shape mentioned ---'
tmplog="$(mktemp)"
tmpuser="$(mktemp)"

cat > "$tmplog" <<'BASH'
#!/bin/bash
set -u

# Simulate the function body and the exact call used in the output.
remove_launchctl_service() {
  echo "remove_launchctl_service: $*"
}

trash() {
  local logged_in_user="$1"
  local target_file="$2"
  local timestamp="1970-01-01-0"
  local rand="123"

  if [[ "$target_file" == ~* ]]; then
    target_file="/Users/$logged_in_user${target_file:1}"
  fi

  local file_name

  if [[ -e "$target_file" ]]; then
    echo "removing $target_file."
    mv -f "$target_file" "/Users/$logged_in_user/.Trash/${file_name}_${timestamp}_${rand}" || true
  else
    echo "$target_file doesn't exist."
  fi
}

echo "LOGGED_IN_USER: [${LOGGED_IN_USER}]"
trash $LOGGED_IN_USER '~/Library/Application Scripts/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'
BASH

chmod +x "$tmplog"
for logged_in_user in '' 'root' 'loginwindow' 'alice'; do
  echo "=== LOGGED_IN_USER=${logged_in_user:-<empty>} ==="
  LOGGED_IN_USER="$logged_in_user" bash "$tmplog"
done

rm -f "$tmplog" "$tmpuser"

Repository: fleetdm/fleet

Length of output: 10103


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo '--- scan Setapp uninstall references for installed uninstall refs ---'
rg -n '"uninstall_script_ref":\s*"9ef05eb6"|uninstall_script_ref|LOGGED_IN_USER|Library/Application Scripts|Library/LaunchAgents' . --glob '!node_modules/**' --glob '!dist/**' --glob '!build/**' || true

echo '--- shell argument-shape probe with current-dir function definitions isolated ---'
tmp="$(mktemp -d)"
cat > "$tmp/uninstall.sh" <<'BASH'
#!/bin/bash
set -u

APPDIR="/Applications/"
LOGGED_IN_USER=$(printf '%s' "$1")

trash() {
  local logged_in_user="$1"
  local target_file="$2"
  local timestamp="1970-01-01-0"
  local rand="123"

  if [[ "$target_file" == ~* ]]; then
    target_file="/Users/$logged_in_user${target_file:1}"
  fi

  file_name="$(basename "$target_file")"

  if [[ -e "$target_file" ]]; then
    echo "removing $target_file."
    echo "trash target: $target_file"
  else
    echo "$target_file doesn't exist."
  fi
}

remove_launchctl_service() {
  echo "remove_launchctl_service: $*"
}

remove_launchctl_service 'com.setapp.DesktopClient.SetappAgent'
sudo_rm_status=0
sudo -n rm -rf "$APPDIR/Setapp.app" 2>/dev/null || sudo_rm_status="$?"
echo "sudo rm return: $sudo_rm_status"

trash $LOGGED_IN_USER '~/Library/Application Scripts/com.setapp.DesktopClient.SetappAgent.FinderSyncExt'
BASH
chmod +x "$tmp/uninstall.sh"

for logged_in_user in '' 'root' 'loginwindow' 'alice'; do
  echo "=== LOGGED_IN_USER=${logged_in_user:-<empty>} ==="
  bash "$tmp/uninstall.sh" "$logged_in_user" || true
done
rm -rf "$tmp"

Repository: fleetdm/fleet

Length of output: 50370


Handle the no-consoul-user case before invoking trash.

LOGGED_IN_USER can be empty, root, or loginwindow; with an empty value, trash $LOGGED_IN_USER '~/Library/...' sends the file path into $1 and leaves $2 empty, so the ~ expansion and cleanup path become invalid. Validate LOGGED_IN_USER and skip or specially handle per-user cleanup when no GUI console user exists.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ee/maintained-apps/outputs/setapp/darwin.json` at line 20, The cleanup script
must handle cases where LOGGED_IN_USER is empty, root, or loginwindow before
invoking trash. Add validation after determining LOGGED_IN_USER and skip the
per-user trash calls when no valid GUI console user exists; preserve system-wide
cleanup such as launchctl removal and deleting Setapp.app.

@github-actions

Copy link
Copy Markdown
Contributor

Closing in favor of #49776.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants