Skip to content

Update Fleet-maintained apps - #50686

Closed
fleet-release wants to merge 2 commits into
mainfrom
fma-2608061506
Closed

Update Fleet-maintained apps#50686
fleet-release wants to merge 2 commits into
mainfrom
fma-2608061506

Conversation

@fleet-release

@fleet-release fleet-release commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Automated ingestion of latest Fleet-maintained app data.

Summary by CodeRabbit

  • Updates
    • Refreshed available versions, release detection, download links, and checksums for numerous macOS and Windows applications, including AltTab, Amadine, Brave Browser, CMake, DataGrip, Firefox Nightly, Postman, Prisma Access Browser, Rider, Spyder, and others.
    • Updated installer metadata for the latest application builds.
  • Bug Fixes
    • Improved Krita’s macOS uninstall process to remove additional application data, caches, containers, scripts, and settings.

Generated automatically with cmd/maintained-apps.
@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Script Diff Results

ee/maintained-apps/outputs/alt-tab/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/amadine/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/badgeify/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/brave-browser/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/cmake-app/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/datagrip/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/downie/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/drofus/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/firefox@nightly/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/framer/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/gog-galaxy/darwin.json

=== Install // 9f170824 -> 89b9a1b7 ===

--- /tmp/old.JxvrPa	2026-08-06 15:13:37.032646730 +0000
+++ /tmp/new.bBkx3l	2026-08-06 15:13:37.032646730 +0000
@@ -96,5 +96,5 @@
 
 # install pkg files
 quit_and_track_application 'com.gog.galaxy.cef.renderer'
-sudo installer -pkg "$TMPDIR/galaxy_client_2.1.7.22.pkg" -target / || exit $?
+sudo installer -pkg "$TMPDIR/galaxy_client_2.1.8.32.pkg" -target / || exit $?
 relaunch_application 'com.gog.galaxy.cef.renderer'

=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/ibm-semeru-jre-11/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/imageglass/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/krita/darwin.json

=== Install Script (no changes) ===
=== Uninstall // 7b9f27dc -> 3947b0f0 ===

--- /tmp/old.iIqbs3	2026-08-06 15:13:37.130646516 +0000
+++ /tmp/new.9vvCY5	2026-08-06 15:13:37.130646516 +0000
@@ -52,8 +52,11 @@
   fi
 }
 
-sudo rm -rf "$APPDIR/krita.app"
-trash $LOGGED_IN_USER '~/Library/Application Support/krita'
+sudo rm -rf "$APPDIR/Krita.app"
+trash $LOGGED_IN_USER '~/Library/Application Scripts/org.krita.*'
+trash $LOGGED_IN_USER '~/Library/Application Support/krita*'
+trash $LOGGED_IN_USER '~/Library/Caches/krita'
+trash $LOGGED_IN_USER '~/Library/Containers/org.krita.*'
 trash $LOGGED_IN_USER '~/Library/Preferences/kritadisplayrc'
 trash $LOGGED_IN_USER '~/Library/Preferences/kritarc'
 trash $LOGGED_IN_USER '~/Library/Saved Application State/org.krita.savedState'

ee/maintained-apps/outputs/masscode/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/nordpass/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/notesnook/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/opera/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/pale-moon/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/parallels/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/postman/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/postman/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/prisma-browser/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/prisma-browser/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/rider/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/rive/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/rustrover/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/spyder/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/webex/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/whatsapp/darwin.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

ee/maintained-apps/outputs/xnconvert/windows.json

=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===

@coderabbitai

coderabbitai Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Review Change Stack

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: dd23296f-fe7e-4f1a-ba54-07f8af215a0d

📥 Commits

Reviewing files that changed from the base of the PR and between 1f84b27 and 1f9bb92.

📒 Files selected for processing (1)
  • ee/maintained-apps/outputs/webex/darwin.json

Walkthrough

Updated maintained-app manifests for newer Darwin and Windows releases. Changes synchronize versions, patch queries, installer URLs, and SHA-256 checksums. The GOG Galaxy installation script now references package version 2.1.8.32. Krita now uses an updated uninstall script that removes the capitalized application bundle and additional user data paths.

Possibly related PRs

🚥 Pre-merge checks | ✅ 4 | ❌ 1

❌ Failed checks (1 inconclusive)

Check name Status Explanation Resolution
Description check ❓ Inconclusive The description identifies automated app-data ingestion but omits the required issue reference, checklist responses, testing details, and relevant impact information. Complete the required template sections, mark applicable checklist items, provide testing results, and add the related issue or state that none applies.
✅ Passed checks (4 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly summarizes the primary change: updating Fleet-maintained app data.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fma-2608061506

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Actionable comments posted: 2

🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Inline comments:
In `@ee/maintained-apps/outputs/krita/darwin.json`:
- Line 11: Align the Krita bundle path casing used by the install and uninstall
scripts so both target the same canonical application name on case-sensitive
volumes. Update the referenced install script identifier alongside the
uninstall_script_ref if needed, ensuring installation, rollback, and removal
consistently use that bundle path.

In `@ee/maintained-apps/outputs/nordpass/windows.json`:
- Around line 4-12: Update the NordPass entry’s installer validation
configuration while preserving the pinned sha256 behavior; do not replace it
with no_check, since this maintained-app uses an explicit SHA for ingestion
despite the unversioned installer_url. Keep the existing version, queries, and
script references unchanged.
🪄 Autofix

Fix all unresolved CodeRabbit comments on this PR:

  • Push a commit to this branch (recommended)
  • Create a new PR with the fixes

ℹ️ Review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 87ca9d00-a185-4511-ae02-9d540e7d5b22

📥 Commits

Reviewing files that changed from the base of the PR and between a6b541d and 1f84b27.

📒 Files selected for processing (31)
  • ee/maintained-apps/outputs/alt-tab/darwin.json
  • ee/maintained-apps/outputs/amadine/darwin.json
  • ee/maintained-apps/outputs/badgeify/darwin.json
  • ee/maintained-apps/outputs/brave-browser/windows.json
  • ee/maintained-apps/outputs/cmake-app/windows.json
  • ee/maintained-apps/outputs/datagrip/darwin.json
  • ee/maintained-apps/outputs/downie/darwin.json
  • ee/maintained-apps/outputs/drofus/windows.json
  • ee/maintained-apps/outputs/firefox@nightly/darwin.json
  • ee/maintained-apps/outputs/framer/darwin.json
  • ee/maintained-apps/outputs/gog-galaxy/darwin.json
  • ee/maintained-apps/outputs/ibm-semeru-jre-11/windows.json
  • ee/maintained-apps/outputs/imageglass/windows.json
  • ee/maintained-apps/outputs/krita/darwin.json
  • ee/maintained-apps/outputs/masscode/darwin.json
  • ee/maintained-apps/outputs/nordpass/windows.json
  • ee/maintained-apps/outputs/notesnook/windows.json
  • ee/maintained-apps/outputs/opera/darwin.json
  • ee/maintained-apps/outputs/pale-moon/windows.json
  • ee/maintained-apps/outputs/parallels/darwin.json
  • ee/maintained-apps/outputs/postman/darwin.json
  • ee/maintained-apps/outputs/postman/windows.json
  • ee/maintained-apps/outputs/prisma-browser/darwin.json
  • ee/maintained-apps/outputs/prisma-browser/windows.json
  • ee/maintained-apps/outputs/rider/windows.json
  • ee/maintained-apps/outputs/rive/darwin.json
  • ee/maintained-apps/outputs/rustrover/darwin.json
  • ee/maintained-apps/outputs/spyder/windows.json
  • ee/maintained-apps/outputs/webex/darwin.json
  • ee/maintained-apps/outputs/whatsapp/darwin.json
  • ee/maintained-apps/outputs/xnconvert/windows.json

"installer_url": "https://download.kde.org/stable/krita/5.3.3/krita-5.3.3-signed.dmg",
"install_script_ref": "cdb966e7",
"uninstall_script_ref": "7b9f27dc",
"uninstall_script_ref": "3947b0f0",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

Keep the Krita bundle path consistent across install and uninstall.

The new uninstall script removes /Applications/Krita.app at Line 19. The referenced install script cdb966e7 still copies and rolls back /Applications/krita.app. On a case-sensitive macOS volume, these paths are different, so uninstall leaves the installed app behind. Use one canonical bundle name in both scripts and update the corresponding script reference if required.

Also applies to: 19-19

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ee/maintained-apps/outputs/krita/darwin.json` at line 11, Align the Krita
bundle path casing used by the install and uninstall scripts so both target the
same canonical application name on case-sensitive volumes. Update the referenced
install script identifier alongside the uninstall_script_ref if needed, ensuring
installation, rollback, and removal consistently use that bundle path.

Comment on lines +4 to +12
"version": "7.9.3",
"queries": {
"exists": "SELECT 1 FROM programs WHERE name = 'NordPass' AND publisher = 'NordPass Team';",
"patched": "SELECT 1 WHERE NOT EXISTS (SELECT 1 FROM programs WHERE name = 'NordPass' AND publisher = 'NordPass Team' AND version_compare(version, '7.7.13') < 0);"
"patched": "SELECT 1 WHERE NOT EXISTS (SELECT 1 FROM programs WHERE name = 'NordPass' AND publisher = 'NordPass Team' AND version_compare(version, '7.9.3') < 0);"
},
"installer_url": "https://downloads.npass.app/windows/NordPassSetup.exe",
"install_script_ref": "17ae065a",
"uninstall_script_ref": "472381ce",
"sha256": "1442b20921236be4f97f7f8ba1dbedcde9f373b4e0415700e9458487e813a514",
"sha256": "cb2392c7733236335243441caf89aaa0dfc7ce028e9fb6f27e43254ce1c94fe5",

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win

🧩 Analysis chain

🏁 Script executed:

#!/bin/bash
set -euo pipefail

url='https://downloads.npass.app/windows/NordPassSetup.exe'
expected='cb2392c7733236335243441caf89aaa0dfc7ce028e9fb6f27e43254ce1c94fe5'
tmp="$(mktemp)"
trap 'rm -f "$tmp"' EXIT

curl --fail --location --silent --show-error --retry 3 --output "$tmp" "$url"
actual="$(sha256sum "$tmp" | awk '{print $1}')"
test "$actual" = "$expected"

Repository: fleetdm/fleet

Length of output: 151


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Tracked files matching windows.json:"
git ls-files | grep -F 'ee/maintained-apps/outputs/nordpass/windows.json' || true

echo
echo "Target file excerpt:"
sed -n '1,80p' ee/maintained-apps/outputs/nordpass/windows.json

echo
echo "Search for maintained-apps install URL/hash handling references:"
rg -n "installer_url|checksum|sha256|rolling|urlless|unversioned|downloads\.npass|maintained-apps" -S . --glob '!node_modules' --glob '!dist' --glob '!build' | head -n 200

echo
echo "Find maintained-apps related files/dirs:"
fd -t f . ee cmd scripts 2>/dev/null | grep -i "maintained\|app\|windows" | head -n 200 || true

Repository: fleetdm/fleet

Length of output: 49992


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "cmd/maintained-apps/validate/windows.go outline and contents:"
wc -l cmd/maintained-apps/validate/windows.go
sed -n '1,260p' cmd/maintained-apps/validate/windows.go

echo
echo "Search for install URL hash validation in maintained-apps server/service files:"
rg -n "installer_url|sha256|hash.*installer|installer.*hash|versionless|rolling|unversioned|checksum|Digest" -S ee server orbit --glob '*.go' | head -n 250

Repository: fleetdm/fleet

Length of output: 40880


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "software_installers.go hash validation excerpt:"
sed -n '3520,3645p' ee/server/service/software_installers.go

echo
echo "maintained_apps.go installer URL/hash handling excerpt:"
sed -n '320,440p' ee/server/service/maintained_apps.go
sed -n '440,560p' ee/server/service/maintained_apps.go

echo
echo "maintained_apps_auto_update_download_test.go excerpt:"
sed -n '1,180p' ee/server/service/maintained_apps_auto_update_download_test.go

echo
echo "Search for auto-update generated hash logic:"
rg -n "hashSHA256|HashSHA256|installer_url|sha256|download.*installer|installer.*download" -S ee/server/service/maintained_apps.go ee/server/service/maintained_apps_auto_update*.go ee/server/service/software_installers.go --context 8

Repository: fleetdm/fleet

Length of output: 50369


🏁 Script executed:

#!/bin/bash
set -euo pipefail

echo "Fleet-maintained apps output excerpt from software installer ingestion:"
sed -n '3620,3660p' ee/server/service/software_installers.go

echo
echo "Search for noCheckHash constant and its semantics:"
rg -n "noCheckHash|NoCheckHash|SHA256.*noCheckHash|Rolling|rolling|latest.*URL" -S ee cmd --glob '*.go' --context 6

echo
echo "Read-only model for hash validation paths relevant to rolling URLs:"
python3 - <<'PY'
from pathlib import Path

for p in [Path("ee/server/service/software_installers.go"), Path("ee/server/service/maintained_apps.go"), Path("ee/server/service/maintained_apps_auto_update.go")]:
    text = p.read_text()
    phrases = ["p.MaintainedApp.SHA256 == \"noCheckHash\"", "p.SHA256 != \"noCheckHash\"", "if app.SHA256 != noCheckHash", "generated by Fleet", "downloaded installer hash does not match", "generated the SHA256"]
    print(f"\n--- {p} ---")
    for phrase in phrases:
        idx = text.find(phrase)
        print((phrase, idx != -1, text[max(0, idx-350): idx+400] if idx != -1 else ""))
PY

Repository: fleetdm/fleet

Length of output: 29322


Keep the pinned SHA hash for NordPass.

installer_url is not versioned, but an explicit sha256 value is still used by the maintained-app ingestion path, so a replaced NordPassSetup.exe causes the installation request to fail. Use no_check only when the installer must support rolling latest content.

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@ee/maintained-apps/outputs/nordpass/windows.json` around lines 4 - 12, Update
the NordPass entry’s installer validation configuration while preserving the
pinned sha256 behavior; do not replace it with no_check, since this
maintained-app uses an explicit SHA for ingestion despite the unversioned
installer_url. Keep the existing version, queries, and script references
unchanged.

Source: MCP tools

@github-actions

github-actions Bot commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Closing in favor of #50735.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants