Update Fleet-maintained apps - #50686
Conversation
Generated automatically with cmd/maintained-apps.
Script Diff Resultsee/maintained-apps/outputs/alt-tab/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/amadine/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/badgeify/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/brave-browser/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/cmake-app/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/datagrip/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/downie/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/drofus/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/firefox@nightly/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/framer/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/gog-galaxy/darwin.json=== Install // 9f170824 -> 89b9a1b7 ===
--- /tmp/old.JxvrPa 2026-08-06 15:13:37.032646730 +0000
+++ /tmp/new.bBkx3l 2026-08-06 15:13:37.032646730 +0000
@@ -96,5 +96,5 @@
# install pkg files
quit_and_track_application 'com.gog.galaxy.cef.renderer'
-sudo installer -pkg "$TMPDIR/galaxy_client_2.1.7.22.pkg" -target / || exit $?
+sudo installer -pkg "$TMPDIR/galaxy_client_2.1.8.32.pkg" -target / || exit $?
relaunch_application 'com.gog.galaxy.cef.renderer'
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/ibm-semeru-jre-11/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/imageglass/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/krita/darwin.json=== Install Script (no changes) ===
=== Uninstall // 7b9f27dc -> 3947b0f0 ===
--- /tmp/old.iIqbs3 2026-08-06 15:13:37.130646516 +0000
+++ /tmp/new.9vvCY5 2026-08-06 15:13:37.130646516 +0000
@@ -52,8 +52,11 @@
fi
}
-sudo rm -rf "$APPDIR/krita.app"
-trash $LOGGED_IN_USER '~/Library/Application Support/krita'
+sudo rm -rf "$APPDIR/Krita.app"
+trash $LOGGED_IN_USER '~/Library/Application Scripts/org.krita.*'
+trash $LOGGED_IN_USER '~/Library/Application Support/krita*'
+trash $LOGGED_IN_USER '~/Library/Caches/krita'
+trash $LOGGED_IN_USER '~/Library/Containers/org.krita.*'
trash $LOGGED_IN_USER '~/Library/Preferences/kritadisplayrc'
trash $LOGGED_IN_USER '~/Library/Preferences/kritarc'
trash $LOGGED_IN_USER '~/Library/Saved Application State/org.krita.savedState'ee/maintained-apps/outputs/masscode/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/nordpass/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/notesnook/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/opera/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/pale-moon/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/parallels/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/postman/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/postman/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/prisma-browser/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/prisma-browser/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/rider/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/rive/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/rustrover/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/spyder/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/webex/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/whatsapp/darwin.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) ===ee/maintained-apps/outputs/xnconvert/windows.json=== Install Script (no changes) ===
=== Uninstall Script (no changes) === |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (1)
WalkthroughUpdated maintained-app manifests for newer Darwin and Windows releases. Changes synchronize versions, patch queries, installer URLs, and SHA-256 checksums. The GOG Galaxy installation script now references package version Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 inconclusive)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Actionable comments posted: 2
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
Inline comments:
In `@ee/maintained-apps/outputs/krita/darwin.json`:
- Line 11: Align the Krita bundle path casing used by the install and uninstall
scripts so both target the same canonical application name on case-sensitive
volumes. Update the referenced install script identifier alongside the
uninstall_script_ref if needed, ensuring installation, rollback, and removal
consistently use that bundle path.
In `@ee/maintained-apps/outputs/nordpass/windows.json`:
- Around line 4-12: Update the NordPass entry’s installer validation
configuration while preserving the pinned sha256 behavior; do not replace it
with no_check, since this maintained-app uses an explicit SHA for ingestion
despite the unversioned installer_url. Keep the existing version, queries, and
script references unchanged.
🪄 Autofix
Fix all unresolved CodeRabbit comments on this PR:
- Push a commit to this branch (recommended)
- Create a new PR with the fixes
ℹ️ Review info
⚙️ Run configuration
Configuration used: Path: .coderabbit.yaml
Review profile: CHILL
Plan: Pro Plus
Run ID: 87ca9d00-a185-4511-ae02-9d540e7d5b22
📒 Files selected for processing (31)
ee/maintained-apps/outputs/alt-tab/darwin.jsonee/maintained-apps/outputs/amadine/darwin.jsonee/maintained-apps/outputs/badgeify/darwin.jsonee/maintained-apps/outputs/brave-browser/windows.jsonee/maintained-apps/outputs/cmake-app/windows.jsonee/maintained-apps/outputs/datagrip/darwin.jsonee/maintained-apps/outputs/downie/darwin.jsonee/maintained-apps/outputs/drofus/windows.jsonee/maintained-apps/outputs/firefox@nightly/darwin.jsonee/maintained-apps/outputs/framer/darwin.jsonee/maintained-apps/outputs/gog-galaxy/darwin.jsonee/maintained-apps/outputs/ibm-semeru-jre-11/windows.jsonee/maintained-apps/outputs/imageglass/windows.jsonee/maintained-apps/outputs/krita/darwin.jsonee/maintained-apps/outputs/masscode/darwin.jsonee/maintained-apps/outputs/nordpass/windows.jsonee/maintained-apps/outputs/notesnook/windows.jsonee/maintained-apps/outputs/opera/darwin.jsonee/maintained-apps/outputs/pale-moon/windows.jsonee/maintained-apps/outputs/parallels/darwin.jsonee/maintained-apps/outputs/postman/darwin.jsonee/maintained-apps/outputs/postman/windows.jsonee/maintained-apps/outputs/prisma-browser/darwin.jsonee/maintained-apps/outputs/prisma-browser/windows.jsonee/maintained-apps/outputs/rider/windows.jsonee/maintained-apps/outputs/rive/darwin.jsonee/maintained-apps/outputs/rustrover/darwin.jsonee/maintained-apps/outputs/spyder/windows.jsonee/maintained-apps/outputs/webex/darwin.jsonee/maintained-apps/outputs/whatsapp/darwin.jsonee/maintained-apps/outputs/xnconvert/windows.json
| "installer_url": "https://download.kde.org/stable/krita/5.3.3/krita-5.3.3-signed.dmg", | ||
| "install_script_ref": "cdb966e7", | ||
| "uninstall_script_ref": "7b9f27dc", | ||
| "uninstall_script_ref": "3947b0f0", |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
Keep the Krita bundle path consistent across install and uninstall.
The new uninstall script removes /Applications/Krita.app at Line 19. The referenced install script cdb966e7 still copies and rolls back /Applications/krita.app. On a case-sensitive macOS volume, these paths are different, so uninstall leaves the installed app behind. Use one canonical bundle name in both scripts and update the corresponding script reference if required.
Also applies to: 19-19
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@ee/maintained-apps/outputs/krita/darwin.json` at line 11, Align the Krita
bundle path casing used by the install and uninstall scripts so both target the
same canonical application name on case-sensitive volumes. Update the referenced
install script identifier alongside the uninstall_script_ref if needed, ensuring
installation, rollback, and removal consistently use that bundle path.
| "version": "7.9.3", | ||
| "queries": { | ||
| "exists": "SELECT 1 FROM programs WHERE name = 'NordPass' AND publisher = 'NordPass Team';", | ||
| "patched": "SELECT 1 WHERE NOT EXISTS (SELECT 1 FROM programs WHERE name = 'NordPass' AND publisher = 'NordPass Team' AND version_compare(version, '7.7.13') < 0);" | ||
| "patched": "SELECT 1 WHERE NOT EXISTS (SELECT 1 FROM programs WHERE name = 'NordPass' AND publisher = 'NordPass Team' AND version_compare(version, '7.9.3') < 0);" | ||
| }, | ||
| "installer_url": "https://downloads.npass.app/windows/NordPassSetup.exe", | ||
| "install_script_ref": "17ae065a", | ||
| "uninstall_script_ref": "472381ce", | ||
| "sha256": "1442b20921236be4f97f7f8ba1dbedcde9f373b4e0415700e9458487e813a514", | ||
| "sha256": "cb2392c7733236335243441caf89aaa0dfc7ce028e9fb6f27e43254ce1c94fe5", |
There was a problem hiding this comment.
🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
#!/bin/bash
set -euo pipefail
url='https://downloads.npass.app/windows/NordPassSetup.exe'
expected='cb2392c7733236335243441caf89aaa0dfc7ce028e9fb6f27e43254ce1c94fe5'
tmp="$(mktemp)"
trap 'rm -f "$tmp"' EXIT
curl --fail --location --silent --show-error --retry 3 --output "$tmp" "$url"
actual="$(sha256sum "$tmp" | awk '{print $1}')"
test "$actual" = "$expected"Repository: fleetdm/fleet
Length of output: 151
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "Tracked files matching windows.json:"
git ls-files | grep -F 'ee/maintained-apps/outputs/nordpass/windows.json' || true
echo
echo "Target file excerpt:"
sed -n '1,80p' ee/maintained-apps/outputs/nordpass/windows.json
echo
echo "Search for maintained-apps install URL/hash handling references:"
rg -n "installer_url|checksum|sha256|rolling|urlless|unversioned|downloads\.npass|maintained-apps" -S . --glob '!node_modules' --glob '!dist' --glob '!build' | head -n 200
echo
echo "Find maintained-apps related files/dirs:"
fd -t f . ee cmd scripts 2>/dev/null | grep -i "maintained\|app\|windows" | head -n 200 || trueRepository: fleetdm/fleet
Length of output: 49992
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "cmd/maintained-apps/validate/windows.go outline and contents:"
wc -l cmd/maintained-apps/validate/windows.go
sed -n '1,260p' cmd/maintained-apps/validate/windows.go
echo
echo "Search for install URL hash validation in maintained-apps server/service files:"
rg -n "installer_url|sha256|hash.*installer|installer.*hash|versionless|rolling|unversioned|checksum|Digest" -S ee server orbit --glob '*.go' | head -n 250Repository: fleetdm/fleet
Length of output: 40880
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "software_installers.go hash validation excerpt:"
sed -n '3520,3645p' ee/server/service/software_installers.go
echo
echo "maintained_apps.go installer URL/hash handling excerpt:"
sed -n '320,440p' ee/server/service/maintained_apps.go
sed -n '440,560p' ee/server/service/maintained_apps.go
echo
echo "maintained_apps_auto_update_download_test.go excerpt:"
sed -n '1,180p' ee/server/service/maintained_apps_auto_update_download_test.go
echo
echo "Search for auto-update generated hash logic:"
rg -n "hashSHA256|HashSHA256|installer_url|sha256|download.*installer|installer.*download" -S ee/server/service/maintained_apps.go ee/server/service/maintained_apps_auto_update*.go ee/server/service/software_installers.go --context 8Repository: fleetdm/fleet
Length of output: 50369
🏁 Script executed:
#!/bin/bash
set -euo pipefail
echo "Fleet-maintained apps output excerpt from software installer ingestion:"
sed -n '3620,3660p' ee/server/service/software_installers.go
echo
echo "Search for noCheckHash constant and its semantics:"
rg -n "noCheckHash|NoCheckHash|SHA256.*noCheckHash|Rolling|rolling|latest.*URL" -S ee cmd --glob '*.go' --context 6
echo
echo "Read-only model for hash validation paths relevant to rolling URLs:"
python3 - <<'PY'
from pathlib import Path
for p in [Path("ee/server/service/software_installers.go"), Path("ee/server/service/maintained_apps.go"), Path("ee/server/service/maintained_apps_auto_update.go")]:
text = p.read_text()
phrases = ["p.MaintainedApp.SHA256 == \"noCheckHash\"", "p.SHA256 != \"noCheckHash\"", "if app.SHA256 != noCheckHash", "generated by Fleet", "downloaded installer hash does not match", "generated the SHA256"]
print(f"\n--- {p} ---")
for phrase in phrases:
idx = text.find(phrase)
print((phrase, idx != -1, text[max(0, idx-350): idx+400] if idx != -1 else ""))
PYRepository: fleetdm/fleet
Length of output: 29322
Keep the pinned SHA hash for NordPass.
installer_url is not versioned, but an explicit sha256 value is still used by the maintained-app ingestion path, so a replaced NordPassSetup.exe causes the installation request to fail. Use no_check only when the installer must support rolling latest content.
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.
In `@ee/maintained-apps/outputs/nordpass/windows.json` around lines 4 - 12, Update
the NordPass entry’s installer validation configuration while preserving the
pinned sha256 behavior; do not replace it with no_check, since this
maintained-app uses an explicit SHA for ingestion despite the unversioned
installer_url. Keep the existing version, queries, and script references
unchanged.
Source: MCP tools
|
Closing in favor of #50735. |
Automated ingestion of latest Fleet-maintained app data.
Summary by CodeRabbit