Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1633 commits
Select commit Hold shift + click to select a range
6ae6d11
Update Fleet-maintained apps (#50838)
fleet-release Aug 9, 2026
e45c5d6
Update Fleet-maintained apps (#50847)
fleet-release Aug 9, 2026
cc13bb2
remove webpack notifier (#50855)
MagnusHJensen Aug 10, 2026
a1b11aa
hide turn on MDM banner until details have been fetched (#50859)
MagnusHJensen Aug 10, 2026
d601dbf
Make custom DDM activations opt-in on the server (#50863)
raju249 Aug 10, 2026
3b47482
Update Fleet-maintained apps (#50867)
fleet-release Aug 10, 2026
841cc42
Fix invalid JSON payload in TUF root Slack notification (#50874)
lucasmrod Aug 10, 2026
2e67fc3
Update limitations and reports for ChromeOS (#50512)
noahtalerman Aug 10, 2026
9694366
Update fleet-4.89.0.md (#50819)
irenareedy Aug 10, 2026
24e9c07
Add API endpoint warnings (#47841)
spalmesano0 Aug 10, 2026
79305ea
Fix Docker Desktop macOS FMA not reporting an installed version (#50885)
allenhouchins Aug 10, 2026
c200bed
check local MDM enrollment status before firing MDM migration webhook…
MagnusHJensen Aug 10, 2026
3dd9534
Update Fleet-maintained apps (#50890)
fleet-release Aug 10, 2026
b6661f7
Add guide: build and validate configuration profiles with AI instead …
kitzy Aug 10, 2026
9d13d02
Improve failed install modal copy for Android hosts (#50547)
Leanngove Aug 10, 2026
c41bd92
always check update on ADE with latest configured (#50861)
MagnusHJensen Aug 10, 2026
d462b16
Added issue prioritization to handbook. (#50889)
getvictor Aug 10, 2026
e5777fe
Read real Windows ACLs in ai_tools fsutil.Stat
juan-fdz-hawa Aug 10, 2026
d51dab1
Enhance os_version.yml with policy query and notes (#50906)
nonpunctual Aug 10, 2026
9f39f44
fix: Normalize CRLF to LF endings for scripts & installers (#50840)
hmacr Aug 10, 2026
afc1987
Website: Update Vanta script error handling (#50928)
eashaw Aug 11, 2026
d1db83c
Rename the custom activations setting to mdm.allow_custom_activations…
raju249 Aug 11, 2026
0b484b7
Fix label_updated_at reset (#50845)
JordanMontgomery Aug 11, 2026
d817cfd
Fix Linux passphrase escrow capturing shell startup output
juan-fdz-hawa Aug 11, 2026
3e5fe9c
Update Fleet-maintained apps (#50939)
fleet-release Aug 11, 2026
20b1541
fix outdated osquery schema (#50936)
MagnusHJensen Aug 11, 2026
c9c73ec
Fix formatting issue in Engineering handbook page (#50873)
noahtalerman Aug 11, 2026
00bf00d
Stop returning host details to GitOps users from the host by identifi…
nulmete Aug 11, 2026
34b5878
Fleet UI: Align technician empty state with EmptyState styling on con…
RachelElysia Aug 11, 2026
7249ac9
Fix installer extensions not being saved as lowercase (#50920)
jkatz01 Aug 11, 2026
a3fedd9
Fix santa_allowed and santa_denied returning no results
juan-fdz-hawa Aug 11, 2026
b1a20d8
Detect VS Code bundled built-in extensions in ai_tools
juan-fdz-hawa Aug 11, 2026
56e2a28
Find per-user and MSIX-packaged AI apps in the ai_tools Windows colle…
juan-fdz-hawa Aug 11, 2026
d5f499a
Backfill historical load test metrics (4.63–4.85) from the results sp…
xpkoala Aug 11, 2026
f2423c7
Filter label spec host membership by the requesting user's teams (#50…
nulmete Aug 11, 2026
daa871b
Fix Apple MDM reconciler resetting cursor too early (#50979)
JordanMontgomery Aug 11, 2026
77ca0dc
Add Matías Spinarolli to Software Engineer list in Power to the PC pr…
jbelbo Aug 11, 2026
ec8334c
Distinguish API-only endpoint-restriction 403s from role-based permis…
lukeheath Aug 11, 2026
1f923ad
Fixed slow migration. (#50992)
getvictor Aug 11, 2026
dd1080f
Move orbit changelog entries for #50114 and #50996 into orbit/changes…
cdcme Aug 11, 2026
f158c24
Host endpoints: Show brief description + URL before warnings/notes (#…
rachaelshaw Aug 11, 2026
a2f8b6c
Fix malformed JSON examples and status lines in REST API docs (#50998)
lukeheath Aug 11, 2026
fda3c41
Update REST API docs to explain why Wipe is free for Android (#50650)
Leanngove Aug 11, 2026
a6e50e9
Docs: recommend scoping the Vanta API-only user to specific endpoints…
GuillaumeRoss Aug 11, 2026
ab4e53b
Add Infrastructure Engineer position to open positions (#50980)
zayhanlon Aug 12, 2026
1889162
Show the profile detail on a verified profile's tooltip (#51027)
raju249 Aug 12, 2026
05f1da3
Validate NDES credentials when only the username or password changes
juan-fdz-hawa Aug 12, 2026
244262c
Fixed Windows config profile not deleted properly (#51005)
getvictor Aug 12, 2026
368ec4c
update DDM asset auth error (#50972)
MagnusHJensen Aug 12, 2026
1270939
Fleet UI: Fix undersized icons on default-size buttons (#51015)
RachelElysia Aug 12, 2026
338f0a0
Don't let Turn off MDM run twice on the same host (#50858)
raju249 Aug 12, 2026
07493d8
Add in-house app setup experience schema (#51029)
raju249 Aug 12, 2026
531fa7d
Fix .NET runtime winget ingestion after upstream Scope flip (#51022)
allenhouchins Aug 12, 2026
1430848
Windows Autopilot pending hosts foundations and configs (#50727)
getvictor Aug 12, 2026
583b723
Fix disabled-state bypass for host-targeted and team-targeted packs (…
sharon-fdm Aug 12, 2026
eed9e3e
Fix 5XXs on software install endpoints from software row locking
juan-fdz-hawa Aug 12, 2026
3e716ee
Add Windows and macOS MDM enrollment count metrics to Datadog (#50977)
sharon-fdm Aug 12, 2026
d8ea00e
Fix Worksheet Crafter homebrew ingestion after upstream cask rename (…
allenhouchins Aug 12, 2026
28d7737
always load macos software capture in osquery-perf (#50935)
MagnusHJensen Aug 12, 2026
5bbbf55
Add a zero-dependency dashboard for visualizing load test metrics run…
xpkoala Aug 12, 2026
dd72825
Fleet UI: Fix "Advanced options" not expanding for .msix packages (#5…
RachelElysia Aug 12, 2026
10642b2
Fix RSS protocol feed checker (#51032)
JordanMontgomery Aug 12, 2026
0f5a24c
Update Fleet-maintained apps (#51044)
fleet-release Aug 12, 2026
4fa2352
Update Fleet-maintained apps (#51055)
fleet-release Aug 12, 2026
84f8039
Add osquery-perf Apple MDM profile tracking (#51009)
JordanMontgomery Aug 12, 2026
be5c901
Roadmap preview: Update issue referenced for host vitals labels (#51064)
rachaelshaw Aug 12, 2026
a4ff784
Revert per-team pack config cache (#48702) (#51045)
sharon-fdm Aug 12, 2026
813fd97
Support display name for Fleet-maintained apps in GitOps (#50876)
jkatz01 Aug 12, 2026
5fb3e82
Website: "Manage ~~your~~ devices" - Update homepage.ejs (#51080)
mikermcneil Aug 12, 2026
92eed29
Website: Update homepage.ejs - Change hero desc + the kicker in its u…
mikermcneil Aug 12, 2026
bd39fe0
Add user channel to example DDM snippet (#50995)
spalmesano0 Aug 12, 2026
70dced9
Make generate-gitops use appropriate extension for script filenames (…
jkatz01 Aug 12, 2026
233cdb2
Fix duplicate App Store app install queueing (#51065)
cdcme Aug 12, 2026
308d9ed
Fix high Dependabot alerts in tools/upgrade and tools/hangar (#51076)
lukeheath Aug 12, 2026
3893353
Move Microsoft Graph credential logic to ee/ (#51041)
getvictor Aug 12, 2026
8a87079
Fleet UI: Fix fleets dropdown menu position on Software detail pages …
RachelElysia Aug 12, 2026
0597a85
Remove byVersion sorting from FMA versions function (#51071)
jkatz01 Aug 12, 2026
fd1b0f9
Fixing minor SCEP proxy issues. (#51014)
getvictor Aug 12, 2026
1020a56
Website: update thrown error in get-one-compliance-status-result (#51…
eashaw Aug 12, 2026
1dbfbab
Update Fleet-maintained apps (#51111)
fleet-release Aug 13, 2026
8f473ed
Unfreeze Wins (macOS) (#51068)
allenhouchins Aug 13, 2026
cfe307f
Update Evernote maintained app to 11.29.2 for macOS (#51042)
allenhouchins Aug 13, 2026
5dd3f36
Update Fleet-maintained apps (#51116)
fleet-release Aug 13, 2026
0e251a7
always run loadtest with --dev (#51121)
MagnusHJensen Aug 13, 2026
3d7e8cf
Fleet UI: Add edit button to Software installer rows (#51077)
RachelElysia Aug 13, 2026
44efbb7
"Self service" the noun, doesn't have a hyphen (#51095)
noahtalerman Aug 13, 2026
ff0668e
Software: Fix label color for script fields in advanced options (#51081)
RachelElysia Aug 13, 2026
403d4a2
Host activity UI: Extra space before period (#51114)
noahtalerman Aug 13, 2026
0ed8144
Orbit file download stall timeout and 30s context timeout (#50984)
MagnusHJensen Aug 13, 2026
ee8d500
Add article: What ChatGPT's new Linux desktop app means for shadow AI…
allenhouchins Aug 13, 2026
726002d
Update migration test guidance for Claude (#51143)
getvictor Aug 13, 2026
d49d49d
Attribute ai_tools Windows rows from ProfileList, not the directory o…
juan-fdz-hawa Aug 13, 2026
e17ad33
Document fleetdm/security repo in handbook (#51144)
lukeheath Aug 13, 2026
087128c
Fleet UI: Fix self-service reinstall/uninstall stuck disabled after c…
RachelElysia Aug 13, 2026
51fffd5
Update chatgpt-linux-desktop-app-shadow-ai.md (#51150)
allenhouchins Aug 13, 2026
2861410
Fix typo in historical event records deletion note (#51151)
fevzisahinler Aug 13, 2026
f25884d
Fix doc to call out ACME endpoint as required (#51154)
JordanMontgomery Aug 13, 2026
b0b5713
Clarifying Windows MDM cert location (#51152)
getvictor Aug 13, 2026
d2716e6
Add info on location of harware attestation settings (#51149)
spalmesano0 Aug 13, 2026
5c8d6fb
Bind fleet_id to the target report on schedule endpoints (#51048)
nulmete Aug 13, 2026
14f62d4
ADR-0011: Agent WebSocket transport (#50582)
sharon-fdm Aug 13, 2026
f394830
Reject host lists on dynamic labels regardless of length (#51137)
nulmete Aug 13, 2026
b20dd27
31312 mock apns server (#51054)
MagnusHJensen Aug 13, 2026
ee93fe7
Website: Update error handling in get-one-compliance-status-result.js…
eashaw Aug 13, 2026
6156d50
Fixing qa ticket creation for publish (#51174)
georgekarrv Aug 13, 2026
8708c5b
Fix ai_tools apps collector matching AI apps by raw substring
juan-fdz-hawa Aug 13, 2026
fe555ea
Support custom APNs URL in dev mode (#51129)
MagnusHJensen Aug 13, 2026
1c3f37a
Fix false positive CVEs for JetBrains teamcity-cli installed via Home…
juan-fdz-hawa Aug 13, 2026
af72931
Update homepage bottom ticker to feature/value list (#51087)
allenhouchins Aug 13, 2026
414ba17
Update versions of fleetd components in Fleet's TUF [automated] (#51187)
github-actions[bot] Aug 13, 2026
5c629a8
Validate policy scope when ingesting distributed/write results (#51148)
nulmete Aug 13, 2026
d9480ed
Website: update errors returned by update-one-devices-compliance-stat…
eashaw Aug 13, 2026
2b1ef1b
Website: Update models used in prompt helper, replace OpenAI API requ…
eashaw Aug 13, 2026
7ece800
Website: add two exits to MS compliance proxy endpoint (#51200)
eashaw Aug 13, 2026
d73bc7d
Fleet deploys swiftDialog during setup experience and the end user mi…
noahtalerman Aug 14, 2026
033d242
Link to configuration-profiles-with-AI guide from GitOps article (#50…
kitzy Aug 14, 2026
a843701
Remove experimental warning from manually install fleetd (#51019)
noahtalerman Aug 14, 2026
f9eb61c
Update Fleet-maintained apps (#51206)
fleet-release Aug 14, 2026
0e5c80c
Update changelog for fleetd 1.59.0 release (#51184)
lucasmrod Aug 14, 2026
0057309
Disable end user migration save button while saving (#51213)
Dhvanit41 Aug 14, 2026
1219743
Document how to update apps in iOS kiosk mode (Single App Mode) (#51026)
marko-lisica Aug 14, 2026
448635e
Move toast notifications to bottom center (#51224)
marko-lisica Aug 14, 2026
a08a9f1
always show managed account rotation banners (#51232)
MagnusHJensen Aug 14, 2026
b4d20be
Fleet UI: Auto-balance tooltip text and drop hand-rolled <br /> wrap …
RachelElysia Aug 14, 2026
b1ceb7e
return empty list for non supported platforms in DB query (#51230)
MagnusHJensen Aug 14, 2026
79ae02a
Update Orbit CA certs [automated] (#51120)
github-actions[bot] Aug 14, 2026
cf89ef1
Fix case-variant name bypass for built-in label overwrite (#50974)
sharon-fdm Aug 14, 2026
ea79ecf
Fleet UI: Fix clipped Vulnerabilities column and empty version state …
RachelElysia Aug 14, 2026
c194dcf
Website: Update homepage bottom ticker styles (#51245)
eashaw Aug 14, 2026
57ad8d5
Fix Android load testing harness bugs (#51037)
dantecatalfamo Aug 14, 2026
2c44db2
Fix misleading local installer store log (#51240)
cdcme Aug 14, 2026
5408827
Website: Send android management API metrics to datadog (#51250)
eashaw Aug 14, 2026
1a4dd82
Website: Homepage bottom CTA: Shorten ticker words, cut back on thing…
mikermcneil Aug 14, 2026
c052677
Harden hosts report CSV export
juan-fdz-hawa Aug 14, 2026
18f6a7f
Show the CA-specific invalid URL error instead of a generic one
juan-fdz-hawa Aug 14, 2026
9c5eaf3
Coverage info for 'Let's get you set up' calls (#51257)
ds0x Aug 14, 2026
6c7a2af
Add missing articles to Apple MDM setup guide (#51225)
spalmesano0 Aug 14, 2026
b50d4a0
Fix host activity queues blocked by stuck app installs (#51197)
cdcme Aug 14, 2026
c9dde09
Website: Update bottom ticker styles on homepage (#51264)
eashaw Aug 14, 2026
94207f1
Rename skipped install activity flag (#51102)
cdcme Aug 14, 2026
97685e0
Re-timestamp Backfill/DedupeQueued migrations to match 4.90.1 orderin…
georgekarrv Aug 14, 2026
d178563
Document safari_extensions empty-result gotchas (FDA, users JOIN, App…
cacaosteve Aug 14, 2026
c97b61f
Handbook: update AI code review options (remove Claude, add Qodo) (#5…
lukeheath Aug 14, 2026
12ac5f6
Add '~3rd-party' label for partner-related bugs (#51283)
noahtalerman Aug 14, 2026
786d41c
Exclude ~3rd-party bugs from bug KPI report (#51284)
kilo-code-bot[bot] Aug 14, 2026
957732b
Add onTargetEarnings to Infra eng (#51248)
zayhanlon Aug 14, 2026
dbb84c6
Remove Andrew Mellor and Jorge Falcon from handbook (#51287)
kilo-code-bot[bot] Aug 14, 2026
df16b6a
Website: Comment out marketing attribution section in CRM helper (#51…
eashaw Aug 14, 2026
6465b09
[API]: Add callout for global config mdm that it's Apple MDM only (#5…
MagnusHJensen Aug 14, 2026
c4d3a95
Add Windows CSP guides to docs further learning list (#51207)
mike-j-thomas Aug 14, 2026
e49fb7a
Website: update error-handling in update-one-devices-compliance-statu…
eashaw Aug 14, 2026
46f2fad
Update Fleet-maintained apps (#51304)
fleet-release Aug 15, 2026
80b6661
Update Fleet-maintained apps (#51305)
fleet-release Aug 15, 2026
b7cfd41
Fix enrollment URL spacing on iOS & iPadOS tab of Add hosts modal (#5…
allenhouchins Aug 16, 2026
2cd679d
Unfreeze FreeFileSync (darwin) (#51314)
allenhouchins Aug 16, 2026
057800f
Update Fleet-maintained apps (#51319)
fleet-release Aug 16, 2026
1ce2782
Unfreeze Worksheet Crafter (darwin) (#51162)
allenhouchins Aug 16, 2026
65db959
Update Fleet-maintained apps (#51323)
fleet-release Aug 16, 2026
77a2a42
Add guides for deploying printers with Fleet (#51167)
kitzy Aug 16, 2026
c3173b2
Update Fleet-maintained apps (#51328)
fleet-release Aug 16, 2026
afc8ec9
Support mock APNS in osquery-perf (#51130)
MagnusHJensen Aug 16, 2026
5ca7645
Let .ipa apps be selected for iOS/iPadOS setup experience (#51124)
raju249 Aug 17, 2026
977d9a5
remove extra target text in Apple OS updates (#51344)
MagnusHJensen Aug 17, 2026
d612f8a
Fix autofilled inputs rendering white in dark mode (#51221)
Dhvanit41 Aug 17, 2026
89099a5
Add VEX CVE exclusions for `fleetdm/fleetctl` (#51348)
lucasmrod Aug 17, 2026
27e6fe3
Website: Track new key events for signups (#51291)
eashaw Aug 17, 2026
d4231f1
Add EU & UK GDPR representatives to privacy policy (#51360)
allenhouchins Aug 17, 2026
a894385
Add VEX exclusions for fleetdm/wix (#51350)
lucasmrod Aug 17, 2026
2bb1c63
Sort generate-gitops software by name for stable output (#51181)
sjawhar Aug 17, 2026
a7e4a5b
Custom android mdm commands (#50728)
ksykulev Aug 17, 2026
fa9b6c9
Clarify which board to uses for feature request triage (#51384)
rachaelshaw Aug 17, 2026
a6f1ae7
add nano cert auth index (#51342)
MagnusHJensen Aug 17, 2026
2aee426
Website: update marketing attribution in update-or-create-contact-and…
eashaw Aug 17, 2026
a31c99d
delete host_dep_assignment if apple business is not configured when d…
MagnusHJensen Aug 17, 2026
0ce881d
Update fleetd TUF versions in documentation (#51379)
lucasmrod Aug 17, 2026
54d2f79
Add automation for Go patch releases (#51239)
lucasmrod Aug 17, 2026
3175b58
GitOps reference: Clarify `display_name` (#51394)
noahtalerman Aug 17, 2026
2abadba
Bump nanoid from 3.3.17 to 3.3.18 (#51339)
dependabot[bot] Aug 17, 2026
03828ea
Website: collect metrics for android management requests per enterpri…
eashaw Aug 17, 2026
e958b0a
Fix check-go-patch-release workflow: install the new Go version (#51400)
lucasmrod Aug 18, 2026
2912c84
Fix GeoGebra Classic winget ingestion after upstream scope flip (#51407)
allenhouchins Aug 18, 2026
e62e9bb
Force rebuild of entire migration order sequence on fix (#51311)
rfairburn Aug 18, 2026
de8a412
Tell the end user when their SSO sign-in timed out (#51215)
raju249 Aug 18, 2026
5d8884b
Cancel a queued profile removal when the profile is added back (#51346)
raju249 Aug 18, 2026
6955e35
Update Fleet-maintained apps (#51410)
fleet-release Aug 18, 2026
a4f133b
Update Fleet-maintained apps (#51412)
fleet-release Aug 18, 2026
568b04b
Install in-house apps during iOS/iPadOS setup experience (#51135)
raju249 Aug 18, 2026
d7bda78
Add tarball example to note (#51364)
spalmesano0 Aug 18, 2026
ba92fa8
update loadtest with mock apns server (#51136)
MagnusHJensen Aug 18, 2026
ae49b0b
Fix exclude_any label targeting hiding software from all hosts
juan-fdz-hawa Aug 18, 2026
3d09593
Update Go to 1.26.6 [automated] (#51406)
github-actions[bot] Aug 18, 2026
2c04f24
Remove dependabot QA ticket workflow (#51429)
lukeheath Aug 18, 2026
6a71aee
Fix pack config cache to skip caching when label-scoped queries exist…
sharon-fdm Aug 18, 2026
13dd641
Stop retrying VPP install details on a 404 (#51413)
Dhvanit41 Aug 18, 2026
66314ae
add fetch_devices to AB API tool (#51341)
MagnusHJensen Aug 18, 2026
6dfe1c7
fix: return 403/404 instead of 500 when fetching or deleting a nonexi…
hmacr Aug 18, 2026
480d93b
Add article: Detecting the ChainDrop npm worm before it reaches your …
allenhouchins Aug 18, 2026
67d5b05
Handbook: document built-in Slack polls, remove app-request instructi…
kilo-code-bot[bot] Aug 18, 2026
c91fd3b
Update Fleet-maintained apps (#51422)
fleet-release Aug 18, 2026
c44aac4
Update Evernote (darwin) to 11.30.6 (#51432)
allenhouchins Aug 18, 2026
8b36e8e
New guide: Driving automations and reports based on available disk sp…
kilo-code-bot[bot] Aug 18, 2026
18eda7c
Add allenhouchins as a docs/solutions maintainer (auto-approval) (#51…
allenhouchins Aug 18, 2026
c5ef5ca
Add article: Agentic security is only as good as the device data unde…
allenhouchins Aug 18, 2026
b8ff0ad
PARCP: Migration + API layer for resending config profiles via policy…
MagnusHJensen Aug 18, 2026
7cd22bf
Use cache deletion instead of short TTL in pack config tests (#51431)
sharon-fdm Aug 18, 2026
6492197
Add myself to claude codeowners (#51445)
lukeheath Aug 18, 2026
c4c230d
Keep FMA custom script comments admin-facing (new-fma skill) (#50805)
allenhouchins Aug 18, 2026
d448f24
Add EMs to .claude codeowners (#51447)
lukeheath Aug 18, 2026
acef394
Missing fix in tools (#51435)
lucasmrod Aug 18, 2026
879dc7d
Add code comment guidance to Claude project instructions (#51444)
lukeheath Aug 18, 2026
0b31111
Review AI generated issues for accuracy (#51453)
noahtalerman Aug 18, 2026
f0ecc46
Add article: What Apple's latest security update shows about patch la…
allenhouchins Aug 18, 2026
75fc42b
Fix high npm Dependabot alerts across all JS lockfiles (#51078)
lukeheath Aug 18, 2026
0eaa550
Enforce API-only endpoint restrictions on /debug/* routes (#49607)
lukeheath Aug 18, 2026
7bfdb51
MDMStatusModal: use isFetching over isLoading to always show spinner …
MagnusHJensen Aug 18, 2026
5f9bdf5
Update Fleet-maintained apps (#51451)
fleet-release Aug 18, 2026
0acf581
Fleet UI: Align InfoBanner leading icon with first line of wrapped co…
RachelElysia Aug 18, 2026
3771a72
Fix Clear passcode modal checkbox color mismatch (#51438)
melpike Aug 18, 2026
bcdcf6e
Adding changes for Fleet v4.90.1 (#51172)
georgekarrv Aug 18, 2026
df492e3
Fix enrolled hosts chart including pending hosts in platform counts (…
sharon-fdm Aug 18, 2026
485fb69
Fix built-in Linux labels missing derived distributions
juan-fdz-hawa Aug 18, 2026
63f04b4
Autopilot sync (#51109)
getvictor Aug 18, 2026
7bd62f2
Update author information in article (#51477)
allenhouchins Aug 18, 2026
dc3e047
Edit article to remove author details and promotion (#51478)
allenhouchins Aug 18, 2026
21e1cca
Update Fleet-maintained apps (#51480)
fleet-release Aug 18, 2026
93a9709
[Route] Add route for policy automation resend configuration (#51142)
melpike Aug 18, 2026
a81ee4f
Fix 'All hosts' label for osquery-perf hosts (#51481)
lucasmrod Aug 18, 2026
cbb0e20
Docs: Usually see it written differently like semver (rather than Sem…
mikermcneil Aug 18, 2026
76a4e3f
Update yaml-files.md (#51424)
marko-lisica Aug 18, 2026
1cf7ea5
Clarify package order and update labels in YAML docs (#51420)
marko-lisica Aug 18, 2026
a4e0f93
Update attribution (#51503)
Sampfluger88 Aug 19, 2026
5791367
Update Fleet-maintained apps (#51500)
fleet-release Aug 19, 2026
b118647
Verify Apple Business assignment before deleting a host (#51418)
raju249 Aug 19, 2026
9d00867
Update Fleet-maintained apps (#51504)
fleet-release Aug 19, 2026
b139336
Update Fleet-maintained apps (#51505)
fleet-release Aug 19, 2026
6f20ef4
Merge upstream/main (Fleet v4.81.2 → v4.90.1)
oleg-flamingocx Aug 19, 2026
0e3155b
fix(host-assignments): don't share the pack-config cache across hosts…
oleg-flamingocx Aug 19, 2026
88fcf2d
chore(migrations): make the 45 new upstream migrations idempotent
oleg-flamingocx Aug 19, 2026
116b604
test: thread upstream's new signatures through the affected test call…
oleg-flamingocx Aug 19, 2026
cd58be8
fix(verify): follow upstream's tools/fleet-mcp -> cmd/fleet-mcp rename
oleg-flamingocx Aug 19, 2026
1882303
fix(verify): make openframe-verify actually able to pass, and see eve…
oleg-flamingocx Aug 19, 2026
e3b5bc5
docs(sync): correct the upstream-sync runbook against what this sync …
oleg-flamingocx Aug 19, 2026
70aadd0
docs(manifest): record the docs/ deletions and refresh the baseline
oleg-flamingocx Aug 19, 2026
65298eb
docs(helm): update the recorded chart version for the v4.90.1 sync
oleg-flamingocx Aug 19, 2026
d6ceaca
docs(migrations): document the static sweep guard and what v4.90.1 ta…
oleg-flamingocx Aug 19, 2026
a503c48
docs(host-assignments): record why per-host targeting defeats team-le…
oleg-flamingocx Aug 19, 2026
6cc9bdb
docs(waf-shape): record the Windows subject2/issuer2 switch
oleg-flamingocx Aug 19, 2026
667b6d4
fix(test): restore the one docs/ script a new upstream test reads
oleg-flamingocx Aug 19, 2026
e221873
fix(test): make the hosts-report CSV assertions tolerate the fork's e…
oleg-flamingocx Aug 19, 2026
d676d0f
docs(sync): add the "new upstream test reads a deleted path" watchlis…
oleg-flamingocx Aug 19, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
13 changes: 5 additions & 8 deletions .claude/CLAUDE.md
Original file line number Diff line number Diff line change
Expand Up @@ -31,16 +31,13 @@ The following terms were recently renamed. Use the new terms in conversation and
- **"Teams" → "Fleets"** — the concept of grouping hosts. Legacy code still uses `team_id`, `teams` table, etc.
- **"Queries" → "Reports"** — what was formerly a "query" in the product is now a "report." The word "query" now refers solely to a SQL query, which is one aspect of a report.

## Code comments

Keep comments concise and sparse — a diff should be mostly code, not comments. Comment to explain non-obvious "why" (constraints, gotchas, why the expected approach wasn't used), never to restate what the code obviously does, narrate the change, or cite the issue/PR that prompted it.

## Fleet-specific patterns

### Go backend
- **Error wrapping**: `ctxerr.Wrap(ctx, err, "description")` — never pkg/errors
- **Request/Response**: lowercase struct types, `Err error` field, `Error()` method returning `r.Err`
- **Endpoint registration**: `ue.POST("/api/_version_/fleet/resource", fn, reqType{})`
- **Authorization**: `svc.authz.Authorize(ctx, entity, fleet.ActionX)` at start of service methods
- **Logging**: slog with `DebugContext/InfoContext/WarnContext/ErrorContext` — never bare slog.Debug/Info/Warn/Error
- **Pointers**: Use Go 1.26 `new(expression)` for pointer values (e.g., `new("value")`, `new(true)`, `new(42)`). Do NOT use the legacy `server/ptr` package in new code — it exists throughout the codebase but is superseded by `new(expr)`.
- **Reference example**: `server/service/vulnerabilities.go`
Go and API conventions (ctxerr error wrapping, error types, request/response structs, auth, slog, `new(expression)` pointers, endpoint registration) auto-load from `.claude/rules/` when you edit matching files — see `rules/fleet-go-backend.md`, `rules/fleet-api.md`, and `rules/fleet-database.md`. Reference example: `server/service/vulnerabilities.go`.

## Before writing a fix

Expand Down
39 changes: 22 additions & 17 deletions .claude/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# Fleet Claude Code configuration

This directory contains team-shared [Claude Code](https://claude.ai/code) configuration for the Fleet project. Everything here works out of the box with no MCP servers, plugins, or external dependencies required. The full setup adds ~2,500 tokens at startup — rules, skill bodies, and agent bodies only load on demand.
This directory contains team-shared [Claude Code](https://claude.ai/code) configuration for the Fleet project. The core setup works out of the box with no plugins or external services required. Most GitHub-related skills use the `gh` CLI, and a few skills can optionally use MCP servers — both noted in the table below. The full setup adds a few thousand tokens at startup — CLAUDE.md and skill descriptions load up front; rule bodies, skill bodies, and agent bodies only load on demand. Run `/context` to see the current breakdown.

This setup is a starting point. You can customize it by creating `.claude/settings.local.json` (gitignored) to add your own permissions, MCP servers, and plugins. See [Customize your setup](#customize-your-setup) for details.

Expand Down Expand Up @@ -49,7 +49,7 @@ Claude Code is an AI coding assistant that runs in your terminal, VS Code, JetBr

**CLAUDE.md** — Project instructions loaded at session start, like a `.editorconfig` for AI. Claude reads these automatically to understand your project's conventions, architecture, and workflows. There can be multiple: root-level, `.claude/CLAUDE.md`, and user-level `~/.claude/CLAUDE.md`.

**Skills** — Reusable workflows invoked with `/` (e.g., `/test`, `/fix-ci`). Each skill is a `SKILL.md` file with YAML frontmatter that controls when it triggers, which tools it can use, and whether it runs in an isolated context. Skills replace the older `.claude/commands/` format, adding auto-invocation, tool restrictions, and isolated execution.
**Skills** — Reusable workflows invoked with `/` (e.g., `/test`, `/fix-ci`). Each skill is a `SKILL.md` file with YAML frontmatter that controls when it triggers, which tools it can use, and whether it runs in an isolated context. Skills are the successor to the older `.claude/commands/` format, adding auto-invocation, tool restrictions, and isolated execution.

**Agents (subagents)** — Specialized AI assistants that run in isolated contexts with their own tools and model. Claude can delegate to them automatically (if their description includes "PROACTIVELY") or you can invoke them by name.

Expand Down Expand Up @@ -156,19 +156,13 @@ Your local settings override project settings, so you can always customize witho
│ ├── fleet-database.md # MySQL: migrations, goqu, reader/writer
│ ├── fleet-api.md # API: endpoint registration, versioning, error responses
│ └── fleet-orbit.md # Orbit: agent packaging, TUF updates, platform-specific code
├── skills/ # Workflow skills (invoke with /)
│ ├── review-pr/ # /review-pr <PR#>
│ ├── fix-ci/ # /fix-ci <run-url>
│ ├── test/ # /test [filter]
│ ├── find-related-tests/ # /find-related-tests
│ ├── lint/ # /lint [go|frontend]
│ ├── fleet-gitops/ # /fleet-gitops
│ ├── project/ # /project <name>
│ ├── new-endpoint/ # /new-endpoint
│ ├── new-migration/ # /new-migration
│ ├── bump-migration/ # /bump-migration <filename>
│ ├── spec-story/ # /spec-story <issue#>
│ └── cherry-pick/ # /cherry-pick <PR#> [RC_BRANCH]
├── skills/ # 26 workflow skills (invoke with /) — see "Skills reference" below
│ ├── review-pr/ # Review a PR
│ ├── test/ # Run tests for recent changes
│ ├── fix-ci/ # Diagnose CI failures
│ ├── spec-story/ # Break a story into sub-issues
│ ├── new-migration/ # Scaffold a DB migration
│ └── ... # + 21 more (lint, fleet-gitops, vuln-triage, content-style, …)
├── agents/ # Specialized AI agents
│ ├── go-reviewer.md # Go reviewer (proactive, sonnet)
│ ├── frontend-reviewer.md # Frontend reviewer (proactive, sonnet)
Expand All @@ -192,12 +186,23 @@ Several skills use the `gh` CLI for GitHub operations (PR review, CI diagnosis,
| `/find-related-tests` | `/find-related-tests` | Maps changed files to their `_test.go` files, integration tests, and test helpers. Outputs exact `go test` commands. |
| `/fleet-gitops` | `/fleet-gitops` | Validates GitOps YAML: osquery queries against Fleet schema, Apple/Windows/Android profiles against upstream references, and software against the Fleet-maintained app catalog. |
| `/project` | `/project android-mdm` | Loads or creates a workstream context file in your Claude memory directory. Includes a minimal self-improvement mechanism — Claude adds discoveries, gotchas, and key file paths as you work, so each session starts with slightly richer context than the last. |
| `/new-endpoint` | `/new-endpoint` | Scaffolds a Fleet API endpoint: request/response structs, endpoint function, service method, datastore interface, handler registration, and test stubs. |
| `/new-endpoint` | `/new-endpoint` | Scaffolds a Fleet API endpoint: request/response structs, endpoint function, service method, datastore interface, handler registration, and test stubs. User-invoked only (no auto-trigger). |
| `/new-migration` | `/new-migration` | Creates a timestamped migration file and test file with proper naming, init registration, and Up function (Down is always a no-op). |
| `/bump-migration` | `/bump-migration YYYYMMDDHHMMSS_Name.go` | Bumps a migration's timestamp to current time when it conflicts with a migration already merged to main. Renames files and updates function names in both migration and test files. |
| `/spec-story` | `/spec-story 12345` | Breaks down a GitHub story into implementable sub-issues: maps codebase impact, decomposes into atomic tasks per layer (migration/datastore/service/API/frontend), and writes specs with acceptance criteria and a dependency graph. Requires `gh`. |
| `/spec-story` | `/spec-story 12345` | Breaks down a GitHub story into sub-issues via a four-stage gated workflow (Understand → Skeleton → Draft → Create) that pauses for your approval at each gate. Researches prior art (GitHub, Slack, git history) and Figma dev notes, decomposes by specialization (backend/frontend/fleetctl-GitOps/agent) plus a mandatory Documentation & QA sub-issue, writes specs with exact `file:line` references and grouped conditions of satisfaction (no estimation), then creates the sub-issues and wires them as native tasks off the parent. Requires `gh`; uses Figma/Slack MCP tools. |
| `/lint` | `/lint` or `/lint go` | Runs the appropriate linters (golangci-lint, eslint, prettier) on recently changed files. Accepts `go`, `frontend`, or a file path to narrow scope. |
| `/cherry-pick` | `/cherry-pick 43082` or `/cherry-pick 43082 rc-minor-fleet-v4.83.0` | Cherry-picks a merged PR into an RC branch. Auto-detects the latest `rc-minor-fleet-v*` or `rc-patch-fleet-v*` branch, or accepts an explicit target. Handles squash-merged and merge commits. Requires `gh`. |
| `/push-reference-docs` | `/push-reference-docs` | Moves reference-doc updates from one release docs branch to another (e.g., 4.89 → 4.90) when a feature slips to a later release. Handles open/closed/merged PR states. Requires `gh`. |
| `/who-blocks-this-pr` | `/who-blocks-this-pr 12345` | Determines which files still need approval and from whom, based on CODEOWNERS and `website/config/custom.js`. Requires `gh`. |
| `/release-retro` | `/release-retro` | Formats release retro notes into a Slack recap post and `~timebox` GitHub issues. Requires `gh` **and** the Slack MCP server (not part of the out-of-box setup). |
| `/vuln-triage` | `/vuln-triage CVE-2024-1234` | Triages vulnerability false positives/negatives across NVD, OSV, OVAL, MSRC, and Office data sources. Uses the `nvdvuln` tool and WebFetch. |
| `/new-fma` | `/new-fma` | Adds a Fleet-maintained app for macOS (Homebrew) and/or Windows (winget); verifies installer metadata with real tools and debugs FMA validator failures. Uses WebFetch. |
| `/command-palette` | `/command-palette` | Authoring guide for the Fleet command palette — adding/editing items in `frontend/components/CommandPalette/groups/`, router paths, and new pages/actions that need a palette entry. |
| `/tier-modes` | `/tier-modes` | Authoring guide for Fleet Free (`!isPremiumTier`) and Primo (`isPrimoMode`) gating in the frontend — for new pages/surfaces or when introducing new tier gating. |
| `/content-style` | `/content-style` | Writes, edits, and reviews public-facing Fleet content (website, handbook, docs, articles, release notes, UI copy) to follow Fleet's voice and style guidelines. |
| `/fleet-article-formatting` | `/fleet-article-formatting` | Applies Fleet's house article format and article-specific voice to articles (`category` `articles` or `comparison`) — title → dek → key takeaways → CTA button → body → closing. Pairs with `/content-style` for word-level voice. |
| `/aikido-tickets` | `/aikido-tickets` | Creates GitHub issues in `fleetdm/confidential` from Aikido pen test PDF reports. Reads findings, synthesizes attack path and fix recommendations, preserves full Aikido evidence in a collapsible section. Supports batch creation via parallel agents. Requires `gh` with `project` scope for board placement. |
| `/openspec-*` | `/openspec-propose` | OpenSpec spec-driven workflow for larger changes (explore → propose → apply → archive). Four skills: `openspec-explore`, `openspec-propose`, `openspec-apply-change`, `openspec-archive-change`. Vendored by the `openspec` CLI — see `openspec/README.md`. |

### Using `/project` for workstream context

Expand Down
25 changes: 0 additions & 25 deletions .claude/goimports.sh

This file was deleted.

49 changes: 0 additions & 49 deletions .claude/guard-dangerous-commands.sh

This file was deleted.

82 changes: 0 additions & 82 deletions .claude/lint-on-save.sh

This file was deleted.

24 changes: 0 additions & 24 deletions .claude/prettier-frontend.sh

This file was deleted.

4 changes: 3 additions & 1 deletion .claude/rules/fleet-database.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,9 @@ paths:
## Migration Files
- Location: `server/datastore/mysql/migrations/tables/`
- Naming: `YYYYMMDDHHMMSS_CamelCaseName.go` (timestamp + descriptive CamelCase)
- Every migration MUST have a corresponding `_test.go` file
- Every migration that modifies data MUST have a corresponding `_test.go` file. That means changing existing data, adding new data, or
populating a table
- Simple migrations that only add a table, column, or index do not need one
- Structure:
```go
func init() {
Expand Down
Loading
Loading