4.7 KiB
4.7 KiB
Changelog
All notable changes to the probo-agent device posture agent will be
documented in this file.
Unreleased
[0.4.2] - 2026-07-30
Fixed
- macOS auto-update no longer spawns new Background Task Management
entries (and the generic executable icon) on every release; updated
darwin archives are now signed with a stable identifier, signature
downgrades are refused, and daemon/tray jobs are attributed to
Probo Agent.app.
[0.4.1] - 2026-07-29
Changed
- Simplified the macOS PKG installer's welcome and conclusion screens to
point straight at browser-based
/enrollenrollment, dropping the CLI install steps, path inventories, and MDM notes.
[0.4.0] - 2026-07-29
Added
- Posture check submissions now carry a correlation ID grouping each agent push into a single report, powering paginated report history in the console
[0.3.1] - 2026-07-27
Fixed
- Removed the white frame around the
Probo Agent.appFinder/Dock icon by swapping in artwork with transparent corners.
[0.3.0] - 2026-07-24
Added
- Branded Finder icon for
Probo Agent.app(generated from a master PNG viasips/iconutilat PKG build time).
Fixed
- macOS auto-update posture check now reads all five Software Update preferences backing the System Settings toggles, resolving managed (MDM) values before system ones, so disabled downloads/installs are correctly reported as failing instead of PASS.
[0.2.0] - 2026-07-24
Added
- macOS privileged helper (
com.probo.agent.helper) embedded inProbo Agent.appand installed by PKG postinstall for XPC-driven browser enrollment (no SMJobBless / admin prompt on enroll). - Hidden
probo-agent enroll-url --preflightJSON output for the URL handler. make -C cmd/probo-agent install|uninstall|cleanfor local macOS PKG test loops (install tears down leftovers first).
Changed
- Browser enrollment via
Probo Agent.appuses HelperClient + XPC only (osascript elevation and enroll-time SMJobBless removed). - macOS PKG / app builds require
CODESIGN_IDENTITYandAPPLE_TEAM_ID. - CLI
enroll-urlon macOS refuses elevation; use the signed app deeplink orsudo probo-agent install. - macOS
probo-agent uninstallrequires root (sudo). - PKG preinstall removes stale privileged helper files on upgrade; postinstall reinstalls the helper as root.
- macOS release now ships a single universal (arm64 + x86_64) fat
probo-agent_<version>_darwin.pkginstead of separate per-arch packages.
Fixed
- Windows elevated install/uninstall no longer reports success when the user cancels the UAC prompt.
[0.1.1] - 2026-06-11
Changed
- Support email updated to hello@probo.com
[0.1.0] - 2026-05-26
Added
- Initial release of the Probo device posture agent.
probo-agent install,uninstall,run,status,collectCLI commands.- Managed OS service installation for macOS (
launchd), Linux (systemd), FreeBSD (rc.d), and Windows (Service Control Manager). - v1 posture check set per OS: disk encryption, screen lock, firewall, time sync, OS version, auto update, password policy, remote login.
- Enrollment / heartbeat / posture reporting against the new
/api/agent/v1Probo REST API. - Auto-update: the agent periodically checks GitHub Releases for a
newer
probo-agent/v*tag and self-installs it. The running binary is swapped atomically and the OS service supervisor is asked to restart via a dedicated exit code (75). - Cosign signature verification of every release before installation:
checksums.txt.bundleis verified withsigstore-goagainst the Sigstore public-good trust root, pinned to the GitHub Actions OIDC identity forrelease-probo-agent.yamlon a tagged commit. Releases without a Sigstore bundle, with an invalid bundle, or signed by a different workflow are rejected without touching the running binary. probo-agent update [--check]command for manual one-shot upgrade.probo-agent install --no-auto-updateflag to opt out of automatic upgrades; the flag is persisted inconfig.jsonasupdates_disabled.probo-agent statusnow reports the configured update interval and whether auto-update is enabled.- Screen lock detection for additional Linux desktop environments: KDE Plasma, i3, Sway, Hyprland, Xfce, MATE, Cinnamon, UKUI, and LightDM.
Fixed
- macOS launchd service label corrected to
com.probo.agent. - FreeBSD check command failures are now handled before reading service status.
- macOS postinstall script no longer uses
evalto parse configuration. - Windows agent key file replacement is now performed atomically.
- Windows service uninstall is now idempotent.
- FreeBSD
rc.dinstall validates executable and state directory paths to prevent shell injection.