This release includes 1 security fix for security teams reviewing exposed deployments.
Affected surfaces
Summary
AI summaryBroad release touches Other changes, Build info, Bug fixes, and managedsoftwareupdate.
Full changelog
This is the official release of Munki 7.2.0, a feature-add and bug-fix release of the Munki tools.
This is the same build as Release Candidate 1.
Build info
-
This release was built with Xcode 26.5 (17F42) on macOS 26.4 (25E246) via a GitHub Actions workflow here: https://github.com/macadmins/munki-builds. It has been signed and notarized by MacAdmins Open Source.
-
Distribution package version: 7.2.0.5787
- Components:
- com.googlecode.munki.core 7.2.0.5787
- com.googlecode.munki.admin 7.2.0.5787
- com.googlecode.munki.app 7.2.0.5785
- com.googlecode.munki.app_usage 7.2.0.5787
- com.googlecode.munki.launchd 7.0.0.5320
- com.googlecode.munki.pythonlibs 6.7.0.5293
- com.googlecode.munki.libs 5.5
- Components:
New feature:
- Optional (admin-managed) user preference for "allowed notification time windows".
See https://github.com/munki/munki/wiki/Allowed-notification-windows for details on this new feature.
Bug fixes:
- Percent-encode '+' character in all requests for Munki resources; this makes some web servers happier. https://github.com/munki/munki/commit/427a9268ff4d36a8a9063a87e4419683ec2e4e6c
- MSC.app: Fix for an issue where you are repeatedly prompted to install available Apple updates when attempting to quit https://github.com/munki/munki/commit/ec7a61cc4519097d4a1a0f3ede3ffda828a084a9
- MSC.app: Fix positioning/layout of status info on item detail pages. Addresses #1357 Thanks to @chrisgrande and @robertryansqub. https://github.com/munki/munki/commit/2e4e3e1eda3ce07518220fd88116146dc12a78d0
- manifestutil: A fix for a reference to a non-existent subcommand. Thanks to @jc0b. #1365
- managedsoftwareupdate: A fix for clearing bootstrap mode if there is keyboard or mouse activity during a session. https://github.com/munki/munki/commit/57bed10f94b59746ff2ee525a6e688a6d95951b3
Other changes:
- When failing to retrieve the primary manifest, instead of exiting immediately, continue to run any existing Munki postflight script. Addresses #1353 Thanks to @BigMacAdmin. https://github.com/munki/munki/commit/81721f369098076933977e315afec57b6fa451ea
- A fix for a potential security issue: this change prevents embedding external URLs inside munki:// URLs. Thanks to @kevinmcox. ttps://github.com/munki/munki/commit/b015b45d419f21f5315b565627ee8234ef46210b
- managedsoftwareupdate: Changes to status/progress info messages for more consistent/predictable progress info: https://github.com/munki/munki/commit/17838ce7a1d9539a1736c626ad2029456e2cec10
- managedsoftwareupdate: some changes to the handling of pkginfo 'display_name' and 'icon_name' keys to more closely match the behavior of the previous Python code. Thanks to @stevemaser for reporting.
- Managed Software Center.app: improved behavior when quitting the app by better tracking when the quit is initiated by Munki vs the user: https://github.com/munki/munki/commit/e43495c18a2f82f55e5594de75c3b130f703d9eb
Localization
Thanks to the following people for contributing to updated localizations for Managed Software Center:
- Danish: Thanks to Thomas Tvegaard.
- Dutch: Thanks to Dimitri Van Elsen.
- Finnish: Thanks to Tuomo Lindqvist and @MiqViq.
- French: Thanks to Bertrand Chatain.
- German: Thanks to Henning Kessler.
- Italian: Thanks to Daniel Moore and Paolo Bonzini.
- Japanese: Thanks to Koji Arita and @arubdesu.
- Norwegian Bokmål: Thanks to Frank Paul Silye.
- Russian: Thanks to Mike Pullen, Daniel Moore, and Tatiana Ovchinnikova (@xtmprsqzntwlfb)
- Spanish: Thanks to Joaquin Cabrerizo Egea.
- Swedish: Thaks to @MagerValp.
A complete list of changes between 7.1.2 and 7.2.0 is here: https://github.com/munki/munki/compare/v7.1.2...v7.2.0
Security Fixes
- Prevents embedding external URLs inside munki:// URLs – mitigates potential security issue (reported by @kevinmcox)
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Beta — feedback welcome: [email protected]