Skip to content

munki

v7.2.0 Security

This release includes 1 security fix for security teams reviewing exposed deployments.

Published 26d Deployment Automation
✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →
This release patches 1 known CVE

Affected surfaces

auth

Summary

AI summary

Broad release touches Other changes, Build info, Bug fixes, and managedsoftwareupdate.

Full changelog

This is the official release of Munki 7.2.0, a feature-add and bug-fix release of the Munki tools.

This is the same build as Release Candidate 1.

Build info

  • This release was built with Xcode 26.5 (17F42) on macOS 26.4 (25E246) via a GitHub Actions workflow here: https://github.com/macadmins/munki-builds. It has been signed and notarized by MacAdmins Open Source.

  • Distribution package version: 7.2.0.5787

    • Components:
      • com.googlecode.munki.core 7.2.0.5787
      • com.googlecode.munki.admin 7.2.0.5787
      • com.googlecode.munki.app 7.2.0.5785
      • com.googlecode.munki.app_usage 7.2.0.5787
      • com.googlecode.munki.launchd 7.0.0.5320
      • com.googlecode.munki.pythonlibs 6.7.0.5293
      • com.googlecode.munki.libs 5.5

New feature:

  • Optional (admin-managed) user preference for "allowed notification time windows".
    See https://github.com/munki/munki/wiki/Allowed-notification-windows for details on this new feature.

Bug fixes:

  • Percent-encode '+' character in all requests for Munki resources; this makes some web servers happier. https://github.com/munki/munki/commit/427a9268ff4d36a8a9063a87e4419683ec2e4e6c
  • MSC.app: Fix for an issue where you are repeatedly prompted to install available Apple updates when attempting to quit https://github.com/munki/munki/commit/ec7a61cc4519097d4a1a0f3ede3ffda828a084a9
  • MSC.app: Fix positioning/layout of status info on item detail pages. Addresses #1357 Thanks to @chrisgrande and @robertryansqub. https://github.com/munki/munki/commit/2e4e3e1eda3ce07518220fd88116146dc12a78d0
  • manifestutil: A fix for a reference to a non-existent subcommand. Thanks to @jc0b. #1365
  • managedsoftwareupdate: A fix for clearing bootstrap mode if there is keyboard or mouse activity during a session. https://github.com/munki/munki/commit/57bed10f94b59746ff2ee525a6e688a6d95951b3

Other changes:

  • When failing to retrieve the primary manifest, instead of exiting immediately, continue to run any existing Munki postflight script. Addresses #1353 Thanks to @BigMacAdmin. https://github.com/munki/munki/commit/81721f369098076933977e315afec57b6fa451ea
  • A fix for a potential security issue: this change prevents embedding external URLs inside munki:// URLs. Thanks to @kevinmcox. ttps://github.com/munki/munki/commit/b015b45d419f21f5315b565627ee8234ef46210b
  • managedsoftwareupdate: Changes to status/progress info messages for more consistent/predictable progress info: https://github.com/munki/munki/commit/17838ce7a1d9539a1736c626ad2029456e2cec10
  • managedsoftwareupdate: some changes to the handling of pkginfo 'display_name' and 'icon_name' keys to more closely match the behavior of the previous Python code. Thanks to @stevemaser for reporting.
  • Managed Software Center.app: improved behavior when quitting the app by better tracking when the quit is initiated by Munki vs the user: https://github.com/munki/munki/commit/e43495c18a2f82f55e5594de75c3b130f703d9eb

Localization

Thanks to the following people for contributing to updated localizations for Managed Software Center:

  • Danish: Thanks to Thomas Tvegaard.
  • Dutch: Thanks to Dimitri Van Elsen.
  • Finnish: Thanks to Tuomo Lindqvist and @MiqViq.
  • French: Thanks to Bertrand Chatain.
  • German: Thanks to Henning Kessler.
  • Italian: Thanks to Daniel Moore and Paolo Bonzini.
  • Japanese: Thanks to Koji Arita and @arubdesu.
  • Norwegian Bokmål: Thanks to Frank Paul Silye.
  • Russian: Thanks to Mike Pullen, Daniel Moore, and Tatiana Ovchinnikova (@xtmprsqzntwlfb)
  • Spanish: Thanks to Joaquin Cabrerizo Egea.
  • Swedish: Thaks to @MagerValp.

A complete list of changes between 7.1.2 and 7.2.0 is here: https://github.com/munki/munki/compare/v7.1.2...v7.2.0

Security Fixes

  • Prevents embedding external URLs inside munki:// URLs – mitigates potential security issue (reported by @kevinmcox)

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track munki

Get notified when new releases ship.

Sign up free

About munki

Managed software installation for macOS

All releases →

Related context

Beta — feedback welcome: [email protected]