Skip to content

Elevate 1.7.0

Choose a tag to compare

@github-actions github-actions released this 15 Sep 11:27
· 77 commits to main since this release
b7dc794

Changed

  • Windows: the release workflow signs the MSIs, the app's executable and assemblies, elevate.exe
    and elevate-audit.exe with a Certum code-signing certificate (SimplySign) instead of Azure
    Artifact Signing, which is not offered to individuals outside the USA and Canada. The publisher shows as "Open Source
    Developer Frode Hus"; SmartScreen may still warn on a new release until reputation builds.

macOS

Signed with Developer ID and notarized.

Install with Homebrew (the fully qualified cask name is required: this tap is not a homebrew- named repository):

brew tap FrodeHus/elevate https://github.com/FrodeHus/elevate
brew trust frodehus/elevate
brew install --cask frodehus/elevate/elevate

The cask installs the pkg (Homebrew asks for your password), which also puts the elevate CLI on your PATH.

Or download Elevate-1.7.0.dmg below and drag Elevate to Applications. SHA-256: e7dbc7e2e5b0f5a760d4ee6ebdcabb2af53dcadb58b86db062f0316b4561ceef The DMG is the app alone.

Windows

Download the MSI for your architecture below and run it. It installs for the current user (no admin rights) into %LOCALAPPDATA%\Programs\Elevate and needs the .NET 10 runtime: winget install Microsoft.DotNet.Runtime.10.

Code-signed (Certum). SmartScreen can still show "Windows protected your PC" for a new release until the publisher has built reputation; choose More info, then Run anyway.

SHA-256:

  • x64: d15a3f029b985840b676c37349069e1a01986129696b0c54928758efcaf8faf9
  • arm64: d3ceba88728c1c7044800127039d4df2c9d912169290cf73d6d5f8c84a9e3111

CLI (Linux, macOS, Windows)

One self-contained elevate binary per platform, no runtime to install.

macOS (Apple Silicon): the CLI is installed with the app by the Homebrew cask above or by Elevate-1.7.0.pkg, as /usr/local/bin/elevate. The elevate-cli formula is deprecated and will be removed in a later release; it still installs on Linux and Intel Macs:

brew install frodehus/elevate/elevate-cli

Windows: Elevate-1.7.0-x64.msi (or -arm64.msi) installs elevate.exe in a cli folder under the app and adds that folder to your PATH. Standalone: winget install Reothor.Elevate.CLI once the manifest is submitted; until then download elevate-cli-1.7.0-win-x64.zip (or -win-arm64.zip) below and put elevate.exe on your PATH.

Or download the archive for your platform below and unpack it anywhere on your PATH. Verify with sha256sum -c elevate-cli-1.7.0-checksums.txt. See cli/README.md.

elevate-audit

The read-only companion that lists standing privileged access to move to PIM is versioned and released on its own, under the audit-v tags: brew install frodehus/elevate/elevate-audit, winget install Reothor.Elevate.Audit once the manifest is submitted, or the archives of the latest audit release. See docs/audit.md.

Enterprise

Elevate-1.7.0.pkg is a macOS installer package, and installs the elevate CLI (/usr/local/bin/elevate, Apple Silicon), signed with Developer ID Installer and notarized, for Jamf, Intune and sudo installer -pkg Elevate-1.7.0.pkg -target /. SHA-256: 73826cebcb4d011064584f30641d249a2b97e74dc635029d47eb228e9d8e4978

Elevate-enterprise-kit-1.7.0.zip holds the managed configuration templates: the Elevate.admx/Elevate.adml policy definitions and a .reg file for Windows, a mobileconfig, an Intune preference file and a Jamf manifest for macOS, a managed.json template for the CLI, the worked example and keys.md, the key reference. SHA-256: 4061275aeea05ad826b8de0834eda41046977db41f08a7f056870f2068c4fdab

Deploying Elevate to a fleet starts at docs/enterprise/README.md.