From 2f34813d647c07c4cc50a12938ae9ca912485895 Mon Sep 17 00:00:00 2001 From: Allen Houchins Date: Tue, 28 Jul 2026 21:38:21 -0500 Subject: [PATCH 1/2] Remove Yubikey Manager as a macOS FMA The yubico-yubikey-manager cask was removed from homebrew-cask on 2026-07-28 after being disabled on 2025-07-27 because it is discontinued upstream (replaced by yubico-authenticator). The brew API 404s for the token, so the maintained-apps ingester panics with "app not found in brew API". Freezing the app in #50054 did not help, since fetchCask runs before the frozen flag is applied. Removes the Homebrew input, the darwin output, and the darwin apps.json entry, and retargets the bare /software-catalog/yubico-yubikey-manager redirect to the Windows page so the URL keeps resolving. Also drops the macOS-only "Requires Rosetta 2" sentence from the Windows entry's description. The Windows FMA, shared icon, and website image are kept. --- .../homebrew/yubico-yubikey-manager.json | 9 -------- ee/maintained-apps/outputs/apps.json | 9 +------- .../yubico-yubikey-manager/darwin.json | 22 ------------------- website/config/routes.js | 2 +- 4 files changed, 2 insertions(+), 40 deletions(-) delete mode 100644 ee/maintained-apps/inputs/homebrew/yubico-yubikey-manager.json delete mode 100644 ee/maintained-apps/outputs/yubico-yubikey-manager/darwin.json diff --git a/ee/maintained-apps/inputs/homebrew/yubico-yubikey-manager.json b/ee/maintained-apps/inputs/homebrew/yubico-yubikey-manager.json deleted file mode 100644 index 2b640361fd4..00000000000 --- a/ee/maintained-apps/inputs/homebrew/yubico-yubikey-manager.json +++ /dev/null @@ -1,9 +0,0 @@ -{ - "name": "Yubikey Manager", - "slug": "yubico-yubikey-manager/darwin", - "unique_identifier": "com.yubico.ykman", - "token": "yubico-yubikey-manager", - "installer_format": "pkg", - "default_categories": ["Productivity"], - "frozen": true -} diff --git a/ee/maintained-apps/outputs/apps.json b/ee/maintained-apps/outputs/apps.json index 9a98c09d1ef..7bbfeb0ffae 100644 --- a/ee/maintained-apps/outputs/apps.json +++ b/ee/maintained-apps/outputs/apps.json @@ -9500,19 +9500,12 @@ "unique_identifier": "Yubico Authenticator", "description": "Yubico Authenticator is an application for generating TOTP and HOTP codes." }, - { - "name": "Yubikey Manager", - "slug": "yubico-yubikey-manager/darwin", - "platform": "darwin", - "unique_identifier": "com.yubico.ykman", - "description": "YubiKey Manager is an application for configuring any YubiKey. Requires Rosetta 2. YubiKey Manager won't get security updates or bug fixes. It's End of Life: https://www.yubico.com/support/download/yubikey-manager" - }, { "name": "Yubikey Manager", "slug": "yubico-yubikey-manager/windows", "platform": "windows", "unique_identifier": "YubiKey Manager", - "description": "YubiKey Manager is an application for configuring any YubiKey. Requires Rosetta 2. YubiKey Manager won't get security updates or bug fixes. It's End of Life: https://www.yubico.com/support/download/yubikey-manager" + "description": "YubiKey Manager is an application for configuring any YubiKey. YubiKey Manager won't get security updates or bug fixes. It's End of Life: https://www.yubico.com/support/download/yubikey-manager" }, { "name": "Zappy", diff --git a/ee/maintained-apps/outputs/yubico-yubikey-manager/darwin.json b/ee/maintained-apps/outputs/yubico-yubikey-manager/darwin.json deleted file mode 100644 index 2e0bba58ac1..00000000000 --- a/ee/maintained-apps/outputs/yubico-yubikey-manager/darwin.json +++ /dev/null @@ -1,22 +0,0 @@ -{ - "versions": [ - { - "version": "1.2.5", - "queries": { - "exists": "SELECT 1 FROM apps WHERE bundle_identifier = 'com.yubico.ykman';", - "patched": "SELECT 1 WHERE NOT EXISTS (SELECT 1 FROM apps WHERE bundle_identifier = 'com.yubico.ykman' AND version_compare(bundle_short_version, '1.2.5') < 0);" - }, - "installer_url": "https://developers.yubico.com/yubikey-manager-qt/Releases/yubikey-manager-qt-1.2.5-mac.pkg", - "install_script_ref": "11ef47ae", - "uninstall_script_ref": "60cb2225", - "sha256": "009d1ea2ddf98da0ea748df65c2dc88ae16106a684f444a25a49f542413f8732", - "default_categories": [ - "Productivity" - ] - } - ], - "refs": { - "11ef47ae": "#!/bin/bash\n\n# variables\nAPPDIR=\"/Applications/\"\nTMPDIR=$(dirname \"$(realpath \"$INSTALLER_PATH\")\")\n# functions\n\nquit_and_track_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local timeout_duration=10\n\n # check if the application is running\n local app_running\n app_running=$(osascript -e \"application id \\\"$bundle_id\\\" is running\" 2>/dev/null)\n if [[ \"$app_running\" != \"true\" ]]; then\n eval \"export $var_name=0\"\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping quitting application ID '$bundle_id'.\"\n eval \"export $var_name=0\"\n return\n fi\n\n # App was running, mark it for relaunch\n eval \"export $var_name=1\"\n echo \"Application '$bundle_id' was running; will relaunch after installation.\"\n\n echo \"Quitting application '$bundle_id'...\"\n\n # try to quit the application within the timeout period\n local quit_success=false\n SECONDS=0\n while (( SECONDS < timeout_duration )); do\n if osascript -e \"tell application id \\\"$bundle_id\\\" to quit\" >/dev/null 2>&1; then\n if ! pgrep -f \"$bundle_id\" >/dev/null 2>&1; then\n echo \"Application '$bundle_id' quit successfully.\"\n quit_success=true\n break\n fi\n fi\n sleep 1\n done\n\n if [[ \"$quit_success\" = false ]]; then\n echo \"Application '$bundle_id' did not quit.\"\n fi\n}\n\n\nrelaunch_application() {\n local bundle_id=\"$1\"\n local var_name=\"APP_WAS_RUNNING_$(echo \"$bundle_id\" | tr '.-' '__')\"\n local was_running\n\n # Check if the app was running before installation\n eval \"was_running=\\$$var_name\"\n if [[ \"$was_running\" != \"1\" ]]; then\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping relaunching application ID '$bundle_id'.\"\n return\n fi\n\n echo \"Relaunching application '$bundle_id'...\"\n\n # Launch the app in the logged-in user's GUI session. Apps launched by root\n # won't register with the user's Dock/GUI, so run 'open' as the console user.\n # Use 'launchctl asuser' to bootstrap into the console user's Mach namespace\n # and GUI session — 'sudo -u' alone doesn't do this, which can cause\n # LSOpenURLsWithRole() failures even when 'open' exits 0.\n local open_status=0\n if [[ $EUID -eq 0 ]]; then\n local console_uid\n console_uid=$(id -u \"$console_user\")\n /bin/launchctl asuser \"$console_uid\" sudo -u \"$console_user\" open -b \"$bundle_id\" >/dev/null 2>&1 || open_status=$?\n else\n open -b \"$bundle_id\" >/dev/null 2>&1 || open_status=$?\n fi\n\n if [[ $open_status -eq 0 ]]; then\n echo \"Application '$bundle_id' relaunched successfully.\"\n else\n echo \"Failed to relaunch application '$bundle_id'.\"\n fi\n}\n\n\n# install pkg files\nquit_and_track_application 'com.yubico.ykman'\nsudo installer -pkg \"$TMPDIR/yubikey-manager-qt-1.2.5-mac.pkg\" -target /\nrelaunch_application 'com.yubico.ykman'\n", - "60cb2225": "#!/bin/bash\n\n# variables\nLOGGED_IN_USER=$(scutil <<< \"show State:/Users/ConsoleUser\" | awk '/Name :/ { print $3 }')\n# functions\n\nexpand_pkgid_and_map() {\n local PKGID=\"$1\"\n local FUNC=\"$2\"\n if [[ \"$PKGID\" == *\"*\" ]]; then\n local prefix=\"${PKGID%\\*}\"\n echo \"Expanding wildcard for PKGID: $PKGID\"\n for receipt in $(pkgutil --pkgs | grep \"^${prefix}\"); do\n echo \"Processing $receipt\"\n \"$FUNC\" \"$receipt\"\n done\n else\n \"$FUNC\" \"$PKGID\"\n fi\n}\n\nforget_pkg() {\n local PKGID=\"$1\"\n expand_pkgid_and_map \"$PKGID\" forget_receipt\n}\n\nforget_receipt() {\n local PKGID=\"$1\"\n sudo pkgutil --forget \"$PKGID\"\n}\n\nquit_application() {\n local bundle_id=\"$1\"\n local timeout_duration=10\n\n # check if the application is running\n local app_running\n app_running=$(osascript -e \"application id \\\"$bundle_id\\\" is running\" 2>/dev/null)\n if [[ \"$app_running\" != \"true\" ]]; then\n return\n fi\n\n local console_user\n console_user=$(stat -f \"%Su\" /dev/console)\n if [[ -z \"$console_user\" || \"$console_user\" == \"root\" || \"$console_user\" == \"loginwindow\" ]]; then\n echo \"Not logged into a non-root GUI; skipping quitting application ID '$bundle_id'.\"\n return\n fi\n\n echo \"Quitting application '$bundle_id'...\"\n\n # try to quit the application within the timeout period\n local quit_success=false\n SECONDS=0\n while (( SECONDS < timeout_duration )); do\n if osascript -e \"tell application id \\\"$bundle_id\\\" to quit\" >/dev/null 2>&1; then\n if ! pgrep -f \"$bundle_id\" >/dev/null 2>&1; then\n echo \"Application '$bundle_id' quit successfully.\"\n quit_success=true\n break\n fi\n fi\n sleep 1\n done\n\n if [[ \"$quit_success\" = false ]]; then\n echo \"Application '$bundle_id' did not quit.\"\n fi\n}\n\n\nremove_pkg_files() {\n local PKGID=\"$1\"\n expand_pkgid_and_map \"$PKGID\" remove_receipt_files\n}\n\nremove_receipt_files() {\n local PKGID=\"$1\"\n local PKGINFO VOLUME INSTALL_LOCATION FULL_INSTALL_LOCATION\n\n echo \"pkgutil --pkg-info-plist \\\"$PKGID\\\"\"\n PKGINFO=$(pkgutil --pkg-info-plist \"$PKGID\")\n VOLUME=$(echo \"$PKGINFO\" | awk '/volume<\\/key>/ {getline; gsub(/.*|<\\/string>.*/, \"\"); print}')\n INSTALL_LOCATION=$(echo \"$PKGINFO\" | awk '/install-location<\\/key>/ {getline; gsub(/.*|<\\/string>.*/, \"\"); print}')\n\n if [ -z \"$INSTALL_LOCATION\" ] || [ \"$INSTALL_LOCATION\" = \"/\" ]; then\n FULL_INSTALL_LOCATION=\"$VOLUME\"\n else\n FULL_INSTALL_LOCATION=\"$VOLUME/$INSTALL_LOCATION\"\n FULL_INSTALL_LOCATION=$(echo \"$FULL_INSTALL_LOCATION\" | sed 's|//|/|g')\n fi\n\n echo \"sudo pkgutil --only-files --files \\\"$PKGID\\\" | sed \\\"s|^|${FULL_INSTALL_LOCATION}/|\\\" | tr '\\\\\\\\n' '\\\\\\\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\"\n sudo pkgutil --only-files --files \"$PKGID\" | sed \"s|^|/${INSTALL_LOCATION}/|\" | tr '\\n' '\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\n\n echo \"sudo pkgutil --only-dirs --files \\\"$PKGID\\\" | sed \\\"s|^|${FULL_INSTALL_LOCATION}/|\\\" | grep '\\\\.app$' | tr '\\\\\\\\n' '\\\\\\\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\"\n sudo pkgutil --only-dirs --files \"$PKGID\" | sed \"s|^|${FULL_INSTALL_LOCATION}/|\" | grep '\\.app$' | tr '\\n' '\\0' | /usr/bin/sudo -u root -E -- /usr/bin/xargs -0 -- /bin/rm -rf\n\n root_app_dir=$(\n sudo pkgutil --only-dirs --files \"$PKGID\" \\\n | sed \"s|^|${FULL_INSTALL_LOCATION}/|\" \\\n | grep 'Applications' \\\n | awk '{ print length, $0 }' \\\n | sort -n \\\n | head -n1 \\\n | cut -d' ' -f2-\n )\n if [ -n \"$root_app_dir\" ]; then\n echo \"sudo rmdir -p \\\"$root_app_dir\\\" 2>/dev/null || :\"\n sudo rmdir -p \"$root_app_dir\" 2>/dev/null || :\n fi\n}\n\ntrash() {\n local logged_in_user=\"$1\"\n local target_file=\"$2\"\n local timestamp=\"$(date +%Y-%m-%d-%s)\"\n local rand=\"$(jot -r 1 0 99999)\"\n\n # replace ~ with /Users/$logged_in_user\n if [[ \"$target_file\" == ~* ]]; then\n target_file=\"/Users/$logged_in_user${target_file:1}\"\n fi\n\n local trash=\"/Users/$logged_in_user/.Trash\"\n\n # If the target contains glob characters, expand it and move each match.\n if [[ \"$target_file\" == *[*?[]* ]]; then\n local file file_name\n local matched=false\n local i=0\n # compgen -G expands the (quoted) pattern itself, so paths containing\n # spaces glob correctly; reading line by line keeps each match intact.\n while IFS= read -r file; do\n [[ -n \"$file\" ]] || continue\n [[ -e \"$file\" || -L \"$file\" ]] || continue\n matched=true\n i=$((i + 1))\n file_name=\"$(basename \"$file\")\"\n echo \"removing $file.\"\n # The per-match counter keeps matches that share a basename from\n # overwriting each other in the trash.\n mv -f \"$file\" \"$trash/${file_name}_${timestamp}_${rand}_${i}\"\n done < <(compgen -G \"$target_file\" 2>/dev/null)\n if [[ \"$matched\" == false ]]; then\n echo \"$target_file doesn't exist.\"\n fi\n return\n fi\n\n local file_name=\"$(basename \"${target_file}\")\"\n\n if [[ -e \"$target_file\" ]]; then\n echo \"removing $target_file.\"\n mv -f \"$target_file\" \"$trash/${file_name}_${timestamp}_${rand}\"\n else\n echo \"$target_file doesn't exist.\"\n fi\n}\n\nquit_application 'com.yubico.ykman'\nremove_pkg_files 'com.yubico.ykman'\nforget_pkg 'com.yubico.ykman'\nsudo rmdir '~/Library/Caches/Yubico'\ntrash $LOGGED_IN_USER '~/Library/Caches/Yubico/YubiKey Manager'\ntrash $LOGGED_IN_USER '~/Library/Preferences/com.org-yubico.YubiKey Manager.plist'\ntrash $LOGGED_IN_USER '~/Library/Saved Application State/com.yubico.ykman.savedState'\n" - } -} diff --git a/website/config/routes.js b/website/config/routes.js index 5e6f24d3baf..79c0643cf43 100644 --- a/website/config/routes.js +++ b/website/config/routes.js @@ -1136,7 +1136,7 @@ module.exports.routes = { 'GET /software-catalog/zed': '/software-catalog/zed-darwin', 'GET /software-catalog/windows-app': '/software-catalog/windows-app-darwin', 'GET /software-catalog/tunnelblick': '/software-catalog/tunnelblick-darwin', - 'GET /software-catalog/yubico-yubikey-manager': '/software-catalog/yubico-yubikey-manager-darwin', + 'GET /software-catalog/yubico-yubikey-manager': '/software-catalog/yubico-yubikey-manager-windows', 'GET /software-catalog/zoom': '/software-catalog/zoom-darwin', 'GET /software-catalog/vnc-viewer': '/software-catalog/vnc-viewer-darwin', 'GET /apps': '/software-catalog',// This is mostly for mikermcneil who keeps trying to type the old url. From 368936ec4cb1b8d94132d4aded641ff68c5cc8dc Mon Sep 17 00:00:00 2001 From: Allen Houchins <32207388+allenhouchins@users.noreply.github.com> Date: Tue, 28 Jul 2026 21:45:45 -0500 Subject: [PATCH 2/2] Update route for yubico-yubikey-manager to darwin --- website/config/routes.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/website/config/routes.js b/website/config/routes.js index 79c0643cf43..5e6f24d3baf 100644 --- a/website/config/routes.js +++ b/website/config/routes.js @@ -1136,7 +1136,7 @@ module.exports.routes = { 'GET /software-catalog/zed': '/software-catalog/zed-darwin', 'GET /software-catalog/windows-app': '/software-catalog/windows-app-darwin', 'GET /software-catalog/tunnelblick': '/software-catalog/tunnelblick-darwin', - 'GET /software-catalog/yubico-yubikey-manager': '/software-catalog/yubico-yubikey-manager-windows', + 'GET /software-catalog/yubico-yubikey-manager': '/software-catalog/yubico-yubikey-manager-darwin', 'GET /software-catalog/zoom': '/software-catalog/zoom-darwin', 'GET /software-catalog/vnc-viewer': '/software-catalog/vnc-viewer-darwin', 'GET /apps': '/software-catalog',// This is mostly for mikermcneil who keeps trying to type the old url.