Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
91 commits
Select commit Hold shift + click to select a range
b2985a6
fix(assignments): change default mode to append for consistency
kris6673 Jul 13, 2026
ad9caf3
Boilerplate onedrive root permissions cache (not implemented yet)
rvdwegen Jul 13, 2026
610ec61
fix(graph): reconcile AppCache app id drift
Zacgoose Jul 14, 2026
5b42363
feat(nudge-mfa): add group targeting and auth method selection
TecharyJames Jul 14, 2026
176d43b
force external uri to be partner center
KelvinTegelaar Jul 14, 2026
8c4cf8d
fixes resolver for MCP
KelvinTegelaar Jul 14, 2026
32ab1c8
API HF
KelvinTegelaar Jul 14, 2026
2da1872
move snooze to new permission
KelvinTegelaar Jul 14, 2026
9d71e07
Dev to hf (#2140)
KelvinTegelaar Jul 14, 2026
2a86601
Feat: authenticator campaign improvments (#2139)
KelvinTegelaar Jul 14, 2026
a557f51
fix: Change default assignment mode to append (#2137)
KelvinTegelaar Jul 14, 2026
24db2c5
feat(ninjaone): auto-create CVE vulnerability scan group when missing
MWG-Logan Jul 14, 2026
2bc0c8e
fix(standards): cast retention days to integer
Zacgoose Jul 15, 2026
986de02
chore: align frontend file with api file
Zacgoose Jul 15, 2026
8f1dd76
fix(standards): normalize smart lockout mode
Zacgoose Jul 15, 2026
25f38c5
fix(cisa): correct EXO 1.4.1 failure output
Zacgoose Jul 15, 2026
2856852
fix(orca): validate ZAP-supported spam actions
Zacgoose Jul 15, 2026
45bd6c9
feat(cache): implement field projection for test data
Zacgoose Jul 15, 2026
ba8232e
fix(cippdb): cache PIM role data with app token
Zacgoose Jul 15, 2026
98f0778
fix: correct field references in identity and device tests
Zacgoose Jul 15, 2026
003e39f
fix: restore all name/displayName pairings in drift report Intune mat…
MWG-Logan Jul 15, 2026
e247438
feat(config): add copilot policy permissions
Zacgoose Jul 16, 2026
8cde47b
Skip SharePointSharingLinks in DB cache run
Zacgoose Jul 16, 2026
02b0582
fix: restore all name/displayName pairings in drift report Intune mat…
KelvinTegelaar Jul 16, 2026
fb4dec1
feat(ninjaone): auto-create CVE vulnerability scan group when missing…
KelvinTegelaar Jul 16, 2026
01242ff
fix(user): route group updates by effective type
Zacgoose Jul 16, 2026
bc7ace6
Update version_latest.txt
KelvinTegelaar Jul 16, 2026
3529092
Dev to hf (#2144)
KelvinTegelaar Jul 16, 2026
9368bca
SharePoint tests
KelvinTegelaar Jul 16, 2026
eddef92
remove optional error, prettier error.
KelvinTegelaar Jul 16, 2026
ffab43e
(Sharepoint) Site (in)activity cache and report
rvdwegen Jul 16, 2026
a013600
Merge branch 'dev' of https://github.com/KelvinTegelaar/CIPP-API into…
rvdwegen Jul 16, 2026
077c068
Add single lookup support to ListSiteActivity
rvdwegen Jul 16, 2026
ed577f6
feat(alerts): add mailbox types selection for Mailbox quota alert
kris6673 Jul 16, 2026
996e75c
remove guard for retry
KelvinTegelaar Jul 16, 2026
012e8d1
Merge branch 'dev' of https://github.com/KelvinTegelaar/CIPP-API into…
KelvinTegelaar Jul 16, 2026
b183e48
fix(cve-report): scope cache query by tenant
Zacgoose Jul 17, 2026
9b5bdd8
fix(schema): only advance extension status
Zacgoose Jul 17, 2026
cb18769
resource accounts
KelvinTegelaar Jul 17, 2026
9126252
Feat: Add mailbox types selection for quota alerts (#2146)
KelvinTegelaar Jul 17, 2026
fd24542
fix(app-approval): use linked permission set data
Zacgoose Jul 17, 2026
b9534fa
Merge branch 'dev' of https://github.com/KelvinTegelaar/CIPP-API into…
KelvinTegelaar Jul 17, 2026
ffd1d69
licenseAvailable == false when P2
KelvinTegelaar Jul 17, 2026
1072570
AllowedToCreateGroups
KelvinTegelaar Jul 17, 2026
532fff7
fix: use deviceAppManagement endpoints for MAM policies
kris6673 Jul 17, 2026
468d789
Fix: app protection policy deletion by normalizing endpoint URLs (#2147)
KelvinTegelaar Jul 17, 2026
1cfa4bf
stale alert cutoff
KelvinTegelaar Jul 17, 2026
0c13c98
fix(identity): use writeback reset for synced user
Zacgoose Jul 17, 2026
7403b2f
fixes #6319
KelvinTegelaar Jul 17, 2026
68edc5c
Merge branch 'dev' of https://github.com/KelvinTegelaar/CIPP-API into…
KelvinTegelaar Jul 17, 2026
6413f03
ci: add JSON validation workflow for Config, Tools and AddMSPApp
Zacgoose Jul 17, 2026
2ddca8e
ci: add JSON validation workflow
Zacgoose Jul 17, 2026
d348de6
implemets #6390
KelvinTegelaar Jul 18, 2026
83d182d
Merge branch 'dev' of https://github.com/KelvinTegelaar/CIPP-API into…
KelvinTegelaar Jul 18, 2026
99787a0
exclude sharepoint admin center deviations
KelvinTegelaar Jul 18, 2026
4ee94dc
add gdap age group option.
KelvinTegelaar Jul 18, 2026
206f9b1
Alert on new shadow AI tools
KelvinTegelaar Jul 19, 2026
e704077
fix(auditlogs): treat token denial as disable
Zacgoose Jul 20, 2026
06025c8
fix(alert): fix typo in write alert function usage for `QuarantineReq…
Zacgoose Jul 20, 2026
9e51882
fix(ca): correct GuestsOrExternalUsers spelling in CA special-value a…
Zacgoose Jul 20, 2026
ac5a198
fix(standards): log remediation errors instead of silently swallowing…
Zacgoose Jul 20, 2026
b4133f8
fix(intune): stop false App Protection drift from reference-only apps…
Zacgoose Jul 20, 2026
784cff5
fix(intune): preserve @odata.type on synced App Protection templates
Zacgoose Jul 20, 2026
951f831
fix(sherweb): stop migration tasks from running after extension disable
Zacgoose Jul 20, 2026
15efd3d
feat(alert): include license names, SKUs and account status in inacti…
Zacgoose Jul 20, 2026
7d16571
fix(standards): make PWdisplayAppInformationRequiredState able to sat…
Zacgoose Jul 20, 2026
a27aff5
fix(ca): correct guests selector constant
Zacgoose Jul 20, 2026
5a08c2c
fix(http): handle IDictionary request inputs
Zacgoose Jul 20, 2026
f4dd2a7
fix(standards): default untoggled Teams switches to $false instead of…
Zacgoose Jul 20, 2026
e0060db
fix(mem): filter null compare policy results
Zacgoose Jul 20, 2026
e569d2f
add skip when exists
KelvinTegelaar Jul 20, 2026
cf9fc1d
fix(container): reconcile update state on restart
Zacgoose Jul 20, 2026
6bd0081
fix(container): normalize build dates to utc
Zacgoose Jul 20, 2026
835972e
fix(container): restore update check defaults
Zacgoose Jul 20, 2026
32c3878
add sharepoint templated deployments v1
KelvinTegelaar Jul 20, 2026
bd767ff
Merge branch 'dev' of https://github.com/KelvinTegelaar/CIPP-API into…
KelvinTegelaar Jul 20, 2026
096abcf
fix(auth): guard sso migration by permissions
Zacgoose Jul 20, 2026
d141595
fix(autopilot): validate profile names early
Zacgoose Jul 20, 2026
f697a54
fix(dlp): normalize advanced rule handling
Zacgoose Jul 20, 2026
9609ac9
Steps
KelvinTegelaar Jul 20, 2026
9c92086
Revert "feat(ninjaone): auto-create CVE vulnerability scan group when…
JohnDuprey Jul 20, 2026
98d8244
chore: bump version to 10.6.4
JohnDuprey Jul 21, 2026
da332fa
fix: Dev to hotfix (#2148)
JohnDuprey Jul 21, 2026
edd3481
Merge pull request #64 from CyberDrain/dev
github-actions[bot] Jul 24, 2026
9d43278
Merge pull request #79 from CyberDrain/dev
github-actions[bot] Jul 27, 2026
d63b7fa
Merge pull request #88 from CyberDrain/dev
github-actions[bot] Jul 27, 2026
5959b51
Merge pull request #99 from CyberDrain/dev
github-actions[bot] Jul 28, 2026
f1b2c93
Merge pull request #100 from CyberDrain/dev
github-actions[bot] Jul 28, 2026
019f62b
Merge pull request #103 from CyberDrain/dev
github-actions[bot] Jul 29, 2026
82ab262
Merge pull request #115 from CyberDrain/dev
github-actions[bot] Jul 29, 2026
245d9d3
Merge pull request #132 from CyberDrain/dev
github-actions[bot] Jul 30, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
73 changes: 73 additions & 0 deletions .github/scripts/validate-json.mjs
Original file line number Diff line number Diff line change
@@ -0,0 +1,73 @@
import { readFile, readdir, writeFile, appendFile } from "node:fs/promises";
import path from "node:path";

// Usage: node validate-json.mjs [--strip <prefix>] <dir> [dir...]
// --strip removes a leading path prefix from reported filenames, so a PR checked
// out into a subdirectory still reports repo-relative paths.
const argv = process.argv.slice(2);
let strip = "";
const roots = [];
for (let i = 0; i < argv.length; i++) {
if (argv[i] === "--strip") {
strip = argv[++i] ?? "";
} else {
roots.push(argv[i]);
}
}

async function collect(dir) {
let entries;
try {
entries = await readdir(dir, { withFileTypes: true });
} catch (error) {
if (error.code === "ENOENT") return [];
throw error;
}
const files = [];
for (const entry of entries) {
const full = path.join(dir, entry.name);
if (entry.isDirectory()) {
if (entry.name === "node_modules") continue;
files.push(...(await collect(full)));
} else if (entry.name.endsWith(".json")) {
files.push(full);
}
}
return files;
}

const report = (file) => {
const normalised = file.split(path.sep).join("/");
return strip && normalised.startsWith(strip) ? normalised.slice(strip.length) : normalised;
};

const failures = [];
let checked = 0;

for (const root of roots) {
for (const file of await collect(root)) {
checked++;
// Strip a leading UTF-8 BOM: it's tolerated by PowerShell's ConvertFrom-Json
// (how the API loads these files) but rejected by Node's JSON.parse.
const contents = (await readFile(file, "utf8")).replace(/^\uFEFF/, "");
try {
JSON.parse(contents);
} catch (error) {
failures.push({ file: report(file), message: error.message.replace(/\r?\n/g, " ") });
}
}
}

for (const { file, message } of failures) {
// Annotate the PR diff via a GitHub Actions error command.
console.log(`::error file=${file}::${message}`);
}
console.log(`Checked ${checked} JSON file(s), ${failures.length} invalid.`);

// Hand the results to the workflow so it can comment on the PR.
if (process.env.GITHUB_OUTPUT) {
await appendFile(process.env.GITHUB_OUTPUT, `invalid_count=${failures.length}\n`);
}
await writeFile("json-validation-results.json", JSON.stringify(failures, null, 2));

process.exit(failures.length > 0 ? 1 : 0);
121 changes: 121 additions & 0 deletions .github/workflows/Validate_JSON.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,121 @@
---
name: Validate JSON
on:
# pull_request_target (not pull_request) so the token can comment on fork PRs.
# The PR's own code is never executed: it is checked out into ./pr as data only,
# and parsed by the validator script from the trusted base checkout.
pull_request_target:
types: [opened, synchronize, reopened]
branches:
- main
- dev
paths:
- "Config/**/*.json"
- "Tools/**/*.json"
- "AddMSPApp/**/*.json"
- ".github/workflows/Validate_JSON.yml"
- ".github/scripts/validate-json.mjs"
push:
branches:
- dev
paths:
- "Config/**/*.json"
- "Tools/**/*.json"
- "AddMSPApp/**/*.json"
- ".github/workflows/Validate_JSON.yml"
- ".github/scripts/validate-json.mjs"
concurrency:
group: ${{ github.workflow }}-${{ github.event_name == 'pull_request_target' && github.event.pull_request.number || github.ref }}
cancel-in-progress: true
permissions:
contents: read
pull-requests: write
jobs:
validate:
name: Parse JSON in Config, Tools and AddMSPApp
runs-on: ubuntu-latest
steps:
- name: Checkout base (trusted validator script)
uses: actions/checkout@v6

- name: Checkout PR head (untrusted, data only)
if: github.event_name == 'pull_request_target'
uses: actions/checkout@v6
with:
repository: ${{ github.event.pull_request.head.repo.full_name }}
ref: ${{ github.event.pull_request.head.sha }}
path: pr
persist-credentials: false

- name: Validate JSON files
id: validate
continue-on-error: true
env:
ROOT: ${{ github.event_name == 'pull_request_target' && 'pr/' || '' }}
run: >-
node .github/scripts/validate-json.mjs --strip "$ROOT"
"${ROOT}Config" "${ROOT}Tools" "${ROOT}AddMSPApp"

- name: Comment on PR
if: github.event_name == 'pull_request_target'
uses: actions/github-script@v9
with:
github-token: ${{ secrets.GITHUB_TOKEN }}
script: |
const fs = require('fs');
const marker = '<!-- validate-json -->';
const resultsFile = 'json-validation-results.json';
if (!fs.existsSync(resultsFile)) {
// The validator crashed before reporting; let its own error stand.
core.warning('No validation results found — skipping PR comment.');
return;
}
const failures = JSON.parse(fs.readFileSync(resultsFile, 'utf8'));

// Find a previous comment from this workflow so we update instead of piling up.
const { data: comments } = await github.rest.issues.listComments({
...context.repo,
issue_number: context.issue.number,
per_page: 100,
});
const existing = comments.find(
(c) => c.user.type === 'Bot' && c.body.includes(marker)
);

let body;
if (failures.length > 0) {
const list = failures
.map(({ file, message }) => `- \`${file}\`\n > ${message}`)
.join('\n');
body =
`${marker}\n### ⚠️ Invalid JSON detected\n\n` +
`${failures.length} JSON file(s) in this PR could not be parsed. ` +
`These files are loaded directly by CIPP, so a syntax error here breaks the app at runtime.\n\n` +
`${list}\n\n` +
`Please fix the syntax and push again — this comment will update automatically.`;
} else if (existing) {
body = `${marker}\n### ✅ JSON is valid\n\nAll JSON files in \`Config\`, \`Tools\` and \`AddMSPApp\` parse correctly. Thanks for fixing it!`;
} else {
// Nothing was ever broken — stay quiet.
return;
}

if (existing) {
await github.rest.issues.updateComment({
...context.repo,
comment_id: existing.id,
body,
});
} else {
await github.rest.issues.createComment({
...context.repo,
issue_number: context.issue.number,
body,
});
}

- name: Fail if any JSON is invalid
if: steps.validate.outputs.invalid_count != '0'
run: |
echo "::error::${{ steps.validate.outputs.invalid_count }} invalid JSON file(s). See annotations above."
exit 1
28 changes: 14 additions & 14 deletions AddMSPApp/datto.app.xml
Original file line number Diff line number Diff line change
@@ -1,15 +1,15 @@
<ApplicationInfo xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ToolVersion="1.8.3.0">
<Name>install.ps1</Name>
<UnencryptedContentSize>693</UnencryptedContentSize>
<FileName>datto.intunewin</FileName>
<SetupFile>install.ps1</SetupFile>
<EncryptionInfo>
<EncryptionKey>jobB9Ga7J3CbO6acWJyvBRE56nFXwqGfcnGfZRMsJC4=</EncryptionKey>
<MacKey>53SOzs0l6Po2btsGFSMZgkV8vwhH+PxTN8BZDUcfWfg=</MacKey>
<InitializationVector>VjM/osrvPElbu79J+mdXuw==</InitializationVector>
<Mac>UZZXO53Np/tG6Ms+qvwLcNOeD1GRH6NRPFg/TuMz39M=</Mac>
<ProfileIdentifier>ProfileVersion1</ProfileIdentifier>
<FileDigest>KtAWAl29064LG0eyDinbDs0JUbK+EK7GsJovu8obBM4=</FileDigest>
<FileDigestAlgorithm>SHA256</FileDigestAlgorithm>
</EncryptionInfo>
<ApplicationInfo xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ToolVersion="1.8.3.0">
<Name>install.ps1</Name>
<UnencryptedContentSize>693</UnencryptedContentSize>
<FileName>datto.intunewin</FileName>
<SetupFile>install.ps1</SetupFile>
<EncryptionInfo>
<EncryptionKey>jobB9Ga7J3CbO6acWJyvBRE56nFXwqGfcnGfZRMsJC4=</EncryptionKey>
<MacKey>53SOzs0l6Po2btsGFSMZgkV8vwhH+PxTN8BZDUcfWfg=</MacKey>
<InitializationVector>VjM/osrvPElbu79J+mdXuw==</InitializationVector>
<Mac>UZZXO53Np/tG6Ms+qvwLcNOeD1GRH6NRPFg/TuMz39M=</Mac>
<ProfileIdentifier>ProfileVersion1</ProfileIdentifier>
<FileDigest>KtAWAl29064LG0eyDinbDs0JUbK+EK7GsJovu8obBM4=</FileDigest>
<FileDigestAlgorithm>SHA256</FileDigestAlgorithm>
</EncryptionInfo>
</ApplicationInfo>
10 changes: 10 additions & 0 deletions Config/CIPPDBCacheTypes.json
Original file line number Diff line number Diff line change
Expand Up @@ -294,11 +294,21 @@
"friendlyName": "SharePoint Site Usage",
"description": "SharePoint site usage statistics"
},
{
"type": "SiteActivity",
"friendlyName": "Site Activity",
"description": "Per-site activity with siteType classification (SharePoint, SharePointAndTeams, OneDrive) and separate workload activity columns"
},
{
"type": "SharePointSharingLinks",
"friendlyName": "SharePoint & OneDrive Sharing Links",
"description": "Sharing links and external grants on SharePoint and OneDrive files and folders"
},
{
"type": "SharePointPermissions",
"friendlyName": "SharePoint Permissions",
"description": "Site and document library permission assignments, including libraries that no longer inherit and grants to tenant-wide claims such as Everyone except external users"
},
{
"type": "OfficeActivations",
"friendlyName": "Office Activations",
Expand Down
Loading