Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
69 commits
Select commit Hold shift + click to select a range
414be75
Merge pull request #939 from Romanitho/main
Romanitho May 12, 2025
b46bcea
Random Delay
jamiehall123 May 21, 2025
25433f8
Fix to wxs
jamiehall123 May 25, 2025
69ab915
Merge pull request #949 from jamiehall123/main
Romanitho May 27, 2025
792a9ef
2_6_0
Romanitho May 27, 2025
de34b54
2.6.0
Romanitho May 27, 2025
25b3920
Update README.md
AndrewDemski-ad-gmail-com Jun 14, 2025
6c3a4e8
Bump stefanzweifel/git-auto-commit-action from 5.2.0 to 6.0.1
dependabot[bot] Jun 16, 2025
0032272
Bump oxsecurity/megalinter from 8.7.0 to 8.8.0
dependabot[bot] Jun 16, 2025
27e25c5
Enhance deployment instructions and mod functionality in README and s…
KnifMelti Jun 21, 2025
1fe865c
Forgotten Tab
KnifMelti Jun 21, 2025
dc8f39c
Merge branch 'Romanitho:main' into feature/winget-install_mods
KnifMelti Jun 22, 2025
73f2048
Enhance 'Mods for WAU' with JSON output handling
KnifMelti Jun 22, 2025
5823e47
Merge branch 'Romanitho:main' into feature/_WAU-mods_exitcodes
KnifMelti Jun 22, 2025
58dfe8f
Beware!
KnifMelti Jun 22, 2025
91aca59
Merge branch 'feature/_WAU-mods_exitcodes' of https://github.com/Knif…
KnifMelti Jun 22, 2025
b339543
Exit for Reboot too...
KnifMelti Jun 22, 2025
f89d080
WAU Exit Codes from Mods too or standard
KnifMelti Jun 22, 2025
c343fec
Safe Reboot with delay notifying users
KnifMelti Jun 22, 2025
8f26ac3
Small text edits
KnifMelti Jun 23, 2025
4fc97e5
Default reboot message in minutes instead of seconds
KnifMelti Jun 23, 2025
f939719
'Postpone' as an Action too
KnifMelti Jun 24, 2025
06eea1d
Better WU check for Postpone
KnifMelti Jun 24, 2025
b1131ef
Small text change
KnifMelti Jun 24, 2025
f8bb371
Error handling
KnifMelti Jun 25, 2025
253dc4d
Reboot: now basic SCCM client awareness
KnifMelti Jun 26, 2025
3d691b4
Detail: DarkYellow
KnifMelti Jun 26, 2025
1917b61
Add reboot handler option in _WAU-mods-template.ps1 and the check
KnifMelti Jun 26, 2025
fbb8862
Wording more logical
KnifMelti Jun 26, 2025
c9be72c
Full SCCM client awareness (Soft/Hard Reboot)
KnifMelti Jun 26, 2025
a7ce3f1
Enhance mandatory restart (SCCM: Hard Reboot) handling with improved …
KnifMelti Jun 26, 2025
c3af9d7
Refactoring with external 'Test-WAUMods.ps1'
KnifMelti Jun 27, 2025
8f7f279
Rewording comment for clarity
KnifMelti Jun 27, 2025
3a3ede7
Hybrid mandatory SCCM restart handling
KnifMelti Jun 28, 2025
24a00df
Final Hybrid Hard Reboot!
KnifMelti Jun 28, 2025
cf64d97
Not stale
KnifMelti Jun 29, 2025
fd9524d
Merge branch 'Romanitho:main' into feature/ErrorsOnly_NotificationLevel
KnifMelti Jun 29, 2025
a93b567
Update README.md to include 'Errors only' option in notification leve…
KnifMelti Jun 29, 2025
6a9750e
Merge branch 'feature/ErrorsOnly_NotificationLevel' of https://github…
KnifMelti Jun 29, 2025
e1ca1ef
Plural
KnifMelti Jun 29, 2025
dcfa95d
Documentation
KnifMelti Jun 29, 2025
cc0f89a
Nobody cares about functions...
KnifMelti Jun 29, 2025
7f16958
Crash with revision 5.0. Fix a string id row.
KnifMelti Jun 30, 2025
0d7c2c0
revision="4.9" works, next time set in ADMX resources minRequiredRevi…
KnifMelti Jun 30, 2025
2cd9fbe
Bump ncipollo/release-action from 1.16.0 to 1.18.0
dependabot[bot] Jun 30, 2025
909ce39
fix cmd not found error
FaserF Jul 10, 2025
d765ea8
Merge pull request #965 from AndrewDemski-ad-gmail-com/develop
Romanitho Jul 18, 2025
1083097
Merge pull request #972 from KnifMelti/feature/_WAU-mods_exitcodes
Romanitho Jul 18, 2025
058b52c
Merge pull request #979 from FaserF/fix-cmd-not-found
Romanitho Jul 18, 2025
fb526b1
Merge pull request #974 from Romanitho/dependabot/github_actions/deve…
Romanitho Jul 18, 2025
19077d0
Merge pull request #967 from Romanitho/dependabot/github_actions/deve…
Romanitho Jul 18, 2025
100afd0
Merge pull request #966 from Romanitho/dependabot/github_actions/deve…
Romanitho Jul 18, 2025
602bd19
Merge pull request #973 from KnifMelti/feature/ErrorsOnly_Notificatio…
Romanitho Jul 18, 2025
23f1901
Change folder and add header
Romanitho Jul 18, 2025
252f0db
Update README.md too
Romanitho Jul 18, 2025
47e466b
Merge pull request #970 from KnifMelti/feature/winget-install_mods
Romanitho Jul 18, 2025
99e3159
Small fix on merging with comment
Romanitho Jul 18, 2025
e405432
Deprecate ActivateGPOManagement Setting
Romanitho Jul 18, 2025
027bc8d
Merge pull request #987 from Romanitho/cleaning-policies
Romanitho Jul 18, 2025
19d4d27
Docu Detection Script
KnifMelti Jul 18, 2025
07680a5
Link in text
KnifMelti Jul 18, 2025
2eab278
Path error
KnifMelti Jul 18, 2025
a50a4e0
Merge pull request #989 from KnifMelti/docu_detection
Romanitho Jul 18, 2025
5c0fba1
cleaning old deprecated
Romanitho Jul 19, 2025
8c1d5cd
Restore Get-WAUConfig after accidental removal
Romanitho Jul 19, 2025
4e50045
Merge pull request #990 from Romanitho/cleaning
Romanitho Jul 19, 2025
557b95d
Merge pull request #991 from Romanitho/rollback
Romanitho Jul 19, 2025
0a1448f
Update GitFlow_Make-Release-and-Sync-to-Dev.yml
Romanitho Jul 22, 2025
111aab2
Merge pull request #992 from Romanitho/release/2.6.0
Romanitho Jul 23, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/GA_Mega-linter.yml
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,7 @@ jobs:
id: ml
# You can override MegaLinter flavor used to have faster performances
# More info at https://megalinter.github.io/flavors/
uses: oxsecurity/megalinter@5a91fb06c83d0e69fbd23756d47438aa723b4a5a # v8.7.0
uses: oxsecurity/megalinter@e08c2b05e3dbc40af4c23f41172ef1e068a7d651 # v8.8.0
env:
# All available variables are described in documentation
# https://megalinter.github.io/configuration/
Expand Down Expand Up @@ -90,7 +90,7 @@ jobs:
run: sudo chown -Rc $UID .git/
- name: Commit and push applied linter fixes
if: steps.ml.outputs.has_updated_sources == 1 && (env.APPLY_FIXES_EVENT == 'all' || env.APPLY_FIXES_EVENT == github.event_name) && env.APPLY_FIXES_MODE == 'commit' && github.ref != 'refs/heads/main' && (github.event_name == 'push' || github.event.pull_request.head.repo.full_name == github.repository) && !contains(github.event.head_commit.message, 'skip fix')
uses: stefanzweifel/git-auto-commit-action@b863ae1933cb653a53c021fe36dbb774e1fb9403 # v5.2.0
uses: stefanzweifel/git-auto-commit-action@778341af668090896ca464160c2def5d1d1a3eb0 # v6.0.1
with:
branch: ${{ github.event.pull_request.head.ref || github.head_ref || github.ref }}
commit_message: "[MegaLinter] Apply linters fixes"
15 changes: 8 additions & 7 deletions .github/workflows/GitFlow_Make-Release-and-Sync-to-Dev.yml
Original file line number Diff line number Diff line change
Expand Up @@ -24,14 +24,15 @@ jobs:
# Run only when PR is merged (not just closed) and source branch is release/* or hotfix/*
if: github.event.pull_request.merged == true && (startsWith(github.event.pull_request.head.ref, 'release/') || startsWith(github.event.pull_request.head.ref, 'hotfix/'))
runs-on: windows-latest
outputs:
next_semver: ${{ steps.release_version.outputs.NextSemVer }}
steps:
# Step 1: Checkout the code from the main branch after merge
- name: Checkout code
uses: actions/checkout@v4.2.2
uses: actions/checkout@v4
with:
lfs: "true"
fetch-depth: 0
token: ${{ secrets.GITHUB_TOKEN }}

# Step 2: Extract version from branch name and calculate build number
- name: Get final Release Version
Expand Down Expand Up @@ -112,7 +113,7 @@ jobs:

# Step 4: Create stable GitHub release with all artifacts
- name: Create release
uses: ncipollo/release-action@440c8c1cb0ed28b9f43e4d1d670870f059653174 # v1.16.0
uses: ncipollo/release-action@bcfe5470707e8832e12347755757cec0eb3c22af # v1.18.0
with:
tag: v${{ steps.release_version.outputs.NextSemVer }}
prerelease: false # This is a stable release
Expand All @@ -134,10 +135,11 @@ jobs:
needs: build
steps:
- name: Checkout code
uses: actions/checkout@v4.2.2
uses: actions/checkout@v4
with:
fetch-depth: 0

token: ${{ secrets.GH_PAT_SYNC }}

# Step 5: Configure Git for merge back to develop
- name: Configure Git
shell: bash
Expand All @@ -152,9 +154,8 @@ jobs:
# Checkout develop branch
git checkout develop
git pull origin develop

# Merge main into develop with no fast-forward to preserve history
git merge --no-ff origin/main -m "Merge main into develop after the creation of release v${{ steps.release_version.outputs.NextSemVer }}"
git merge --no-ff origin/main -m "Merge main into develop after the creation of release v${{ needs.build.outputs.next_semver }}"

# Push changes to develop branch
git push origin develop
48 changes: 40 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,7 @@ List and Mods folder content will be copied to WAU install location:


### Notification Level
You can choose which notification will be displayed: `Full`, `Success only` or `None`.
You can choose which notification will be displayed: `Full`, `Success only`, `Errors only` or `None`.

### Notification language
You can easily translate toast notifications by creating your locale xml config file (and share it with us :) ).
Expand Down Expand Up @@ -147,7 +147,7 @@ Set `DESKTOPSHORTCUT=1` to create a shortcut for user interaction on the Desktop
Set `STARTMENUSHORTCUT=1` to create shortcuts for user interaction in the Start Menu to run task `Winget-AutoUpdate` and open Logs.

### NOTIFICATIONLEVEL
Specify the Notification level: Full (Default, displays all notification), SuccessOnly (Only displays notification for success) or None (Does not show any popup).
Specify the Notification level: Full (Default, displays all notification), SuccessOnly (Only displays notification for success), ErrorsOnly (Only displays notification for errors) or None (Does not show any popup).

### UPDATESATLOGON
Default value 1. Set `UPDATESATLOGON=0` to disable WAU from running at user logon.
Expand All @@ -158,6 +158,11 @@ Default value Never. Specify the update frequency: Daily, BiDaily, Weekly, BiWee
### UPDATESATTIME
Default value 6AM (06:00:00). Specify the time of the update interval execution time. Example `UPDATESATTIME="11:00:00"`

### UPDATESATTIMEDELAY
Default value is none (00:00). This setting specifies the delay for the scheduled task.
A scheduled task random delay adds a random amount of wait time (up to the specified maximum) before the task starts.
This helps prevent many devices from running the task at the exact same time. This is not applicable to "on logon" triggers.

### DONOTRUNONMETERED
Default value 1. Set `DONOTRUNONMETERED=0` to force WAU to run on metered connections. May add cellular data costs on shared connexion from smartphone for example.

Expand All @@ -175,10 +180,25 @@ Default is 1048576 = 1 MB (ca. 7500 lines)
Specify Winget-AutoUpdate installation location. Default: `C:\Program Files\Winget-AutoUpdate` (Recommended to leave default).

### Deploy with Intune
You can use [Winget-Install](https://github.com/Romanitho/Winget-AutoUpdate/blob/main/Sources/Winget-AutoUpdate/Winget-Install.ps1) to deploy the package for example in Intune:
You can use [Winget-Install](https://github.com/Romanitho/Winget-AutoUpdate/blob/main/Sources/Winget-AutoUpdate/Winget-Install.ps1) to deploy the package (this example with an override of parameters):
```batch
"%systemroot%\sysnative\WindowsPowerShell\v1.0\powershell.exe" -noprofile -executionpolicy bypass -file "C:\Program Files\Winget-AutoUpdate\Winget-Install.ps1" -AppIDs "Adobe.Acrobat.Reader.64-bit --scope machine --override \"-sfx_nu /sAll /rs /msi EULA_ACCEPT=YES DISABLEDESKTOPSHORTCUT=1""
```
### Deploy with SCCM
You can also use [Winget-Install](https://github.com/Romanitho/Winget-AutoUpdate/blob/main/Sources/Winget-AutoUpdate/Winget-Install.ps1) to deploy the same package in **SCCM**:
```batch
"%systemroot%\sysnative\WindowsPowerShell\v1.0\powershell.exe" -noprofile -executionpolicy bypass -file "C:\Program Files\Winget-AutoUpdate\Winget-Install.ps1" -AppIDs "Romanitho.Winget-AutoUpdate --scope machine --override \"/qn RUN_WAU=YES USERCONTEXT=1 STARTMENUSHORTCUT=1 NOTIFICATIONLEVEL=SuccessOnly UPDATESINTERVAL=Daily""
powershell.exe -noprofile -executionpolicy bypass -file "C:\Program Files\Winget-AutoUpdate\Winget-Install.ps1" -AppIDs "Adobe.Acrobat.Reader.64-bit --scope machine --override \"-sfx_nu /sAll /rs /msi EULA_ACCEPT=YES DISABLEDESKTOPSHORTCUT=1""
```
Instead of including the override parameters in the install string you can use a **Mod** (**mods\Adobe.Acrobat.Reader.64-bit-override.txt**) with the content:
```batch
"-sfx_nu /sAll /rs /msi EULA_ACCEPT=YES DISABLEDESKTOPSHORTCUT=1"
```
* A standard single installation: **-AppIDs Notepad++.Notepad++**
* Multiple installations: **-AppIDs "7zip.7zip, Notepad++.Notepad++"**

As a custom detection script you can download/edit [winget-detect.ps1](Sources/Tools/Detection/winget-detect.ps1) (change app to detect [**Application ID**]) in **Intune**/**SCCM**

A nice feature is if you're already using the deprecated standalone script **winget-install.ps1** from the [old repo](https://github.com/Romanitho/Winget-Install) and have placed it somwhere locally on all clients you can make a **SymLink** in its place and keep using the old path (avoiding a lot of work) in your deployed applications (**Winget-Install.ps1** takes care of the SymLink logic).

## GPO / Intune Management
Read more in the [Policies section](https://github.com/Romanitho/Winget-AutoUpdate/tree/main/Sources/Policies).
Expand All @@ -189,8 +209,14 @@ Read more in the [Policies section](https://github.com/Romanitho/Winget-AutoUpda
This script executes **if the network is active/any version of Winget is installed/WAU is running as SYSTEM**.<br>
If **ExitCode** is **1** from `_WAU-mods.ps1` then **Re-run WAU**.

In addition to this legacy handling, a new action-based system is now supported.<br>
This system lets you define multiple actions and conditions directly in your mod scripts, enabling more advanced automation and control over the WAU process.<br>
With actions, you can execute different scripts, check results, and control the WAU flow with greater flexibility and improved logging compared to relying solely on **Exit Code**.

Likewise `_WAU-mods-postsys.ps1` can be used to do things at the end of the **SYSTEM context WAU** process before the user run.

You can find more information in [README Mods for WAU](Sources/Winget-AutoUpdate/mods/README.md)

## Custom scripts (Mods feature for Apps)
The Mods feature allows you to run additional scripts when upgrading or installing an app.
Just put the scripts in question with the **AppID** followed by the `-preinstall`, `-upgrade`, `-install`, `-installed` or `-notinstalled` suffix in the **mods** folder.
Expand All @@ -207,18 +233,24 @@ The **-install** mod will be used for upgrades too if **-upgrade** doesn't exist
> Example:<br>
If you want to run a script that removes the shortcut from **%PUBLIC%\Desktop** (we don't want to fill the desktop with shortcuts our users can't delete) just after installing **Acrobat Reader DC** (32-bit), prepare a powershell script that removes the Public Desktop shortcut **Acrobat Reader DC.lnk** and name your script like this: `Adobe.Acrobat.Reader.32-bit-installed.ps1` and put it in the **mods** folder.

You can find more information on [Winget-Install Repo](https://github.com/Romanitho/Winget-AutoUpdate?tab=readme-ov-file#custom-script-mods-for-wau), as it's a related feature.<br>
Read more in the `README.md` under the directory **mods**.
You can find more information in [README Mods for WAU](Sources/Winget-AutoUpdate/mods/README.md), as it's a related feature.

Share your mods with the community:<br>
<https://github.com/Romanitho/Winget-AutoUpdate/discussions/categories/mods>

### Winget native parameters
Another finess is the **AppID** followed by the `-override` suffix as a **text file** (.**txt**) that you can place under the **mods** folder.
> Example:<br>
**Canneverbe.CDBurnerXP-override.txt** with the content `ADDLOCAL=All REMOVE=Desktop_Shortcut /qn`
**Adobe.Acrobat.Reader.64-bit-override.txt** with the content `"-sfx_nu /sAll /rs /msi EULA_ACCEPT=YES DISABLEDESKTOPSHORTCUT=1"`

This will use the **content** of the text file as a native **winget --override** parameter when upgrading.

Likewise you can use the **AppID** followed by the `-custom` suffix as a **text file** (.**txt**) that you can place under the **mods** folder (*Arguments to be passed on to the installer in addition to the defaults*).
> Example:<br>
**Adobe.Acrobat.Reader.64-bit-custom.txt** with the content `"DISABLEDESKTOPSHORTCUT=1"`

This will use the **content** of the text file as a native **winget --custom** parameter when upgrading.

This will use the **content** of the text file as a native **winget --override** parameter when upgrading (as proposed by [JonNesovic](https://github.com/JonNesovic) in [Mod for --override argument #244](https://github.com/Romanitho/Winget-AutoUpdate/discussions/244#discussion-4637666)).

## Known issues
* As reported by [soredake](https://github.com/soredake), Powershell from MsStore is not supported with WAU in system context. See <https://github.com/Romanitho/Winget-AutoUpdate/issues/113>
Expand Down
46 changes: 19 additions & 27 deletions Sources/Policies/ADMX/WAU.admx
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
<?xml version="1.0" encoding="utf-8"?>
<policyDefinitions xmlns:xsd="http://www.w3.org/2001/XMLSchema"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" revision="4.9"
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" revision="5.0"
schemaVersion="1.0" xmlns="http://www.microsoft.com/GroupPolicy/PolicyDefinitions">
<policyNamespaces>
<target prefix="WAU" namespace="Romanitho.Policies.WAU" />
Expand All @@ -10,6 +10,7 @@
<definitions>
<definition name="SUPPORTED_WAU_1_16_0" displayName="$(string.SUPPORTED_WAU_1_16_0)" />
<definition name="SUPPORTED_WAU_1_16_5" displayName="$(string.SUPPORTED_WAU_1_16_5)" />
<definition name="SUPPORTED_WAU_2_6_0" displayName="$(string.SUPPORTED_WAU_2_6_0)" />
<definition name="SUPPORTED_WAU_EXPERIMENTAL"
displayName="$(string.SUPPORTED_WAU_EXPERIMENTAL)" />
</definitions>
Expand Down Expand Up @@ -163,6 +164,11 @@
<string>SuccessOnly</string>
</value>
</item>
<item displayName="$(string.NotificationLevel_ErrorsOnly)">
<value>
<string>ErrorsOnly</string>
</value>
</item>
<item displayName="$(string.NotificationLevel_None)">
<value>
<string>None</string>
Expand Down Expand Up @@ -366,31 +372,6 @@
<decimal value="0" />
</disabledValue>
</policy>
<policy name="DesktopShortcut_Enable" class="Machine"
displayName="$(string.DesktopShortcut_Name)" explainText="$(string.DesktopShortcut_Explain)"
key="Software\Policies\Romanitho\Winget-AutoUpdate" valueName="WAU_DesktopShortcut">
<parentCategory ref="WAU" />
<supportedOn ref="WAU:SUPPORTED_WAU_1_16_0" />
<enabledValue>
<decimal value="1" />
</enabledValue>
<disabledValue>
<decimal value="0" />
</disabledValue>
</policy>
<policy name="StartMenuShortcut_Enable" class="Machine"
displayName="$(string.StartMenuShortcut_Name)"
explainText="$(string.StartMenuShortcut_Explain)"
key="Software\Policies\Romanitho\Winget-AutoUpdate" valueName="WAU_StartMenuShortcut">
<parentCategory ref="WAU" />
<supportedOn ref="WAU:SUPPORTED_WAU_1_16_0" />
<enabledValue>
<decimal value="1" />
</enabledValue>
<disabledValue>
<decimal value="0" />
</disabledValue>
</policy>
<policy name="MaxLogFiles_Name" class="Machine" displayName="$(string.MaxLogFiles_Name)"
explainText="$(string.MaxLogFiles_Explain)"
key="Software\Policies\Romanitho\Winget-AutoUpdate" presentation="$(presentation.MaxLogFiles)">
Expand Down Expand Up @@ -420,5 +401,16 @@
<text id="WingetSourceCustom" valueName="WAU_WingetSourceCustom" />
</elements>
</policy>
<policy name="UpdatesTime_Delay" class="Machine"
displayName="$(string.UpdatesTimeDelay_Name)"
explainText="$(string.UpdatesTimeDelay_Explain)"
key="Software\Policies\Romanitho\Winget-AutoUpdate"
presentation="$(presentation.UpdatesTimeDelayTime)">
<parentCategory ref="WAU" />
<supportedOn ref="WAU:SUPPORTED_WAU_2_6_0" />
<elements>
<text id="UpdatesTimeDelayTime" valueName="WAU_UpdatesTimeDelay" />
</elements>
</policy>
</policies>
</policyDefinitions>
</policyDefinitions>
Loading