App-Auto-Patch for 3rd party patching (macOS)
What
App-Auto-Patch for macOS is an open-source project designed for user-driven application patching. The downloadable FileWave archive contains three Filesets: a signed and notarized PKG installer for App Auto-Patch, a profile for App Auto-Patch settings, and a profile that manages its background login item. The settings profile controls support details, patching behavior, and application exclusions.

When/Why
This method is ideal when you need an efficient, user-driven approach to manage patch deployments on macOS devices. You might use it when:
- Proactive Maintenance: You want to ensure that systems are always up to date with the latest patches without continuous manual intervention.
- Customized Support: Your organization requires that support details—such as email, phone, and website—be displayed in the application’s help messages to provide end users with immediate assistance.
- Controlled Rollouts: You need the flexibility to exclude certain applications from being patched automatically to avoid potential disruptions to users’ workflows.
- Seamless Updates: By simply updating the Profile Fileset’s settings in FileWave, you can push out configuration changes across all managed devices quickly.

How
Import and configure the Filesets:
- Download: App-Auto-Patch-Filesets v3.6.3.zip
- Import all three Filesets into FileWave and place them in a Fileset group:
- PKG - AppAutoPatch-3.6.3: Installs the signed and notarized App Auto-Patch 3.6.3 package.
- Profile - App-Auto-Patch Settings: Applies the managed App Auto-Patch configuration.
- Profile - App Auto-Patch Managed Login Item: Allows the App Auto-Patch background service through macOS managed login-item controls.
- Open the Profile - App-Auto-Patch Settings Fileset.
- Modify the following settings to match your organization’s support details:
- SupportTeamEmail: The support email shown in help messages (for example, support@company.com).
- SupportTeamName: The support team name shown to users (for example, Company Support Team).
- SupportTeamPhone: The support phone number (for example, 555-867-5309).
- SupportTeamWebsite: The support website URL (for example, https://support.company.com).
- Important for App Auto-Patch 3.6 and later: Background patching of closed apps is enabled by default for Interactive Mode 1 and 2. If closed apps should not update silently before the user dialog appears, add
WorkflowBackgroundPatchClosedAppsto the settings profile and set it tofalsebefore deployment. - For all available configuration options, see the official Configure App-Auto-Patch Settings documentation.
Deploy Using FileWave:
- Deployment: Add the Fileset group to a Deployment for the target macOS devices, start with one test device, and select Update Model.
- Testing: Confirm that the PKG installs App Auto-Patch, both profiles are installed, and the configured patching experience works as expected before widening the Deployment.
- Removal: Removing the Fileset group from the Deployment does not run the vendor uninstaller. Run
/usr/local/bin/appautopatch --uninstallas root on the target devices, then remove the Fileset group from the Deployment.

Pushing Updates:
Modify the Profile Fileset at any time to update preferences. The changes will be pushed out automatically to all connected devices upon redeployment. Adjust settings to exclude or include certain applications from patching based on your organizational needs and user workflows. The included settings in this KB article have it set to patch weekly on Tuesdays, but pick what will work for you.
Leveraging the DDM reporting of Background Tasks in FileWave you can also check to make sure that the helper is present. Depending on the configuration and your testing you might see more than one Identifier listed for the helper, but you should see at least 1 reported so that you know the LaunchDaemon is present.
Related Content
- App-Auto-Patch GitHub Repository
- Configure App-Auto-Patch Settings
- Installomator - The one installer script to rule them all (macOS PKG)
- swiftDialog Deployment (macOS PKG)
Digging Deeper
App-Auto-Patch offers a user-driven patching approach that minimizes the need for manual updates while still giving administrators full control. The profile configuration makes it simple to customize end-user support details—ensuring that when users require help, they see consistent and accurate contact information. Moreover, the ability to exclude certain applications from patching not only protects critical workflows but also allows for staged rollouts, reducing the risk of disruptions in a production environment. This model leverages FileWave’s powerful device management capabilities to ensure all deployed macOS devices receive timely updates with the reassurance of a built-in rollback mechanism through the uninstall script. This integrated approach enhances overall system security and stability while providing an agile method for managing software updates in diverse organizational settings.

No comments to display
No comments to display