Webinar: Beyond WWDC: What the 2026 macOS beta cycle looks like in the field
Register now
Guide

Automatically patch vulnerable packages

Kristján Oddsson

This guide shows you how to create a Vulnerability Patching policy so that vulnerable packages across your fleet are upgraded automatically. You need access to the Workbrew Console with permission to write Policies.

Create a Vulnerability Patching policy

  1. Navigate to the Policies page in the Workbrew Console
  2. Click New Brew Policy
  3. Select Vulnerability Patching
  4. Set a minimum severity for Vulnerable formulae
  5. Set a minimum severity for Vulnerable casks
  6. Click the Device Group dropdown to target a Device Group, or leave it as All Devices
  7. Click Enable Vulnerability Patching

Both package types start at Off, so set at least one of them to a severity. A policy saved with both left Off is created but patches nothing.

Each Device Group can only have one Vulnerability Patching policy, and a policy targeting All Devices counts as one too. The severity levels and the CVSS scores behind them are listed in Package vulnerabilities.

Confirm the policy is active

The policy appears on the Policies page with a badge for each package type showing the threshold you chose, for example "Formulae ≥ High" and "Casks Off". The All threshold shows as "All updates".

Patching runs when a Device next checks in, not when you save the policy, so give the fleet a check-in cycle before expecting the Vulnerabilities page to change.

Update or remove the policy

  1. Navigate to the Policies page
  2. Click the Vulnerability Patching policy you want to change
  3. Adjust the thresholds or Device Group and click Save changes, or click Remove Vulnerability Patching

Removing the policy stops future patching. It does not roll back packages that have already been upgraded.

We use cookies to analyze traffic and improve your experience. You can accept all cookies or decline non-essential ones. Read our Privacy Policy for details.