# Update 0.5.5.90 ## Modular Setup Analyzer profiles - Installer/vendor-specific Setup Analyzer knowledge is moved into declarative analyzer profiles. - System, Community and Local profile sources are supported. - `.amprofile` import/export validates schema, profile API and SHA-256 and contains no executable plugin code. - Profiles can be enabled/disabled; imported Community/Local profiles can be deleted without modifying application source. - Existing Total Commander, PDF24 and Greenshot-specific analyzer behavior is supplied as system profiles instead of Python special cases. - Generic technology signatures for Inno Setup, NSIS, WiX Burn, InstallShield, Advanced Installer, Squirrel, 7-Zip SFX and WinRAR SFX are also supplied as profiles. ## Community repository foundation - Optional HTTPS profile repository support via `ANALYZER_PROFILE_REPOSITORY_URL`. - Repository index schema `assetmanager-analyzer-profile-repository-v1`. - Admins explicitly load the repository catalog and select profiles to install. - Optional repository SHA-256 is checked before a bundle is imported. - Repository format/contribution documentation is included under `docs/analyzer-profiles/`. ## Portable software packages - Stored software packages can now be exported as `.ampkg` bundles. - Package overview can import `.ampkg` bundles and compatible Setup Analyzer ZIP exports. - Imports validate ZIP paths, symlinks, required package files and available SHA-256 metadata. - Import UI requires acknowledgement that software packages may contain executable PowerShell scripts. - Imported analyzer profiles are included in AssetManager backup/restore. ## Automatic persistent directory initialization - Docker Compose now mounts one persistent application root (`./data` -> `/assetmanager-data`) instead of requiring a separate host bind directory for every feature. - The container entrypoint verifies and creates all required application subdirectories on every start, including analyzer profiles and software packages. - Existing host data remains in the same `./data/...` layout; no data migration is required. - The established `/scripts` container path remains available for existing job definitions. - Uploaded images remain available under their existing `/static/uploads/...` URLs while being stored below the persistent data root. ## Import form and generic installer metadata fixes - Software-package import checkboxes are rendered left-aligned, vertically stacked, and no longer inherit full-width input sizing. - EXE analyzer metadata now uses a conservative dotted-version fallback from the installer filename when MSI/MSIX/PE metadata has no product version. - Signed PE installers can use the Authenticode code-signing certificate organization/common name as a manufacturer fallback. - The Authenticode publisher is only a fallback; explicit MSI/MSIX/PE manufacturer metadata still has higher priority. - The generic metadata enrichment contains no VLC-specific Python logic; product-specific naming is supplied by the declarative VLC analyzer profile. ## Follow-up: VLC metadata, localized file picker and client job retention - Added declarative VLC analyzer profile so NSIS VLC packages receive the product name `VLC media player` without product-specific Python code. - Replaced browser-native file selector text in Setup Analyzer, analyzer-profile import and software-package import with translated AssetManager controls. - Added configurable stale client job-directory cleanup with a default retention of 24 hours. Cleanup is limited to AssetManager job directories and runs before a new file-based job is dispatched to that client. ## Follow-up: reliable client job retention cleanup - Stale client cleanup now uses the job-directory creation time on Windows instead of the mutable last-write timestamp. - Current/active job directories are explicitly excluded from cleanup. - Legacy numeric job directories and current `JobID-Attempt` directories are both recognized below the dedicated AssetManager job root. - If deletion of an expired directory fails because of legacy/broken ACLs, AssetManager repairs permissions only inside that already-expired job directory and retries deletion. - Cleanup still runs before new file-based jobs and now also runs periodically for online managed clients with job history, so stale files do not depend on a later deployment to be removed. - Cleanup diagnostics now report found, eligible, removed, failed, young, active and ignored directory counts.