microsoft / microsoft/winget-pkgs
[Package Issue]: Yubico.YubikeyManager 1.2.6 (GUI app) is EOL and affected by CVE-2026-40947 - suggest Yubico.Authenticator package as replacement?
Nobody has claimed this yet.
- Dominant language
- No language data
- Stars
- 11.1k
- Forks
- 9.7k
- Avg merge
- 1h 32m
- Merged PRs (30d)
- 616
Description
### Please confirm these before moving forward
- [x] I have searched for my issue and not found a work-in-progress/duplicate/resolved issue.
- [x] I have not been informed if the issue is resolved in a preview version of the winget client.
### Category of the issue
Other
### Brief description of your issue
https://www.yubico.com/support/terms-conditions/yubico-end-of-life-policy/eol-products/
scroll down to Software products ... indicated GUI-based app for replacement is Yubico.Authenticator (also available through WinGet).
Please note that soon Yubico will start releasing keys based on firmware 5.8 and the EOL apps are likely to have errors when running with new firmware devices.
Also see: https://www.yubico.com/support/security-advisories/ysa-2026-01/
and CVE-2026-40947
### Steps to reproduce
- Yubikey Manager GUI is EOL and affected by known published vulnerabilities.
### Actual behavior
No more updates are available. Yubico advises to migrate to different apps.
### Expected behavior
expected: updated management apps functionality
### Environment
```raw
environment is not relevant - this is a supply chain issue.
```
### Screenshots and Logs
_No response_
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review the Yubico end-of-life policy, YSA-2026-01, and the existing Yubico.YubikeyManager 1.2.6 package metadata. Determine how winget-pkgs handles EOL or vulnerable packages and whether Yubico.Authenticator is an appropriate replacement. Done means the package action and any required manifest changes are clear and validated against repository conventions.
Written by the indexing model from the issue text.
Assessment
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 45/100