Breeze RMM v0.105.0 — fleet hygiene findings with aggregate remediation, an edition-aware agent with a bring-your-own-signing pipeline for self-hosters, first-class organization contacts, and the RMM-migration toolkit: bulk org/site import, PSA company import, and script bundles.
Summary
- Fleet hygiene — a findings feed that surfaces systemic defects org- and partner-wide (instead of one alert per device) and remediates them across N devices from one run. (#3278)
- Edition-aware agent + sign-your-own-agent pipeline — the public release now ships self-host edition agents, plus unsigned signing inputs and a template repo so self-hosters can sign agent packages under their own certificate. See the upgrade notes — this changes what the public MSI is. (#3327, #3330, #3331, #3349, #3350, #3351, #3353, #3360, #3321, #3352)
- Organization contacts — contacts are first-class rows with portal-login linkage, backfilled from the legacy jsonb fields on upgrade. (#3316, #3328)
- RMM-migration toolkit — bulk org/site import (#3273), PSA company import (#3311), script bundle export/import (#3276), a fleet migration posture report (#3264), and unattended tenancy provisioning via partner service principals (#3274).
- Per-technician remote tool — each technician can pick their own remote-access provider instead of sharing one tenant-wide default. (#3391, #3440)
- The v0.104.0 backup known issues are fixed — result-cap loss, slow ACL denials, and lost-VSS-snapshot corruption. (#3266, #3267, #3283, #3285)
Added
- Fleet hygiene findings + aggregate remediation — a findings feed groups devices by systemic defect at org and partner scope; one remediation run targets every affected device, with per-device outcomes tracked. Four new RLS-enforced tables. (#3278)
- Sign Your Own Agent Packages — official releases publish the exact pre-signing Windows build outputs (
*-unsigned.exe) plus a manifestsourceCommit(#3327); a publicbreeze-selfhost-signingtemplate repo re-signs them under your certificate and publishes your own release manifest, with a step-by-step guide (#3331).BINARY_GITHUB_REPOSITORYrepoints an entire deployment — downloads, sync, and update URLs — at your signed repo, with the trust chain validated at boot (#3330, #3352). - Edition-aware agent — agent builds carry an edition (hosted / self-host); the updater refuses a manifest asset whose edition doesn't match the running build (#3349, #3321), the MSI carries a per-edition product identity with a cross-edition install guard (#3350), and the release pipeline fails closed if either edition could be produced mis-labeled (#3351, #3353, #3360).
- First-class organization contacts —
contactsandcontact_external_linkstables with per-contact portal-login linkage; all ten legacy jsonb writers now route through a compat service so old and new surfaces stay in sync. Existing site/billing contacts are backfilled on upgrade. (#3316, #3328, #3326) - Bulk org/site import — CSV-driven creation of organizations, sites, and enrollment keys, with external-system linkage (
organization_external_links), skip-mode link persistence, and constraint-aware recovery. (#3273, #3287) - PSA company import — pull your company list from ConnectWise, Autotask, ServiceNow, Freshservice, Zendesk, or Jira into org import; every adapter now paginates instead of silently truncating at the first page. (#3311, plus connection-test and form fixes in #3291)
- PSA connections are partner-wide capable — dual ownership (org XOR partner), so one PSA connection can serve all orgs under a partner. (#3308)
- Partner-wide CIS baselines — same dual-ownership treatment for CIS hardening baselines. (#3400)
- Script bundle export/import — move a script library between Breeze instances (or in from another RMM) as a versioned JSON bundle carrying parameters, categories, tags, timeouts, run-as levels, and exit-code severity mappings. (#3276)
- Unattended tenancy provisioning — partner service principals gain
organizations:write/sites:write/enrollment-keys:writescopes, so migration scripts can provision tenancy without an MFA'd human session. (#3274) - Fleet migration posture report — a fleet-level view of which competing management tools are still present on each device, from data the agent already collects. (#3264)
- Preferred remote tool per technician — a profile setting selects among the tenant's configured remote-access providers; the selection is an id only and can never inject a provider. (#3391, #3440)
- Discovery asset linking is hidden and automatic, and unlink is durable — manual unlink no longer silently undone by the next discovery scan; link state is visible and suppressions persist. (#3295)
breeze-backupauto-updates alongside the agent — its version is slaved to the agent's, so it no longer stays frozen at installer-time forever; Linuxinstall.shand uninstall now handle it too. (#3293)- Quick Support refinements — codes are now digits (read easily over the phone, shown 3-3-3), session history rows re-open a live detail panel, and rate limiting buckets IPv6 by /64. (#3292)
- What's-new splash on login with a reopen link. (#3317)
- Self-hosted webhooks can reach the LAN — on an affirmatively self-hosted deployment, webhook receivers on private (RFC1918/ULA) addresses are deliverable, including plain HTTP — confined strictly to private addresses. (#3320, #3366)
- Mass-deployment and migration docs — GPO/Intune/JAMF agent deployment guide (#3288) and RMM-to-Breeze migration guides (#3250).
Improved
- Queue enqueues no longer stall behind blocking Redis consumers — blocking commands get dedicated connections instead of sharing the enqueue connection; this was worth up to ~250x on enqueue latency under load. (#3299)
- Remote proxy access is one entry point, and sessions no longer die at the 5-minute cliff. (#3294)
- Agent command results cap raised 1 MiB → 5 MB, matching stdout/stderr — fixes restore browsing for backups with very large file counts. (#3283)
- AI usage accounting counts tool executions and refreshes spend live. (#3297)
search_logskeyset pagination is actually usable. (#3368)- Umbrella DNS integration authenticates with OAuth2 client credentials instead of the retired Basic scheme. (#3275)
Fixed
- Backup (the v0.104.0 known issues): results are bounded to what the server accepts so large runs report completion (#3267); plain NTFS ACL denials take the fast-retry path instead of ~30 s each (#3266); a lost VSS snapshot aborts the run immediately instead of silently producing a bad backup (#3266); and VSS session COM references are held for the whole run with
BackupCompletesignalled, so writers are released cleanly (#3285). - Saved Filters was entirely unusable — building any filter with a condition value crashed the page; also fixed in the same sweeps: device-group creation 400 for multi-org partners, fleet hygiene "all orgs" scope, and org-switcher pagination. (#3448, #3449)
- Organizations lists load every page, not just the first 50 — org pickers and the orgs page were silently truncated for larger partners. (#3447) Same class of bug fixed for the script library (#3305).
- Policy remediation actually dispatches —
POST /policies/:id/remediatecreated runs that were never sent to (or were simulated as completed on) the agent. (#3414, #3417, #3438) - Cmd+K search finds partner-wide scripts, plus three more QA-sweep defects. (#3442)
- Device groups:
nullfilterConditions accepted on create and staticdeviceIdsno longer dropped (#3423); deleting a device group no longer aborts on its membership log (#3314). - Agent (macOS): the breeze group is actually applied to the IPC socket, not just created (#3422); the Keychains directory node itself is denied, not just its contents (#3395); Finder aliases resolve in the file browser (#3384).
- Agent (Windows/Linux): malformed reboot delays are rejected instead of coerced to 0 = "now" (#3393), reboot/shutdown delay is normalized to minutes on Windows (#3371), total shutdown time is bounded so systemd stops the unit cleanly (#3367), and every content-touching file operation routes through path containment (#3398).
- Patch reboots always warn the logged-in user — previously an invariant only by coincidence of defaults. (#3421)
- Discovery: automatic asset classifiers are ranked, so a UniFi switch stops flapping to access_point between scans. (#3383)
- Warranty sync excludes virtual machines. (#3399)
- Viewer answer-polling no longer exhausts the global IP rate limit during remote sessions. (#3377)
- Installer capacity is discriminated per token, not per enrollment key. (#3392)
- Agents receive partner-owned config policies — agent config delivery resolved org-owned policies only, so partner-wide policies silently never reached devices. (#3390)
- SNMP poll dispatch takes its org from the live device row (#3378), and the AI
remediate_vulnerabilitytool resolves its org from the device, not the caller's first accessible org (#3379). - Hand-written SQL templates no longer bind raw JS
Dateobjects — a timezone-dependent correctness hazard. (#3382) - Process samples match on the agent id, not the device id. (#3396)
- Duplicate remote-access provider ids and dangling defaults are rejected at write time. (#3406)
- Quotes/billing: the quote line's name carries onto the converted invoice (#3365) and unit prices stop clipping their last digit (#3370).
- The suspicious-approval report audit row is tenanted to the approval, not the reporter. (#3420)
- Config-policy Automation/Maintenance tabs use the shared searchable timezone picker (#3376); list summaries render their counts as one interpolated string (#3437, #3424); contextual translation fixes (#3296).
Security
- Hosted signup requires a business email — throwaway consumer mailboxes were the zero-cost entry point behind recent abuse clusters. Hosted-only: self-hosted signup is unaffected. (#3289)
- Signup-abuse detection is now hosted-only (it polices untrusted public signups; on a single-team self-hosted install its heuristics are noise), and gains a provider-default hostname detector. Self-hosters running a genuinely multi-tenant service can opt back in with
ABUSE_SIGNALS_ENABLED=true. (#3411) - User-supplied URL fields are scheme-validated — several fields accepted
javascript:and friends and rendered them as clickable links. (#3442, #3448) - Self-hosted cleartext webhook allowance is confined to private addresses — plain HTTP was briefly permitted for any hostname on self-hosted; it now requires the resolved address to actually be private. (#3366, closing the gap opened by #3320)
- Plaintext is sealed into encryption-registered columns even without
APP_ENCRYPTION_KEY_ID— a UI edit could silently rewrite an encrypted column as plaintext. (#3394) - Partner-wide script writes enforce same-partner ownership. (#3272)
- BYO-signing trust chain fails loudly — a re-signing failure aborts the sync instead of reporting success, and a repointed release source must carry a non-official trust root. (#3352)
- The breeze-billing tables' partner-axis RLS is codified in-repo (applied live to hosted in v0.104-era). (#3290)
Self-hosters are encouraged to upgrade.
Self-Hosting / Upgrade Notes
No breaking schema or API changes. The agent edition change (note 3) is the one behavioral shift to read before you pull. Standard upgrade:
# bump BREEZE_VERSION in .env, then:
docker compose pull api web portal && docker compose up -d binaries-init api web portal(If you build from source, run pnpm install — the lockfile changed.)
1. Database — 16 migrations, no large-table rewrites
All idempotent, auto-applied on API boot via autoMigrate (unless AUTO_MIGRATE=false). Nothing rewrites a hot table; the data-writing migrations touch small config/linkage tables and log row counts via RAISE WARNING (visible in your Postgres log):
| Migration | What it changes |
|---|---|
2026-08-19-contacts
| Creates contacts / contact_external_links and backfills them from the legacy sites.contact and organizations.billing_contact jsonb (values bounded and trimmed, so an overlong legacy value cannot abort the migration); links portal users to contacts. The jsonb columns are kept and stay in sync via the compat service.
|
2026-08-18-drop-organizations-accounting-columns
| Migrates accounting_provider / accounting_external_id into organization_external_links, then drops both columns. Conflicting or provider-less legacy values are discarded with a warning naming the count — check your Postgres log if you relied on QuickBooks/Xero org linkage.
|
2026-08-14-drop-patch-policies-sources
| Drops the deprecated patch_policies.sources column (replaced by the Patch Sources toggle set).
|
2026-08-08-proxy-session-lifetime
| Cleans up stale tunnel_allowlists rows (counts warned).
|
2026-08-20-installer-bootstrap-token-usage-kind, 2026-08-20-discovered-asset-detection-source
| Small column backfills on their own tables. |
The rest create the new feature tables (fleet hygiene, external links, editions, PSA/CIS dual ownership) with RLS policies in the same file.
2. No new required environment variables
Everything new is optional with a safe default; the standard upgrade needs no .env changes.
ABUSE_SIGNALS_ENABLED— signup-abuse detection switch; defaults to the value ofIS_HOSTED, so self-hosted deployments now run with abuse detection off (see Security). Settrueto opt a multi-tenant self-hosted service in. Validated as a boolean when set — a typo refuses boot.BINARY_EDITION—self-host(default, today's behavior) |hosted. Leave unset.BINARY_GITHUB_REPOSITORY— BYO signing only: repoints release downloads/sync at your own signed release repo (owner/repo, shape-validated at boot). If you set it, you must also setRELEASE_ARTIFACT_MANIFEST_PUBLIC_KEYSto your manifest key — the API refuses to boot if the official Breeze key is the only trust root for a non-official repo, because every sync would otherwise fail closed and silently freeze your fleet.- Removed:
MSI_SIGNING_URL/MSI_SIGNING_CF_ACCESS_SECRET— the per-download MSI signing path is retired in favor of the release-time BYO pipeline. Leftover values in.envare ignored harmlessly.
3. The agent edition change — read this if you deploy Windows agents
- v0.104.0 is the last public release carrying a Breeze-signed Windows agent. Existing installs are unaffected and previously signed packages remain validly signed. From v0.105.0 on, the public release's agent artifacts are the self-host edition: the Windows MSI (
breeze-agent.msi) is published unsigned, under its own product identity ("Breeze Agent (Self-Hosted)", its own UpgradeCode) — a signed Windows agent now comes from your own certificate (see below), or you accept the SmartScreen warning on interactive installs. - To ship signed agents under your own certificate, use the
breeze-selfhost-signingtemplate repo with the Sign Your Own Agent Packages guide (#3331): it re-signs the published unsigned inputs, emits your own release manifest, and you pointBINARY_GITHUB_REPOSITORY+RELEASE_ARTIFACT_MANIFEST_PUBLIC_KEYSat it. - Existing fleets keep updating normally — manifests without a per-asset edition are accepted for backward compatibility, and edition enforcement only refuses a mismatched declared edition.
- Devices still running a hosted-edition agent against a self-hosted server now report
migrationRequired, and admins see a persistent migration banner until those agents are migrated to the self-host edition. (#3324, #3321) - The two editions refuse to install over each other on the same machine, so a hosted-edition install can't be silently upgrade-chained onto by a self-host MSI (or vice versa). (#3350)
4. Other behavior changes
- Signup-abuse detection defaults off on self-hosted (
IS_HOSTED=false) — see note 2. If it's off, the only artifact is one[AbuseSignals] Disabledline at boot. - Webhooks on self-hosted deployments may now target private (RFC1918/ULA) addresses, including over plain HTTP — strictly confined to private addresses; public targets still require HTTPS. (#3320, #3366)
- Agent command results (including backup results) may now be up to 5 MB instead of 1 MiB. (#3283)
PUBLIC_ENABLE_NETWORK_DEVICES_IN_LIST(web, build-time) exists to show network-discovered assets in the Devices list, but remains off by default and we recommend leaving it off — unified sort/pagination and per-asset detail pages are still in flight.- Quick Support codes are now digits — outstanding letter codes remain redeemable. (#3292)
Full Changelog: v0.104.0...v0.105.0
What's Changed
- docs: v0.102.0..v0.104.0 release sweep by @ToddHebebrand in #3268
- fix(api): enforce same-partner ownership on partner-wide script writes (#3262 follow-up) by @ToddHebebrand in #3272
- feat(orgs): bulk org/site import + organization_external_links (#3242) by @ToddHebebrand in #3273
- feat(devices): fleet migration posture report (#3244) by @ToddHebebrand in #3264
- feat(partner-api): unattended tenancy provisioning via partner service principals (#3243) by @ToddHebebrand in #3274
- feat(scripts): script bundle import/export (#3245) by @ToddHebebrand in #3276
- fix(backup): short-retry ACL denials and abort on a lost VSS snapshot (#3259, #3260) by @ToddHebebrand in #3266
- fix(backup): bound the command result against the server's 1 MiB cap, not the IPC frame (#3001) by @ToddHebebrand in #3267
- test(backup): make vss.Provider injectable to pin RunBackupContext liveness wiring (#3270) by @ToddHebebrand in #3280
- feat(agents): raise the command-result
resultcap to 5 MB, matching stdout/stderr by @ToddHebebrand in #3283 - fix(backup): hold the VSS session COM references for the whole run and signal BackupComplete (#3269) by @ToddHebebrand in #3285
- docs(migration): RMM-to-Breeze migration guides by @ToddHebebrand in #3250
- docs(deploy): GPO/Intune/JAMF mass-deployment guide + fix bulk-enrollment env recipe (#3248) by @ToddHebebrand in #3288
- docs(api): X-API-Key authenticates only MCP, dev-push, and device custom-field surfaces (#3247) by @ToddHebebrand in #3286
- docs(specs,plans): RMM migration epic design specs and implementation plans by @ToddHebebrand in #3279
- fix(orgs): org-import hardening — sites:write gate, skip-mode link persistence, atomic group create, constraint-aware recovery by @ToddHebebrand in #3287
- fix(psa): real connection test, honest 501 sync, working form round-trip, single-source provider list by @ToddHebebrand in #3291
- refactor(accounting): migrate the QuickBooks importer onto the shared org-import seam by @ToddHebebrand in #3298
- chore(orgs): drop the legacy accounting_provider / accounting_external_id columns by @ToddHebebrand in #3309
- feat(psa): dual ownership (org XOR partner) for psa_connections (#2135) by @ToddHebebrand in #3308
- feat(psa): PSA company import via the org-import seam (#3246) by @ToddHebebrand in #3311
- feat(contacts): first-class organization contacts — tables, contracts, compat service (#3258) by @ToddHebebrand in #3316
- feat(release): publish unsigned signing-input artifacts + manifest sourceCommit (BYO signing phase 1) by @ToddHebebrand in #3327
- feat(api): unified release source + deployment re-signing trust chain (BYO signing phase 2) by @ToddHebebrand in #3330
- feat(selfhost-signing): BYO-signing template repo contents + Sign Your Own Agent Packages guide (phase 3) by @ToddHebebrand in #3331
- feat(web): what's-new splash on login with reopen link by @ToddHebebrand in #3317
- docs: BYO signing design spec + phase implementation plans by @ToddHebebrand in #3348
- feat(web): surface agent migrationRequired signal — persistent self-hosted migration banner by @ToddHebebrand in #3324
- feat(agent): compile-time control-plane build-mode host policy (inert by default) by @ToddHebebrand in #3321
- feat(agent): enforce edition match on release manifest assets by @ToddHebebrand in #3349
- feat(installer): parameterize MSI edition identity by @ToddHebebrand in #3350
- feat(api): edition-aware release sources, BINARY_EDITION mode, agent_versions edition by @ToddHebebrand in #3353
- feat(release): edition-aware build pipeline + self-host artifact publication by @ToddHebebrand in #3351
- docs: what's-new splash design spec + implementation plan by @ToddHebebrand in #3359
- feat(selfhost-signing): build BYO MSIs under the self-host edition identity by @ToddHebebrand in #3360
- docs: integration-test blocks PRs — it is smoke-test that is continue-on-error by @bdunncompany in #3310
- test(web): give the InvoiceWorkspace queued-Issue tests real waitFor headroom (#3219) by @bdunncompany in #3284
- fix(groups): clear group_membership_log before deleting a device group (#3313) by @bdunncompany in #3314
- fix(web): walk every page of /scripts so the full library is reachable (#3301) by @bdunncompany in #3305
- fix(contacts): bound backfill projections so an overlong jsonb value cannot abort the migration by @bdunncompany in #3326
- test(ai): pin the aiTools registry against TOOL_TIERS, both directions (#3300) by @bdunncompany in #3306
- fix(dns): authenticate Umbrella with OAuth2 client credentials, not Basic (#3271) by @bdunncompany in #3275
- feat(webhooks): honour the self-hosted private-network gate, drop the local IP policy by @bdunncompany in #3320
- feat(release): optional draft-first gate via RELEASE_DRAFT_FIRST variable by @ToddHebebrand in #3362
- fix(web): org scoping for CIS Hardening and audit baselines by @ToddHebebrand in #3372
- feat(remote): consolidate proxy access to one entry point, fix the 5-minute session cliff (#3199) by @ToddHebebrand in #3294
- feat(abuse): require a business email for hosted partner signup by @ToddHebebrand in #3289
- chore(rls): codify partner-axis RLS for the breeze-billing tables by @ToddHebebrand in #3290
- feat(quick-support): refinement pass — digit codes, session re-open, IPv6 /64 rate limiting, tenant-wide domain descope by @ToddHebebrand in #3292
- fix(i18n): correct contextual translations by @ToddHebebrand in #3296
- fix(ai): count tool executions in the usage rollup and refresh spend live by @ToddHebebrand in #3297
- fix(api): give blocking Redis consumers their own connections by @ToddHebebrand in #3299
- docs(plans): Phase 3 design handoff prompt for the RMM migration epic by @ToddHebebrand in #3315
- feat(contacts): route all ten legacy jsonb writers through the compat service (#3258) by @ToddHebebrand in #3328
- fix(agent): filter BroadcastNotification on the notify scope (#3255) by @ToddHebebrand in #3364
- fix(billing): carry the quote line name onto the converted invoice (#3319) by @ToddHebebrand in #3365
- feat(api,web): partner-wide CIS baselines — dual-ownership (org XOR partner) by @ToddHebebrand in #3400
- fix(api): match process-sample path id against the agent id, not the device id (#3387) by @bdunncompany in #3396
- fix(api,secrets): seal plaintext into registered columns without requiring APP_ENCRYPTION_KEY_ID by @bdunncompany in #3394
- fix(agent): bound total shutdown time so systemd stops cleanly (#3323) by @ToddHebebrand in #3367
- fix(api): make search_logs keyset pagination usable (#3329) by @ToddHebebrand in #3368
- fix(quotes): stop the quote line unit price clipping its last digit (#3318) by @ToddHebebrand in #3370
- fix(agent): normalize reboot/shutdown delay to minutes on Windows (#3252) by @ToddHebebrand in #3371
- fix(ci): retire the update-community-readme schedule (#3173) by @ToddHebebrand in #3375
- fix(web): use shared TimezoneSelect in config-policy Automation/Maintenance tabs (#3361) by @ToddHebebrand in #3376
- fix(snmp): make the live device row the sole org authority for poll dispatch (#3226) by @ToddHebebrand in #3378
- fix(ai): resolve remediate_vulnerability's org from the device, not accessibleOrgIds[0] (#3322) by @ToddHebebrand in #3379
- fix(api): stop binding raw JS Dates into hand-written sql templates (#3369) by @ToddHebebrand in #3382
- fix(discovery): rank the automatic asset classifiers so a UniFi switch stops flapping to access_point (#3187) by @ToddHebebrand in #3383
- fix(agent): resolve macOS Finder aliases in the file browser (#3344) by @ToddHebebrand in #3384
- fix(config): make the env↔compose parity guard see commented-out vars (#3239) by @ToddHebebrand in #3388
- fix(api): resolve partner-owned config policies for agent config delivery (#2930) by @ToddHebebrand in #3390
- fix(api): discriminate installer capacity per token, not per key (#3034) by @ToddHebebrand in #3392
- fix(agent): deny the Keychains directory node, not just its contents (#3385) by @ToddHebebrand in #3395
- fix(agent): route every content-touching file op through containment (#3397) by @ToddHebebrand in #3398
- fix(webhooks): confine the self-hosted cleartext allowance to private addresses by @bdunncompany in #3366
- fix(desktop): stop viewer answer-poll from exhausting the global IP rate limit (#3041) by @ToddHebebrand in #3377
- fix(api): exclude virtual machines from warranty sync (#3201) by @bdunncompany in #3399
- fix(api): abort sync on re-signing failure, enforce non-official trust root (BYO signing phase 2 follow-up) by @ToddHebebrand in #3352
- fix(agent): reject malformed reboot delays instead of coercing them to 0 (#3373) by @ToddHebebrand in #3393
- chore(deps): bump node from
f70403etod32cdf6in /apps/web by @dependabot[bot] in #3354 - chore(deps): bump node from
f70403etod32cdf6in /apps/api by @dependabot[bot] in #3355 - chore(deps): bump node from
f70403etod32cdf6in /docker by @dependabot[bot] in #3356 - chore(deps): bump node from
f70403etod32cdf6in /apps/m365-communications-executor by @dependabot[bot] in #3357 - chore(deps): bump node from
f70403etod32cdf6in /apps/m365-graph-actions-executor by @dependabot[bot] in #3358 - chore(deps): bump @types/pg from 8.20.0 to 8.20.4 in /e2e-tests by @dependabot[bot] in #3334
- chore(deps): bump the expo-sdk group with 3 updates by @dependabot[bot] in #3332
- chore(deps): bump tsx from 4.23.1 to 4.23.11 in /e2e-tests by @dependabot[bot] in #3335
- chore(deps): bump werift from 0.24.2 to 0.24.3 in /e2e-tests by @dependabot[bot] in #3336
- chore(deps): bump postcss from 8.5.25 to 8.5.26 in the tailwind group by @dependabot[bot] in #3340
- chore(deps): bump the hono group with 2 updates by @dependabot[bot] in #3341
- chore(deps): bump @testing-library/user-event from 14.6.1 to 14.6.3 in the testing group by @dependabot[bot] in #3342
- chore(deps): bump @sentry/node from 10.68.0 to 10.69.0 by @dependabot[bot] in #3345
- fix(deps): dedup pnpm-lock.yaml — duplicated mapping keys break every JS job on main by @bdunncompany in #3407
- chore(api): drop deprecated patch_policies.sources column (#3151) by @ToddHebebrand in #3154
- chore(deps): bump the react-native-animation group across 1 directory with 2 updates by @dependabot[bot] in #3333
- chore(deps): bump the astro group across 1 directory with 3 updates by @dependabot[bot] in #3339
- chore(deps): bump the mobile group across 1 directory with 3 updates by @dependabot[bot] in #3337
- fix(orgs): reject duplicate remote-access provider ids and dangling defaults by @ToddHebebrand in #3406
- feat(abuse): provider-default hostname detector, and make abuse detection hosted-only by @ToddHebebrand in #3411
- feat(remote): let a technician pick their own remote-access provider (#3389) by @bdunncompany in #3391
- chore(deps): bump the typescript-tooling group across 1 directory with 5 updates by @dependabot[bot] in #3412
- fix(api): dispatch policy remediation instead of simulating completion (#3413) by @bdunncompany in #3414
- fix(api): dispatch the run created by POST /policies/:id/remediate (#3416) by @bdunncompany in #3417
- refactor(api): extract scriptDispatch core; consolidate 5 script dispatch sites (#3409 PR 0) by @ToddHebebrand in #3418
- fix(patching): make the patch-reboot user warning an invariant, not a coincidence (#3197) by @ToddHebebrand in #3421
- fix(agent): apply the breeze group to the macOS IPC socket, not just create it (#3137) by @ToddHebebrand in #3422
- fix(groups): accept a null filterConditions on create and stop dropping static deviceIds (#3159) by @ToddHebebrand in #3423
- fix(web): render the config-policy count as one interpolated string by @ToddHebebrand in #3424
- docs(release): v0.105.0 change list, test checklist, and UI QA sweep log by @ToddHebebrand in #3427
- chore(deps): bump the aws-sdk group in /agent with 5 updates by @dependabot[bot] in #3433
- chore(deps): bump google.golang.org/api from 0.291.0 to 0.292.0 in /agent by @dependabot[bot] in #3434
- chore(deps): bump @azure/msal-browser from 4.30.0 to 5.18.0 by @dependabot[bot] in #3343
- fix(deps): repair broken pnpm-lock.yaml (duplicated hono@4.13.1 key) by @ToddHebebrand in #3439
- fix(api): scriptDispatch review findings — cleanup gap, AI payload echo, batch cap (#3409 PR 0 follow-up) by @ToddHebebrand in #3438
- feat(fleet): fleet hygiene findings feed + aggregate remediation by @ToddHebebrand in #3278
- fix(web): count-glue defects in five list summaries by @ToddHebebrand in #3437
- fix(web,api): four defects found by the UI QA sweep by @ToddHebebrand in #3442
- feat(remote): slim provider-list endpoint + preferred-remote-tool profile control (#3389) by @bdunncompany in #3440
- fix(approvals): tenant the suspicious-report audit row to the approval, not the reporter (#3234) by @ToddHebebrand in #3420
- feat(agent): auto-update the breeze-backup binary alongside the agent by @ToddHebebrand in #3293
- fix(web): load every page of organizations, not just the first 50 (#3446) by @bdunncompany in #3447
- feat(discovery): hidden-and-automatic asset linking with durable unlink (#3261) by @ToddHebebrand in #3295
- fix(web,api): two blocking crashes and two more unvalidated URL fields by @ToddHebebrand in #3448
- fix: pre-release QA sweep round 3 — device groups, saved filters, fleet all-orgs, org switcher pagination by @ToddHebebrand in #3449
Full Changelog: v0.104.0...v0.105.0