github LanternOps/breeze v0.105.0

latest releases: v0.119.0, v0.118.2, v0.118.1...
one month ago

Breeze RMM v0.105.0 — fleet hygiene findings with aggregate remediation, an edition-aware agent with a bring-your-own-signing pipeline for self-hosters, first-class organization contacts, and the RMM-migration toolkit: bulk org/site import, PSA company import, and script bundles.

Summary

  • Fleet hygiene — a findings feed that surfaces systemic defects org- and partner-wide (instead of one alert per device) and remediates them across N devices from one run. (#3278)
  • Edition-aware agent + sign-your-own-agent pipeline — the public release now ships self-host edition agents, plus unsigned signing inputs and a template repo so self-hosters can sign agent packages under their own certificate. See the upgrade notes — this changes what the public MSI is. (#3327, #3330, #3331, #3349, #3350, #3351, #3353, #3360, #3321, #3352)
  • Organization contacts — contacts are first-class rows with portal-login linkage, backfilled from the legacy jsonb fields on upgrade. (#3316, #3328)
  • RMM-migration toolkit — bulk org/site import (#3273), PSA company import (#3311), script bundle export/import (#3276), a fleet migration posture report (#3264), and unattended tenancy provisioning via partner service principals (#3274).
  • Per-technician remote tool — each technician can pick their own remote-access provider instead of sharing one tenant-wide default. (#3391, #3440)
  • The v0.104.0 backup known issues are fixed — result-cap loss, slow ACL denials, and lost-VSS-snapshot corruption. (#3266, #3267, #3283, #3285)

Added

  • Fleet hygiene findings + aggregate remediation — a findings feed groups devices by systemic defect at org and partner scope; one remediation run targets every affected device, with per-device outcomes tracked. Four new RLS-enforced tables. (#3278)
  • Sign Your Own Agent Packages — official releases publish the exact pre-signing Windows build outputs (*-unsigned.exe) plus a manifest sourceCommit (#3327); a public breeze-selfhost-signing template repo re-signs them under your certificate and publishes your own release manifest, with a step-by-step guide (#3331). BINARY_GITHUB_REPOSITORY repoints an entire deployment — downloads, sync, and update URLs — at your signed repo, with the trust chain validated at boot (#3330, #3352).
  • Edition-aware agent — agent builds carry an edition (hosted / self-host); the updater refuses a manifest asset whose edition doesn't match the running build (#3349, #3321), the MSI carries a per-edition product identity with a cross-edition install guard (#3350), and the release pipeline fails closed if either edition could be produced mis-labeled (#3351, #3353, #3360).
  • First-class organization contacts — contacts and contact_external_links tables with per-contact portal-login linkage; all ten legacy jsonb writers now route through a compat service so old and new surfaces stay in sync. Existing site/billing contacts are backfilled on upgrade. (#3316, #3328, #3326)
  • Bulk org/site import — CSV-driven creation of organizations, sites, and enrollment keys, with external-system linkage (organization_external_links), skip-mode link persistence, and constraint-aware recovery. (#3273, #3287)
  • PSA company import — pull your company list from ConnectWise, Autotask, ServiceNow, Freshservice, Zendesk, or Jira into org import; every adapter now paginates instead of silently truncating at the first page. (#3311, plus connection-test and form fixes in #3291)
  • PSA connections are partner-wide capable — dual ownership (org XOR partner), so one PSA connection can serve all orgs under a partner. (#3308)
  • Partner-wide CIS baselines — same dual-ownership treatment for CIS hardening baselines. (#3400)
  • Script bundle export/import — move a script library between Breeze instances (or in from another RMM) as a versioned JSON bundle carrying parameters, categories, tags, timeouts, run-as levels, and exit-code severity mappings. (#3276)
  • Unattended tenancy provisioning — partner service principals gain organizations:write / sites:write / enrollment-keys:write scopes, so migration scripts can provision tenancy without an MFA'd human session. (#3274)
  • Fleet migration posture report — a fleet-level view of which competing management tools are still present on each device, from data the agent already collects. (#3264)
  • Preferred remote tool per technician — a profile setting selects among the tenant's configured remote-access providers; the selection is an id only and can never inject a provider. (#3391, #3440)
  • Discovery asset linking is hidden and automatic, and unlink is durable — manual unlink no longer silently undone by the next discovery scan; link state is visible and suppressions persist. (#3295)
  • breeze-backup auto-updates alongside the agent — its version is slaved to the agent's, so it no longer stays frozen at installer-time forever; Linux install.sh and uninstall now handle it too. (#3293)
  • Quick Support refinements — codes are now digits (read easily over the phone, shown 3-3-3), session history rows re-open a live detail panel, and rate limiting buckets IPv6 by /64. (#3292)
  • What's-new splash on login with a reopen link. (#3317)
  • Self-hosted webhooks can reach the LAN — on an affirmatively self-hosted deployment, webhook receivers on private (RFC1918/ULA) addresses are deliverable, including plain HTTP — confined strictly to private addresses. (#3320, #3366)
  • Mass-deployment and migration docs — GPO/Intune/JAMF agent deployment guide (#3288) and RMM-to-Breeze migration guides (#3250).

Improved

  • Queue enqueues no longer stall behind blocking Redis consumers — blocking commands get dedicated connections instead of sharing the enqueue connection; this was worth up to ~250x on enqueue latency under load. (#3299)
  • Remote proxy access is one entry point, and sessions no longer die at the 5-minute cliff. (#3294)
  • Agent command results cap raised 1 MiB → 5 MB, matching stdout/stderr — fixes restore browsing for backups with very large file counts. (#3283)
  • AI usage accounting counts tool executions and refreshes spend live. (#3297)
  • search_logs keyset pagination is actually usable. (#3368)
  • Umbrella DNS integration authenticates with OAuth2 client credentials instead of the retired Basic scheme. (#3275)

Fixed

  • Backup (the v0.104.0 known issues): results are bounded to what the server accepts so large runs report completion (#3267); plain NTFS ACL denials take the fast-retry path instead of ~30 s each (#3266); a lost VSS snapshot aborts the run immediately instead of silently producing a bad backup (#3266); and VSS session COM references are held for the whole run with BackupComplete signalled, so writers are released cleanly (#3285).
  • Saved Filters was entirely unusable — building any filter with a condition value crashed the page; also fixed in the same sweeps: device-group creation 400 for multi-org partners, fleet hygiene "all orgs" scope, and org-switcher pagination. (#3448, #3449)
  • Organizations lists load every page, not just the first 50 — org pickers and the orgs page were silently truncated for larger partners. (#3447) Same class of bug fixed for the script library (#3305).
  • Policy remediation actually dispatches — POST /policies/:id/remediate created runs that were never sent to (or were simulated as completed on) the agent. (#3414, #3417, #3438)
  • Cmd+K search finds partner-wide scripts, plus three more QA-sweep defects. (#3442)
  • Device groups: null filterConditions accepted on create and static deviceIds no longer dropped (#3423); deleting a device group no longer aborts on its membership log (#3314).
  • Agent (macOS): the breeze group is actually applied to the IPC socket, not just created (#3422); the Keychains directory node itself is denied, not just its contents (#3395); Finder aliases resolve in the file browser (#3384).
  • Agent (Windows/Linux): malformed reboot delays are rejected instead of coerced to 0 = "now" (#3393), reboot/shutdown delay is normalized to minutes on Windows (#3371), total shutdown time is bounded so systemd stops the unit cleanly (#3367), and every content-touching file operation routes through path containment (#3398).
  • Patch reboots always warn the logged-in user — previously an invariant only by coincidence of defaults. (#3421)
  • Discovery: automatic asset classifiers are ranked, so a UniFi switch stops flapping to access_point between scans. (#3383)
  • Warranty sync excludes virtual machines. (#3399)
  • Viewer answer-polling no longer exhausts the global IP rate limit during remote sessions. (#3377)
  • Installer capacity is discriminated per token, not per enrollment key. (#3392)
  • Agents receive partner-owned config policies — agent config delivery resolved org-owned policies only, so partner-wide policies silently never reached devices. (#3390)
  • SNMP poll dispatch takes its org from the live device row (#3378), and the AI remediate_vulnerability tool resolves its org from the device, not the caller's first accessible org (#3379).
  • Hand-written SQL templates no longer bind raw JS Date objects — a timezone-dependent correctness hazard. (#3382)
  • Process samples match on the agent id, not the device id. (#3396)
  • Duplicate remote-access provider ids and dangling defaults are rejected at write time. (#3406)
  • Quotes/billing: the quote line's name carries onto the converted invoice (#3365) and unit prices stop clipping their last digit (#3370).
  • The suspicious-approval report audit row is tenanted to the approval, not the reporter. (#3420)
  • Config-policy Automation/Maintenance tabs use the shared searchable timezone picker (#3376); list summaries render their counts as one interpolated string (#3437, #3424); contextual translation fixes (#3296).

Security

  • Hosted signup requires a business email — throwaway consumer mailboxes were the zero-cost entry point behind recent abuse clusters. Hosted-only: self-hosted signup is unaffected. (#3289)
  • Signup-abuse detection is now hosted-only (it polices untrusted public signups; on a single-team self-hosted install its heuristics are noise), and gains a provider-default hostname detector. Self-hosters running a genuinely multi-tenant service can opt back in with ABUSE_SIGNALS_ENABLED=true. (#3411)
  • User-supplied URL fields are scheme-validated — several fields accepted javascript: and friends and rendered them as clickable links. (#3442, #3448)
  • Self-hosted cleartext webhook allowance is confined to private addresses — plain HTTP was briefly permitted for any hostname on self-hosted; it now requires the resolved address to actually be private. (#3366, closing the gap opened by #3320)
  • Plaintext is sealed into encryption-registered columns even without APP_ENCRYPTION_KEY_ID — a UI edit could silently rewrite an encrypted column as plaintext. (#3394)
  • Partner-wide script writes enforce same-partner ownership. (#3272)
  • BYO-signing trust chain fails loudly — a re-signing failure aborts the sync instead of reporting success, and a repointed release source must carry a non-official trust root. (#3352)
  • The breeze-billing tables' partner-axis RLS is codified in-repo (applied live to hosted in v0.104-era). (#3290)

Self-hosters are encouraged to upgrade.

Self-Hosting / Upgrade Notes

No breaking schema or API changes. The agent edition change (note 3) is the one behavioral shift to read before you pull. Standard upgrade:

# bump BREEZE_VERSION in .env, then:
docker compose pull api web portal && docker compose up -d binaries-init api web portal

(If you build from source, run pnpm install — the lockfile changed.)

1. Database — 16 migrations, no large-table rewrites

All idempotent, auto-applied on API boot via autoMigrate (unless AUTO_MIGRATE=false). Nothing rewrites a hot table; the data-writing migrations touch small config/linkage tables and log row counts via RAISE WARNING (visible in your Postgres log):

Migration What it changes
2026-08-19-contacts Creates contacts / contact_external_links and backfills them from the legacy sites.contact and organizations.billing_contact jsonb (values bounded and trimmed, so an overlong legacy value cannot abort the migration); links portal users to contacts. The jsonb columns are kept and stay in sync via the compat service.
2026-08-18-drop-organizations-accounting-columns Migrates accounting_provider / accounting_external_id into organization_external_links, then drops both columns. Conflicting or provider-less legacy values are discarded with a warning naming the count — check your Postgres log if you relied on QuickBooks/Xero org linkage.
2026-08-14-drop-patch-policies-sources Drops the deprecated patch_policies.sources column (replaced by the Patch Sources toggle set).
2026-08-08-proxy-session-lifetime Cleans up stale tunnel_allowlists rows (counts warned).
2026-08-20-installer-bootstrap-token-usage-kind, 2026-08-20-discovered-asset-detection-source Small column backfills on their own tables.

The rest create the new feature tables (fleet hygiene, external links, editions, PSA/CIS dual ownership) with RLS policies in the same file.

2. No new required environment variables

Everything new is optional with a safe default; the standard upgrade needs no .env changes.

  • ABUSE_SIGNALS_ENABLED — signup-abuse detection switch; defaults to the value of IS_HOSTED, so self-hosted deployments now run with abuse detection off (see Security). Set true to opt a multi-tenant self-hosted service in. Validated as a boolean when set — a typo refuses boot.
  • BINARY_EDITION — self-host (default, today's behavior) | hosted. Leave unset.
  • BINARY_GITHUB_REPOSITORY — BYO signing only: repoints release downloads/sync at your own signed release repo (owner/repo, shape-validated at boot). If you set it, you must also set RELEASE_ARTIFACT_MANIFEST_PUBLIC_KEYS to your manifest key — the API refuses to boot if the official Breeze key is the only trust root for a non-official repo, because every sync would otherwise fail closed and silently freeze your fleet.
  • Removed: MSI_SIGNING_URL / MSI_SIGNING_CF_ACCESS_SECRET — the per-download MSI signing path is retired in favor of the release-time BYO pipeline. Leftover values in .env are ignored harmlessly.

3. The agent edition change — read this if you deploy Windows agents

  • v0.104.0 is the last public release carrying a Breeze-signed Windows agent. Existing installs are unaffected and previously signed packages remain validly signed. From v0.105.0 on, the public release's agent artifacts are the self-host edition: the Windows MSI (breeze-agent.msi) is published unsigned, under its own product identity ("Breeze Agent (Self-Hosted)", its own UpgradeCode) — a signed Windows agent now comes from your own certificate (see below), or you accept the SmartScreen warning on interactive installs.
  • To ship signed agents under your own certificate, use the breeze-selfhost-signing template repo with the Sign Your Own Agent Packages guide (#3331): it re-signs the published unsigned inputs, emits your own release manifest, and you point BINARY_GITHUB_REPOSITORY + RELEASE_ARTIFACT_MANIFEST_PUBLIC_KEYS at it.
  • Existing fleets keep updating normally — manifests without a per-asset edition are accepted for backward compatibility, and edition enforcement only refuses a mismatched declared edition.
  • Devices still running a hosted-edition agent against a self-hosted server now report migrationRequired, and admins see a persistent migration banner until those agents are migrated to the self-host edition. (#3324, #3321)
  • The two editions refuse to install over each other on the same machine, so a hosted-edition install can't be silently upgrade-chained onto by a self-host MSI (or vice versa). (#3350)

4. Other behavior changes

  • Signup-abuse detection defaults off on self-hosted (IS_HOSTED=false) — see note 2. If it's off, the only artifact is one [AbuseSignals] Disabled line at boot.
  • Webhooks on self-hosted deployments may now target private (RFC1918/ULA) addresses, including over plain HTTP — strictly confined to private addresses; public targets still require HTTPS. (#3320, #3366)
  • Agent command results (including backup results) may now be up to 5 MB instead of 1 MiB. (#3283)
  • PUBLIC_ENABLE_NETWORK_DEVICES_IN_LIST (web, build-time) exists to show network-discovered assets in the Devices list, but remains off by default and we recommend leaving it off — unified sort/pagination and per-asset detail pages are still in flight.
  • Quick Support codes are now digits — outstanding letter codes remain redeemable. (#3292)

Full Changelog: v0.104.0...v0.105.0

What's Changed

  • docs: v0.102.0..v0.104.0 release sweep by @ToddHebebrand in #3268
  • fix(api): enforce same-partner ownership on partner-wide script writes (#3262 follow-up) by @ToddHebebrand in #3272
  • feat(orgs): bulk org/site import + organization_external_links (#3242) by @ToddHebebrand in #3273
  • feat(devices): fleet migration posture report (#3244) by @ToddHebebrand in #3264
  • feat(partner-api): unattended tenancy provisioning via partner service principals (#3243) by @ToddHebebrand in #3274
  • feat(scripts): script bundle import/export (#3245) by @ToddHebebrand in #3276
  • fix(backup): short-retry ACL denials and abort on a lost VSS snapshot (#3259, #3260) by @ToddHebebrand in #3266
  • fix(backup): bound the command result against the server's 1 MiB cap, not the IPC frame (#3001) by @ToddHebebrand in #3267
  • test(backup): make vss.Provider injectable to pin RunBackupContext liveness wiring (#3270) by @ToddHebebrand in #3280
  • feat(agents): raise the command-result result cap to 5 MB, matching stdout/stderr by @ToddHebebrand in #3283
  • fix(backup): hold the VSS session COM references for the whole run and signal BackupComplete (#3269) by @ToddHebebrand in #3285
  • docs(migration): RMM-to-Breeze migration guides by @ToddHebebrand in #3250
  • docs(deploy): GPO/Intune/JAMF mass-deployment guide + fix bulk-enrollment env recipe (#3248) by @ToddHebebrand in #3288
  • docs(api): X-API-Key authenticates only MCP, dev-push, and device custom-field surfaces (#3247) by @ToddHebebrand in #3286
  • docs(specs,plans): RMM migration epic design specs and implementation plans by @ToddHebebrand in #3279
  • fix(orgs): org-import hardening — sites:write gate, skip-mode link persistence, atomic group create, constraint-aware recovery by @ToddHebebrand in #3287
  • fix(psa): real connection test, honest 501 sync, working form round-trip, single-source provider list by @ToddHebebrand in #3291
  • refactor(accounting): migrate the QuickBooks importer onto the shared org-import seam by @ToddHebebrand in #3298
  • chore(orgs): drop the legacy accounting_provider / accounting_external_id columns by @ToddHebebrand in #3309
  • feat(psa): dual ownership (org XOR partner) for psa_connections (#2135) by @ToddHebebrand in #3308
  • feat(psa): PSA company import via the org-import seam (#3246) by @ToddHebebrand in #3311
  • feat(contacts): first-class organization contacts — tables, contracts, compat service (#3258) by @ToddHebebrand in #3316
  • feat(release): publish unsigned signing-input artifacts + manifest sourceCommit (BYO signing phase 1) by @ToddHebebrand in #3327
  • feat(api): unified release source + deployment re-signing trust chain (BYO signing phase 2) by @ToddHebebrand in #3330
  • feat(selfhost-signing): BYO-signing template repo contents + Sign Your Own Agent Packages guide (phase 3) by @ToddHebebrand in #3331
  • feat(web): what's-new splash on login with reopen link by @ToddHebebrand in #3317
  • docs: BYO signing design spec + phase implementation plans by @ToddHebebrand in #3348
  • feat(web): surface agent migrationRequired signal — persistent self-hosted migration banner by @ToddHebebrand in #3324
  • feat(agent): compile-time control-plane build-mode host policy (inert by default) by @ToddHebebrand in #3321
  • feat(agent): enforce edition match on release manifest assets by @ToddHebebrand in #3349
  • feat(installer): parameterize MSI edition identity by @ToddHebebrand in #3350
  • feat(api): edition-aware release sources, BINARY_EDITION mode, agent_versions edition by @ToddHebebrand in #3353
  • feat(release): edition-aware build pipeline + self-host artifact publication by @ToddHebebrand in #3351
  • docs: what's-new splash design spec + implementation plan by @ToddHebebrand in #3359
  • feat(selfhost-signing): build BYO MSIs under the self-host edition identity by @ToddHebebrand in #3360
  • docs: integration-test blocks PRs — it is smoke-test that is continue-on-error by @bdunncompany in #3310
  • test(web): give the InvoiceWorkspace queued-Issue tests real waitFor headroom (#3219) by @bdunncompany in #3284
  • fix(groups): clear group_membership_log before deleting a device group (#3313) by @bdunncompany in #3314
  • fix(web): walk every page of /scripts so the full library is reachable (#3301) by @bdunncompany in #3305
  • fix(contacts): bound backfill projections so an overlong jsonb value cannot abort the migration by @bdunncompany in #3326
  • test(ai): pin the aiTools registry against TOOL_TIERS, both directions (#3300) by @bdunncompany in #3306
  • fix(dns): authenticate Umbrella with OAuth2 client credentials, not Basic (#3271) by @bdunncompany in #3275
  • feat(webhooks): honour the self-hosted private-network gate, drop the local IP policy by @bdunncompany in #3320
  • feat(release): optional draft-first gate via RELEASE_DRAFT_FIRST variable by @ToddHebebrand in #3362
  • fix(web): org scoping for CIS Hardening and audit baselines by @ToddHebebrand in #3372
  • feat(remote): consolidate proxy access to one entry point, fix the 5-minute session cliff (#3199) by @ToddHebebrand in #3294
  • feat(abuse): require a business email for hosted partner signup by @ToddHebebrand in #3289
  • chore(rls): codify partner-axis RLS for the breeze-billing tables by @ToddHebebrand in #3290
  • feat(quick-support): refinement pass — digit codes, session re-open, IPv6 /64 rate limiting, tenant-wide domain descope by @ToddHebebrand in #3292
  • fix(i18n): correct contextual translations by @ToddHebebrand in #3296
  • fix(ai): count tool executions in the usage rollup and refresh spend live by @ToddHebebrand in #3297
  • fix(api): give blocking Redis consumers their own connections by @ToddHebebrand in #3299
  • docs(plans): Phase 3 design handoff prompt for the RMM migration epic by @ToddHebebrand in #3315
  • feat(contacts): route all ten legacy jsonb writers through the compat service (#3258) by @ToddHebebrand in #3328
  • fix(agent): filter BroadcastNotification on the notify scope (#3255) by @ToddHebebrand in #3364
  • fix(billing): carry the quote line name onto the converted invoice (#3319) by @ToddHebebrand in #3365
  • feat(api,web): partner-wide CIS baselines — dual-ownership (org XOR partner) by @ToddHebebrand in #3400
  • fix(api): match process-sample path id against the agent id, not the device id (#3387) by @bdunncompany in #3396
  • fix(api,secrets): seal plaintext into registered columns without requiring APP_ENCRYPTION_KEY_ID by @bdunncompany in #3394
  • fix(agent): bound total shutdown time so systemd stops cleanly (#3323) by @ToddHebebrand in #3367
  • fix(api): make search_logs keyset pagination usable (#3329) by @ToddHebebrand in #3368
  • fix(quotes): stop the quote line unit price clipping its last digit (#3318) by @ToddHebebrand in #3370
  • fix(agent): normalize reboot/shutdown delay to minutes on Windows (#3252) by @ToddHebebrand in #3371
  • fix(ci): retire the update-community-readme schedule (#3173) by @ToddHebebrand in #3375
  • fix(web): use shared TimezoneSelect in config-policy Automation/Maintenance tabs (#3361) by @ToddHebebrand in #3376
  • fix(snmp): make the live device row the sole org authority for poll dispatch (#3226) by @ToddHebebrand in #3378
  • fix(ai): resolve remediate_vulnerability's org from the device, not accessibleOrgIds[0] (#3322) by @ToddHebebrand in #3379
  • fix(api): stop binding raw JS Dates into hand-written sql templates (#3369) by @ToddHebebrand in #3382
  • fix(discovery): rank the automatic asset classifiers so a UniFi switch stops flapping to access_point (#3187) by @ToddHebebrand in #3383
  • fix(agent): resolve macOS Finder aliases in the file browser (#3344) by @ToddHebebrand in #3384
  • fix(config): make the env↔compose parity guard see commented-out vars (#3239) by @ToddHebebrand in #3388
  • fix(api): resolve partner-owned config policies for agent config delivery (#2930) by @ToddHebebrand in #3390
  • fix(api): discriminate installer capacity per token, not per key (#3034) by @ToddHebebrand in #3392
  • fix(agent): deny the Keychains directory node, not just its contents (#3385) by @ToddHebebrand in #3395
  • fix(agent): route every content-touching file op through containment (#3397) by @ToddHebebrand in #3398
  • fix(webhooks): confine the self-hosted cleartext allowance to private addresses by @bdunncompany in #3366
  • fix(desktop): stop viewer answer-poll from exhausting the global IP rate limit (#3041) by @ToddHebebrand in #3377
  • fix(api): exclude virtual machines from warranty sync (#3201) by @bdunncompany in #3399
  • fix(api): abort sync on re-signing failure, enforce non-official trust root (BYO signing phase 2 follow-up) by @ToddHebebrand in #3352
  • fix(agent): reject malformed reboot delays instead of coercing them to 0 (#3373) by @ToddHebebrand in #3393
  • chore(deps): bump node from f70403e to d32cdf6 in /apps/web by @dependabot[bot] in #3354
  • chore(deps): bump node from f70403e to d32cdf6 in /apps/api by @dependabot[bot] in #3355
  • chore(deps): bump node from f70403e to d32cdf6 in /docker by @dependabot[bot] in #3356
  • chore(deps): bump node from f70403e to d32cdf6 in /apps/m365-communications-executor by @dependabot[bot] in #3357
  • chore(deps): bump node from f70403e to d32cdf6 in /apps/m365-graph-actions-executor by @dependabot[bot] in #3358
  • chore(deps): bump @types/pg from 8.20.0 to 8.20.4 in /e2e-tests by @dependabot[bot] in #3334
  • chore(deps): bump the expo-sdk group with 3 updates by @dependabot[bot] in #3332
  • chore(deps): bump tsx from 4.23.1 to 4.23.11 in /e2e-tests by @dependabot[bot] in #3335
  • chore(deps): bump werift from 0.24.2 to 0.24.3 in /e2e-tests by @dependabot[bot] in #3336
  • chore(deps): bump postcss from 8.5.25 to 8.5.26 in the tailwind group by @dependabot[bot] in #3340
  • chore(deps): bump the hono group with 2 updates by @dependabot[bot] in #3341
  • chore(deps): bump @testing-library/user-event from 14.6.1 to 14.6.3 in the testing group by @dependabot[bot] in #3342
  • chore(deps): bump @sentry/node from 10.68.0 to 10.69.0 by @dependabot[bot] in #3345
  • fix(deps): dedup pnpm-lock.yaml — duplicated mapping keys break every JS job on main by @bdunncompany in #3407
  • chore(api): drop deprecated patch_policies.sources column (#3151) by @ToddHebebrand in #3154
  • chore(deps): bump the react-native-animation group across 1 directory with 2 updates by @dependabot[bot] in #3333
  • chore(deps): bump the astro group across 1 directory with 3 updates by @dependabot[bot] in #3339
  • chore(deps): bump the mobile group across 1 directory with 3 updates by @dependabot[bot] in #3337
  • fix(orgs): reject duplicate remote-access provider ids and dangling defaults by @ToddHebebrand in #3406
  • feat(abuse): provider-default hostname detector, and make abuse detection hosted-only by @ToddHebebrand in #3411
  • feat(remote): let a technician pick their own remote-access provider (#3389) by @bdunncompany in #3391
  • chore(deps): bump the typescript-tooling group across 1 directory with 5 updates by @dependabot[bot] in #3412
  • fix(api): dispatch policy remediation instead of simulating completion (#3413) by @bdunncompany in #3414
  • fix(api): dispatch the run created by POST /policies/:id/remediate (#3416) by @bdunncompany in #3417
  • refactor(api): extract scriptDispatch core; consolidate 5 script dispatch sites (#3409 PR 0) by @ToddHebebrand in #3418
  • fix(patching): make the patch-reboot user warning an invariant, not a coincidence (#3197) by @ToddHebebrand in #3421
  • fix(agent): apply the breeze group to the macOS IPC socket, not just create it (#3137) by @ToddHebebrand in #3422
  • fix(groups): accept a null filterConditions on create and stop dropping static deviceIds (#3159) by @ToddHebebrand in #3423
  • fix(web): render the config-policy count as one interpolated string by @ToddHebebrand in #3424
  • docs(release): v0.105.0 change list, test checklist, and UI QA sweep log by @ToddHebebrand in #3427
  • chore(deps): bump the aws-sdk group in /agent with 5 updates by @dependabot[bot] in #3433
  • chore(deps): bump google.golang.org/api from 0.291.0 to 0.292.0 in /agent by @dependabot[bot] in #3434
  • chore(deps): bump @azure/msal-browser from 4.30.0 to 5.18.0 by @dependabot[bot] in #3343
  • fix(deps): repair broken pnpm-lock.yaml (duplicated hono@4.13.1 key) by @ToddHebebrand in #3439
  • fix(api): scriptDispatch review findings — cleanup gap, AI payload echo, batch cap (#3409 PR 0 follow-up) by @ToddHebebrand in #3438
  • feat(fleet): fleet hygiene findings feed + aggregate remediation by @ToddHebebrand in #3278
  • fix(web): count-glue defects in five list summaries by @ToddHebebrand in #3437
  • fix(web,api): four defects found by the UI QA sweep by @ToddHebebrand in #3442
  • feat(remote): slim provider-list endpoint + preferred-remote-tool profile control (#3389) by @bdunncompany in #3440
  • fix(approvals): tenant the suspicious-report audit row to the approval, not the reporter (#3234) by @ToddHebebrand in #3420
  • feat(agent): auto-update the breeze-backup binary alongside the agent by @ToddHebebrand in #3293
  • fix(web): load every page of organizations, not just the first 50 (#3446) by @bdunncompany in #3447
  • feat(discovery): hidden-and-automatic asset linking with durable unlink (#3261) by @ToddHebebrand in #3295
  • fix(web,api): two blocking crashes and two more unvalidated URL fields by @ToddHebebrand in #3448
  • fix: pre-release QA sweep round 3 — device groups, saved filters, fleet all-orgs, org switcher pagination by @ToddHebebrand in #3449

Full Changelog: v0.104.0...v0.105.0

Don't miss a new breeze release

NewReleases is sending notifications on new releases.