Changes
-
Removed both
FLEET_MDM_APPLE_ENABLE
andFLEET_DEV_MDM_ENABLED
feature flags. -
Automatically send a configuration profile for the
fleetd
agent to teams that use DEP enrollment. -
DEP JSON profiles are now automatically created with default values when the server is run.
-
Added the
--mdm
and--mdm-pending
flags to thefleetctl get hosts
command to list hosts enrolled in Fleet MDM and pending enrollment in Fleet MDM, respectively. -
Added support for the "enrolled" value for the
mdm_enrollment_status
filter and the newmdm_name
filter for the "List hosts", "Count hosts" and "List hosts in label" endpoints. -
Added the
fleetctl mdm run-command
command, to run any of the Apple-supported MDM commands on a host. -
Added the
fleetctl get mdm-command-results
sub-command to get the results for a previously-executed MDM command. -
Added API support to filter the host by the disk encryption status on "GET /hosts", "GET /hosts/count", and "GET /labels/:id/hosts" endpoints.
-
Added API endpoint for disk encryption aggregate status data.
-
Automatically install
fleetd
for DEP enrolled hosts. -
Updated hosts' profiles status sync to set to "pending" immediately after an action that affects their list of profiles.
-
Updated FileVault configuration profile to disallow device user from disabling full-disk encryption.
-
Updated MDM settings so that they are consistent, and updated documentation for clarity, completeness and correctness.
-
Added
observer_plus
user role to Fleet. Observers+ are observers that can run any live query. -
Added a premium-only "Published" column to the vulnerabilities table to display when a vulnerability was first published.
-
Improved version detection for macOS apps. This fixes some false positives in macOS vulnerability detection.
-
If a new CPE translation rule is pushed, the data in the database should reflect that.
-
If a false positive is patched, the data in the database should reflect that.
-
Include the published date from NVD in the vulnerability object in the API and the vulnerability webhooks (premium feature only).
-
User management table informs which users only have API access.
-
Added configuration option
websockets_allow_unsafe_origin
to optionally disable the websocket origin check. -
Added new config
prometheus.basic_auth.disable
to allow running the Prometheus endpoint without HTTP Basic Auth. -
Added missing tables to be cleared on host deletion (those that reference the host by UUID instead of ID).
-
Introduced new email backend capable of sending email directly using SES APIs.
-
Upgraded Go version to 1.19.8 (includes minor security fixes for HTTP DoS issues).
-
Uninstalling applications from hosts will remove the corresponding entry in
software
if no more hosts have the application installed. -
Removed the unused "Issuer URI" field from the single sign-on configuration page of the UI.
-
Fixed an issue where some icons would appear clipped at certain zoom levels.
-
Fixed a bug where some empty table cells were slightly different colors.
-
Fixed e-mail sending on user invites and user e-mail change when SMTP server has credentials.
-
Fixed logo misalignment.
-
Fixed a bug where for certain org logos, the user could still click on it even outside the navbar.
-
Fixed styling bugs on the SelectQueryModal.
-
Fixed an issue where custom org logos might be displayed off-center.
-
Fixed a UI bug where in certain states, there would be extra space at the right edge of the Manage Hosts table.
Upgrading
Please visit our update guide for upgrade instructions.
Documentation
Documentation for Fleet is available at fleetdm.com/docs.
Binary Checksum
SHA256
33498aadcf77414cac6e35b0ba7d09afa707c659ba44611fa12b624641fcabad fleet_v4.30.0_linux.tar.gz
5671f4e0fef5393f1633276b44747b0b8274a8a8b31bcb6d9ecd2379ea119b73 fleetctl_v4.30.0_windows.tar.gz
841ef38e697caae45e85bbbb950f400c51598bddff8cbbb28594f65ab81a4606 fleetctl_v4.30.0_macos.zip
8fca74d09775a4977b510c98a7968f55534be4a61cf1c7f11c5fa25c5ada6d08 fleetctl_v4.30.0_linux.zip
d764f79fea8d8bb5b220e5ebd495b7153b6665a625e177a778ecb377f1794030 fleetctl_v4.30.0_windows.zip
e5f0d6b216ecd2f9e3d3922cf90f44cc3098259b77c93773bfe57f3801c3e1fe fleetctl_v4.30.0_linux.tar.gz
f2bb957204ca4f6dc9546c1ab034a265f6dc718f0cc5c95e138f41c5c0924c2b fleetctl_v4.30.0_macos.tar.gz