github fleetdm/fleet fleet-v4.57.0

14 hours ago

Fleet 4.57.0 (Sep 23, 2024)

Endpoint Operations

  • Added support for configuring policy installers via GitOps.
  • Added support for policies in "No team" that run on hosts that belong to "No team".
  • Added reserved team names: "All teams" and "No team".
  • Added support the software status filter for 'No teams' on the hosts page.
  • Enable 'No teams' funcitonality for the policies page and associated workflows.
  • Added reset install counts and cancel pending installs/uninstalls when GitOps installer updates change package contents.
  • Added support for software installer packages, self-service flag, scripts, pre-install query, and self-service availability to be edited in-place rather than deleted and re-added.

Device Management (MDM)

  • Added feature allowing automatic installation of software on hosts that fail policies.
  • Added feature for end users to enroll BYOD devices into Fleet MDM.
  • Added the ability to use Fleet to uninstall packages from hosts.
  • Added an endpoint for getting an OTA MDM profile for enrolling iOS and iPadOS hosts.
  • Added protocol support for OTA enrollment and automatic team assignment for hosts.
  • Added validation of Setup Assistant profiles on profile upload.
  • Added validation to prevent installing software on a host with a pending installation.
  • Allowed custom SCEP CA certificates with any kind of extendedKeyUsage attributes.
  • Modified POST /api/latest/fleet/software/batch endpoint to be asynchronous and added a new endpoint GET /api/latest/fleet/software/batch/{request_uuid} to retrieve the result of the batch upload.

Vulnerability Management

  • Fixed a false negative vulnerability for git.
  • Fixed false positive vulnerabilities for minio.
  • Fixed an issue where virtual box for macOS wasn't matching against the NVD product name.
  • Fixed Ubuntu python package false positive vulnerabilities by removing duplicate entries for ubuntu python packages installed by dpkg and renaming remaining pip installed packages to match OVAL definitions.

Bug fixes and improvements

  • Updated Go to go1.23.1.
  • Removed validation of APNS certificate from server startup.
  • Removed invalid node keys from server logs.
  • Improved the UX of turning off MDM on an offline host.
  • Improved clarity of GitOps VPP app ID type errors.
  • Improved gitops error message about enabling windows MDM.
  • Improved messaging for VPP token constraint errors.
  • Improved loading state for UI tables when no data is present yet.
  • Improved permissions so that hosts can no longer access installers that aren't directly assigned to them.
  • Improved verification of premium license before uploading VPP tokens.
  • Added "0 items" description on empty software tables for UI consistency.
  • Updated the macos target minimum version tooltip.
  • Fixed logic to properly catch and log APNs errors.
  • Fixed UI overflow issues with OS settings table data.
  • Fixed regression for checking email used to get a signed CSR.
  • Fixed bugs on enrollment profiles when the organization name contains invalid XML characters.
  • Fixed an issue with cron profiles delivery failing if a Windows VM is enrolled twice.
  • Fixed issue where Fleet server could start when an expired ABM certificate was provided as server config.
  • Fixed self-service checkbox appearing when iOS or iPadOS app is selected.

Fleet's agent

The following version of Fleet's agent (fleetd) support the latest changes to Fleet:

  1. orbit-v1.33.0
  2. fleet-desktop-v1.33.0 (included with Orbit)
  3. fleetd-chrome-v1.3.1

While newer versions of fleetd still function with older versions of the Fleet server (and vice versa), Fleet does not actively test these scenarios and some newer features won't be available.

Upgrading

Please visit our update guide for upgrade instructions.

Documentation

Documentation for Fleet is available at fleetdm.com/docs.

Binary Checksum

SHA256

5add72a4f9ebfcf7d3adbb20b37bac886c920aa055b0fbbfe4f84dccf6047cbc  fleet_v4.57.0_linux.tar.gz
42f207bf0a39df2d50e2adcf33760fdf504f9924790df2d02a4ccdb928fe31d2  fleetctl_v4.57.0_linux.tar.gz
1fbbc2618817200af95533d1682ba5c522346e49f162456ad3efc4b3fff7c3c2  fleetctl_v4.57.0_linux.zip
83afac7d2dbd4a7707e7268fa893dbdc15ae1b8dfce280720760af27d20b0063  fleetctl_v4.57.0_macos.tar.gz
688837872c0aad1a2c48d89a600b38a40f89bdb550b25d4f9f265d3a95468539  fleetctl_v4.57.0_macos.zip
588ee392e35e4e4e74606977bae8413cde82f248cb23bf053747cb3ab947d4dc  fleetctl_v4.57.0_windows.tar.gz
255e79e4b352b24d865e82a01f982b3d0ae72615b411649a20fb9780828ec87c  fleetctl_v4.57.0_windows.zip

Don't miss a new fleet release

NewReleases is sending notifications on new releases.