# Fleet changelog > Open-source device management and vulnerability reporting for laptops and servers. - Vendor: Fleet Device Management - Category: Developer Tools - Official site: https://fleetdm.com - Tracked by: What's New (https://whatsnew.fyi/product/fleet) - Harvested from: GitHub (fleetdm/fleet) - Entries below: 25 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## Releases ### v4.90.0 - Date: 2026-08-06 - Version: v4.90.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.90.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.90.0 - **added** — Added ability to upload multiple custom packages (up to 10) for the same software title on a team, with first-added package installed when a host matches more than one - **added** — Added support for editing existing configuration profiles via PATCH /api/v1/fleet/configuration_profiles/:profile_uuid - **added** — Added custom host vitals that admins can define and reference as $FLEET_HOST_VITAL_ variables in scripts and configuration profiles - **added** — Added ability to enforce a host naming template on macOS, iOS, and iPadOS hosts under Controls > OS settings - **added** — Added POST /api/v1/fleet/host_name_template to set or clear the naming template - **added** — Added name_template key under controls in GitOps for fleets and included it in fleetctl generate-gitops output - **added** — Added host name enforcement status row with enforcement status and resend action to host details OS settings modal - **added** — Added host name enforcement statuses to Controls OS settings aggregate cards and os_settings host filter - **added** — Added edited_host_name_template activity - **added** — Added support for Python (.py) script-only software packages as custom packages for macOS and Linux hosts - **added** — Added support for provisioning macOS users during setup and keeping passwords in sync with OAUTH ROPG supporting IdP via Fleet Desktop on macOS 26+ hosts - **added** — Added UI for configuring Apple account provisioning (FPSSO) in integrations settings - **added** — Enabled Microsoft Entra conditional access for self-hosted Fleet Premium instances - **added** — Added native Splunk HEC log destination for osquery status, result, and audit logs - **added** — Added support for escrowing disk encryption recovery keys from Linux hosts that use TPM-backed full-disk encryption - **added** — Added FLEET_MDM_ENABLE_CUSTOM_DISK_ENCRYPTION as cross-platform alias for FLEET_MDM_ENABLE_CUSTOM_FILEVAULT - **changed** — Enabled Turn off MDM button for offline macOS hosts with unenroll command queued for delivery when device comes online - **added** — Added enrollment profile URL to macOS tab in Add hosts modal with enrollment type selection for MDM users - **added** — Added support for targeting declarations to user channel on macOS - **added** — Added ability to handle DDM assets and unblocked more declaration types ##### Fleet 4.90.0 (Aug 05, 2026) ###### IT Admins - Added the ability to upload multiple custom packages (up to 10) for the same software title on a team, so IT admins can deploy different versions or architectures (for example, Arm vs. Intel builds or staged rollouts) to label-scoped hosts instead of splitting them across teams. When a host matches more than one package, the first-added package is installed. - Added support for editing existing configuration profiles (Apple `.mobileconfig`, Apple DDM declarations, Windows, and Android) in place via `PATCH /api/v1/fleet/configuration_profiles/:profile_uuid`. - Added custom host vitals: admins can define custom host fields, set their values per host manually or via the API, and reference them as `$FLEET_HOST_VITAL_` variables in scripts and configuration profiles. - Added the ability to enforce a host naming template on macOS, iOS, and iPadOS hosts under Controls > OS settings > Host names, for a fleet or for "No team" (Fleet Premium). - Added `POST /api/v1/fleet/host_name_template` to set or clear the naming template (`fleet_id` omitted or `0` targets "No team"); an empty template clears it without renaming any host. - Added a `name_template` key under `controls` in GitOps for fleets and "No team", and included it in `fleetctl generate-gitops` output. - Added a "Host name" row with enforcement status (Enforcing, Verifying, Verified, Failed) to the host details OS settings modal, including a resend action via `POST /api/v1/fleet/hosts/{id}/name_template/resend`. - Added host name enforcement statuses to the Controls OS settings aggregate cards and the `os_settings` host filter. - Added the `edited_host_name_template` activity. - Added support for Python (`.py`) script-only software packages, which can be uploaded as custom packages (the file contents become the install script) and installed on macOS and Linux hosts, via the UI, REST API, and GitOps. - Added support for provisioning macOS users during setup and keeping passwords in sync with any OAUTH ROPG supporting IdP via the Fleet Desktop app on macOS 26+ hosts. - Added UI for configuring Apple account provisioning (FPSSO) in the integrations settings. - Enabled Microsoft Entra conditional access for self-hosted Fleet Premium instances (previously available only on Fleet Cloud). The `microsoft_compliance_partner.proxy_api_key` server configuration has been removed; the feature is now gated on the Fleet Premium license tier. - Added native Splunk HEC log destination for osquery status, result, and audit logs. - Added support for escrowing disk encryption recovery keys from Linux hosts that use TPM-backed full-disk encryption (e.g. Ubuntu 26). On these hosts, orbit escrows a dedicated Fleet-owned snapd recovery key silently, without prompting the end user for a passphrase. - Added `FLEET_MDM_ENABLE_CUSTOM_DISK_ENCRYPTION` (`mdm.enable_custom_disk_encryption`) as a cross-platform alias for `FLEET_MDM_ENABLE_CUSTOM_FILEVAULT`. When set, it allows both custom Apple MDM profiles for FileVault and custom Windows configuration profiles for BitLocker. - Enabled "Turn off MDM" button for offline macOS hosts. The unenroll command is now queued and delivered when the device comes back online, consistent with iOS/iPadOS behavior. - Added enrollment profile URL to the macOS tab in the "Add hosts" modal, with enrollment type selection (company-owned or personal/BYOD) for MDM users. - Added support for targeting declarations to the user channel on macOS. - Added the ability to handle DDM assets, and unblocked more declaration types. - Added the certificates list to the host details page for Windows hosts, showing each certificate's scope (System or User). This requires osquery 5.23.1 or higher on the host. - Added a "View certificate" modal to Controls > OS settings > Certificates so admins can inspect and copy an existing certificate's details. - Surfaced hardware-bound ACME certificates on macOS host vitals by retrieving them via th _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.90.0]_ ### v4.89.2 - Date: 2026-07-24 - Version: v4.89.2 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.89.2 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.89.2 - **fixed** — Fixed a bug where a failed software install was reported as successfully installed when the install script exited with an error but a post-install script exited successfully - **fixed** — Fixed Windows Autopilot enrollments intermittently hanging on the Enrollment Status Page at Account setup - **fixed** — Fixed an issue where devices given a mandatory update during ADE enrollment might display a failure or fail to display the update - **fixed** — Fixed a bug where adding Windows software via GitOps could create a duplicate software title when a host had already reported the same program - **fixed** — Fixed a bug where Apple MDM devices re-enrolling manually with a pending SCEP renewal would not be treated as a new renewal and might skip apps, profiles, etc - **fixed** — Fixed a bug where a Fleet-maintained app install could run a stale, previously-cached version after the app was auto-updated; installs now target the version Fleet currently displays - **fixed** — Fixed a bug where pinning a Fleet-maintained app to a different version didn't update the patch policy for it ###### Bug fixes - Fixed a bug where a failed software install was reported as successfully installed when the install script exited with an error but a post-install script exited successfully. - Fixed Windows Autopilot enrollments intermittently hanging on the Enrollment Status Page at "Account setup". - Fixed an issue where devices given a mandatory update during ADE enrollment might display a failure or fail to display the update - Fixed a bug where adding Windows software via GitOps could create a duplicate software title when a host had already reported the same program. - Fixed a bug where Apple MDM devices re-enrolling manually with a pending SCEP renewal would not be treated as a new renewal and might skip apps, profiles, etc - Fixed a bug where a Fleet-maintained app install could run a stale, previously-cached version after the app was auto-updated; installs (including automatic retries) now target the version Fleet currently displays. - Fixed a bug where pinning a Fleet-maintained app to a different version didn't update the patch policy for it. ###### Upgrading ##### **Please note this upgrade has an elevated migration time for a one time table rebuild that could take up to 30m** Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 6939f39a5a3290e9254b8dd030e48ebe34eb1ca757f84c252116cece082a2bb7 fleet_v4.89.2_linux.tar.gz a60f0bdef6940a97500f589221c037400ae2827ffecadd86a6de9185a6366306 fleetctl_v4.89.2_linux_amd64.tar.gz 7753dbdca016bb68d5f2b8975902c8f1dc3677ad3aa33a8d6421bdaac6123202 fleetctl_v4.89.2_linux_amd64.zip d7e463a015beb0c22818b96284bcef017737fa3b1a2a5b983af22c37638d1e10 fleetctl_v4.89.2_linux_arm64.tar.gz 2d4e9e3099ef5d7986771c8050175d7f5110020646b41df91d13f4e62b556a77 fleetctl_v4.89.2_linux_arm64.zip 38222bb2a5cb010e3de1337e6cd500a4d8773f68da1f74696850ed4ec1b18270 fleetctl_v4.89.2_macos.tar.gz 2b458368f444f8b352a42afd3b16e37085a9bcc6262800523e0d6c0337805644 fleetctl_v4.89.2_macos.zip aa5d5083b94cc0bf166e70a01a62604f1a48554a2dfd2d88f4c7d09f0db2d904 fleetctl_v4.89.2_windows_amd64.tar.gz 89fb65ea511a49b85331ee74b1b1acc029750f85eb1972115c5fbbe23c65a775 fleetctl_v4.89.2_windows_amd64.zip a36936f41280ff13c8c2364254b57d2fb08f6888626cd01e1e700c429d55d37d fleetctl_v4.89.2_windows_arm64.tar.gz 9d5ac115c810d8a9db30254e3bfb1362e5549a21c27114217032d224c3947a73 fleetctl_v4.89.2_windows_arm64.zip ``` ### v4.89.1 - Date: 2026-07-16 - Version: v4.89.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.89.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.89.1 - **fixed** — Fixed a bug where fresh Windows 11 25H2 and other recent builds failed MDM enrollment with error 80180006 because the device's discovery RequestVersion was rejected by an exact-match allow-list by now accepting any MS-MDE2 discovery RequestVersion at or above the minimum supported version 4.0 ###### Bug fixes - Fixed a bug where fresh Windows 11 25H2 (and other recent builds) failed MDM enrollment with error 80180006 because the device's discovery `RequestVersion` (e.g. "9.0") was rejected by an exact-match allow-list. Fleet now accepts any MS-MDE2 discovery `RequestVersion` at or above the minimum supported version ("4.0"). ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 72fb53b632048d94a475082050a3fb9ee147c120b90b4bd03407668b0643eb2f fleet_v4.89.1_linux.tar.gz 5fdccf39237db3c96fa69468539e22c2cd69cfff5a4b147fdbcb5ca22ea1f2be fleetctl_v4.89.1_linux_amd64.tar.gz 7a2316437e9183cfaf1b18047df6245e8a88b338f8879fbe2ebaf06a39a00cda fleetctl_v4.89.1_linux_amd64.zip ff6e4225004fb2db43d5f1f178ea780d82db0925258015a67379d52056aed092 fleetctl_v4.89.1_linux_arm64.tar.gz 62617b3fec54ccf4d458b1f69ab0d82b91299594e802c9d27f5e3ce61789d5f2 fleetctl_v4.89.1_linux_arm64.zip a13f88800e59792af3480feb1ac0e6fe4f63775e87f237b5a47264a5e05f85e6 fleetctl_v4.89.1_macos.tar.gz faee6f1383eb9c745c8d225e2d8972b5c51c89b86db68da14e1cc84c641722ba fleetctl_v4.89.1_macos.zip e57afa95adbb86592495583fb61f6669d40629dd8ee16aebce426ab3443580c2 fleetctl_v4.89.1_windows_amd64.tar.gz 1d9a5a250d5367a8252a3eefc016c3d83edfb5a1ef795809a215f6ad84df5948 fleetctl_v4.89.1_windows_amd64.zip 39d7a5b4fe7533cb696bb6de6da42928801f96315bb98719d9225add5d650263 fleetctl_v4.89.1_windows_arm64.tar.gz df97595ce284ccb1ff86e27644ad337ed34af17b12350cefd12a0d4654ec7eb4 fleetctl_v4.89.1_windows_arm64.zip ``` ### v4.89.0 - Date: 2026-07-15 - Version: v4.89.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.89.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.89.0 - **added** — Added the ability to target a policy to hosts using a combination of include and exclude labels - **added** — Added the ability to run a policy check before installing Windows and Linux setup experience software, skipping install when the policy passes - **changed** — Changed calendar remediation events to be scheduled on the next business day after a policy failure instead of always on the next Tuesday - **changed** — Updated policy details page to show automations and labels as a single property and changed the layout of policy properties - **added** — Added automation runs table to the policy details page showing per-host automation outcomes with filtering, search, and reset policy action - **added** — Added per-host activity log entries when policy automations fail or succeed - **added** — Added POST /api/v1/fleet/policies/:policy_id/reset endpoint to reset a policy's pass/fail results - **added** — Added GET /api/v1/fleet/policies/:id/automation_activities endpoint to list automation activities for a policy - **added** — Added the ability to keep Fleet-maintained apps automatically updated to the latest version, pin them to a specific version or major version, or roll back to a previously cached version from the UI and via GitOps - **added** — Surfaced .sh script-only software packages on the macOS tab of Controls > Setup experience > Install software with selections tracked independently from the Linux tab - **added** — Added setup_experience_platform on software packages in GitOps YAML so .sh script-only installers can be selected for the macOS setup experience declaratively - **added** — Added support for pre-install query, post-install script, and uninstall script on script-only packages via the UI, REST API, and GitOps - **added** — Added an error on the Windows enrollment status page when setup experience software fails to install during automatic enrollment and cancel setup if software fails is turned off - **added** — Added Support as a new default self-service software category - **added** — Added support for $FLEET_VAR_HOST_* variables in Android configuration profiles - **added** — Added support for $FLEET_VAR_HOST_* variables in Android managed app configuration - **added** — Android certificate templates and managed app configurations are now automatically resent when IdP variable values change - **added** — Added support for defining the default fleet BYO Apple devices enroll into ##### Fleet 4.89.0 (Jul 15, 2026) ###### IT Admins - Added the ability to target a policy to hosts using a combination of "include" and "exclude" labels. - Added the ability to run a policy check before installing Windows and Linux setup experience software. When a team policy's install-software automation points at a setup experience installer, Fleet runs that policy during setup and skips the install when it passes (the software is already installed and up to date), speeding up the end user setup experience. When the policy fails, the software is installed as part of setup experience. - Changed calendar remediation events to be scheduled on the next business day (skipping weekends) after a policy failure, instead of always being scheduled on the next Tuesday. - Updated policy details page to show automations and labels as a single property. Also changed the layout of policy properties. - Added automation runs table to the policy details page, showing per-host automation outcomes with filtering, search, and a reset policy action. - Added per-host activity log entries when policy automations (webhook, tickets, Google Calendar, and Microsoft conditional access) fail or succeed. - Added `POST /api/v1/fleet/policies/:policy_id/reset` endpoint to reset a policy's pass/fail results, clearing counts and membership immediately. - Added `GET /api/v1/fleet/policies/:id/automation_activities` endpoint to list automation activities for a policy. - Added the ability to keep Fleet-maintained apps automatically updated to the latest version, pin them to a specific version or major version, or roll back to a previously cached version, from the UI and via GitOps (Fleet Premium). - Surfaced `.sh` script-only software packages on the macOS tab of Controls > Setup experience > Install software, with selections tracked independently from the Linux tab. - Added `setup_experience_platform` on software packages in GitOps YAML so `.sh` script-only installers can be selected for the macOS setup experience declaratively, matching the per-platform UI selection. The value is authoritative on every batch apply and reconciles the cross-platform selection table. - Added support for pre-install query, post-install script, and uninstall script on script-only packages (`.sh` and `.ps1`) via the UI, REST API, and GitOps. - Added an error on the Windows enrollment status page (ESP) when setup experience software fails to install during automatic enrollment (Autopilot and other OOBE flows) and "Cancel setup if software fails" is turned off. - Added "🛟 Support" as a new default self-service software category. - Added support for `$FLEET_VAR_HOST_*` variables in Android configuration profiles. - Added support for `$FLEET_VAR_HOST_*` variables in Android managed app configuration. - Android certificate templates and managed app configurations are now automatically resent when IdP variable values change. - Added support for defining the default fleet BYO Apple devices enroll into. - Added a Google Workspace integration that maps identity provider (IdP) users to hosts, populating IdP host vitals directly from your Google Workspace directory. - Added an activity feed entry when a user runs a custom Apple or Windows MDM command, visible in both the global activity feed and the host's activity feed. - Added an activity when editing the managed local account setting using the update fleet endpoint or GitOps. - Enabled tracking of mobile devices for the "hosts online" chart, and added default filtering to that chart that excludes mobile platforms. - Added tooltips on the Settings > Users and My account pages to show assigned fleets and roles when a user has multiple. ###### Security Engineers - Started collecting non-critical CVEs, filtering them out of charts by default. - Added the ability to filter vulnerable software by severity (CVSS score) and known exploit status on the Fleet Desktop **My device > Software** tab (Fleet Premium). The c _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.89.0]_ ### v4.88.1 - Date: 2026-07-10 - Version: v4.88.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.88.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.88.1 - **fixed** — Fixed an issue where a configuration profile could be enqueued multiple times for a single host - **fixed** — Fixed recovery lock password being enforced on personally-owned (BYOD) macOS hosts, which would always fail because personal enrollments have device lock rights stripped, and these hosts are now skipped - **fixed** — Fixed a bug where a user's BYOD selection was not persisted through IdP authentication - **fixed** — Fixed a bug where installing App Store (VPP) or in-house apps on an iOS/iPadOS host enrolled with the manual (profile-driven) BYOD enrollment profile failed while trying to look up a VPP user, so these device-channel hosts now install apps to the device like company-owned manual enrollment ###### Bug fixes - Fixed an issue where a configuration profile could be enqueued multiple times for a single host. - Fixed recovery lock password being enforced on personally-owned (BYOD) macOS hosts, where it would always fail because personal enrollments have device lock rights stripped. These hosts are now skipped. - Fixed a bug where a user's BYOD selection was not persisted through IdP authentication - Fixed a bug where installing App Store (VPP) or in-house apps on an iOS/iPadOS host enrolled with the manual (profile-driven) BYOD enrollment profile failed while trying to look up a VPP user. These device-channel hosts now install apps to the device, the same as company-owned manual enrollment; user-scoped licensing is reserved for Account-Driven User Enrollment. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 1adc9236a16edfdbaa321b3abcbea8fd93354bf348aa1984f1dbf41929f837be fleet_v4.88.1_linux.tar.gz c0e6db9c7559487036572a292c8a4acb586fa041524d4e59d76730b4932a7375 fleetctl_v4.88.1_linux_amd64.tar.gz 3396a776f736513f511c7e8486838c0a4d6548d42329b66967d5abe33d8d1616 fleetctl_v4.88.1_linux_amd64.zip 6587d56fa84b8b93a25bc26551c86170de61a3ff00f7ad2745b841522fb9cff9 fleetctl_v4.88.1_linux_arm64.tar.gz b79a62d090d562fd223b6674a9393f7276b5735fbae38ea5438927ba7a21554e fleetctl_v4.88.1_linux_arm64.zip c308cce437f2cca7b24e27aa3501f8da5b072192f31ab68bd763dd33de7facad fleetctl_v4.88.1_macos.tar.gz 18256e18353febc7205cdaf5512ea820af282c0993ab8908704ee7a958814887 fleetctl_v4.88.1_macos.zip b6028f87ca1c9f0302f0c8fa496de8f36afb06aab5838131befede5b20d95e93 fleetctl_v4.88.1_windows_amd64.tar.gz 6d67da0f5a97310abfd5772876d6baabe110bc8219e49e08cbea674f8086e60c fleetctl_v4.88.1_windows_amd64.zip ff8334a6c8527a7d9ae069492aecf67403197ef4761e99c5526038adf39cc202 fleetctl_v4.88.1_windows_arm64.tar.gz 04db52fdd300cc55ffa94e84163551c0d8777414652ae995ab56fed778d1d873 fleetctl_v4.88.1_windows_arm64.zip ``` ### v4.88.0 - Date: 2026-07-02 - Version: v4.88.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.88.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.88.0 - **added** — Support for personal (BYOD) Apple MDM enrollment with per-host enrollment permission tracking to prevent remote wiping or locking of personal devices - **changed** — Preserve enrollment permissions across SCEP/ACME certificate renewal - **fixed** — Fixed an issue where fleetd could intermittently fail to install during Windows MDM enrollment, which could cause the Windows Autopilot Enrollment Status Page to hang ###### Bug fixes - Added support for personal (BYOD) Apple MDM enrollment, tracking per-host enrollment permissions so that personal devices cannot be remotely wiped or locked, and preserving those permissions across SCEP/ACME certificate renewal. - Fixed an issue where fleetd could intermittently fail to install during Windows MDM enrollment, which could cause the Windows Autopilot Enrollment Status Page to hang. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 85280edd8db7ad2212ba5456997cfacdfeeabaf5b6124732f6fb95df45324163 fleet_v4.88.0_linux.tar.gz 847f9bfee46cd8a2f637975efbb4e8b5b2a5ed290af3759361721a4623338631 fleetctl_v4.88.0_linux_amd64.tar.gz 8698436ad196fb0542705d9a1872f7f45a3804e40d87d5e66d889e5def928d73 fleetctl_v4.88.0_linux_amd64.zip 80d52c9b38960a6ddbaf9e6b1545f2aba24210e5c9274efe716eaf7ec33183a5 fleetctl_v4.88.0_linux_arm64.tar.gz e2be3aa46de32dbde7e998ebf4ccf807021dec2468242f22f1efdd77e1f2014a fleetctl_v4.88.0_linux_arm64.zip e6cd3e2e28c955a9f64c8f12c50e1e78935b7a30dac0f9253726725633f19b5d fleetctl_v4.88.0_macos.tar.gz f192245fde09f6f9a2a14c34d443114104f55ec93841ec330d6149845b9a8794 fleetctl_v4.88.0_macos.zip 3a113fdf800011ce006a1c68c00f039eaab5d3546c64d21b4bb02209391f55ff fleetctl_v4.88.0_windows_amd64.tar.gz 109eda99ba889f9aa2d3e676748158cdacfa759125f8484817035beeae42a950 fleetctl_v4.88.0_windows_amd64.zip 5b370cc2d208ce752b073fc11e24f77ad02294881b8ad01fc7ac6f4bc9518860 fleetctl_v4.88.0_windows_arm64.tar.gz 4d029140b782793f5051068129410decfb19d819fb41f83880dccc2ee8304596 fleetctl_v4.88.0_windows_arm64.zip ``` ### v4.87.1 - Date: 2026-06-27 - Version: v4.87.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.87.1 - **fixed** — Fixed a bug where an Apple SCEP certificate profile backed by NDES could be marked "failed" and consume one of the host's limited profile retry attempts when its challenge password expired, instead of being automatically resent with a fresh challenge - **fixed** — Fixed GitOps runs failing with a software_categories duplicate-entry error when a software category's name differed only by characters MySQL's collation treats as equal - **fixed** — Fixed the My device > Software tab appending a macos_applications query parameter to the URL when paginating ###### Bug fixes - Fixed a bug where an Apple SCEP certificate profile backed by NDES could be marked "failed" and consume one of the host's limited profile retry attempts when its challenge password expired, instead of being automatically resent with a fresh challenge. - Fixed GitOps runs failing with a `software_categories` duplicate-entry error when a software category's name differed only by characters MySQL's collation treats as equal (such as the Unicode variation selector in default categories like "🖥️ Productivity"). - Fixed the **My device > Software** tab appending a `macos_applications` query parameter to the URL when paginating, even though that page has no /Applications filter. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` f2d4e41a21bb117adf090a5803866214ce976880fab0343252b8396d722c8447 fleet_v4.87.1_linux.tar.gz 36adc7723f4b03eea01b287f1235010d036d7aa724dc6b1549150c43ce53c04d fleetctl_v4.87.1_linux_amd64.tar.gz c16fc64a4d82176d1f81eb3031024669a2c94f12a49eb2de081b9ca79986e399 fleetctl_v4.87.1_linux_amd64.zip 634d314705e9f081a4a35c2eed0b689234b5883a18c88f2ca6129a251e685d43 fleetctl_v4.87.1_linux_arm64.tar.gz 14bdf0e98f40e2620055cbf35dc7d2d2e51335a215a56290b74d1f4a5f162e25 fleetctl_v4.87.1_linux_arm64.zip a050f589a44152138527e42d0f2727f2f193eff3c9888f21805e6591b66ba14c fleetctl_v4.87.1_macos.tar.gz 1901517bb3b62293c1666289795bd04438d43d0817a770a8e2655714c1300dc1 fleetctl_v4.87.1_macos.zip f1b86d55d567e56168b5760231aec16d1a7f3b6481bd077bdf96044e286958f5 fleetctl_v4.87.1_windows_amd64.tar.gz 8bd5baa2ef829926b6539e935bdd34562018c640a28e53bdb14fcbf591b11db5 fleetctl_v4.87.1_windows_amd64.zip 3fdccd663a6facd8b6dcd79d43c576b108090e7dcab9d00b8b3ffcd465781384 fleetctl_v4.87.1_windows_arm64.tar.gz 08df1022f8fbd6b58995729697c6d520d7bda89253898f28ce405fcf169b4994 fleetctl_v4.87.1_windows_arm64.zip ``` ### v4.87.0 - Date: 2026-06-20 - Version: v4.87.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.87.0 - **added** — Added 236 new Fleet-maintained apps for Windows including Microsoft Office, PowerShell, PowerToys, Power BI, Power Automate, SQL Server Management Studio, Microsoft .NET Runtime 8 and 10, Git, Node.js, Python 3.13 and 3.14, PostgreSQL 15–18, and other tools - **added** — Added 727 new Fleet-maintained apps for macOS including Kiro, Codex, OpenCode, Claude DevTools, Granola, Logitune, and hundreds more tools across development, security, productivity, and design - **added** — Added the ability to deploy custom OS update configuration profiles for Apple and Windows - **added** — Added support for issuing Lock, Wipe, and Clear passcode commands to Android hosts - **added** — Made the Wipe command available to Fleet Free users for Android company-owned hosts in both the UI and the API - **changed** — Android host display name now uses "{IdP first name}'s {hardware model}" when an IdP account is associated - **changed** — Reduced Windows MDM server and database load by relaxing the device management poll schedule from 1 minute to 8 hours for hosts running fleetd 1.57.0 and later with on-demand Windows MDM sync support - **changed** — Renamed Apple Business Manager (ABM) terminology to Apple Business (AB) in the API, GitOps YAML, and fleetctl CLI - **deprecated** — Deprecated /abm_tokens, /mdm/apple/abm_public_key, apple_business_manager, and mdm-apple-bm endpoints and commands in favor of /api/v1/fleet/ab_tokens, /api/v1/fleet/mdm/apple/ab_public_key, mdm.apple_business, and fleetctl get mdm-ab/fleetctl generate mdm-ab - **added** — Added support for combining labels_exclude_any with labels_include_all or labels_include_any when uploading MDM configuration profiles - **added** — Added support for setting the end user account type to standard for non-admin users or none to skip end-user account creation - **added** — Added a Continuous option to policy automations that re-runs script and software automations on every subsequent policy failure - **added** — Made editable automations available directly on the policy create, edit, and details pages - **added** — Added the ability for users with the Technician role to transfer hosts between fleets via the Fleet UI and REST API - **added** — Added Self-service categories page under Software > Library for managing custom categories per fleet - **added** — Added macos_applications filter for host software list - **added** — Added Fleet Spotlight command palette that opens when pressing Command + K or Control + K - **added** — Added support for validating Microsoft Entra v2 access tokens during Windows MDM enrollment - **added** — Hardened in-house iOS app distribution by requiring a per-install token in the manifest and package download URLs bound to the target host with 6-hour expiration ##### Fleet 4.87.0 (Jun 19, 2026) ###### IT Admins - Added 236 new Fleet-maintained apps for Windows, including Microsoft Office, PowerShell, PowerToys, Power BI, Power Automate, SQL Server Management Studio, Microsoft .NET Runtime 8 and 10, Git, Node.js, Python 3.13 and 3.14, PostgreSQL 15–18, Windsurf, Kiro, Dell Command Update, Lenovo Dock Manager, Nessus Agent, Bitwarden, Canva, Miro, Snagit, Tableau Desktop, VirtualBox, TortoiseGit, GitHub Desktop, and more. - Added 727 new Fleet-maintained apps for macOS, including Kiro, Codex, OpenCode, Claude DevTools, Granola, Logitune, and hundreds more tools across development, security, productivity, and design. - Added the ability to deploy custom OS update configuration profiles for Apple and Windows. - Added support for issuing Lock, Wipe, and Clear passcode commands to Android hosts. Lock and Clear passcode work for both BYO (personal) and COBO (company-owned) Android hosts; Wipe is COBO-only. For BYO hosts, Unenroll now issues an AMAPI WIPE under the hood, which removes only the work profile and leaves personal data intact. All Android commands are issued with `duration=315360000s` (10 years), matching the pending-forever queue semantics Fleet uses for Apple and Windows MDM. - Made the Wipe command available to Fleet Free users for Android (company-owned) hosts, in both the UI and the API. Wipe for macOS, iOS, iPadOS, Linux, and Windows hosts remains a Fleet Premium feature. - Android host display name now uses "{IdP first name}'s {hardware model}" when an IdP account is associated. - Reduced Windows MDM server and database load by relaxing the device management poll schedule from 1 minute to 8 hours for hosts running a version of fleetd that supports on-demand Windows MDM sync (1.57.0 and later). When commands are queued, the server wakes these devices through fleetd to start a management session, so command delivery stays near real-time. Hosts on older fleetd versions keep the previous poll behavior. - Renamed Apple Business Manager (ABM) terminology to Apple Business (AB) in the API, GitOps YAML, and `fleetctl` CLI. The new `/api/v1/fleet/ab_tokens` and `/api/v1/fleet/mdm/apple/ab_public_key` endpoints, `mdm.apple_business` YAML key, and `fleetctl get mdm-ab`/`fleetctl generate mdm-ab` commands are canonical. The now-deprecated `/abm_tokens`, `/mdm/apple/abm_public_key`, `apple_business_manager`, `mdm-apple-bm` aliases continue to work for backwards compatibility and log a deprecation warning when used. - `labels_exclude_any` can now be combined with `labels_include_all` or `labels_include_any` when uploading MDM configuration profiles, allowing hosts to be included by label membership and excluded by another set of labels simultaneously. - Added support for setting the end user account type to `standard` for a standard (non-admin) user or `none` to skip end-user account creation, both requiring a local admin account. - Added a "Continuous" option to policy automations that re-runs script and software automations on every subsequent policy failure, with editable automations now available directly on the policy create, edit, and details pages. - Added the ability for users with the Technician role to transfer hosts between fleets (Fleet Premium only). Global technicians can transfer hosts via the Fleet UI (manage hosts and host details pages) and the REST API. Fleet-scoped technicians can transfer hosts between fleets they manage via the REST API. - Added Self-service categories page (Premium) under Software > Library for managing custom categories per fleet, including add, edit, and delete flows. - Added Categories button to the Software > Library page that navigates to the new categories page. - Replaced the static category sidebar on the My device > Self-service page with a custom-category dropdown driven by the org's self-service categories, and added an "Install all (n)" button per category (with a confirmation modal) that posts to `/device/{token}/sof _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.87.0]_ ### v4.86.2 - Date: 2026-06-12 - Version: v4.86.2 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.2 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.86.2 - **fixed** — Fixed Fleet failing to start on a read-only root filesystem by storing custom org logos in the database when no S3 software installers bucket is configured, instead of writing to local disk - **fixed** — Fixed a bug where host vitals labels scoped to a fleet/team never got any hosts due to the membership cron only looking at global labels and team-scoped IdP labels failing to populate due to an incorrect SQL join - **fixed** — Fixed a server out-of-memory crash that could occur when Apple's VPP API repeatedly returned transient errors during VPP API operations ###### Bug fixes - Fixed Fleet failing to start on a read-only root filesystem by storing custom org logos in the database when no S3 software installers bucket is configured, instead of writing to local disk. - Fixed a bug where host vitals labels (e.g. IdP group/department labels) scoped to a fleet/team never got any hosts. The membership cron only looked at global labels, and team-scoped IdP labels also failed to populate due to an incorrect SQL join. - Fixed a server out-of-memory crash that could occur when Apple's VPP (App and Book Management) API repeatedly returned transient errors (HTTP 500 with Retry-After, or error 9646) during VPP API operations (e.g., app installs, user registration, license seat releases). ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 85d05a46359c6cedfc876ea6646e86c46530a5e0253a4144310dc2f8f9b64055 fleet_v4.86.2_linux.tar.gz f523b48ac462afbefec073a1f04f622bbc0b2b6263377be85d64b8feb5cc219b fleetctl_v4.86.2_linux_amd64.tar.gz e55e5d95c8c20b9be7e1b3d30bea077a37b1530440309ff068e9a13812d6e6be fleetctl_v4.86.2_linux_amd64.zip 0c921a88d30de3679e903cacd8256d1905f0013438827f7569e7bf8cb301284b fleetctl_v4.86.2_linux_arm64.tar.gz 406910bcc05ec7b6e4629717d5c990295388677ba2b432cb1d05d8cdd591d7ba fleetctl_v4.86.2_linux_arm64.zip d8ccd61b5765c8b4052c09c2b5ac832479bf296f77e8f2789cd6397c21d4375d fleetctl_v4.86.2_macos.tar.gz c97d41a5defcdebbc049fae4ddfa1b4167e6f39eb5eb5a45c29d39517c9c1187 fleetctl_v4.86.2_macos.zip 978ce2ef670afe9ed539426eb635331ca358f83ebebd3823225c530704b9302b fleetctl_v4.86.2_windows_amd64.tar.gz 8c310d15fdc7264804b6d22a013fbe0bb09804799234668490840b00258f1004 fleetctl_v4.86.2_windows_amd64.zip be8bab06e4ff592d7cd3a177ec2cb3487b4f0bf1da1d0afd4f49d7a9299b163e fleetctl_v4.86.2_windows_arm64.tar.gz b72948b6f18cf5a01ab5d95702b1d501350a60f9f8fe841a5b07cf9233dea278 fleetctl_v4.86.2_windows_arm64.zip ``` ### v4.86.1 - Date: 2026-06-03 - Version: v4.86.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.86.1 - **fixed** — Updated conditional access policy query to use parameter binding for platform filter ###### Bug fixes * Updated conditional access policy query to use parameter binding for platform filter. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 995b74191f79783defd244c5538f93b9ae0da7a2bf99f7668775088cd8f7a735 fleet_v4.86.1_linux.tar.gz 0c5b031e5e973e3f8f96307cfdaa55a33a0ab4e7859eee52150bda51572c7349 fleetctl_v4.86.1_linux_amd64.tar.gz 2883b8166c8b09a584de75708558c926b74df4eab48229972b098d40570952d0 fleetctl_v4.86.1_linux_amd64.zip eab4e7814d6bd76ec07b662833a0289ecade4b9226efb24b8727459bfc3f3fcc fleetctl_v4.86.1_linux_arm64.tar.gz 92ceee1089c4be0d74afc5289f6e3faa165efb38d4a1a9059fe06c13794cfbbd fleetctl_v4.86.1_linux_arm64.zip d4f7db86dcb60dc241177505819c20619401dbbbd6003c0091a2888e1d921d36 fleetctl_v4.86.1_macos.tar.gz ab6510afc7686f5416596da16476b5a996dfa86d5b7dded6d77f85ff228f96a0 fleetctl_v4.86.1_macos.zip faaa144f2c26ca72cefc398fe126ab04808bee859860f0ad913c6571e6594036 fleetctl_v4.86.1_windows_amd64.tar.gz de073acde2f4ced32dff7a20250058085134d0a220714208aee51ecde345b665 fleetctl_v4.86.1_windows_amd64.zip d2b2473f6d6e11c6dfb511b6f44d22c2d4f69b4d8c4065129e334d13734ec6a7 fleetctl_v4.86.1_windows_arm64.tar.gz 70ddf117dbd1b86a6eeb2a2cec97fe89611e621040c4e33092c1ce1d247c7d3e fleetctl_v4.86.1_windows_arm64.zip ``` ### v4.85.2 - Date: 2026-06-03 - Version: v4.85.2 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.85.2 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.85.2 - **fixed** — Fixed a server out-of-memory crash that could occur when Apple's VPP API repeatedly returned transient errors during VPP API operations ###### Bug fixes * Fixed a server out-of-memory crash that could occur when Apple's VPP (App and Book Management) API repeatedly returned transient errors (HTTP 500 with Retry-After, or error 9646) during VPP API operations (e.g., app installs, user registration, license seat releases). ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 78ebca78943efcd4e86a0096ab60520014261e2081446e9ef6452c50430d4eea fleet_v4.85.2_linux.tar.gz d86d60c67b45fa02de9408a5a8d8ed9770c95ceeb9e0709be17aa65ce9d06b0d fleetctl_v4.85.2_linux_amd64.tar.gz ba300343e351f9fe514b46147115836ecb61eaf479ef28e2918eb5d55dec8641 fleetctl_v4.85.2_linux_amd64.zip 8611adc78afb8556b14e745616355a870e85ea6d32e9d11e2e0ae9724841c689 fleetctl_v4.85.2_linux_arm64.tar.gz 642cd1a47ed8e13214785d0fc0c8892d8690adbca062ea3a7bab715983e7a20d fleetctl_v4.85.2_linux_arm64.zip 2f84e5fe342117b7f1eb4a4349eeaf8a1b6ceaf7b5454230a9cc751c9c1c95bb fleetctl_v4.85.2_macos.tar.gz 26b95926eb50904b5302f83c0a47760f486c08b1e8c9fb3703ba9a331fe9cd70 fleetctl_v4.85.2_macos.zip a85f85b022c850a70372e7c1707f76c8f87f187758c5289ed570e26065c430b8 fleetctl_v4.85.2_windows_amd64.tar.gz 8473a426386690468bf4a689027eab588fdaeb73cb4b701fd4e5eb50a5e44a2e fleetctl_v4.85.2_windows_amd64.zip c155bb3393354c33da9c8b67ff5974fff690a11af1857d3d5e44008fd47df148 fleetctl_v4.85.2_windows_arm64.tar.gz 4b38085f4df9574f27a1a36f73a2d192f3faeee973face0c357c4b4dc94b7b2d fleetctl_v4.85.2_windows_arm64.zip ``` ### v4.86.0 - Date: 2026-05-29 - Version: v4.86.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.86.0 - **added** — Add automatic rotation of managed local admin account passwords after they have been viewed - **added** — Add `require_all_software_windows` setting to cancel the Windows setup experience if any software install fails during Autopilot enrollment - **added** — Add GitOps support for uploading custom org logos with `org_logo_path_dark_mode` and `org_logo_path_light_mode` keys - **added** — Add support for installing VPP and in-house apps on iOS and iPadOS hosts enrolled via Account-Driven User Enrollment - **added** — Enable self-service software installs from the My device page for user-enrolled iOS and iPadOS hosts - **added** — Enable setup experience software to install automatically on user-enrolled iOS and iPadOS hosts at enrollment - **added** — Add managed app configuration for iOS and iPadOS apps with `$FLEET_VAR_*` substitution - **added** — Add support for VPP apps purchased from non-US-based Apple Business accounts - **added** — Add ability to upload custom organization logos for light and dark modes hosted by Fleet - **added** — Add `include_all` label scope to policies and `include_all` and `include_any` label scopes to reports - **added** — Add 'Custom' target dropdown when creating or updating reports under the premium tier - **added** — Add 'Include all' option to the 'Custom' target dropdown on Policies for premium users - **added** — Add permissions for the GitOps user to list software titles - **added** — Add support for setting `gitops_mode_enabled` and `repository_url` via GitOps - **added** — Add output to GitOps for scripts indicating how many scripts would be applied or were applied - **added** — Add activity entries for retried software installs and script runs from policy automations - **added** — Add activity when hosts fail enrollment profile renewal - **added** — Add activity entries when users create, edit, or delete labels - **added** — Add 'Hosts online', 'Hosts enrolled', and 'Vulnerability exposure' charts to the dashboard - **added** — Add option to convert and return a PEM-encoded X.509 certificate instead of a PEM-encoded PKCS7 envelope from the Request a Certificate endpoint - **added** — Add macOS 26 CIS Benchmark v1.0.0 - **added** — Add SVG support for custom organization logos with strict server-side sanitization - **added** — Add support for the `subject_alternative_name` field on Android certificate templates - **added** — Release `fleetctl` as a `pkg` for macOS - **added** — Release `fleetctl` as an `msi` for Windows - **changed** — Update CIS Windows 11 Enterprise benchmark policies from v4.0.0 to v5.0.1, adding 17 new L1 policies and updating 42 existing policy titles - **changed** — Update OS version reporting for iOS and iPadOS to include the Rapid Security Response suffix - **changed** — Update fleetd and MDM enroll activities to display the serial number and preserve the osquery-provided display name - **changed** — Update the default automatic enrollment profile and add ability to download and view the applied default profile - **changed** — Update Go to 1.26.3 - **changed** — Improve Windows MDM performance when transferring large numbers of hosts between teams or applying bulk profile changes - **changed** — Add Redis-backed cache for host lookups on the osquery and orbit authentication paths - **deprecated** — Deprecate `setup_experience.software` or `macos_setup.software` keys in config - **deprecated** — Deprecate `GET /api/v1/fleet/commands` without a `host_identifier` - **fixed** — Surface hardware-bound ACME certificates on macOS host vitals by retrieving them via the MDM `CertificateList` command - **fixed** — Optimize OSV vulnerability scanning to query distinct software per OS version rather than per host - **fixed** — Improve vulnerability scanning performance by using a per-vendor product cache during CVE matching - **fixed** — Reduce database load from `GET /api/latest/fleet/device/{token}/desktop` and other Fleet Desktop endpoints when invalid or expired device auth tokens are presented - **fixed** — Remove debug symbols from fleet and fleetctl executables to reduce binary size - **fixed** — Add missing uninstall option on the host software library when an installer has no matching software in the host's inventory - **removed** — Remove `GET /api/v1/fleet/commands` endpoint when called without a `host_identifier` ##### Fleet 4.86.0 (May 29, 2026) ###### IT Admins - Added automatic rotation of managed local admin account passwords after they have been viewed. - Added a `require_all_software_windows` setting to cancel the Windows setup experience if any software install fails during Autopilot enrollment, matching the existing macOS behavior. - Added GitOps support for uploading custom org logos. `fleetctl gitops` accepts `org_logo_path_dark_mode` and `org_logo_path_light_mode` keys to upload local files, and `fleetctl generate-gitops` exports Fleet-hosted logos as local files alongside path keys while keeping external URLs as `org_logo_url_*_mode` keys. - Added support for installing VPP and in-house (`.ipa`) apps on iOS and iPadOS hosts enrolled via Account-Driven User Enrollment with a Managed Apple Account. - Enabled self-service software installs from the My device page for user-enrolled iOS and iPadOS hosts. - Enabled setup experience software in Controls > Setup experience to install automatically on user-enrolled iOS and iPadOS hosts at enrollment. - Provisioned a VPP client user per Managed Apple Account on first install, and associated VPP licenses to the user rather than the device, supporting Apple's up-to-5-devices-per-user licensing semantics. - Added managed app configuration for iOS and iPadOS apps (VPP and in-house), configurable via UI, REST API, and GitOps, with `$FLEET_VAR_*` substitution. - Added support for VPP apps purchased from non-US-based Apple Business accounts. - Added the ability to upload a custom organization logo for light and dark modes, hosted by Fleet, replacing the previous URL-only flow on the setup screen and organization settings page. - Added `include_all` label scope to policies, and `include_all` and `include_any` label scopes to reports, including support via GitOps and `fleetctl`. - Added a "Custom" target dropdown when creating or updating reports under the premium tier. - Added an "Include all" option to the "Custom" target dropdown on Policies for premium users only. - Added permissions for the GitOps user to list software titles. - Added support for setting `gitops_mode_enabled` and `repository_url` via GitOps. - Added output to GitOps for scripts, indicating how many scripts would be applied (dry run) or were applied. - Added activity entries for retried software installs and script runs from policy automations. - Added an activity when hosts fail enrollment profile renewal. - Added activities when users create, edit, or delete labels (`created_label`, `edited_label`, and `deleted_label`). - Added "Hosts online", "Hosts enrolled", and "Vulnerability exposure" charts to the dashboard. - Added an option to convert and return a PEM-encoded X.509 certificate instead of a PEM-encoded PKCS7 envelope from the Request a Certificate endpoint. - Added a deprecation warning when using `setup_experience.software` or `macos_setup.software` keys in config. - Released `fleetctl` as a `pkg` for macOS. - Released `fleetctl` as an `msi` for Windows. - Enabled wiping a host to cancel all of its upcoming activities. - Updated the default automatic enrollment profile, and added the ability to download and view the applied default profile. - Updated OS version reporting for iOS and iPadOS to include the Rapid Security Response suffix (e.g. `(a)`) when the device reports a `SupplementalOSVersionExtra` field via MDM. - Updated fleetd and MDM enroll activities to display the serial number and preserve the osquery-provided display name. - Required the `--host` flag for `fleetctl get mdm-commands`, and deprecated `GET /api/v1/fleet/commands` without a `host_identifier`. - Cleared host vitals on ABM host re-enrollment, with a config option to preserve past host activities. ###### Security Engineers - Added macOS 26 CIS Benchmark v1.0.0. - Updated CIS Windows 11 Enterprise benchmark policies from v4.0.0 to v5.0.1, adding 17 new L1 policies and updating 42 existing policy tit _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.86.0]_ ### v4.85.1 - Date: 2026-05-22 - Version: v4.85.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.85.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.85.1 - **fixed** — Fixed fleetctl gitops rejecting Android or Windows configuration profiles when editing an existing team, even when the corresponding MDM platform was configured - **changed** — Implement roaring bitmaps in historical data collection for improved performance - **fixed** — Fixed dynamic SCEP certificate issuance failing with an Invalid NDES admin credentials error when the NDES Admin URL is fronted by Okta or another gateway that uses HTTP Basic auth instead of NTLM - **fixed** — Remove unneeded call to get tracked CVEs when reading CVE chart data ###### Bug fixes - Fixed `fleetctl gitops` rejecting Android or Windows configuration profiles when editing an existing team, even when the corresponding MDM platform was configured. - Implement roaring bitmaps in historical data collection for improved performance. - Fixed dynamic SCEP certificate issuance failing with an "Invalid NDES admin credentials" error when the NDES Admin URL is fronted by Okta or another gateway that uses HTTP Basic auth instead of NTLM. - Remove unneeded call to get tracked CVEs when reading CVE chart data ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 1aa5bbaf65833a60040fe28aa1d8b88535a025947185842c6dc6d128052f6132 fleet_v4.85.1_linux.tar.gz 1ca2b8543d5e2cb738536db75f92192c63b8bd650022b0f9ffe5b01fff3c791d fleetctl_v4.85.1_linux_amd64.tar.gz 04d9f24669ceabad7467c40c2ca631e076a700def73291dd621c22a2dd1dad26 fleetctl_v4.85.1_linux_amd64.zip 5bd235b4840ab2fde87456267843c2ff4f29cae3fb4d431e1d0b87287d15b568 fleetctl_v4.85.1_linux_arm64.tar.gz 118dcc5a485bf1bb337496ab5bb75c6b437b8ecb9858b5ff29d405172a5cc8bd fleetctl_v4.85.1_linux_arm64.zip 43667769f2d59e45c78d7558e05cd9350f4606681642e8238eaeea6247b7c337 fleetctl_v4.85.1_macos.tar.gz def4fa7b8d40d6525822ef2a4e810ba8fd9b1525f6ffafa384110f4547df3fc9 fleetctl_v4.85.1_macos.zip e7567a7e1d61cbe1a6dadc19d0c7ba6e4801dc51b9c91e58f4d303a4fe86cfdb fleetctl_v4.85.1_windows_amd64.tar.gz 18d8861a7a0242fe2eb032b4d262c4a02411609463f0314adb7e915ccf437e03 fleetctl_v4.85.1_windows_amd64.zip 7e0ae875f2e0a86fb8cd5b746b885f10b1f6c176b404776be79a1480b21a510f fleetctl_v4.85.1_windows_arm64.tar.gz 7c5604be0976801b00bb6bdb7199a02e10bf88bfcf3feab58011a891caf4d382 fleetctl_v4.85.1_windows_arm64.zip ``` ### v4.85.0 - Date: 2026-05-14 - Version: v4.85.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.85.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.85.0 - **added** — Added a dark theme to the Fleet UI, selectable in account settings with light, dark, and system options - **added** — Implemented Clear Passcode feature for iOS and iPadOS - **added** — Added support for Fleet variables in Apple's declaration profiles (DDM) - **added** — Added support for passing end-user authentication context to the Fleet MSI installer during Windows MDM enrollment to prevent duplicate authentication prompts when EUA is enabled - **changed** — Switched to Docker as the default WiX runtime on macOS (including Apple Silicon) when generating .msi packages via fleetctl package, making Wine no longer required on macOS for the default path - **changed** — Updated macOS 15 CIS benchmark to include v2.0.0 changes - **changed** — Updated the macOS 14 (Sonoma) CIS policy set to benchmark v3.0.0 - **changed** — Switched Fleet-maintained apps serving location from GitHub to https://maintained-apps.fleetdm.com/manifests with fallback to previous GitHub-hosted copies if inaccessible - **added** — Added conditional HTTP downloads using ETag headers for software in GitOps, skipping re-download when content hasn't changed - **added** — Added always_download option for software in GitOps to bypass the new conditional download feature - **added** — Added automatic escaping of JSON special characters in GitOps variables used in .json configuration profiles (Apple DDM declarations and Android profiles) - **changed** — Updated fleetctl gitops to process Android certificates before Android profiles - **changed** — Made fleet name uniqueness rules consistent across the UI, API, and GitOps paths, requiring fleet names to differ by more than letter case and returning a 409 error on all code paths for conflicts - **added** — Enabled renewing and deleting AB tokens in the UI in GitOps mode - **changed** — Changed the team's script_execution_timeout in agent options to default to the global agent options value when unset - **added** — Added ability to save policies whose SQL is flagged as a syntax error - **changed** — Withheld Android Wi-Fi configuration profiles (openNetworkConfiguration with ClientCertKeyPairAlias) until the referenced certificate is installed or terminally failed on the device - **changed** — Updated the host OS settings detail column to show the reason when an Android profile is pending due to a certificate dependency - **added** — Added Hosts online, Vulnerability exposure, and Hosts enrolled charts to the dashboard - **added** — Added an admin setting to control retention of vulnerability-exposure data used by the dashboard chart ##### Fleet 4.85.0 (May 14, 2026) ###### IT Admins - Added a dark theme to the Fleet UI, selectable in account settings with light, dark, and system options. - Implemented Clear Passcode feature for iOS and iPadOS. - Added support for Fleet variables in Apple's declaration profiles (DDM). - Added support for passing end-user authentication context to the Fleet MSI installer during Windows MDM enrollment, so end users are not prompted to authenticate twice when EUA is enabled. - Switched to Docker as the default WiX runtime on macOS (including Apple Silicon) when generating `.msi` packages via `fleetctl package`. Wine is no longer required on macOS for the default path. - Updated macOS 15 CIS benchmark to include v2.0.0 changes. - Updated the macOS 14 (Sonoma) CIS policy set to benchmark v3.0.0. - Switched Fleet-maintained apps serving location from GitHub to https://maintained-apps.fleetdm.com/manifests. If this site is inaccessible, Fleet will fall back to the previous GitHub-hosted copies of manifest files. - Added conditional HTTP downloads using ETag headers for software in GitOps, skipping re-download when content hasn't changed. - Added `always_download` option for software in GitOps to bypass the new conditional download feature. - Added automatic escaping of JSON special characters in GitOps variables used in `.json` configuration profiles (Apple DDM declarations and Android profiles). - Updated `fleetctl gitops` to process Android certificates before Android profiles. - Made fleet name uniqueness rules consistent across the UI, API, and GitOps paths. Fleet names must now differ by more than letter case, and conflicts return a 409 error on all code paths. - Enabled renewing and deleting AB tokens in the UI in GitOps mode. - Changed the team's `script_execution_timeout` in agent options to default to the global agent options value when unset. - Added ability to save policies whose SQL is flagged as a syntax error. - Withheld Android Wi-Fi configuration profiles (`openNetworkConfiguration` with `ClientCertKeyPairAlias`) until the referenced certificate is installed or terminally failed on the device. - Updated the host OS settings detail column to show the reason when an Android profile is pending due to a certificate dependency. - Added "Hosts online", "Vulnerability exposure", and "Hosts enrolled" charts to the dashboard. - Added an admin setting to control retention of vulnerability-exposure data used by the dashboard chart. - Added new policy details page with a read-only view of policy information. - Updated edit policy page to redirect users with read-only access to the policy details page. - Added dedicated `/policies/:id/live` route for running policies. ###### Security Engineers - Added UI pages for creating and editing API-only users with support for fleet assignment, role selection, and API endpoint access control. - Added new middleware (`APIOnlyEndpointCheck`) that enforces a 403 response for API-only users whose request either isn't in the API endpoint catalog or falls outside their configured per-user endpoint restrictions. - Added `POST /users/api_only` endpoint for creating API-only users. - Added `PATCH /users/api_only/{id}` endpoint for updating existing API-only users. - Updated `fleetctl user create --api-only` to remove email and password field requirements. - Added a new premium `GET /api/_version_/fleet/rest_api` endpoint that returns the contents of the embedded `api_endpoints.yml` artifact. - Updated `GET /users/{id}` response to include the new `api_endpoints` field for API-only users. - Added `user_api_endpoints` table to track per-user API endpoint permissions. ###### Bug fixes and improvements - Updated Go to 1.26.3. - Improved MySQL writer performance by skipping no-op `UPDATE host_orbit_info` and `UPDATE host_disks` writes when the stored values already match the incoming ingest values from osquery, cutting these writes to near zero at steady _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.85.0]_ ### v4.84.3 - Date: 2026-05-07 - Version: v4.84.3 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.84.3 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.84.3 - **fixed** — Reduced database load from GET /api/latest/fleet/device/{token}/desktop and other Fleet Desktop endpoints when invalid or expired device auth tokens are presented by resolving the token to a host id with a single-table indexed lookup before running the multi-join host-details query ###### Bug fixes - Reduced database load from `GET /api/latest/fleet/device/{token}/desktop` and other Fleet Desktop endpoints when invalid or expired device auth tokens are presented, by resolving the token to a host id with a single-table indexed lookup before running the multi-join host-details query. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 8323559b7c4a586beb31997c585f4000305a754d90902b42796ca84929e8c442 fleet_v4.84.3_linux.tar.gz deaa661f852646cdbffd50d48278635717661b294c3d02279d112a787e228c1e fleetctl_v4.84.3_linux_amd64.tar.gz c6fb3708ea246ee05b756c242cb6f8978bd124d216b3621c2d7fb6637494afb8 fleetctl_v4.84.3_linux_amd64.zip bce3986624a1d33badb31df1b533feafae877206ac81d3c268cc7428a8625461 fleetctl_v4.84.3_linux_arm64.tar.gz 1a0219499f50cc190949b7ad08686a49df4edb74349283e5c965aa2dc38d8859 fleetctl_v4.84.3_linux_arm64.zip 2d002968c2e2b03b1a05b7925087acce75df90e00458c91af6435e7a9ad87f73 fleetctl_v4.84.3_macos.tar.gz 5d3383af113eed7f12b75b07f8d834c6fa79299e8dce0a3f2bc7a92c10b8453e fleetctl_v4.84.3_macos.zip 56e88759715ee94f64197869bc60799df06426493b4efa662e55bf8148b057f5 fleetctl_v4.84.3_windows_amd64.tar.gz 6f3d202f5ac908dd6261eee70ee39a9cad91f00687fa93adf13121f67d96777c fleetctl_v4.84.3_windows_amd64.zip d3ceac170d1f3315c71f5d71e57f288ceb73e2dc14a04414ad1f63a55286f9bf fleetctl_v4.84.3_windows_arm64.tar.gz 6a9e17827f10c99dcddfe2d61bff309daf685159411cb4481483e1a8be4f5214 fleetctl_v4.84.3_windows_arm64.zip ``` ### v4.84.2 - Date: 2026-05-01 - Version: v4.84.2 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.84.2 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.84.2 - **fixed** — Fixed filtering in /api/v1/fleet/labels/:id/hosts endpoint - **fixed** — Fixed a dead SQL condition in hostVPPInstalls with a clarifying comment - **fixed** — Fixed access control in Fleet UI Settings Variables to prevent adding custom variables while in GitOps mode - **fixed** — Fixed a bug where custom package installers were not removed when adding an FMA for the same title via GitOps - **fixed** — Fixed a bug where host environment variables in script-only packages would cause GitOps to fail - **changed** — Updated Go to 1.26.2 - **fixed** — Fixed an issue where trying to wipe a device after its certificate was renewed could fail due to a missing bootstrap token - **fixed** — Fixed a bug where duplicate software installers for Linux could be added - **changed** — Improved validation for invalid order_key values in /api/v1/fleet/commands, /api/v1/fleet/mdm/commands and /api/v1/fleet/mdm/apple/commands endpoints - **fixed** — Fixed a server panic when an Apple MDM DeviceInformation refetch response omitted DeviceName or other expected fields ###### Bug fixes - Fixed filtering in `/api/v1/fleet/labels/:id/hosts` endpoint. - Fixed a dead SQL condition in `hostVPPInstalls` that was misleading but harmless: Android VPP apps never produce `nano_command_results` entries (they use Google's Android Management API, not nanoMDM), so the previous `(hvsi.platform != 'android' OR ncr.id IS NULL)` guard was a tautology. Replaced with a clarifying comment. - Fleet UI > Settings > Variables: Fixed access to not allow adding custom variable while in gitops mode both in the empty state and when a variable already exists - Fixed a bug where custom package installers were not removed when adding an FMA for the same title via GitOps, which caused setup experience to install duplicate software. - Fixed a bug where host environment variables in script-only packages would cause gitops to fail - Updated go to 1.26.2 - Fixed an issue where trying to wipe a device after its certificate was renewed could fail due to a missing bootstrap token. _Note: The device might still have wiped_ - Fixed a bug where duplicate software installers for linux could be added. - Improved validation for invalid `order_key` values in `/api/v1/fleet/commands`, `/api/v1/fleet/mdm/commands` and `/api/v1/fleet/mdm/apple/commands` endpoints. - Fixed a server panic when an Apple MDM `DeviceInformation` refetch response omitted `DeviceName` or other expected fields. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 5bb555863948d05299e252e6df5b11914b981773f9b7e7253a1a8b2dc8d83143 fleet_v4.84.2_linux.tar.gz 1b2c7c3a320fc506de9f8b185c9d66de847e14d0d1b5ebffdc9179aeefe0c05c fleetctl_v4.84.2_linux_amd64.tar.gz b75e046e5fc70060e7c6383d4fe2d9b388e42367b816bee837491c3274c30000 fleetctl_v4.84.2_linux_amd64.zip aec1812e1b406f9ac2e4694a2477902760bb3475d58506707f3626e88ef0aa12 fleetctl_v4.84.2_linux_arm64.tar.gz b1c590f38a1992aa569783c66707986eed2418ccc557570a3bf71d249102ec86 fleetctl_v4.84.2_linux_arm64.zip 6f2d7dbdd6d51722e9373a9558fa78377c83f9b904ad5930031644d07f5e5607 fleetctl_v4.84.2_macos.tar.gz 358bc348bcf54008ac4892dc8d09553acb221b6f0f163039fd56b0ddd8e9dfa3 fleetctl_v4.84.2_macos.zip 69f8b57c80e702a9edf608dd698d3572f8a30860228a381cbbd004c4c1c3346f fleetctl_v4.84.2_windows_amd64.tar.gz c58b932c5aa9f003a53262a45021f3af1d94723f703cb50bf6feba8fcf9bf065 fleetctl_v4.84.2_windows_amd64.zip ec94d3257a195336bd1a6843eaff7440a58e8a51299589725c7bb37bbb5a524a fleetctl_v4.84.2_windows_arm64.tar.gz 425fb7a53842a0d0f0da43e1d781b5446a5817eee204edd88e94c62be77f1e6c fleetctl_v4.84.2_windows_arm64.zip ``` ### v4.84.1 - Date: 2026-05-01 - Version: v4.84.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.84.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.84.1 - **fixed** — Fixed Fleet's Docker image failing to start in Kubernetes with an unknown userid error triggered by a fleetctl dependency side effect - **changed** — Use Docker as the default WiX runtime on macOS including Apple Silicon when generating .msi packages via fleetctl package, removing the Wine requirement on macOS for the default path ###### Bug fixes - Fixed Fleet's Docker image failing to start in Kubernetes with an `unknown userid` error, triggered by a fleetctl dependency side effect. - Use Docker as the default WiX runtime on macOS (including Apple Silicon) when generating `.msi` packages via `fleetctl package`. Wine is no longer required on macOS for the default path. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` d8f4cfe973fdba253eae70d6e0c83e681d6d945ec52d37a8c9e20a887cc21c32 fleet_v4.84.1_linux.tar.gz 615567928c7e94f9cee9ae60e81852f9d300031f1e3933c5c34981f5883b9861 fleetctl_v4.84.1_linux_amd64.tar.gz ba79ac36c7aef0e7259c9f2bc6615a42ff098b18dd4baf3564ed704c973a730b fleetctl_v4.84.1_linux_amd64.zip d042ff15c6c2a27eba7e992d4b11fbfd9b1dcc99b95741c6b19723601e7025cc fleetctl_v4.84.1_linux_arm64.tar.gz 8da325cf0c2c4c729c22d4c66ab2c53c355fabb16aae1a45b43df04c8c6bfb6d fleetctl_v4.84.1_linux_arm64.zip 75acdbd6945eb374c77cde0f65350945712cd93f9098f93bf246df88b520ae8d fleetctl_v4.84.1_macos.tar.gz 6809e7b94fd8c99fe9f243130d1049ff4735b7c3eedb65a00d51e4526602d761 fleetctl_v4.84.1_macos.zip 72819485c95a0c7b1b765c4b64f34241d3a2712de6700c2059533427e9bded52 fleetctl_v4.84.1_windows_amd64.tar.gz 2e3cf8977a08f331fa441af11aecc0592f833f079bacdd9efb26768cd94a258e fleetctl_v4.84.1_windows_amd64.zip eacfbeb4cb83e8ea42fab4ea9e430ff114b6f0c7d742f781c552921b5ecdfa82 fleetctl_v4.84.1_windows_arm64.tar.gz 433efde225f9f62f95812a0b76a4335f7446210dd1d2e7319905618ff724026d fleetctl_v4.84.1_windows_arm64.zip ``` ### v4.84.0 - Date: 2026-04-25 - Version: v4.84.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.84.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.84.0 - **added** — Support for Entra conditional access to Windows devices - **added** — Ability to pin Fleet-maintained apps to a specific major version in GitOps - **added** — ACME for MDM protocol communication and hardware device attestation - **added** — GET /api/v1/fleet/hosts/{id}/reports endpoint that lists query reports associated with a specific host - **added** — Support for labels_include_all conditional scoping for software installers and apps - **added** — Validation for software install, uninstall, and post-install scripts - **added** — Ability to specify custom patch policy query in an FMA manifest - **added** — Ability to re-send Android certificates to a specific host - **added** — Reports tab to Host details page - **added** — Support for specifying a Fleet-Maintained App as a policy software automation in GitOps - **added** — Support for running python scripts on macOS and Linux - **added** — Automatic retry up to 3 times when the Android agent reports a certificate install failure - **added** — Activity logging when a certificate is installed or fails to install on an Android host - **added** — Host activity card on the Android host details page - **added** — disk_space fleetd table for macOS that reports available disk space including purgeable storage - **added** — Configuration profile deletion when a Windows configuration profile is deleted or a host moves teams via SyncML Delete commands - **added** — Support for outputting VPP policy automations in fleetctl generate-gitops - **added** — Vulnerability detection for Microsoft 365 Apps and Office products on Windows - **added** — OSV data source for Ubuntu vulnerability scanning - **changed** — Fleet-maintained apps serving location from GitHub to https://maintained-apps.fleetdm.com/manifests - **changed** — Increased automatic retry limit for failed Apple configuration profiles from 1 to 3 - **changed** — Increased default limit for the software batch endpoint from 1MiB to 25MiB - **changed** — Increased default SSO session validity period from 5 to 15 minutes - **changed** — Improved performance of distributed read endpoint by reducing mutex contention using sync.RWMutex instead of sync.Mutex - **changed** — Automatic rotation of Mac recovery lock passwords 1 hour after the password is viewed via the API - **changed** — Updated ingestion/CVE logic to support JetBrains software with 2 version numbers - **fixed** — Addressed false positive vulnerabilities CVE-2019-17201 and CVE-2019-17202 reported for Admin By Request on macOS and Linux hosts - **fixed** — Generated correct CPE from malformed ipswitch whatsup CPE to ensure applicable CVEs are matched - **fixed** — Removed incorrect report key from get/create/modify API responses - **fixed** — Fixed host detail queries not being sent to hosts running Flatcar Container Linux and CoreOS - **added** — FLEET_MDM_CERTIFICATE_PROFILES_LIMIT server config option to throttle the number of CA certificate profile installations per reconciler cycle **NOTE FOR SELF-HOSTED**: the fleetdm/fleet:v4.84.0 Docker image is broken in Kubernetes environments. Use [fleetdm/fleet:v4.84.1](https://github.com/fleetdm/fleet/releases/tag/fleet-v4.84.1) instead. ##### Fleet 4.84.0 (Apr 24, 2026) ###### IT Admins - Added support for Entra conditional access to Windows devices. - Added ability to pin Fleet-maintained apps to a specific major version in GitOps. - Implemented ACME for MDM protocol communication, and hardware device attestation. - Added `GET /api/v1/fleet/hosts/{id}/reports` endpoint (also accessible as `/hosts/{id}/queries`) that lists the query reports associated with a specific host. - Added support for `labels_include_all` conditional scoping for software installers and apps. - Added validation for software install, uninstall, and post-install scripts. - Added ability to specify custom patch policy query in an FMA manifest. - Added ability to re-send Android certificates to a specific host. - Added Reports tab to Host details page. - Allowed specifying a Fleet-Maintained App (FMA) as a policy software automation in GitOps. - Added support for running python scripts on macOS and Linux. - Added automatic retry (up to 3 times) when the Android agent reports a certificate install failure. - Added activity logging when a certificate is installed or fails to install on an Android host. - Enabled the host activity card on the Android host details page. - Switched Fleet-maintained apps serving location from GitHub to https://maintained-apps.fleetdm.com/manifests. **NOTE:** If you limit outbound Fleet server traffic, make sure it can access the new FMA manifests location. - Increased automatic retry limit for failed Apple (macOS, iOS, iPadOS) configuration profiles from 1 to 3. Windows profiles remain at 1 retry. - Added a new `disk_space` fleetd table for macOS that reports available disk space including purgeable storage, matching the value shown in Finder's "Get Info" dialog and System Settings → General → Storage. - Added configuration profile deletion when a Windows configuration profile is deleted or a host moves teams via SyncML `` commands, bringing Windows profile removal to parity with macOS. - Added support for outputting VPP policy automations in `fleetctl generate-gitops`. - Added logging of profile names alongside MDM commands installing or removing them. - Added indication in the UI when a profile command was deferred via `NotNow` status. - Added activity when setup experience is canceled due to software install failure. - Added cancel activities for each VPP app install skipped due to setup experience cancellation, and switched "failed" activity to "canceled" for package-based software installs in the same situation. - Added install failure activity when VPP installs fail due to licensing issues during setup experience. ###### Security Engineers - Added vulnerability detection for Microsoft 365 Apps and Office products on Windows. - Added OSV data source for Ubuntu vulnerability scanning. - Added automatic rotation of Mac recovery lock passwords 1 hour after the password is viewed via the API. - Updated ingestion/CVE logic to support JetBrains software with 2 version numbers, like WebStorm 2025.1 - Addressed false positive vulnerabilities (CVE-2019-17201, CVE-2019-17202) reported for Admin By Request on macOS and Linux hosts. These CVEs are Windows-specific. - Generated correct CPE from malformed ipswitch whatsup CPE, ensuring applicable CVEs are matched. - Added software source to ecosystem matching to help prevent non-deterministic CPE selection when multiple vendors exist for the same product. ###### Other improvements and bug fixes - Upped the default limit for the software batch endpoint, from 1MiB to 25MiB. - Added `FLEET_MDM_CERTIFICATE_PROFILES_LIMIT` server config option to throttle the number of CA certificate profile installations per reconciler cycle, preventing CA server overload in large deployments _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.84.0]_ ### v4.83.2 - Date: 2026-04-14 - Version: v4.83.2 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.83.2 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.83.2 - **fixed** — Fixed a crash on the "My device" page for Fleet Free instances that returned a 402 error when the host was assigned to a team because the device endpoint called a premium-only API ###### Bug fixes - Fixed a crash on the "My device" page for Fleet Free instances. The page returned a 402 error when the host was assigned to a team because the device endpoint called a premium-only API, and also crashed when accessing undefined policies data. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 08ef96bfc8c7b2d7650169054fa68fc9fa99a33409459d9f569859df34fb5602 fleet_v4.83.2_linux.tar.gz 9594c7a29cb210efe74eb3ac82aeeb6720a0f9a99af17197b21f7fcebbe42128 fleetctl_v4.83.2_linux_amd64.tar.gz b6e230fe251f8f8a6a03ba3690abb012870c19944002e199a88e61f9051f4f3a fleetctl_v4.83.2_linux_amd64.zip 46946bb498bf98f0d00265addbffba4e3a192350e6f90567021a04f679b452cb fleetctl_v4.83.2_linux_arm64.tar.gz 0385f2981215df1e3a1ed9d1ef044066c1038a09564b2500cdda2075006e9b89 fleetctl_v4.83.2_linux_arm64.zip 8bbe2ab6244d9a04fdd555777bc9a1838cd6b988dadf4b30c45983ac0c9786aa fleetctl_v4.83.2_macos.tar.gz 414340f61c7d31b67000311b6f91ebd0b8d4b4da280c7ffdb08cfea2ab81a0ea fleetctl_v4.83.2_macos.zip a52bc3bbd14cbad8227b1d68a68a0192a978381e10f70f24fb6125a0e8c7c1d2 fleetctl_v4.83.2_windows_amd64.tar.gz 0296691003856e6129a1191e8dc23d3e52f46ba627674750e533c658b5e62dc9 fleetctl_v4.83.2_windows_amd64.zip cb009ccba74c1893607b22d57738507ff324f622d836d94f9fcf6e027dfe869b fleetctl_v4.83.2_windows_arm64.tar.gz d66710c52f78484b3a087c35db18d749b674f9921834bf15a299cbcd90c281b8 fleetctl_v4.83.2_windows_arm64.zip ``` ### v4.83.1 - Date: 2026-04-11 - Version: v4.83.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.83.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.83.1 - **fixed** — Fixed policy creation failing when type was omitted - **fixed** — Fixed auth token not persisting when logging in via SSO - **fixed** — Fixed infinite page loop pagination bug on software table page happening when viewing a subsequent page and then using the software filter dropdown to filter - **fixed** — Fixed software table page number to be bookmarkable ###### Bug fixes - Fixed policy creation failing when type was omitted. - Fixed auth token not persisting when logging in via SSO. - Fleet UI: Fixed infinite page loop pagination bug on software table page happening when viewing a subsequent page and then using the software filter dropdown to filter. - Fleet UI: Fixed software table page number to be bookmarkable ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` 441e87e397898df479f0ef2cece844a40d43954e5481e2ff5ca02b45ddf2e589 fleet_v4.83.1_linux.tar.gz 66db9fb3c7eb517afc7e6200ae5187b6697c032ba49bebd0d68cce6e34a522c1 fleetctl_v4.83.1_linux_amd64.tar.gz 3ba7302fe8d7ed6940d249163fb1f4ddedb1b83adc61928e31994482ea8d2f47 fleetctl_v4.83.1_linux_amd64.zip c474120d20e4faedd57d8a82fc5fd9d87f29b03f0307daba1815cb6ae3c614d9 fleetctl_v4.83.1_linux_arm64.tar.gz 56f9bdb2f2532f855ef568a908a20c211b0d64afb673c5de9cec22fe5e138e51 fleetctl_v4.83.1_linux_arm64.zip 89576e2506797b631d80672f02a9e5ce7e3fc80dbcbc8a7f2db615568c158cca fleetctl_v4.83.1_macos.tar.gz 2b28948788d53bdbf72a53e064f5de781409c4e2df2b4a0db6517ef5f905e3c5 fleetctl_v4.83.1_macos.zip 7a83a83b1cce5ca3cdf66d27fb57c0b4470797143fc2771df3ce8f405153c63d fleetctl_v4.83.1_windows_amd64.tar.gz 4d6ef7d46b6cf2e3d1c9da8457e7c4959b2fe05f70fb39baff423d57508bbf50 fleetctl_v4.83.1_windows_amd64.zip 4eca5f033644966859eb44df73962b98d687c926ee56d83276982cf166515a7a fleetctl_v4.83.1_windows_arm64.tar.gz 5fd20d2dc1a9a62ddb256f52ef06d707db9edb44d4005f7b955d20904df3e2cb fleetctl_v4.83.1_windows_arm64.zip ``` ### v4.83.0 - Date: 2026-04-01 - Version: v4.83.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.83.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.83.0 - **added** — Added ability to deploy an Android web app via setup experience or self-service - **added** — Added ability to set and manually rotate Mac recovery lock passwords - **added** — Added ability to lock the pre-filled user information for macOS hosts that login via End User Authentication during Setup Experience - **added** — Added automatic retries for failed software installs, excluding VPP apps - **added** — Added retry functionality when adding software installers to Fleet via GitOps - **added** — Added `fleetctl new` command to initialize a GitOps folder - **added** — Added support for `paths:` key under `reports:`, `labels:` and `policies:` in GitOps files - **added** — Added glob support for `configuration_profiles` in GitOps files - **added** — Added support for referencing `.sh` or `.ps1` script files directly in the GitOps `path` field for software packages - **added** — Added `fleet_name` and `fleet_id` columns to hosts CSV export - **added** — Added resend button in the OS settings modal for iOS and iPadOS hosts - **added** — Added patch policies for Fleet-maintained apps that automatically update when the app is updated - **added** — Added support for NDES CA for Windows hosts - **added** — Added vulnerability scanning support for Windows Server 2025 hosts - **added** — Added OTEL instrumentation to Fleet's internal HTTP client - **fixed** — Fixed python package false positives on Ubuntu, such as `python3-setuptools` on Ubuntu 24.04 with version 68.1.2-2ubuntu1.2 - **fixed** — Fixed false positive vulnerabilities for Mattermost Desktop - **changed** — Updated host software library to always allow filtering - **changed** — Improved host search to always match against host email addresses, not only when the query looks like an email - **deprecated** — Deprecated configuration keys `custom_settings`, `macos_settings`, `macos_setup` and `macos_setup_assistant` in favor of `configuration_profiles`, `apple_settings`, `setup_experience` and `apple_setup_assistant` respectively ##### Fleet 4.83.0 (Apr 1, 2026) ###### IT Admins - Added ability to deploy an Android web app via setup experience or self-service. - Added ability to set and manually rotate Mac recovery lock passwords. - Added ability to lock the pre-filled user information for macOS hosts that login via End User Authentication during Setup Experience. - Added automatic retries for failed software installs, excluding VPP apps. - Updated host software library to always allow filtering. - Added retry functionality when adding software installers to Fleet via GitOps. - Added `fleetctl new` command to initialize a GitOps folder. - Added support for `paths:` key under `reports:`, `labels:` and `policies:` in GitOps files. - Added glob support for `configuration_profiles` in GitOps files. - Added support for referencing `.sh` or `.ps1` script files directly in the GitOps `path` field for software packages. - Implemented `webhooks_and_tickets_enabled` flag for policies in GitOps. - Added server config for allowing all Apple MDM declaration types. - Added ability to use `FLEET_JIT_USER_ROLE_FLEET_` as a prefix on SAML attributes. - Added `fleet_name` and `fleet_id` columns to hosts CSV export. - Added resend button in the OS settings modal for iOS and iPadOS hosts. - Added patch policies for Fleet-maintained apps that automatically update when the app is updated. ###### Security Engineers - Added support for NDES CA for Windows hosts. - Added vulnerability scanning support for Windows Server 2025 hosts. - Added OTEL instrumentation to Fleet's internal HTTP client. - Added Content-Type header to Smallstep authorization requests to prevent Cloudflare from blocking them. - Added ability to omit `secrets:` in GitOps files to retain existing enroll secrets on server. - Fixed python package false positives on Ubuntu, such as `python3-setuptools` on Ubuntu 24.04 with version 68.1.2-2ubuntu1.2. - Fixed false positive vulnerabilities for Mattermost Desktop. ###### Other improvements and bug fixes - Most top-level keys can now be omitted from GitOps files in place of supplying them with an empty value. - Improved host search to always match against host email addresses, not only when the query looks like an email. - Prevented a 500 error on the host details page when an MDM command reference in `host_mdm_actions` pointed to a non-existent command (orphan reference). - Allowed Fleet-maintained apps to be added if they have default categories configured that are not available in older builds from this point forward. - Migrated to using Policy `critical` option when disallowing Okta conditional access bypass. - Updated DEP enrollment flow to apply minimum macOS version check when specified. - Updated GitOps to fail runs when unknown keys are detected in files. - Updated default last opened time diff to 2m to increase the chances of updating the last opened time for software that is opened frequently. - Updated the host results endpoint URL to be consistent with the other URLs. - Added tooltip to batch run result host count to clarify that the count might include deleted hosts. - Updated table heading and result filter styles. - Reordered the columns on the Hosts page. - Updated Fleet desktop to surface custom transparency links to the device user. - Changed `PostJSONWithTimeout` to log response body in error case. - Removedd unused and confusingly-named --mdm_apple_scep_signer_allow_renewal_days config. - Refactored `NewActivity` functionality by moving it to the new activity bounded context. - Modified Android certificate renewal logic to make it easier to test. - Optimized `api/latest/fleet/software/titles` endpoint. - Trimmed incoming `ABM` suffix for Arch Linux hosts so Arch OSs are grouped together in the database and UI. - Updated determination process used for selecting which user email address to use when scheduling a maintenance event for a host failing policies. - Added license checks for `fleet-fre _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.83.0]_ ### v4.82.2 - Date: 2026-03-28 - Version: v4.82.2 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.82.2 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.82.2 - **fixed** — Fixed a metadata extraction bug for .pkg macOS installers that prevented updating some packages added in a previous Fleet version - **fixed** — Fixed FMA apps not showing up for a fleet when added via GitOps after an automated FMA version update with an unchanged binary ###### Bug fixes - Fixed a [metadata extraction bug](https://github.com/fleetdm/fleet/issues/38356) for `.pkg` macOS installers (introduced in 4.77). It prevented updating some packages that were added in a previous Fleet version. Before this fix, deleting and re-adding the package as a workaround didn’t work. Now it does. - You'll know you ran into this bug if you tried updating a package and you saw this error: "The selected package is for different software". - Fixed FMA apps not showing up for a fleet when added via GitOps after an automated FMA version update with an unchanged binary. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` c73e7ebc8418ea5407fc4f77fd7818fc9a6ef519939f28bba2d5d0a12ec7937b fleet_v4.82.2_linux.tar.gz d836f068c89567434a0b533e79213828dcd15733fdc1d4498a2c629c38691a76 fleetctl_v4.82.2_linux_amd64.tar.gz fa7d4b53775ed2d0ff15a3966c71fc6c9e9e6fbecdb89915124df11424a0f305 fleetctl_v4.82.2_linux_amd64.zip 00f811ae423103a16ec78fbb7f8b70f7fcd7c9af698a987bf5e724cf6670067b fleetctl_v4.82.2_linux_arm64.tar.gz 034755490342ac0fd9864e810c8e1ad38ac22d248370c9b80837204634967109 fleetctl_v4.82.2_linux_arm64.zip a0afd5cb2dab1ac7ed32b2841c2b987630bcc0d8e33cba615b2c7e473a36e3b4 fleetctl_v4.82.2_macos.tar.gz 9608053f4491d5100ca88d8cfb6d11b4cd18d3b6c0e26f0e0a08c2b690b4ef09 fleetctl_v4.82.2_macos.zip 732ce2b3f1d3cd39e904ccd3a8546cf1fd94249fdaa955720236c713d55f87a9 fleetctl_v4.82.2_windows_amd64.tar.gz f7baa714c0e3ce155a13f8fd55733f98bbbbc8361b39836a0095db6dc2e90f2b fleetctl_v4.82.2_windows_amd64.zip 100a578c7ed57bf0d82e5b8357ba7a957e54290405ea9a5a04f3555e78e6f806 fleetctl_v4.82.2_windows_arm64.tar.gz f65494eaf8df124e7082aea4846ccb0139bc73e7fc1d68426253540b2e8097ed fleetctl_v4.82.2_windows_arm64.zip ``` ### v4.81.3 - Date: 2026-03-21 - Version: v4.81.3 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.81.3 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.81.3 - **added** — Add configurable body size limits for the /api/osquery/log and /api/osquery/distributed/write endpoints - **fixed** — Fix false positive PayloadTooLargeError errors ###### Bug fixes - Added configurable body size limits for the `/api/osquery/log` and `/api/osquery/distributed/write` endpoints. - Fixed false positive `PayloadTooLargeError` errors. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` bce0a2bdd79381abb94dd04f443f241e04b1e933edbeb9f0b0df34a0ef9c24db fleet_v4.81.3_linux.tar.gz b0355092e52a3139cb50eae770c2815099eb47599a113222bcf3b6cf2b340aa9 fleetctl_v4.81.3_linux_amd64.tar.gz 103d5ef83efecdcd94088cf636e785e5476f19d312d01ebefe60133a048cf472 fleetctl_v4.81.3_linux_amd64.zip c0655b309f702cddb4a749dcb50d504a8d59ce3cfc797a80adbad3a5d0eeae4f fleetctl_v4.81.3_linux_arm64.tar.gz 6a39dda1a423de92bef0c2ab26f0aca455a168b0efd8a4656bce68192d65ef3f fleetctl_v4.81.3_linux_arm64.zip 0dca8a860b4d8fdf3e63ac230ed6d35535fc0e41273a582965dca12d1105c926 fleetctl_v4.81.3_macos.tar.gz b0dc4c32758843c00e838c72e0a9c643d118dd0623f59a07a20c7481c3f24885 fleetctl_v4.81.3_macos.zip ee8bee43398232d4733d62ac9ff31748f81f9359216ab1673ec54bafdd781469 fleetctl_v4.81.3_windows_amd64.tar.gz 26d11698c033ca7fbe304ad440480d80086b081a219a04d8dbfa6224db13ba77 fleetctl_v4.81.3_windows_amd64.zip 5fe7a8394427e61d06819d4c65ed5ae98dea34977560c6db4aff58afd3934d17 fleetctl_v4.81.3_windows_arm64.tar.gz 0178565774d229634db4ab3534a5bcf778495c13392c0afd45c23cf513b7d37f fleetctl_v4.81.3_windows_arm64.zip ``` ### v4.82.1 - Date: 2026-03-19 - Version: v4.82.1 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.82.1 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.82.1 - **fixed** — Fixed a crash on the "My device" page for Fleet Free instances when the host was assigned to a team because the device endpoint called a premium-only API and crashed when accessing undefined policies data - **fixed** — Stopped duplicate Fleet-maintained app entries from showing up in setup experience - **fixed** — Reduced database contention during the vulnerability cron - **added** — Added a secondary index on host_software(software_id) to improve query performance - **fixed** — Fixed an issue where the "add Fleet-maintained app" endpoint incorrectly added software to the Unassigned fleet - **fixed** — Muted deprecation warnings for body params when the "deprecated-field-names" topic is not enabled - **fixed** — Fixed custom app icons not getting set via GitOps when the same software title exists in multiple teams ###### Bug fixes - Fixed a crash on the "My device" page for Fleet Free instances. The page returned a 402 error when the host was assigned to a team because the device endpoint called a premium-only API, and also crashed when accessing undefined policies data. - Stopped duplicate Fleet-maintained app entries from showing up in setup experience. - Reduced database contention during the vulnerability cron. - Added a secondary index on `host_software(software_id)` to improve query performance. - Fixed an issue where the "add Fleet-maintained app" endpoint incorrectly added software to the Unassigned fleet. - Muted deprecation warnings for body params when the "deprecated-field-names" topic is not enabled. - Fixed custom app icons not getting set via GitOps when the same software title exists in multiple teams. ###### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ###### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ###### Binary Checksum **SHA256** ``` e20f5e600b04e5e76b97cc4d72d25857996401e50b30c349c33d814d25e60a17 fleet_v4.82.1_linux.tar.gz 2bf908c90db1b310e0806b614dc3d01620a36cd30771db713374023a3487cbdd fleetctl_v4.82.1_linux_amd64.tar.gz 98daf26686fc909ca0aa396c9b379a98c4aa381b082141fa4b5a5c9143145bfe fleetctl_v4.82.1_linux_amd64.zip 6c9701ab0fe725389aa411766ab2012972d9b7a01bb994ffb9ca65b5884c2034 fleetctl_v4.82.1_linux_arm64.tar.gz 04cb955bcccf23334a24dbe36a35d9f8a8a1b84a1948f9217653c5553f601f6f fleetctl_v4.82.1_linux_arm64.zip 965147846622d1e4c52689fa8ee044c3dfd884b2c523c13f29a0d676b0e8bd46 fleetctl_v4.82.1_macos.tar.gz 50b332c3bfe7aaefd7dedd6537d8c347b314786b6f90494176f807a75977455d fleetctl_v4.82.1_macos.zip 740ddd324b592b0e48a0ecd25d8da9df9eb889439e9b23c4fbc45e9cf80b972a fleetctl_v4.82.1_windows_amd64.tar.gz 5913036d550e30bedafc6f309f0a72058b6e45e65b5d247a0b056f3f2ff71c60 fleetctl_v4.82.1_windows_amd64.zip b348a265022cd1311db5cd4a8a4faf754ce155dee2360e7e86a5caf4bfcfc64b fleetctl_v4.82.1_windows_arm64.tar.gz 18330c5416c54739beddfb23d49f4cc9daa30de6e226d2cff3407738477db07e fleetctl_v4.82.1_windows_arm64.zip ``` ### v4.82.0 - Date: 2026-03-12 - Version: v4.82.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.82.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.82.0 - **added** — Support for enrolling fully managed Android hosts without a work profile - **added** — Capability to uninstall Android apps on the device and removal from self-service in the managed Google Play store when an app is removed from Fleet - **added** — Ability to allow or disallow end-users to bypass conditional access on a per-policy basis - **added** — Filtering by platform and add status to the Software > Add Fleet-maintained apps table - **changed** — Android status reports to re-verify profiles that previously failed - **added** — Ability to roll back to previously added versions of Fleet-maintained apps - **added** — New Technician role designed for help desk and IT support teams with capability to run scripts, view results, and install or uninstall software - **added** — Support for JIT provisioning of the Technician role via SSO SAML attributes - **added** — Automatic retries for failed software operations - **added** — Ability to scan for kernel vulnerabilities on RHEL based hosts - **added** — AWS GovCloud RDS CA certificates to the RDS MySQL TLS bundle, enabling IAM authentication for Fleet deployments connecting to RDS in AWS GovCloud regions - **added** — CVE alias for python visual studio code extension - **added** — New activity for edited enroll secrets - **changed** — Renamed teams and queries to fleets and reports in the UI, API, CLI, and GitOps - **deprecated** — no-team.yml in GitOps in favor of unassigned.yml - **deprecated** — Certain API field names to reflect the renaming of teams to fleets and queries to reports - **added** — Configurable body size limits for the /api/osquery/log and /api/osquery/distributed/write endpoints - **added** — Ability to specify allowed Entra tenant IDs for enrollments - **changed** — Increased the maximum script execution timeout from 1 hour to 5 hours - **fixed** — Adding Windows Fleet maintained apps failing when a software title with the same upgrade code already exists ##### Fleet 4.82.0 (Mar 11, 2026) ###### IT Admins - Added support for enrolling fully managed Android hosts without a work profile. - Added capability to uninstall Android apps on the device (and removal from self-service in the managed Google Play store) when an app is removed from Fleet. - Added ability to allow or disallow end-users to bypass conditional access on a per-policy basis. - Added filtering by platform and add status to the Software > Add Fleet-maintained apps table. - Updated Android status reports to re-verify profiles that previously failed. - Added ability to roll back to previously added versions of Fleet-maintained apps. - Added new Technician role designed for help desk and IT support teams. Technicians can run scripts, view results, and install or uninstall software. - Added support for JIT provisioning of the Technician role via SSO SAML attributes. - Added automatic retries for failed software operations. ###### Security Engineers - Added ability to scan for kernel vulnerabilities on RHEL based hosts. - Added AWS GovCloud RDS CA certificates to the RDS MySQL TLS bundle, enabling IAM authentication for Fleet deployments connecting to RDS in AWS GovCloud regions (us-gov-east-1, us-gov-west-1). - Added CVE alias for python visual studio code extension. - Added new activity for edited enroll secrets. ###### Other improvements and bug fixes - Renamed teams and queries to fleets and reports in the UI, API, CLI, and GitOps. - Deprecated no-team.yml in GitOps in favor of unassigned.yml. - Deprecated certain API field names to reflect the renaming of "teams" to "fleets" and "queries" to "reports". - Updated Android MDM profiles to show up as pending on upload, the same as Apple MDM profiles. - Improved the speed of a database query that runs every minute to avoid database locking. - Added configurable body size limits for the `/api/osquery/log` and `/api/osquery/distributed/write` endpoints. - Updated logic to trigger vulnerability webhook when on Fleet free tier. - Updated storage of the auth token used in the UI. - Dynamically alphabetized vitals on the host details page. - Reworked how we handle server/worker delays to fix flaky tests. - Disabled "Calendar" dropdown option in Policy > Manage automations for Unassigned. - Added Go slog logging infrastructure and migrated a portion of the code from go-kit/log to slog. - Added CTA to turn on Android MDM for Android software setup experience if MDM is not configured. - Left-aligned "Critical" checkbox in Save policy form. - Improved spacing on the Controls > OS Settings page. - Updated to not allow editing Fleet-maintained app in the UI while GitOps mode is enabled. - Updated to accept the previous device authentication token for up to one rotation cycle, so the My Device page URL remains valid after token refresh. - Updated default macOS, iOS, and iPadOS update deadline time to 7PM (19:00) local time. - Updated UI to enable adding/removing multiple Microsoft Entra tenant ids. - Added additional logging for SCEP proxy requests and SCEP profile renewals. - Added warning message on gitops label rename to clarify to users that renaming a label implies a delete operation. - Added the ability to specify allowed Entra tenant IDs for enrollments. - Updated the DEP syncer to properly reassign a profile when ABM unilaterally removes it. - Increased the maximum script execution timeout from 1 hour (3600 seconds) to 5 hours (18000 seconds). - Improved error handling on AWS DB failover. Fleet will now fail health check if the primary DB is read-only, or trigger graceful shutdown when write operations encounter read-only errors. - Generated a server-side device token in the Okta conditional access flow when none exists or the current token is expired. - Moved the copy button for text areas out of the text area itself and in line with its label. - Removed unnecessary calls to `svc.ds.BulkSetPendingMDMHostProfiles` in `POST /ap _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.82.0]_