# Fleet v4.56.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2024-09-07 - Version: v4.56.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.56.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.56.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Index to query_results DB table to speed up finding last query timestamp for a given query and host - **added** — Link in the UI to the error message when a CSR cannot be downloaded due to missing private key - **added** — Disabled overlay to the Other Workflows modal on the policy page - **changed** — Performance of live queries to accommodate for higher volumes when utilizing zero-trust workflows - **changed** — fleetctl gitops error message when trying to change team name to a team that already exists - **added** — Server support for multiple VPP tokens - **added** — New endpoints and updated existing endpoints for managing multiple Apple Business Manager tokens - **added** — Support for S3 to store MDM bootstrap packages using the same bucket configuration as for software installers - **added** — UI support for self service VPP software - **added** — Backend and gitops support for self service VPP - **added** — Ability for MDM migrations if the host is manually enrolled to a 3rd party MDM - **added** — Offline screen to the macOS MDM migration flow - **added** — New ABM page to Fleet UI - **added** — New VPP page to the Fleet UI - **added** — Support to track the Apple Business Manager terms expired API error per token and a global flag that gets set as soon as one token has its terms expired - **changed** — Instructions on My device for MDM migrations on pre-Sonoma macOS hosts - **changed** — Process to allow multiple teams to be assigned to the same VPP Token - **changed** — Process so that deleting installed software or VPP app now makes it available for re-installation - **changed** — Enforcement of minimum OS version settings during Apple Automated Device Enrollment ##### Fleet 4.56.0 (Sep 7, 2024) ###### Endpoint operations - Added index to `query_results` DB table to speed up finding last query timestamp for a given query and host. - Added a link in the UI to the error message when a CSR can't be downloaded due to missing private key. - Added a disabled overlay to the Other Workflows modal on the policy page. - Improved performance of live queries to accommodate for higher volumes when utilizing zero-trust workflows. - Improved `fleetctl` gitops error message when trying to change team name to a team that already exists. ###### Device management - Added server support for multiple VPP tokens. - Added new endpoints and updated existing endpoints for managing multiple Apple Business Manager tokens. - Added support for S3 to store MDM bootstrap packages (uses the same bucket configuration as for software installers). - Added support to UI for self service VPP software. - Added backend and gitops support for self service VPP. - Added ability for MDM migrations if the host is manually enrolled to a 3rd party MDM. - Added an offline screen to the macOS MDM migration flow. - Added new ABM page to Fleet UI. - Added new VPP page to the fleet UI - Added support to track the Apple Business Manager "terms expired" API error per token, as well as a global flag that gets set as soon as one token has its terms expired. - Updated the instructions on "My device" for MDM migrations on pre-Sonoma macOS hosts. - Updated to allow multiple teams to be assigned to the same VPP Token. - Updated process so that deleting installed software or VPP app now makes it available for re-installation. - Updated to enforce minimum OS version settings during Apple Automated Device Enrollment (ADE). - Updated ABM ingestion so that deleted iOS/iPadOS host will continue to report to Fleet as long as host is in Apple Business Manager (ABM). - Updated so that refetching an offline iOS/iPadOS host will not add new MDM commands to the queue if previous refetch has not completed yet. - Updated UI so that downloading a software installer package now shows the browser's built-in progress bar. - Updated relevant documentation to include references to multiple ABM and VPP tokens. - Consolidated Automatic Enrollment and VPP settings under the MDM settings integration page. - Cleared apps associated with a VPP token if it's moved off of a team. ###### Vulnerability management - Added ALAS bulletins as vulnerability source for Amazon Linux (instead of OVAL for Amazon Linux 2, and adds support for Amazon Linux 1, 2022, and 2023). - Added matching rules for July and August Microsoft 365 security updates (https://learn.microsoft.com/en-us/officeupdates/microsoft365-apps-security-updates). - Added the following filters to `/software/titles` and `/software/versions` API endpoints: `exploit: bool`, `min_cvss_score: float`, `max_cvss_score: float`. - Updated software titles/versions tables to allow for filtering by vulnerabilities including severity and known exploit. - Updated to use empty CVE description when the NVD CVE feed doesn't include description entries (instead of panicking). - Updated matching software that is not installed by Fleet so that it shows up as 'Available for install' on host details page. - Updated base images of `fleetdm/fleetctl`, `fleetdm/bomutils` and `fleetdm/wix` to fix critical vulnerabilities found by Trivy. - Updated vulnerability scanning to use `macos` SW target for CPEs of homebrew packages. - Updated vulnerability scanning to not ignore software with non-ASCII en dash and em dash characters. - Updated `GET /api/v1/fleet/vulnerabilities/{cve}` endpoint to add validation of CVE format, and a 204 response. The 204 response indicates that the vulnerability is known to Fleet but not present on any hosts. - Updated the UI to add new empty states for searching vulnerabilities: invalid CVE format searched, a known CVE serached but not present on hosts, not a known _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.56.0]_