# Fleet v4.57.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2024-09-23 - Version: v4.57.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.57.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.57.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Support for configuring policy installers via GitOps - **added** — Support for policies in "No team" that run on hosts that belong to "No team" - **added** — Reserved team names: "All teams" and "No team" - **added** — Support for the software status filter for 'No teams' on the hosts page - **added** — Enable 'No teams' functionality for the policies page and associated workflows - **added** — Reset install counts and cancel pending installs/uninstalls when GitOps installer updates change package contents - **added** — Support for software installer packages, self-service flag, scripts, pre-install query, and self-service availability to be edited in-place rather than deleted and re-added - **added** — Feature allowing automatic installation of software on hosts that fail policies - **added** — Feature for end users to enroll BYOD devices into Fleet MDM - **added** — Ability to use Fleet to uninstall packages from hosts - **added** — Endpoint for getting an OTA MDM profile for enrolling iOS and iPadOS hosts - **added** — Protocol support for OTA enrollment and automatic team assignment for hosts - **added** — Validation of Setup Assistant profiles on profile upload - **added** — Validation to prevent installing software on a host with a pending installation - **added** — Support for custom SCEP CA certificates with any kind of extendedKeyUsage attributes - **changed** — Modified POST /api/latest/fleet/software/batch endpoint to be asynchronous and added new endpoint GET /api/latest/fleet/software/batch/{request_uuid} to retrieve the result of the batch upload - **changed** — Updated Go to go1.23.1 - **changed** — Removed validation of APNS certificate from server startup - **fixed** — False negative vulnerability for git - **fixed** — False positive vulnerabilities for minio ##### Note: 4.57.0 contains two critical bugs Two critical bugs have been identified in 4.57.0: 1. [Fleet uninstall script removes other apps from the host](https://github.com/fleetdm/fleet/issues/22571) 2. [Software Package installs for Windows .exe and .msi installers stuck in Pending state](https://github.com/fleetdm/fleet/issues/22558) We are currently developing fixes for both and will issue 4.57.2 as soon as possible. ##### Fleet 4.57.0 (Sep 23, 2024) **Endpoint Operations** - Added support for configuring policy installers via GitOps. - Added support for policies in "No team" that run on hosts that belong to "No team". - Added reserved team names: "All teams" and "No team". - Added support the software status filter for 'No teams' on the hosts page. - Enable 'No teams' funcitonality for the policies page and associated workflows. - Added reset install counts and cancel pending installs/uninstalls when GitOps installer updates change package contents. - Added support for software installer packages, self-service flag, scripts, pre-install query, and self-service availability to be edited in-place rather than deleted and re-added. **Device Management (MDM)** - Added feature allowing automatic installation of software on hosts that fail policies. - Added feature for end users to enroll BYOD devices into Fleet MDM. - Added the ability to use Fleet to uninstall packages from hosts. - Added an endpoint for getting an OTA MDM profile for enrolling iOS and iPadOS hosts. - Added protocol support for OTA enrollment and automatic team assignment for hosts. - Added validation of Setup Assistant profiles on profile upload. - Added validation to prevent installing software on a host with a pending installation. - Allowed custom SCEP CA certificates with any kind of extendedKeyUsage attributes. - Modified `POST /api/latest/fleet/software/batch` endpoint to be asynchronous and added a new endpoint `GET /api/latest/fleet/software/batch/{request_uuid}` to retrieve the result of the batch upload. **Vulnerability Management** - Fixed a false negative vulnerability for git. - Fixed false positive vulnerabilities for minio. - Fixed an issue where virtual box for macOS wasn't matching against the NVD product name. - Fixed Ubuntu python package false positive vulnerabilities by removing duplicate entries for ubuntu python packages installed by dpkg and renaming remaining pip installed packages to match OVAL definitions. **Bug fixes and improvements** - Updated Go to go1.23.1. - Removed validation of APNS certificate from server startup. - Removed invalid node keys from server logs. - Improved the UX of turning off MDM on an offline host. - Improved clarity of GitOps VPP app ID type errors. - Improved gitops error message about enabling windows MDM. - Improved messaging for VPP token constraint errors. - Improved loading state for UI tables when no data is present yet. - Improved permissions so that hosts can no longer access installers that aren't directly assigned to them. - Improved verification of premium license before uploading VPP tokens. - Added "0 items" description on empty software tables for UI consistency. - Updated the macos target minimum version tooltip. - Fixed logic to properly catch and log APNs errors. - Fixed UI overflow issues with OS settings table data. - Fixed regression for checking email used to get a signed CSR. - Fixed bugs on enrollment profiles when the organization name contains invalid XML characters. - Fixed an issue with cron profiles delivery failing if a Windows VM is enrolled twice. - Fixed issue where Fleet server could start when an expired ABM certificate was provided as server config. - Fixed self-service checkbox appearing when iOS or iPadOS app is selected. ###### Fleet's agent The following version of Fleet's agent (`fleetd`) support the latest changes to Fleet: 1. [orbit-v1.33.0](https://github.com/fleetdm/fleet/releas _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.57.0]_