# Fleet v4.77.0 - Product: Fleet (https://whatsnew.fyi/product/fleet) - Vendor: Fleet Device Management - Date: 2025-12-02 - Version: v4.77.0 - Original notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.77.0 - Permalink: https://whatsnew.fyi/product/fleet/releases/v4.77.0 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **added** — Activity log entries for host deletion and expiration, updating or deleting host IdP mappings - **fixed** — Multiple false positive vulnerability matches for the VSCode golang extension - **fixed** — False positive CVE matches for Logi Bolt.app - **added** — Detection of vulnerabilities in JetBrains IDE plugins - **changed** — MDM enrollment flow for BYOD macOS hosts to enable end user authentication prior to downloading the MDM profile via the My device page - **added** — Self-service install support for custom IPA apps on iOS and iPadOS - **added** — Support for in-house .ipa apps to fleetctl gitops - **changed** — POST /setup_experience/script endpoint to allow updating the macOS setup experience script in-place and modified GitOps to remove the DELETE call - **added** — Support for Custom EST certificate authorities - **added** — Ability to deploy certificates from Custom SCEP certificate authorities on Windows - **added** — Status counts to batch script detail page tabs - **added** — InstallAnywhere as a self-extracting archive for PE metadata extraction - **added** — Ingestion of upgrade_codes from Windows software and provided to all relevant software endpoints - **changed** — Performance of /api/latest/fleet/software/versions API endpoint - **changed** — Host expiry logic to not delete macOS hosts that checkin via MDM protocol but not via fleetd - **changed** — Apple host profiles cleanup query to reduce probability of DB locking - **added** — Experimental FLEET_MDM_ENABLE_CUSTOM_OS_UPDATES_AND_FILEVAULT configuration to allow deploying custom OS settings including Filevault payloads and macOS and Windows update settings - **added** — Ability to change software display names in the UI - **fixed** — Table styling for selecting table rows - **fixed** — Installer for Cisco Secure Client not showing as installed in inventory/library due to using the wrong bundle identifier ##### Fleet 4.77.0 (Dec 02, 2025) ###### Security Engineers - Added activity log entries for: host deletion and expiration, updating or deleting host IdP mappings. - Resolved multiple false positive vulnerability matches for the VSCode golang extension. - Resolved false positive CVE matches for [`Logi Bolt.app`](https://support.logi.com/hc/en-us/articles/4418089333655-Logi-Bolt-App). - Detected vulnerabilities in JetBrains IDE plugins. ###### IT Admins - Updated MDM enrollment flow for BYOD macOS hosts to enable end user authentication prior to downloading the MDM profile via the "My device" page. - Added self-service install support for custom IPA apps on iOS and iPadOS. - Added support for in-house (".ipa") apps to `fleetctl gitops`. - Updated existing `POST /setup_experience/script` endpoint to allow updating the macOS setup experience script in-place, and modified GitOps to remove the `DELETE` call. - Added support for Custom EST certificate authorities. - Added ability to deploy certificates from Custom SCEP certificate authorities on Windows. - Added status counts to batch script detail page tabs. - Added `InstallAnywhere` as a self-extracting archive for PE metadata extraction. - Added ingestion of `upgrade_code`s from Windows software, and provided to all relevant software endpoints. ###### Other improvements and bug fixes - Improved performance of `/api/latest/fleet/software/versions` API endpoint. - Updated host expiry logic to not delete macOS hosts that checkin via MDM protocol but not via `fleetd`. - Optimized the cleanup Apple host profiles query to reduce probability of DB locking. - Implemented UI logic to call existing manual update IdP API functionality. - Implemented UI logic and new DELETE endpoint to manually remove host IdP mappings. - Added experimental `FLEET_MDM_ENABLE_CUSTOM_OS_UPDATES_AND_FILEVAULT` configuration to allow deploying custom OS settings including Filevault payloads and macOS and Windows update settings. - Added ability to change software display names in the UI. - Fixed table styling for selecting table rows. - Simplified setup experience configuration UI. - Added better error messages when using build-in labels on GitOps and on the LabelSpecs endpoint. - Hid software host count and version table when no hosts have the software installed. - Adjusted UI section headers and layout of Settings > Integrations in Fleet Free. - Added vulnerability seeding and performance testing tools. - Moved end user authentication SSO settings under Integrations > SSO in global settings. - Removed the premium check for host OS settings in host summary UI. - Reduced Android device reconciler frequency to 1 hour. - Reduced Android API usage by listing devices instead of getting and checking Android Enterprise disconnects hourly. - Set the order of software installed during the setup experience to alphanumeric. - Updated Go to 1.25.3. - Fixed a layout issue on the script batch details page. - Fixed installer for Cisco Secure Client not showing as installed in inventory/library due to using the wrong bundle identifier. This application should show up correctly now in the software inventory. - Fixed errors when trying to run the `apple_mdm_iphone_ipad_refetcher` cron job. - Fixed bug that prevented users from editing custom EST certificates URLs. - Fixed incorrect UI placeholder element by replacing it with it's actual value. - Fixed issue where vulnerabilities would occasionally show as missing. > Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade. ###### Fleet's agent The following version of Fleet's agent (`fleetd`) support the latest changes to Fleet: 1. [orbit-v1.50.1](https://github.com/fleetdm/fleet/releases/tag/orbit-v1.50.1) 2. `fleet-desktop-v1.50.1` (included with Orbit) 3. `osquery-5.20.0` (included with Orbit) 4. [fleetd-chrome-v1.3.3](https://github.com/fleetdm/fleet/releases/tag/fleetd-chrome-v _[Truncated at 4000 characters — full notes: https://github.com/fleetdm/fleet/releases/tag/fleet-v4.77.0]_