Fleet v4.79.0

v4.79.0
Added 14
  • Added ability to view past and upcoming MDM commands for a host in Fleet
  • Added ability to apply Android app configurations
  • Added support for resending Windows MDM profiles
  • Added support for renewal of custom SCEP profiles for Windows
  • Added support for team-specific labels
  • Implemented ability to create, list, and delete Android certs from the UI
Changed 2
  • Implemented streaming for the GET /hosts API to improve performance
  • Changed the host details page to hide builtin labels in-line with other areas such as the label filter
Fixed 4
  • Fixed host query report to display 'Report clipped' when a query has reached the 1k result limit
  • Fixed an issue where batch uploading .mobileconfig profiles failed due to display name checks
  • Fixed an issue where GitOps would fail if $FLEET_SECRET contained XML characters in XML files due to not escaping the value
  • Fixed a bug where iOS and iPadOS hosts enrolling via ABM MDM Migration did not have VPP apps installed
Fleet 4.79.0 (Jan 14, 2025)
IT Admins
  • Added ability to view past and upcoming MDM commands for a host in Fleet.
  • Added ability to apply Android app configurations.
  • Added support for resending Windows MDM profiles.
  • Added support for renewal of custom SCEP profiles for Windows.
  • Added support for team-specific labels. Currently team-specific labels must be created via spec endpoints, used by GitOps.
  • Implemented ability to create, list, and delete Android certs from the UI.
  • Added Android agent application (automatically deployed via Android MDM) to support automated installation of SCEP certificates on Android hosts.
  • Added messaging around Apple VPP update failures due to the application being open.
  • Added ability to indicate that new MacOS hosts enrolling via ADE should be updated to the latest operating system version.
  • Added ability to edit Android software config in UI.
Security Engineers
  • Added support for ingesting Windows certificates via osquery.
  • Added activities for when certificates templates are created/deleted.
Other improvements and bug fixes
  • Implemented streaming for the GET /hosts ("list hosts") API to improve performance.
  • Updated API and GitOps to support AppleOSUpdateSettings.UpdateNewHosts.
  • Added ability to search teams in dropdown when transferring teams.
  • Added pagination metadata to the GET /mdm/commands endpoint.
  • Updated the refresh_vpp_app_versions cron job to only attempt to refresh versions for Apple app store apps.
  • Improved edit VPP UX by disabling a form that hasn't been edited.
  • Updated logic used for determining whether to update a macOS host during DEP enrollment based solely on UpdateNewHosts flag.
  • Added note to descriptions on schema tables using "count" as column name.
  • Aligned Android MDM unenrollment endpoint with the already existing endpoint, DELETE /api/latest/fleet/hosts/{id}/mdm, for consistency across MDM platforms.
  • Added migration for adding update_new_hosts flag to both App and Team configs.
  • Changed the host details page to hide builtin labels in-line with other areas such as the label filter.
  • Changed iOS/iPadOS and Android enrollment links on Add hosts modal to monospaced font to improve readability.
  • Improved software upload progress modal.
  • Improved consistency of gitops output language.
  • Added loading state to turn off Android modal UI.
  • Updated the migrate_to_per_host_policy cron job to no-op if Android MDM is not enabled.
  • Updated software table so that all teams selection will now remove any unsupported url params.
  • Improved unclear error message when uploading an APNS certificate if the CSR was not downloaded.
  • Refactored RDS IAM authentication logic into a dedicated rdsauth package.
  • Modified the automatic enrollment profile verification logic to only verify with Apple when a profile changes
  • Updated S3 username/password when running in dev mode to remove outdated mentions of MinIO.
  • Hid option to transfer hosts to their current team.
  • Updated setup experience links to point to add software page relevant to platform.
  • Revised auth requirements for /debug endpoints.
  • Added additional validation to URL parameter for MS MDM auth endpoint.
  • Improved SOAP message validation on Windows MDM endpoints.
  • Fixed host query report to display "Report clipped" when a query has reached the 1k result limit.
  • Fixed UI error message regarding adding software to a team with a duplicate title.
  • Fixed an issue where batch uploading .mobileconfig profiles failed due to display name checks.
  • Fixed an issue where certificate details modal overflowed the screen.
  • Fixed click area of edit software file button.
  • Fixed an issue where GitOps would fail if $FLEET_SECRET contained XML characters in XML files, due to not escaping the value.
  • Fixed query behind fleetctl get mdm-commands to correctly get completed Windows MDM commands.
  • Fixed MDM install command output to correctly display UTF-8 characters in the UI.
  • Fixed missing upgrade code persistence when adding Windows software to Fleet via GitOps.
  • Fixed duplicate entry error when updating upgrade_code during software ingestion
  • Fixed case sensitivity mismatches causing duplicate titles during software ingestion
  • Fixed a bug where iOS and iPadOS hosts enrolling via ABM MDM Migration did not have VPP apps installed.

Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade.

Fleet's agent

The following version of Fleet's agent (fleetd) support the latest changes to Fleet:

  1. orbit-v1.50.2
  2. fleet-desktop-v1.50.2 (included with Orbit)
  3. osquery-5.21.0 (included with Orbit)
  4. fleetd-chrome-v1.3.3
  5. fleetd-android-v1.0.2

While newer versions of fleetd still function with older versions of Fleet, old versions of fleetd and osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet.

Upgrading

Please visit our upgrade guide for upgrade instructions.

Documentation

Documentation for Fleet is available at fleetdm.com/docs.

Binary Checksum

SHA256

532857020b0f1a46cdb5ad16f215d3b3264ebf0bb97754b302b6cce97255927a  fleet_v4.79.0_linux.tar.gz
51c169304d14383a38e74b81e19b34c562c91e14ef0f23037062a66721611415  fleetctl_v4.79.0_linux_amd64.tar.gz
ed128983f454c39cdb93b7e204c90fc9f172db81b8e98c9f754be9430a53b9a3  fleetctl_v4.79.0_linux_amd64.zip
d996e16bf6de750815a536a9c3e1bf0821bcc71e7d4a2fddaa705cdfa6558876  fleetctl_v4.79.0_linux_arm64.tar.gz
7fa1cbbb2234855321f840c41bd7935fe292615dde2c4af214f2e65ed3e9b56d  fleetctl_v4.79.0_linux_arm64.zip
3ccf4c1b47992574a88938bbb3064e729e93886c392af55a417fb57abfb22605  fleetctl_v4.79.0_macos.tar.gz
d03d43987893597d2c45bafa268bcfe7f89331f41ba93fec1415aa303f68a16e  fleetctl_v4.79.0_macos.zip
7438b13ae5be9ad38e647a7880ea74220a801e4573db99a41de3b17641cb3dae  fleetctl_v4.79.0_windows_amd64.tar.gz
99469dc84555612ebcc31e0a24ad806891f2a9d46fa96f6b1e7790297fa54858  fleetctl_v4.79.0_windows_amd64.zip
91ff4bc4936dabe7ee183d2fdc30b55cc3c2d8eefd3247ba52071039ecf038b2  fleetctl_v4.79.0_windows_arm64.tar.gz
af67a95a3195d4bcb8719612dc823705183736aa6d68b596d1c3dcf3bcb738ee  fleetctl_v4.79.0_windows_arm64.zip
View original

Upgraded? How did it go?

Discussion