版本发布 8
### Bug fixes - Fixed policy creation failing when type was omitted. - Fixed auth token not persisting when logging in via SSO. - Fleet UI: Fixed infinite page loop pagination bug on software table page happening when viewing a subsequent page and then using the software filter dropdown to filter. - Fleet UI: Fixed software table page number to be bookmarkable ### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` 441e87e397898df479f0ef2cece844a40d43954e5481e2ff5ca02b45ddf2e589 fleet_v4.83.1_linux.tar.gz 66db9fb3c7eb517afc7e6200ae5187b6697c032ba49bebd0d68cce6e34a522c1 fleetctl_v4.83.1_linux_amd64.tar.gz 3ba7302fe8d7ed6940d249163fb1f4ddedb1b83adc61928e31994482ea8d2f47 fleetctl_v4.83.1_linux_amd64.zip c474120d20e4faedd57d8a82fc5fd9d87f29b03f0307daba1815cb6ae3c614d9 fleetctl_v4.83.1_linux_arm64.tar.gz 56f9bdb2f2532f855ef568a908a20c211b0d64afb673c5de9cec22fe5e138e51 fleetctl_v4.83.1_linux_arm64.zip 89576e2506797b631d80672f02a9e5ce7e3fc80dbcbc8a7f2db615568c158cca fleetctl_v4.83.1_macos.tar.gz 2b28948788d53bdbf72a53e064f5de781409c4e2df2b4a0db6517ef5f905e3c5 fleetctl_v4.83.1_macos.zip 7a83a83b1cce5ca3cdf66d27fb57c0b4470797143fc2771df3ce8f405153c63d fleetctl_v4.83.1_windows_amd64.tar.gz 4d6ef7d46b6cf2e3d1c9da8457e7c4959b2fe05f70fb39baff423d57508bbf50 fleetctl_v4.83.1_windows_amd64.zip 4eca5f033644966859eb44df73962b98d687c926ee56d83276982cf166515a7a fleetctl_v4.83.1_windows_arm64.tar.gz 5fd20d2dc1a9a62ddb256f52ef06d707db9edb44d4005f7b955d20904df3e2cb fleetctl_v4.83.1_windows_arm64.zip ```
### Bug fixes - Fixed a crash on the "My device" page for Fleet Free instances. The page returned a 402 error when the host was assigned to a team because the device endpoint called a premium-only API, and also crashed when accessing undefined policies data. - Stopped duplicate Fleet-maintained app entries from showing up in setup experience. - Reduced database contention during the vulnerability cron. - Added a secondary index on `host_software(software_id)` to improve query performance. - Fixed an issue where the "add Fleet-maintained app" endpoint incorrectly added software to the Unassigned fleet. - Muted deprecation warnings for body params when the "deprecated-field-names" topic is not enabled. - Fixed custom app icons not getting set via GitOps when the same software title exists in multiple teams. ### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` e20f5e600b04e5e76b97cc4d72d25857996401e50b30c349c33d814d25e60a17 fleet_v4.82.1_linux.tar.gz 2bf908c90db1b310e0806b614dc3d01620a36cd30771db713374023a3487cbdd fleetctl_v4.82.1_linux_amd64.tar.gz 98daf26686fc909ca0aa396c9b379a98c4aa381b082141fa4b5a5c9143145bfe fleetctl_v4.82.1_linux_amd64.zip 6c9701ab0fe725389aa411766ab2012972d9b7a01bb994ffb9ca65b5884c2034 fleetctl_v4.82.1_linux_arm64.tar.gz 04cb955bcccf23334a24dbe36a35d9f8a8a1b84a1948f9217653c5553f601f6f fleetctl_v4.82.1_linux_arm64.zip 965147846622d1e4c52689fa8ee044c3dfd884b2c523c13f29a0d676b0e8bd46 fleetctl_v4.82.1_macos.tar.gz 50b332c3bfe7aaefd7dedd6537d8c347b314786b6f90494176f807a75977455d fleetctl_v4.82.1_macos.zip 740ddd324b592b0e48a0ecd25d8da9df9eb889439e9b23c4fbc45e9cf80b972a fleetctl_v4.82.1_windows_amd64.tar.gz 5913036d550e30bedafc6f309f0a72058b6e45e65b5d247a0b056f3f2ff71c60 fleetctl_v4.82.1_windows_amd64.zip b348a265022cd1311db5cd4a8a4faf754ce155dee2360e7e86a5caf4bfcfc64b fleetctl_v4.82.1_windows_arm64.tar.gz 18330c5416c54739beddfb23d49f4cc9daa30de6e226d2cff3407738477db07e fleetctl_v4.82.1_windows_arm64.zip ```
## Fleet 4.80.3 (Feb 20, 2026) ### Bug fixes - Fixed validation and error handling issues. > Fleet-maintained app updates and vulnerability feed fixes are applied, whether or not you upgrade. ### Fleet's agent and fleetctl CLI The following version of Fleet's agent (fleetd) and fleetctl support the latest changes to Fleet: 1. [orbit-v1.52.1](https://github.com/fleetdm/fleet/releases/tag/orbit-v1.52.1) 2. `fleet-desktop-v1.52.1` (included with Orbit) 3. `osquery-5.21.0` (included with Orbit) 4. [fleetd-chrome-v1.3.5](https://github.com/fleetdm/fleet/releases/tag/fleetd-chrome-v1.3.5) 5. [fleetd-android-v1.0.2](https://github.com/fleetdm/fleet/releases/tag/fleetd-android-v1.0.2) > While newer versions of fleetd and fleetctl still function with older versions of the Fleet server (and vice versa), Fleet does not actively test these scenarios and some newer features won't be available. ### Upgrading Please visit our [upgrade guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` c83b87c6cddf052c4b44798d1d618563f7e965201cbe9c11638a5b72ad2a6a2c fleet_v4.80.3_linux.tar.gz a0cf0ead01feda43be097d0ce868ac56d5473885ef51b76be82f3bd7c7dcda0c fleetctl_v4.80.3_linux_amd64.tar.gz 6c39466958adbe599a412059702ddce3868b9799da611112e8b9c4f77888b87f fleetctl_v4.80.3_linux_amd64.zip e8f983a032bf602aaa51332528aa88d50590ad317518ec0325bb2b52416fd745 fleetctl_v4.80.3_linux_arm64.tar.gz d7c615162205455dbb097a1e3a5c28e78d27eba503777b54273b9224648258c7 fleetctl_v4.80.3_linux_arm64.zip 8b3e22ed1ba700d89e0d1783e200f64bb5501ee878d6cd0776c0be531bdba046 fleetctl_v4.80.3_macos.tar.gz 47fed78d73ecd1307ecad2589193e5532b870f5dc8707a1d9796c97a3218d718 fleetctl_v4.80.3_macos.zip a5a86cf892f5bc32242ddc74085669e033ba5a6c350928a1c29be97281422092 fleetctl_v4.80.3_windows_amd64.tar.gz 396d990f3cd5ff2b9ee2a73393f3a54b092e58cda3d9af2387f83f11969674a4 fleetctl_v4.80.3_windows_amd64.zip adebdb0c9dddfdd3a7db335c018e2d5dcb9e8aac96b3c4927ed082cd6cab2f9d fleetctl_v4.80.3_windows_arm64.tar.gz ad59b2d4d6a45b235848663d3fff566fec758f0b03b4e9b8718de3981794d070 fleetctl_v4.80.3_windows_arm64.zip ```
### Bug fixes - Improved SOAP message validation on Windows MDM endpoints - Revised auth requirements for /debug endpoints - Added additional validation to URL parameter for MS MDM auth endpoint ### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` f4a2912237059bbb782f519442406ae49285d5888f1d2c6692307c22d707e405 fleet_v4.75.2_linux.tar.gz fd01105903052a38c1c0542dd0837fab64beb81e20640bcc14611e310fca9403 fleetctl_v4.75.2_linux_amd64.tar.gz 3745b6e6894424cdd4ced29d4445fea94acbfb7bf9f6d6d26bb9628ee59f8b1f fleetctl_v4.75.2_linux_amd64.zip 5cf86eb721cf5cb12f8552845fcd2f097f4182c42efbb7834c3c5edc013d661a fleetctl_v4.75.2_linux_arm64.tar.gz 8817c72f016704fac43146fd0f50290cbeabddd5c31ead9087fb153c067cc20f fleetctl_v4.75.2_linux_arm64.zip 31a3f5f057f075e499ddc86c32769a9f26c47a6fe197b4ad1752b374fdb7aeda fleetctl_v4.75.2_macos.tar.gz 2134bf29f762368a5e2a8ccb2d28014834a1a5ccd451bd99dcf5eebc184a426d fleetctl_v4.75.2_macos.zip c86bb2efe8113201ede7b2ec9e727d8589f41fb23d1ca88d5733cd0dc6fae68e fleetctl_v4.75.2_windows_amd64.tar.gz f9678a604d419266b35d43378c9bff6d0c7767e6acdc74ebabd7857aa45b5956 fleetctl_v4.75.2_windows_amd64.zip 16cb60a38bd66be3fab396528aaed991a2528a4609b6f25bc5d8a453aab0e51c fleetctl_v4.75.2_windows_arm64.tar.gz 7bf75c69cba73124966b374531af774cba4801b22aaa3b8f7c4a12dae7d95e9c fleetctl_v4.75.2_windows_arm64.zip ```
### Bug fixes - Added additional validation to URL parameter for MS MDM auth endpoint ### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` 3c0fb6373c6a87c7a8916c4f98066ea6843b02ad2586db9333ae990f63c6ae9e fleet_v4.78.2_linux.tar.gz 5302b78e17a512fd44add3c9ba9e58f79f52d2e9dc526a2759720a5252e6ee11 fleetctl_v4.78.2_linux_amd64.tar.gz 2fdf8bf785cfa4f354d78feb081e7c904568113913c3cfc8c72dcc4246aff568 fleetctl_v4.78.2_linux_amd64.zip 302814ea80c1684fc0f5d54340bdf37a33e72bae21ee5a8c65e0c4a660ad32f1 fleetctl_v4.78.2_linux_arm64.tar.gz e4efd7f8f64f71cdc4f0cec00d9ae6e1a9fe7e4356b27307726f061386525690 fleetctl_v4.78.2_linux_arm64.zip 4658b0d3ba46f4b390ed2d2f700e35ae71a6b9aacb47e7ec6f3d62a6366445d4 fleetctl_v4.78.2_macos.tar.gz e41d2a963f9e9e9aab5a1e2008660c4ccc91d814b8fd7b99b2fcc3f738b275d3 fleetctl_v4.78.2_macos.zip b89a98d079e077838b9e396e82841da2b0f3e0a9dc46814bd55ce2a3c8e47773 fleetctl_v4.78.2_windows_amd64.tar.gz 3ffd1c548bcca390a10f586afbd48632a318dee790aa05c0b7ac8b4b78ee12a8 fleetctl_v4.78.2_windows_amd64.zip 030fd16627f907a379ea69c05be8612e2fbe99a65a1438cc43a8642284419a7b fleetctl_v4.78.2_windows_arm64.tar.gz bfd111fa990523196afeea3a009f56a682b1f5ed41cfc3c8201c0566cc13739f fleetctl_v4.78.2_windows_arm64.zip ```
## Fleet 4.78.0 (Dec 19, 2025) ### IT Admins - Added support for Android setup experience software installation. - Added support for Android self-service apps to `fleetctl gitops`. - Added support for Android `systemUpdate` profiles. - Added ability to create/view/delete Google Play Store software for Android in UI. - Added `$FLEET_VAR_HOST_PLATFORM` for Apple platforms (`macos`, `ios`, `ipados`). - Added support for installation of setup-experience VPP apps on manually-enrolled iOS/iPadOS devices. - Added ability to deploy user-scoped SCEP profiles for Windows hosts. - Added a configuration option to require Windows users turn on MDM manually via work or school account, rather than have enrollment happen automatically. - Added UI to allow Windows hosts to manually enroll into Fleet MDM. - Added support for `$FLEET_VAR_HOST_HARDWARE_SERIAL` and `$FLEET_VAR_HOST_PLATFORM` in Windows profiles. ### Security Engineers - Added ability to filter the activites on the dashboard page. - Updated to regenerate FileVault profile when Apple MDM is turned on if the device's team has disk encryption enabled. - Added Okta conditional access configuration to the Fleet UI under Settings -> Integrations -> Conditional access. - Added endpoint for hosts to update certificate status. - Added detail column to `host_certificate_template` table and added `certificate_templates` property with GitOps support. - Updated `fleetd/certificates/<id>` and `fleetd/certificates/<id>/status` to authenticate using the orbit_node_key provided in the `Authentication` header. - Updated MDM-enrolled Android devices to receive certificate templates in `managedConfigurations`. ### Other improvements and bug fixes - Improved performance by making the `host_count` property optional in the `GET /labels` API endpoints. - Improved performance by avoiding unneeded extra queries when fetching team information. - Improved request validation by returning an informative error when trying to filter `software_titles` with `platform` without a `team_id`. - Allowed users to save Fleet queries even if their SQL is deemed invalid by the Fleet UI. - Added a new error UI for file uploaders, and applied it in the Okta Conditional Access modal. - Returned pre-install query output in Install Details modal. - Translated `idp` to `mdm_idp_accounts` on API responses. - Updated `last_restarted_at` property for hosts to be more reliable. - Added Mosyle to the list of well-known MDM platforms. - Changed where `mdm_enrolled` activity is created so it occures after the inital Token Update command to allowa the webhook to fire after the host can recieve additonal commands from Fleet MDM. - Improved MDM command result endpoint response for pending Windows commands. - Switched configurations referencing Redis 5 to Redis 6. Fleet is no longer verified to work with Redis 5 or below. - Redacted API tokens in `fleetctl config set` to prevent accidental logging. - Updated error message when attempting to run software install script on host with scripts disabled to refer to `--enable-scripts` flag (instead of `--scripts-enabled`). - Updated queries APIs that drive the OS Settings UI to include the status of host cert templates. - Updated the layout and styling of file uploader buttons across the UI. - Updated built-in SVG icons to avoid rendering issues when certain combinations of icons are on the same page. - Added consistant spacing to UI elements on the MDM page. - Updated Go to 1.25.5. - Fixed an issue where using bitwise operators in a query incorrectly marked the query as invalid. - Fixed issue where MDM profile retry limits were interfering with Smallstep SCEP proxy renewal attempts, particularly in cases of expired SCEP challenges. - Fixed incorrect status code on failure to interpolate certificate template variables. - Fixed Android configuration profiles downloading as unusable .xml files with content `[object Object]`. Android profiles now download correctly as .json files with properly formatted JSON content, matching what was originally uploaded. - Fixed the tab order of elements in the login form. - Fixed UI bug where the option to resend MDM profiles for macOS hosts was incorrectly presented to non-admin and non-maintainer users. - Fixed an issue that prevented GitOps from saving multiple queries with the same label. - Fixed an issue where "Exclude Any" label scoping did work properly for iOS, iPadOS and Android hosts. - Fixed bug that prevented filtering by platform when listing hosts with failed profiles. - Fixed software action buttons to disable immediately on click to prevent multiple clicks. - Fixed an issue where newly-enrolled Windows or Linux hosts were not automatically linked with existing SCIM user account data. - Fixed UI bug in OS settings modal that caused status tooltip to flicker when refetching host details. - Fixed a race condition when resending Apple Profiles that would not truly resend the latest profile. - Fixed a missing redirect to the Fleet website. - Fixed the connect message on the controls end user auth page so that it is consistant with the other set up experience subsections. - Fixed a bug where "installed" software sometimes showed up as "uninstalled" when certain other pieces of data were not also present. > Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade. ### Fleet's agent The following version of Fleet's agent (`fleetd`) support the latest changes to Fleet: 1. [orbit-v1.50.2](https://github.com/fleetdm/fleet/releases/tag/orbit-v1.50.2) 2. `fleet-desktop-v1.50.2` (included with Orbit) 3. `osquery-5.21.0` (included with Orbit) 4. [fleetd-chrome-v1.3.3](https://github.com/fleetdm/fleet/releases/tag/fleetd-chrome-v1.3.3) > While newer versions of `fleetd` still function with older versions of Fleet, old versions of `fleetd` and osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet. ### Upgrading Please visit our [upgrade guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` a75667c3362b5ffa11d1c95e2839aeb4fe74cd274994aee08148fd6179527c74 fleet_v4.78.0_linux.tar.gz 5753557878a06de58c7aabdc2d55f27792ccacaed43ff9cc41ed9ef9f52bd943 fleetctl_v4.78.0_linux_amd64.tar.gz ed9bf44b737e2285066ccf0c0f0fa328b7d6ec0033edb119183e4ded5d20f2c2 fleetctl_v4.78.0_linux_amd64.zip 1ba0a5d96566efed20a1ce96d3303e42ff2a0b7b8d3527bb35066efdb23ca5a0 fleetctl_v4.78.0_linux_arm64.tar.gz cfd528a01f463a6b5afcc696fbaffc896b4f4a4e8a8dde6034eff9fa1082f582 fleetctl_v4.78.0_linux_arm64.zip c6b2ad11c958f38b53168ee9396f6bded3ed5f863c253ade07eaf00921672488 fleetctl_v4.78.0_macos.tar.gz e721bd5cf7c2fc378dc968cb24d229590bfd376226d50387d2ad1db42c17cb50 fleetctl_v4.78.0_macos.zip a188080d9c972dc883e1a268a4d040dadf7912901a7a91c25c9e4f640396054b fleetctl_v4.78.0_windows_amd64.tar.gz 8c41eafab9cb38e4a97b464f86e926da12c7b0531f848a3c306dc04ecfd7960c fleetctl_v4.78.0_windows_amd64.zip 87e80393f956b137571cf6bce870c3eb0256c155d0ea76cef69fba1d6b5ca49c fleetctl_v4.78.0_windows_arm64.tar.gz e3aeddceada71115e53d86f74b8300566660cb44e2229c4cbd4f97d96ee668e7 fleetctl_v4.78.0_windows_arm64.zip ```
### Bug fixes - Fixed `fleetctl generate-gitops` when MDM is not turned on. - Reduced load on migration from 4.74.0 and below. ### Upgrading Please visit our [update guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` 579c79becb7bea7812185150fd0706e161b3f4753f81302d920aba9bfc2bf3a4 fleet_v4.75.1_linux.tar.gz 77afc5ca0f1051f41b787c52ffd401fbe1eaefc4a7d1859732f87f8491828b99 fleetctl_v4.75.1_linux_amd64.tar.gz c170ac336de734ddd86d3039761bf58be3261ff34685a1df2539d9661113e713 fleetctl_v4.75.1_linux_amd64.zip 91a2d95d08a52327882385883c43ad51b7a580c49f8db3ee887808c9d3222e72 fleetctl_v4.75.1_linux_arm64.tar.gz a8a628d01e789611452ef3ce715eb7fc7f5e1bac5658a2c4965ab7b9a059b7d4 fleetctl_v4.75.1_linux_arm64.zip b7571b281fdb8ea4e419248c3cff4f5df772133527e3c2645f46c42a6eb0f5ac fleetctl_v4.75.1_macos.tar.gz 149dfe86fcf295e66e05e53f511988f859452e9f167f5dcfa0389f7f29bc1c36 fleetctl_v4.75.1_macos.zip aca922953dda7f9760df7d2f3fd707e6f0edb9b92c18f037adb4a06a66d6e7aa fleetctl_v4.75.1_windows_amd64.tar.gz 9465a688d4ded8193490edd889f9859cefae3550eea5ab783558db370f5b3ed8 fleetctl_v4.75.1_windows_amd64.zip 1bc35a50adba0336d86a6dcb7d21a9226d1fae0422b6993f465ed90249e2819e fleetctl_v4.75.1_windows_arm64.tar.gz 4d6c09b7afa67ba3a129a2e9eeb9d8b45aa75c43cb70e4939c63f4570204ebf2 fleetctl_v4.75.1_windows_arm64.zip ```
## Fleet 4.74.0 (Oct 6, 2025) ### Security Engineers - Added support for Hydrant as a Certificate Authority and added an experimental API that can be used to have Fleet request a certificate from a Hydrant. - Added a check to disallow FLEET_SECRET variables in Apple configuration profile `<PayloadDisplayName>` fields for security. - Added `/batch/{batch_execution_id:[a-zA-Z0-9-]+}/host-results` API endpoint to list hosts targeted in batch. - Added `POST /api/v1/fleet/configuration_profiles/batch` API endpoint to batch modify MDM configuration profiles. - Added a new page in the UI for batch script run details. - Added support for AWS RDS (MySQL) IAM authentication. - Added support for AWS ElastiCache (Redis) IAM authentication. - Added support for hosts enrolled with Company Portal using the legacy SSO extension for Entra's conditional access. ### IT Admins - Added setup experience software items for Linux devices. - Added API endpoints for Linux setup experience. - Device API endpoints for fleetd: `POST /api/fleet/orbit/setup_experience/init` and `POST /api/v1/fleet/device/{token}/setup_experience/status`. - `PUT /api/v1/fleet/setup_experience/software` and `GET /api/v1/fleet/setup_experience/software` now have a `platform` argument (`linux` or `macos`, defaults to `macos`). - Added IdP `fullname` attribute as a valid Fleet variable for Apple configuration profiles. - Added the username of the managed user account user-scoped profiles are delivered to for macOS hosts. - Enabled configuring webhook and ticket policy (Jira/Zendesk) automations for "No team". - Added support for writing multiple packages in a single GitOps YAML file included under `software.packages`. - Moved `self_service`, `labels_include_any`, `labels_exclude_any`, `categories`, and `setup_experience` declarations to team level for software in GitOps; `setup_experience` can now be set on a software package, Fleet Maintained App, or App Store app. - Changed `GET /host/:id` to return an empty array for `software` field when `exclude_software=true`. - Updated `generate-gitops` command to output filenames with emojis and other special characters where applicable. - Added a Fleet-maintained app for macOS: Omnissa Horizon Client. - Added opening instructions to self-service macOS apps and Windows programs. ### Other improvements and bug fixes - Added index to `distributed_query_campaign_targets` table to speed up DB performance for live queries. > **WARNING:** For deployments with millions of rows in `distributed_query_campaign_targets`, the database migration to add the index may take significant time. We recommend testing migration duration in a staging environment first. The initial cleanup of old campaign targets will occur progressively over multiple hours to avoid database overload. - Added clean up of live query campaign targets 24 hours after campaign completion. This keeps the DB size in check for performance of large and frequent live query campaigns. - Improved OpenTelemetry integration to add tracing to async tasks (host seen, labels, policies, query stats) and improve HTTP span naming, enabled gzip compression, reduced batch size to prevent gRPC errors. - Updated output from `packages_only=true` so that it only returns software with available installers. - Added tarballs summary card back into UI. - Improved the sorting of batch scripts in the Batch Progress UI. Batches in the "started" state now sort by started date, and batches in the "finished" state now sort by the finished date. - Removed inaccurate host count timestamp on the software version details page. - Downgraded "distributed query is denylisted" error to a warning on the Fleet server since this message indicates a likely issue on the host and not the server. We will surface this issue in the UI in the future. - Improved performance for YARA rules: when modifying config (`PATCH /api/latest/fleet/config`) with a large number of yara rules and when large numbers of hosts fetch rules via /api/osquery/yara/{name} endpoint. - Improved performance when updating multiple policies in the UI. The policies are now updated in series to reduce server/DB load. - Added user icon to OS settings custom profiles on host details page if they are user scoped. - Added clearer error messages when a new password doesn't meet the password criteria. - Removed extra spacing from under disk encryption table. - Updated `fleetctl get mdm-command-results` to show output in a vertical format instead of a table. - Optimized os_versions API response time. - Added logic to detect and fix migration issues caused by improperly published Fleet v4.73.2 Linux binary. - Refactored ApplyQueries DS method so that queries are upserted in batches, this was done to avoid deadlocks during large gitops runs. - Refactored the way failing policies are computed on host details endpoint to avoid discrepancies due to read replica delays and async computation. - Refactored PATH fleet/config endpoint to use the primary DB node for both persisting changes and fetching modified App Config. - Fixed missing ticket integration options in Policies -> Other workflows modal for teams. - Fixed deduplicating bug in UI to only count unique vulns when counting software title vulnerabilities across versions in various software title vulnerabilities count, and host software title vulnerabilities count. - Fixed cases where the default auto-install policy for .deb packages would treat installed-then-uninstalled software as still installed. - Fixed the message rendered from user_failed_login global activities on the Activity feed if the email is not specified. - Fixed fleetctl printing binary data to terminal in debug mode. - Fixed a bug where incorrect CVEs were received from MSRC feed. - Fixed Fleet-installed host count not updating after software is installed over an older version. - Fixed UI issue in the Dashboard page. The software card is now rendered while content is been fetched to avoid the layout to jump around. - Fixed error when updating a script to exactly match the contents of another script. - Fixed an issue where string concatenations in a LIKE expression caused a syntax error in the query editor. - Fixed `fleetctl gitops` issue uploading an Apple configuration profile with a FLEET_SECRET in a `<data>` field. - Fixed Linux lock script on Ubuntu with GDM to now switch UI to text mode to work around GUI issues. - Fixed Google Cloud Storage (GCS) support broken since Fleet 4.71.0 by implementing a workaround for AWS Go SDK v2 signature compatibility issues with GCS endpoints. - Fixed banner link colors in UI. - Fixed an alignment issue on the My device page. - Fix deadlocks when updating automations for 10+ policies at one time. > Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade. ### Fleet's agent The following version of Fleet's agent (`fleetd`) support the latest changes to Fleet: 1. [orbit-v1.47.2](https://github.com/fleetdm/fleet/releases/tag/orbit-v1.48.1) 2. `fleet-desktop-v1.48.1` (included with Orbit) 3. [fleetd-chrome-v1.3.3](https://github.com/fleetdm/fleet/releases/tag/fleetd-chrome-v1.3.3) > While newer versions of `fleetd` still function with older versions of the Fleet server (and vice versa), Fleet does not actively test these scenarios and some newer features won't be available. ### Upgrading Please visit our [upgrade guide](https://fleetdm.com/docs/deploying/upgrading-fleet) for upgrade instructions. ### Documentation Documentation for Fleet is available at [fleetdm.com/docs](https://fleetdm.com/docs). ### Binary Checksum **SHA256** ``` 530df71bda192c2468c2d0e26bfbcd76137decab25c7f80749e67c6bdce84167 fleet_v4.74.0_linux.tar.gz fa54e95129c4c33dd15245de7107cbcea666c9b83fc5facc54f1be9995ab1984 fleetctl_v4.74.0_linux_amd64.tar.gz 94865880a4514d2a0ccfb6e47746d13b030675286f8053b4e274934144b6a140 fleetctl_v4.74.0_linux_amd64.zip d1ae2a3ab9d51456cda7fe3e165f2a42213db95090d3a92bb94ebf302bd61b77 fleetctl_v4.74.0_linux_arm64.tar.gz 63acdbcbea1de155a45381e97dfb86cff286ff8d551ca803292fada84171153f fleetctl_v4.74.0_linux_arm64.zip 751d6b30d2cb0afd040fce9af784305c1a72c5d129fe1df1e47cd1a280f81019 fleetctl_v4.74.0_macos.tar.gz 696c8e59a2890bf03e68359db62ea5994ae273202748bc7fbdc6a6ab22761783 fleetctl_v4.74.0_macos.zip 44a549e26072d749a5328e8fbf2a831cfc69689254a9c424d13a862b41a232ac fleetctl_v4.74.0_windows_amd64.tar.gz 2cefc31893421fb2400d88323c5fbef0e6d57ec52fe5473eda2d6aaac563ee1d fleetctl_v4.74.0_windows_amd64.zip 701d0df3ad16e370303eca9cc16d0669079c93d0835e8513aa5e06187b069038 fleetctl_v4.74.0_windows_arm64.tar.gz 9f03fdde86877beb19547fcd09473edb65dec20c650598e4ae26f932f9df66b0 fleetctl_v4.74.0_windows_arm64.zip ```