Fleet Release Notes

Follow

61 release notes curated from 26 sources by the Releasebot Team. Last updated: Oct 4, 2026

Get this feed:
  • Oct 4, 2026
    • Date parsed from source:
      Oct 4, 2026
    • First seen by Releasebot:
      Oct 4, 2026
    Fleet logo

    Fleet

    fleet-v4.92.3

    Fleet releases bug fixes with improved SSO session handling, helping make sign-in sessions more reliable across the platform.

    Bug fixes

    Improved SSO session handling.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    ef05d274309a47207142c00904acb91ccfb7d4107e84e5fb34d46521b6d2d00e fleet_v4.92.3_linux.tar.gz
    a37a8ddee76145791b197925681aae8e3ace24e1f734efafb525dc1580ac8e6c fleetctl_v4.92.3_linux_amd64.tar.gz
    8455542cd6e2c6366ded842c3b597d9e4f12a5e3eecc3a4e1d3c504cebeadaa9 fleetctl_v4.92.3_linux_amd64.zip
    a7bf915904e6dbe2726f529467af7806a985ea71cd624776a3e9a0a2cd5c1b22 fleetctl_v4.92.3_linux_arm64.tar.gz
    15fc447c241075808d754b691e2ecca03e6269b5cc0078ce76f3e5a3fd31c2c2 fleetctl_v4.92.3_linux_arm64.zip
    6fa17a3907ac491cd015ea9d6e0950889049bc51b319fdf50654b81e6e623ffa fleetctl_v4.92.3_macos.tar.gz
    5deb2fc9da5ddacbc19a2c11f1d4237dadd8ddf22f195b59281900b9207af6de fleetctl_v4.92.3_macos.zip
    5c34e81094ba668f50dc03283848b32bcf142caf501fc9cee4b69b04627f0374 fleetctl_v4.92.3_windows_amd64.tar.gz
    af12c75a3cec83584bd2f9bcb6e82c3d531b13f354d910e6b3f74f8ee6634d57 fleetctl_v4.92.3_windows_amd64.zip
    c932e015c011322b871a366183a9ed0395bdcf6765d859c0e342f299e034c437 fleetctl_v4.92.3_windows_arm64.tar.gz
    3c8b5719d7ba2477c304f68f0e0f45ec250c58e608853ff3f6751441861981fc fleetctl_v4.92.3_windows_arm64.zip
    
    Original source
  • Oct 2, 2026
    • Date parsed from source:
      Oct 2, 2026
    • First seen by Releasebot:
      Oct 2, 2026
    Fleet logo

    Fleet

    fleetd-chrome-v1.3.6-beta

    Fleet releases fleetd-chrome 1.3.6.

    Release fleetd-chrome 1.3.6

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from Fleet and hundreds of other software products.

    Create account
  • Sep 30, 2026
    • Date parsed from source:
      Sep 30, 2026
    • First seen by Releasebot:
      Oct 1, 2026
    Fleet logo

    Fleet

    fleet-v4.92.2

    Fleet fixes Android Management API rate-limit retries so user actions like lock, wipe, and custom commands are less likely to drop, improves software page performance, and adds hourly cleanup for old software install and script results.

    Bug fixes

    Fleet now retries Android Management API calls that fail because the API rate limit was exceeded (HTTP 429), waiting 60 seconds and then backing off exponentially, so user-initiated actions like lock, wipe, and custom commands are no longer dropped on a transient rate limit. Background jobs (profile delivery, device reconciliation, software jobs) still fail fast and retry on their next run.

    Fixed software title details pages and the hosts list software status filter timing out for software with a large install history.

    Added an hourly cleanup that deletes software install and uninstall records more than 30 days old, configurable with server.software_install_results_retention.

    Improved the performance of applying scripts through GitOps on Fleet instances with a large script-run history.

    Added an hourly cleanup that deletes script results more than 30 days old, configurable with server.script_results_retention.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    cece684541a46faca40ba5821c7c6cf3248df381a4adb442291ec37eea3bccae fleet_v4.92.2_linux.tar.gz
    167fb6b8cbbd1f3c7ce80b92811be98724d4672c955c36f2e135162913450f60 fleetctl_v4.92.2_linux_amd64.tar.gz
    63def34fbe603ce45a0d375c4c7fddadffd09d7ad27d65e6b416e57bb22620a5 fleetctl_v4.92.2_linux_amd64.zip
    cdb2c087c60747e200660a98ba0cb81d619815b7b1a7f6eb638f00749db63e43 fleetctl_v4.92.2_linux_arm64.tar.gz
    aff1c3b9742f392159e4bf3d337963a7ab54e0981f4a68c72fcc4f06f086eeb2 fleetctl_v4.92.2_linux_arm64.zip
    2d0599c2f56fb14c53753f4353134b853d695ea8864d95b5d775a8ac426d9b8d fleetctl_v4.92.2_macos.tar.gz
    02249cbc4b9481578e60710380751774328bd8782572ddce96340402f2539cb2 fleetctl_v4.92.2_macos.zip
    a8c3fea6faac839c4c93d9f7505cc2babac4c470047ec4cb87245507e2bec3ce fleetctl_v4.92.2_windows_amd64.tar.gz
    1f0b3876881ec3a62ab2fed2e594fdff31c7cc35ca25d88fe6e4d15d901b5315 fleetctl_v4.92.2_windows_amd64.zip
    6b3f61ddb962c54ab583d082c8286223245514e1680c1e9ea721301f9b7042cd fleetctl_v4.92.2_windows_arm64.tar.gz
    74d61c87e91ba08030ac9439e7bfdfb6a83903965fb58d26ebc1a21529d25402 fleetctl_v4.92.2_windows_arm64.zip
    
    Original source
  • Sep 28, 2026
    • Date parsed from source:
      Sep 28, 2026
    • First seen by Releasebot:
      Sep 28, 2026
    Fleet logo

    Fleet

    fleet-desktop-macos-v1.5.1

    Fleet updates the schema used for mobileconfig and DDM profile generation.

    Website: update schema used for mobileconfig and ddm profile generati…

    Original source
  • Sep 25, 2026
    • Date parsed from source:
      Sep 25, 2026
    • First seen by Releasebot:
      Sep 26, 2026
    Fleet logo

    Fleet

    fleet-v4.92.1

    Fleet fixes several bugs in GitOps, software reporting, and macOS identity handling, including preventing repeated re-downloads of Fleet-maintained apps, improving blank software name display, and preserving IdP user details after certificate renewal or re-enrollment.

    Bug fixes

    Fixed GitOps re-downloading Fleet-maintained apps whose manifest carries no hash, such as 1Password, Google Chrome, Slack, Webex, and Zoom, on every run.

    Fixed software with an invisible reported name rendering as a blank row in Host details > Software, the Software page, and My device > Software. Some macOS system apps (e.g. MediaRemoteUI on macOS 27) hide themselves by setting their display name to a single zero-width character, which is neither empty nor trimmable; Fleet now falls back to the bundle identifier for these.

    Fixed the GitOps starter's CI jobs failing when the FLEET_URL secret ended in a slash.

    Fixed macOS hosts losing their IdP username, full name, groups, and department (and dropping out of IdP-group labels) after an MDM certificate renewal or re-enrollment when the IdP user had been set manually.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    81fe0e41e64a33fc953d1b1a1707a316f40dd74750f37ed968b35dac937f4b1a fleet_v4.92.1_linux.tar.gz

    1ae57c4a41835c43698b25add316de0d94cd2ead8380e7873199a0cd57f561de fleetctl_v4.92.1_linux_amd64.tar.gz

    748adb58e27d26894e2c561bcc6449b52d3a88a02d8b7f4cef6703aecfd3704e fleetctl_v4.92.1_linux_amd64.zip

    efeb18c4d5799cdfba93d615234e01b0001fa766c1d74898289e3890edb1dd22 fleetctl_v4.92.1_linux_arm64.tar.gz

    fe2383e8e6f7230611d0414b02477f56a11c7cf20e9e2c9d4eff41cec8a8edfb fleetctl_v4.92.1_linux_arm64.zip

    daf5ac5e5eba524054fcc43733efdefed313c43333d5187f7a38005e87594a43 fleetctl_v4.92.1_macos.tar.gz

    c687b37622756d3dcf232e0d530bdd0d64321e47037144d6af6e4094b5a58c00 fleetctl_v4.92.1_macos.zip

    94c7bc730dfd41cb441d57f7c7b0a9b61bce614f4229733681e5666975676326 fleetctl_v4.92.1_windows_amd64.tar.gz

    c36fa7b4cea870a395bffbf9071fccfddad7b897d83172feccf59472d7f13610 fleetctl_v4.92.1_windows_amd64.zip

    ce628198b6123447429e4beb3840f50e8b7b13da32a3b470d6eb82c572520813 fleetctl_v4.92.1_windows_arm64.tar.gz

    6038977b0cbae1fa14b1f1a44bf25cd982ba028b4c92ef33df25ed351db0eba4 fleetctl_v4.92.1_windows_arm64.zip

    Original source
  • Similar to Fleet with recent updates:

  • Sep 21, 2026
    • Date parsed from source:
      Sep 21, 2026
    • First seen by Releasebot:
      Sep 22, 2026
    Fleet logo

    Fleet

    Fleet 4.92.0 | Android commands, Windows Autopilot hosts, custom FileVault, and more...

    Fleet releases 4.92.0 with broader Android, Windows, macOS, and Fleet Desktop controls, including custom Android commands, pre-enrollment Autopilot assignment, custom macOS FileVault, cancelable MDM actions, SSO for Fleet Desktop, and vulnerability severity filtering, plus major performance and reliability improvements.

    Fleet 4.92.0 is now available.

    See the complete changelog or read on for highlights. For upgrade instructions, visit the upgrade guide in the Fleet docs.

    Highlights

    • Android: run any command
    • Android: scope self-service software
    • Fleet assignment for Windows Autopilot hosts before enrollment
    • Custom macOS FileVault
    • Cancel upcoming lock/wipe commands
    • Policy automations: resend a configuration profile
    • Filter vulnerability exposure by severity
    • Require SSO for Fleet Desktop

    Android: run any command

    IT admins can now send any command from the Android Management API to an Android host via fleetctl mdm run-command or Fleet's API, in addition to any Apple (macOS, iOS, iPadOS) or Windows command. This unlocks automations for commands Fleet doesn't have built-in UI/API action for yet, like requesting device info or relinquishing ownership.

    IT admins can see Android commands results on a host's Host details page or via fleetctl get mdm-commands and fleetctl get mdm-command-results, the same way we already could for Apple and Windows hosts. This makes it easier to troubleshoot a command sent to an Android host, whether it came from the Fleet UI, GitOps, or a custom command sent through the API.

    See an example Android command, like rebooting a host, in the MDM commands guide.

    GitHub issues: #23232, #33158

    Android: scope self-service software

    Available in Fleet Premium

    IT admins adding software to Android hosts' managed Google Play Store can now target hosts using labels, the same targeting options already available for macOS, Windows, and Linux software. This makes it possible to make an app available in self-service on a more specific set of Android hosts instead of every host in a fleet. Learn how to add an Android app.

    GitHub issue: #33062

    Scoping an different Android app configuration to specifc hosts is coming soon.

    Fleet assignment for Windows Autopilot hosts before enrollment

    Available in Fleet Premium

    Windows Autopilot now show up in Fleet as "Pending" hosts, along with their Autopilot group tag, before they ever enroll. IT admins can manually transfer a pending host to the right fleet from the Hosts page, or build an automation on top of Fleet's API to do it before the host ever enrolls, instead of waiting for it to land in "Unassigned" first.

    GitHub issue: #43481

    Custom macOS FileVault

    Available in Fleet Premium

    IT admins can now add custom disk encryption (FileVault) settings for macOS. This makes it possible to upload a custom FDEFileVaultOptions configuration profile, for example, to defer FileVault until the next login, or allow a third-party tool such as Xcreds to enforce FileVault, while Fleet still escrows the recovery key.

    GitHub issue: #48654

    Cancel upcoming lock/wipe commands

    IT admins can now cancel a pending lock, wipe, clear passcode, or enable lost mode command on Apple (macOS, iOS, iPadOS) hosts before a host receives it, from the host's Host details > Activity > Upcoming > MDM commands or via Fleet's API. Even if the host runs a lock command before the cancellation reaches it, Fleet still shows the unlock PIN, once the result comes back.

    Lock on Windows/Linux and wipe on Linux run as scripts, but can be canceled via Host details > Activity > Upcoming, or via Fleet's API. Wipe on Windows and lock, wipe, and clear passcode on Android aren't cancelable yet.

    GitHub issue: #43181

    Policy automations: resend a configuration profile

    Available in Fleet Premium

    IT admins can now automatically resends a configuration profile when a host fails the policy, the same way Fleet already supports automatically running scripts and installing software. This makes it possible to build automated fixes for configuration drift, like renewing a certificate, fixing a Wi-Fi profile, or re-enforcing a CIS benchmark setting.

    GitHub issue: #40637

    Filter vulnerability exposure by severity

    Available in Fleet Premium

    The vulnerability exposure chart on the dashboard can now be filtered by severity (CVSS score), giving Security Engineers more control over what the chart shows. We can also set the default severity filter for the whole organization by configuring cvss_min/cvss_max in GitOps.

    GitHub issue: #47326

    Require SSO for Fleet Desktop

    Available in Fleet Premium

    IT admins can now require end users to sign in with SSO before they can access self-service in Fleet Desktop for macOS, Windows, Linux, or iOS/iPadOS hosts. In Organization settings > Fleet Desktop, turn on the new "End user authentication" setting, or set fleet_desktop.sso_enabled in GitOps, to add an extra layer of authentication in front of Fleet Desktop.

    GitHub issue: #47116

    Changes

    IT Admins

    • Added support for running custom Android MDM commands via the Fleet API.
    • Added support for listing and viewing results of Android custom MDM commands via the API and fleetctl CLI.
    • Added support for automatically installing in-house apps (.ipa) on iOS and iPadOS hosts when they enroll into Fleet.
    • Added Windows devices registered in a connected Microsoft Entra tenant's Autopilot registry to Fleet as pending hosts before they enroll; they become regular hosts on enrollment without creating a duplicate.
    • Added support for resending a configuration profile on policy failure as part of a policy automation.
    • Added collection of additional Android host vitals from AMAPI status reports (USB debugging, passcode set, Google Play Protect, encryption status, manufacturer, security update version, kernel and bootloader version, software update status, API level, security posture, and per-SIM phone numbers), returned by the get host endpoints for Android hosts.
    • Added a QR code for the enrollment link on the Android and iOS/iPadOS tabs of the Add hosts modal, so the enrollment flow can be started by scanning instead of copying the link to a device.
    • Added the osquery.config_in_memory_cache server configuration option and disabled the in-memory cache of the osquery config's scheduled-report section by default; set it to true to re-enable the cache.
    • Added server.endpoint_request_size_overrides to configure a max request body size per API endpoint, with the largest of the endpoint's default and the override winning.
    • Added mdm.is_personal_enrollment to host API responses, reporting whether the last MDM enrollment Fleet recorded for the host was personal (BYOD). Unlike mdm.enrollment_status, it is not cleared when the host unenrolls.
    • Added mdm.bootstrap_token_escrowed to the get host and get host by Fleet Desktop token API responses, so admins can see whether Fleet has escrowed a macOS host's bootstrap token without querying the database directly.
    • Added support for display_name on Fleet-maintained apps in GitOps.
    • Added the ability to sort the versions table by version on the Software details page.

    Security Engineers

    • Added per-platform disk encryption settings: enforcement and key escrow for macOS, enforcement for Windows, and key escrow for Linux.
    • Added a new "End user authentication" setting (fleet_desktop.sso_enabled, Fleet Premium) that requires end users to sign in via single sign-on (SSO) before accessing Fleet Desktop's "My device" page.
    • Added a severity (CVSS score) filter to the Vulnerability exposure dashboard chart, which now requires Fleet Premium, and updated the severity filter on the Software, Host details, and My device pages so the min and max score inputs appear only when custom severity is selected.
    • Added an audit activity when a deprovisioned SCIM user has no email to match a Fleet account, so operators can spot accounts that may remain active.
    • Added the ability to cancel a pending Apple MDM lock, wipe, clear passcode, or enable lost mode command before the host receives it, via DELETE /api/v1/fleet/hosts/:id/commands/:command_uuid. If the host executes a canceled lock or wipe anyway, Fleet now restores the host's lock/wipe state (including the unlock PIN) when the result arrives.

    Bug fixes and improvements

    • Reduced the size of the Fleet UI JavaScript bundle by ~89% (14.9 MB to 1.6 MB gzipped) by serving Fleet-maintained app icons as individual static files instead of embedding all ~1,100 of them in the bundle downloaded on every page load.
    • Reduced the size of the Fleet UI JavaScript bundle by a further ~62% (1.6 MB to 632 KB gzipped) by loading each page's code when its route is opened rather than compiling every page into the bundle downloaded on first load.
    • Reduced memory usage of the vulnerabilities cron by streaming NVD matches to the database in bounded chunks instead of holding every matched vulnerability in memory (8.5 GB → 2.1 GB peak on a 22.7M-match fleet), and inserts now start during matching so large fleets no longer exceed the vulnerability processing time limit.
    • Reduced database load when processing osquery result logs by resolving scheduled query names in a single batch lookup instead of one query per result.
    • Added an "Inactive" status with an explanatory tooltip to the Users table for accounts that haven't been used for 30+ days. Regular users are inactive when they haven't logged in (or had session activity) for 30+ days; API-only users are inactive when their token has made no API requests for 30+ days. Fleet now records each user's last login time in a new last_login_at field, reports last session activity in a new last_activity_at field, and returns a server-computed status field (active, inactive, or no_access) from the users API.
    • Added an experimental WebSocket notification transport for fleetd agents (ADR-0011), disabled by default (enable with the websocket.transport_enabled server configuration): connected agents are pushed a "check now" notification when a live query targets them or when interval work (labels, policies, host vitals, refetch) is due, instead of polling distributed/read every 10 seconds.
    • Added conditional request (etag) support to the osquery config endpoint (/api/osquery/config), behind the osquery.config_etags server option (FLEET_OSQUERY_CONFIG_ETAGS, default off). When it's enabled, agents that send an etag field in the request body receive the minimal {"etag":"ok"} response when their configuration is unchanged, reducing agent config bandwidth; agents that don't send the field see no change. While it's off, every config request is served exactly as before.
    • Added an osquery.redis_config_etags server option (FLEET_OSQUERY_REDIS_CONFIG_ETAGS, default off, and requires osquery.config_etags): when both are enabled, config check-ins with a matching etag are answered directly from a Redis-backed ETag store, skipping the config build and its database reads entirely. Fleets with uniform configs share one ETag per fleet and platform; fleets with label-scoped reports use isolated per-host ETags invalidated whenever a host's label results are recorded. The short circuit fails open (any Redis error falls back to a full build) and is bypassed automatically for deployments with 2017 packs.
    • Windows user-scoped configuration profiles (./User/...) are now held in "Pending" until a user signs in, instead of failing during setup. On hosts enrolled by a user (Windows Autopilot, Entra ID) that user releases the hold; on hosts enrolled by installing fleetd, any signed-in user does, and Windows applies the settings to whoever is signed in. User-scoped profiles that already failed on an earlier Fleet version are not resent automatically: after upgrading, resend them once (or edit the profile) and Fleet will deliver them when a user is signed in.
    • Removing a Windows user-scoped configuration profile now waits for a signed-in user as well, instead of being reported as removed while the setting was still applied.
    • Windows configuration profiles now retry up to 3 times before being marked "Failed", matching Apple. Retries cover profiles the host rejects and profiles whose Fleet-proxied SCEP certificate never arrives. A profile stays "Pending" while Fleet retries.
    • Fleet no longer marks a configuration profile "Failed" when it briefly can't reach the NDES admin URL to fetch a SCEP challenge. The profile stays pending and Fleet tries again. Challenge failures that need an admin to act (invalid credentials, a full password cache, or an account without SCEP enroll permission) still fail the profile immediately with the same message as before.
    • Escaped values interpolated into the conditional access Apple configuration profile so a value containing markup is carried as literal text.
    • Fleet now clears dynamic labels and pending commands and software installs when an Android host re-enrolls. Manually assigned labels are preserved, and pending software installs are reported as failed. Past host activities for the host are also cleared unless preserve_host_activities_on_reenrollment is enabled.
    • Increased Android certificate delivery retries from 3 to 7 and added exponential backoff between attempts.
    • Improved SCIM user deactivation to more reliably deprovision the matching Fleet user.
    • Moved the host's OS settings table out of the "OS settings" modal into a dedicated Controls tab on Host details and My device.
    • Moved toast notifications to the bottom center of the screen so they no longer cover buttons in the bottom-right of pages and modals.
    • Updated the macOS enroll modal's "Company-owned" label and helper text to match iOS/iPadOS and Android ("Company-owned (fully-managed)").
    • Updated wipe modal for Apple and Windows hosts to call out deleting may remove the Wipe Pending status.
    • Updated the message end users see when they take too long to sign in during MDM enrollment to say their session may have timed out, instead of a generic error.
    • Added a descriptive message when a script produces empty standard output.
    • Improved fleetctl generate-gitops to emit software titles in name order instead of the default hosts_count order.
    • Improved the hosts report CSV export (GET /api/v1/fleet/hosts/report) so that exported cell values are treated as text by spreadsheet applications.
    • Changed duration fields in Fleet server logs (e.g. took) to render as human-readable strings with time units (e.g. "1.116187ms") instead of raw nanosecond numbers. Log pipelines that parse these fields numerically will need to be updated.
    • Changed requests denied by an API-only user's endpoint restrictions to return a distinct 403 message ("endpoint not permitted for this API-only user"), logged at info level with the route and denial reason, so they can be distinguished from role-based permission denials.
    • Enforced API-only endpoint restrictions on the debug routes so a restricted API-only token can no longer reach /debug/*.
    • Removed the unused jq binary from the fleetdm/fleet Docker image to reduce the image's attack surface and prevent SBOM scanners from flagging jq CVEs.
    • Deprecated osquery_max_log_write_body_size and osquery_max_distributed_write_body_size in favor of new configs.
    • Deprecated fleetdm/bomutils docker image. Starting in 4.90.0, fleetctl does not use fleetdm/bomutils to generate .pkg fleetd installers.
    • Updated the EPSS scores feed to download from its new canonical URL (epss.empiricalsecurity.com) instead of relying on the redirect from the old host (epss.cyentia.com).
    • Improved outbound address filtering to cover the unspecified addresses (0.0.0.0 and ::), the deprecated IPv4-compatible IPv6 form, and IPv4 addresses reached through a NAT64 prefix.
    • Made vulnerability host count updates recover automatically after an interrupted table swap.
    • Added support for sending blank APNS pings to Apple devices.
    • Improved parsing of Apple MachineInfo blobs during enrollment.
    • Improved validation of the order_key parameter when listing software, rejecting sort keys that aren't supported instead of passing them through to the query.
    • Improved validation of the order_key parameter on GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities, rejecting unsupported sort keys.
    • Added MDM profile counts (Apple, Windows, Android configuration profiles and Apple DDM declarations) to usage statistics for troubleshooting.
    • Added conditional config request support to osquery-perf simulated hosts, including stats for conditional requests and estimated bandwidth saved, for load-testing the above.
    • Added a useFormValidation hook as the single source of truth for the documented form validation behavior, and applied it to the new user and new API-only user forms.
    • Updated the DDM asset error message shown when the Authentication key is provided to explain that Fleet defaults to MDM authentication.
    • Removed mention of osquery when viewing a DDM profile that is verifying.
    • Removed the QR code from the "Add hosts" enrollment instructions for company-owned Android hosts, since fully-managed enrollment isn't done by scanning a code.
    • Disabled the Save button in the end user migration workflow while a request is in flight.
    • Documented why safari_extensions returns empty without Full Disk Access or a uid constraint (users JOIN/CROSS JOIN, or WHERE uid = ...), noted the /Applications-only scan limitation, fixed standard Safari inventory SQL to include a users CROSS JOIN, and replaced legacy .safariextz bash equivalents with modern Safari App/Web Extension paths.
    • Fleet now restores BitLocker protection on Windows hosts that are encrypted but whose protection is off, where disk encryption is enforced. This includes hosts that require a startup PIN but do not have one yet, and hosts where an admin, third-party software, or a previous MDM forbade the TPM-only protector Fleet needs, which Fleet now clears. Such a host shows "Enforcing" while Fleet repairs it, and "Action required" with the reason in its disk encryption details only once fleetd reports it cannot.
    • Fixed a Windows host's disk encryption status naming an action the end user cannot take. A host whose protection is off no longer asks them to create a BitLocker PIN, since Windows only offers PIN setup on a protected volume, and a repair waiting on a pending restart now asks for that restart on both the host details page and the end user's My device page.
    • Fixed an issue where a second user signing in to a Windows device that was already enrolled via Autopilot would get stuck on the "Account setup" Enrollment Status Page for up to 3 hours.
    • Fixed built-in and starter library Linux labels being too strict to match derived distributions, so hosts running Pop!_OS, Linux Mint, Zorin OS, Debian, older Fedora releases, Amazon Linux, and SUSE now appear in the Linux labels that apply to them.
    • Fixed an upgrade failure where a MySQL "Prepared statement needs to be re-prepared" error (1615) aborted a database migration instead of being retried.
    • Fixed osquery and orbit config endpoints returning HTTP 500 when a host references a recently deleted team by invalidating the Redis host cache on team deletion.
    • Fixed the dashboard "Hosts enrolled" chart drill-down including pending hosts in the filtered host list, by adding an "Enrolled hosts" status filter (status=enrolled on the list hosts and count hosts endpoints) that excludes hosts pending MDM enrollment.
    • Fixed pending hosts (Apple Business Manager, Windows Autopilot) showing a "Fetching fresh vitals" spinner and a "This host is offline. Please try refetching host vitals later." error on the host details page, even though nobody asked for a refetch.
    • Fixed "Turn off MDM" being available again after it succeeded, which let an offline host be sent duplicate unenroll commands.
    • Fixed an Apple configuration profile that was removed and then added back before the host came online being stripped from the host and reinstalled, instead of staying in place.
    • Fixed ACME certificates deployed via user-scoped profiles not showing on the macOS host details page, and recorded them under the enrolled user's scope instead of the system keychain.
    • Fixed an issue where a misleading detail was shown for pending/verifying DDM profiles.
    • Fixed iOS/iPadOS refetch getting blocked when an online device acknowledged a refetch command before Fleet finished recording the command as sent.
    • Fixed duplicate IdP device mapping ("2 users") shown for a host after it re-enrolled through ADE with end user authentication when its IdP username had previously been set manually. The enrollment now replaces the manually set mapping instead of adding a second one.
    • Fixed the host details Vitals card replacing Enrollment ID with an empty Serial number after a personal (BYOD) Android host is unenrolled.
    • Fixed Android MDM commands returning 500 instead of the actual error code from the Google Android Enterprise API.
    • Fixed an issue where Homebrew cask metadata for a Fleet-maintained app (macOS) could reach the generated install/uninstall scripts without being escaped for shell use. All cask-controlled values interpolated into generated scripts are now escaped, so shell metacharacters in the metadata are treated as literal text.
    • Fixed macOS Fleet-maintained apps with in-bundle login items or background helpers (e.g. 1Password's browser helper) always being detected as open. The Fleet-managed "app is open" check now matches only the app's own executable instead of any process running inside the app bundle.
    • Fixed Fleet-maintained apps selecting the wrong version to be active.
    • Fixed the Fleet-maintained app auto-update cron not updating install and uninstall scripts when it advances an app to a new version.
    • Fixed the Fleet-maintained apps auto-update cron job not updating scripts when they change in the manifest without a version change.
    • Fixed software search to match on bundle_identifier and custom display_name so admins and end users can find macOS custom packages by their visible name.
    • Fixed the transient empty state shown when changing Self-service search and category filters.
    • Fixed self-service reinstall and uninstall buttons remaining disabled after cancelling the uninstall confirmation modal.
    • Fixed the VPP install details modal retrying the command results request four times when the result isn't available yet and the API returns a 404.
    • Fixed activity feed rendering a blank actor for failed iPad VPP installs: auto-update terminal failures now attribute to Fleet, and any install whose initiating admin has since been deleted also renders "Fleet" instead of an empty name.
    • Fixed uninstalling .sh and .py script packages from macOS hosts, which was rejected even though installing them there is allowed. The rejection message for other platforms now names them the same way the install message does ("macOS and Linux" rather than "linux").
    • Fixed the "Advanced options" reveal button on the Edit software modal not expanding for .msix packages (e.g., Claude, Slack on Windows), which prevented users from viewing or editing install/uninstall scripts.
    • Fixed the error toast shown when selecting a custom package with an unsupported extension so the friendly message stays on the main line and the extension reason appears in the expandable raw-response panel.
    • Fixed the Save button never activating when adding a package from the software title page while GitOps mode is enabled.
    • Fixed the "Software" automation filter on the Policies page to no longer include patch policies. Added a dedicated "Patch" filter option.
    • Fixed the total number of retries of a failing software install automation across policy runs not being limited.
    • Fixed exclude-label-scoped policies running, and their automations firing, on newly enrolled hosts before the host had evaluated the label's membership.
    • Fixed an issue where label-scoped reports could run on hosts outside the target label (or be skipped for hosts inside it).
    • Fixed a race where a newly created or edited label-scoped query could briefly be delivered to every host (and out-of-scope results stored in its report) because the query row was committed before its labels.
    • Fixed built-in labels being overwritten, renamed, or deleted by supplying a label name that differs from the built-in name only in letter casing.
    • Fixed the modify label endpoint so that a dynamic label's membership can no longer be cleared by sending an empty hosts or host_ids list, which is now rejected like a non-empty one.
    • Fixed the label spec endpoints so that the host membership list only includes hosts the requesting user is authorized to see, preventing cross-team host ID disclosure through global manual labels.
    • Fixed an issue where disabled packs could still be applied to hosts in certain targeting configurations.
    • Fixed query (report) results submitted to /api/osquery/log so that they are only accepted when the query is actually scheduled for the submitting host, preventing an enrolled host from adding rows to reports it was never assigned or from streaming results for those queries to a log destination.
    • Fixed report descriptions so that newlines are preserved when the description is displayed, instead of being collapsed onto a single line.
    • Fixed the fleet and global schedule endpoints accepting reports that belong to a different fleet, and made them return the same "not found" response for a report outside the caller's access as for one that doesn't exist.
    • Fixed live query authorization so that an empty team selection is authorized like an omitted one.
    • Fixed policy result ingestion so a host can no longer report results for policies it is not assigned, preventing forged policy membership across fleet, platform, and label scopes.
    • Fixed an issue where an activity might not be created when an MDM command was enqueued via the API.
    • Fixed GET /api/v1/fleet/hosts/identifier/:identifier disclosing host details to GitOps users, who are denied on all other host read endpoints. Unlike GET /api/v1/fleet/hosts/:id, which returns an error for GitOps users, this endpoint still succeeds and returns the host's id (and nothing else), for backwards compatibility with the deprecated Puppet module.
    • Fixed authentication and enrollment tokens (including session, invite, email-change, MFA, host device, and MDM enrollment/installer tokens) so that case-mutated tokens are no longer accepted; these tokens are now matched case-sensitively.
    • Fixed deleting a certificate template that doesn't exist returning a 500 internal server error. Users authorized to manage certificate templates now get a 404, and users who aren't get a 403 whether or not the template exists.
    • Fixed getting a certificate template by ID disclosing whether templates a user can't access exist. Reading a template on another fleet now returns a 404, the same as a template that doesn't exist.
    • Fixed the add/edit certificate authority modals showing a generic "Please try again." error instead of the invalid URL error returned by the server. The error now names the certificate authority, for example "Invalid Hydrant URL. Please correct and try again."
    • Fixed editing only the username or only the password of an NDES SCEP certificate authority skipping validation against the NDES server. Fleet now verifies the credentials on save and returns an error if they're wrong, instead of saving a broken certificate authority whose misconfiguration only surfaced later as a profile failure on hosts.
    • Fixed editing only the SCEP URL of an NDES SCEP certificate authority failing with a "password" must be set when modifying an existing certificate authority error. The password field is now cleared when the SCEP URL changes, so it's re-entered and sent with the update.
    • Fixed an empty username or password being saved on an NDES SCEP certificate authority.
    • Fixed adding or editing a certificate authority with a bad NDES admin URL or credentials showing a generic "Please try again." message instead of "Invalid admin URL or credentials."
    • Fixed updating an NDES SCEP certificate authority with the masked password (********) returned by the GET endpoint sending the mask to the NDES server as the literal password and failing with a misleading "invalid credentials" error. The mask is now rejected with an invalid-password error, matching GitOps behavior.
    • Fleet now skips validating NDES credentials against the NDES server when an update leaves the admin URL, username, and password unchanged, so a no-op edit doesn't consume a slot in NDES's password cache.
    • Fixed an unreachable NDES admin URL (timeout, DNS failure, connection refused) being reported as "Invalid admin URL or credentials" when editing an NDES SCEP certificate authority. It's now reported as "Couldn't connect to admin URL."
    • Fixed the Save button staying enabled in the edit certificate authority modal after Fleet clears the unchanged NDES password, which let the form submit an empty password.
    • Fixed editing a Windows configuration profile so that uploading a replacement file with a different name updates the profile's name.
    • Fixed uploading a Windows configuration profile with a file name longer than 255 characters returning a database error.
    • Fixed a bug where Windows disk encryption showed a "Resend" action that always failed, since BitLocker enforcement isn't a configuration profile.
    • Fixed an issue where Observer, Observer+ and Technician could not see the managed account rotation banner.
    • Fixed the error returned when a free-tier request sets a premium-only field so that it names the field as it appears in the request payload (for example critical) instead of Fleet's internal Go field name (for example Critical).
    • Fixed a query returning a MySQL error if hit with unsupported platforms, by now returning an empty result.
    • Fixed an issue where stale fleet names could appear in mdm.apple_business after renaming a fleet.
    • Fixed false positive vulnerabilities reported for JetBrains teamcity-cli installed via Homebrew, which was incorrectly matched to the TeamCity CI server's CPE.
    • Fixed fleetctl gitops silently dropping ios_updates and ipados_updates when it creates a new fleet.
    • Fixed fleetctl generate-gitops failing with an unsupported Content-Type error when the org logo is an SVG.
    • Fixed fleetctl generate-gitops not using .sh and .ps1 extensions for install scripts.
    • Fixed an issue where deleting an ADE device after turning off Apple Business could leave orphaned rows.
    • Fixed form validation on the new/edit user and API-only user forms: field errors no longer appear before a field has been edited, clear as soon as the field is focused, and the "select at least one fleet" error now renders on the selector instead of as a toast.
    • Updated validation error copy on the new/edit user and API-only user forms to the standard wording (e.g. "Enter an email" instead of "Email field must be completed").
    • Fixed the fleet, role, and API access controls staying editable while a user was being saved on the new/edit user and API-only user forms.
    • Fixed error toasts showing an expandable "Raw response" panel containing an empty {} when the underlying error carried no details.
    • Fixed inconsistent spacing around the enrollment URL on the iOS & iPadOS tab of the Add hosts modal, so it now matches the macOS and Android tabs.
    • Fixed the confirmation checkbox on the "Clear passcode" host modal rendering in green instead of red, so it now matches the destructive "Clear passcode" button.
    • Fixed incorrect background color on authentication pages (login, SSO, registration) in dark mode.
    • Fixed autofilled inputs showing a white background in dark mode. The autofill style now uses theme colors instead of a hardcoded white, and covers Firefox via the standard :autofill selector.
    • Fixed label color for install/post-install/uninstall script fields in software package advanced options to match Fleet's standard form label color.
    • Fixed long unbreakable words (e.g. file paths in inline code) overflowing the table info side panel on the report and policy editor pages.
    • Matched the height of the host status and platform/label filter dropdowns on the Hosts page.
    • Fixed the "Collecting results..." empty state on the report details page reading "about about X hours".

    Ready to upgrade?

    Visit our Upgrade guide in the Fleet docs to update to Fleet 4.92.0.

    Manage all your devices like it's 2026
    Open MDM, patching, and vuln management for every OS.

    Read case studies
    Try it yourself

    Original source
  • Sep 21, 2026
    • Date parsed from source:
      Sep 21, 2026
    • First seen by Releasebot:
      Sep 22, 2026
    Fleet logo

    Fleet

    fleet-v4.92.0

    Fleet releases 4.92.0 with major Android, Apple, Windows, and Fleet API upgrades, plus stronger security controls, faster UI performance, and many bug fixes across enrollment, software, profiles, labels, and reporting.

    Fleet 4.92.0 (Sep 21, 2026)

    IT Admins

    • Added support for running custom Android MDM commands via the Fleet API.
    • Added support for listing and viewing results of Android custom MDM commands via the API and fleetctl CLI.
    • Added support for automatically installing in-house apps (.ipa) on iOS and iPadOS hosts when they enroll into Fleet.
    • Added Windows devices registered in a connected Microsoft Entra tenant's Autopilot registry to Fleet as pending hosts before they enroll; they become regular hosts on enrollment without creating a duplicate.
    • Added support for resending a configuration profile on policy failure as part of a policy automation.
    • Added collection of additional Android host vitals from AMAPI status reports (USB debugging, passcode set, Google Play Protect, encryption status, manufacturer, security update version, kernel and bootloader version, software update status, API level, security posture, and per-SIM phone numbers), returned by the get host endpoints for Android hosts.
    • Added a QR code for the enrollment link on the Android and iOS/iPadOS tabs of the Add hosts modal, so the enrollment flow can be started by scanning instead of copying the link to a device.
    • Added the osquery.config_in_memory_cache server configuration option and disabled the in-memory cache of the osquery config's scheduled-report section by default; set it to true to re-enable the cache.
    • Added server.endpoint_request_size_overrides to configure a max request body size per API endpoint, with the largest of the endpoint's default and the override winning.
    • Added mdm.is_personal_enrollment to host API responses, reporting whether the last MDM enrollment Fleet recorded for the host was personal (BYOD). Unlike mdm.enrollment_status, it is not cleared when the host unenrolls.
    • Added mdm.bootstrap_token_escrowed to the get host and get host by Fleet Desktop token API responses, so admins can see whether Fleet has escrowed a macOS host's bootstrap token without querying the database directly.
    • Added support for display_name on Fleet-maintained apps in GitOps.
    • Added the ability to sort the versions table by version on the Software details page.

    Security Engineers

    • Added per-platform disk encryption settings: enforcement and key escrow for macOS, enforcement for Windows, and key escrow for Linux.
    • Added a new "End user authentication" setting (fleet_desktop.sso_enabled, Fleet Premium) that requires end users to sign in via single sign-on (SSO) before accessing Fleet Desktop's "My device" page.
    • Added a severity (CVSS score) filter to the Vulnerability exposure dashboard chart, which now requires Fleet Premium, and updated the severity filter on the Software, Host details, and My device pages so the min and max score inputs appear only when custom severity is selected.
    • Added an audit activity when a deprovisioned SCIM user has no email to match a Fleet account, so operators can spot accounts that may remain active.
    • Added the ability to cancel a pending Apple MDM lock, wipe, clear passcode, or enable lost mode command before the host receives it, via DELETE /api/v1/fleet/hosts/:id/commands/:command_uuid. If the host executes a canceled lock or wipe anyway, Fleet now restores the host's lock/wipe state (including the unlock PIN) when the result arrives.

    Bug fixes and improvements

    • Reduced the size of the Fleet UI JavaScript bundle by ~89% (14.9 MB to 1.6 MB gzipped) by serving Fleet-maintained app icons as individual static files instead of embedding all ~1,100 of them in the bundle downloaded on every page load.
    • Reduced the size of the Fleet UI JavaScript bundle by a further ~62% (1.6 MB to 632 KB gzipped) by loading each page's code when its route is opened rather than compiling every page into the bundle downloaded on first load.
    • Reduced memory usage of the vulnerabilities cron by streaming NVD matches to the database in bounded chunks instead of holding every matched vulnerability in memory (8.5 GB → 2.1 GB peak on a 22.7M-match fleet), and inserts now start during matching so large fleets no longer exceed the vulnerability processing time limit.
    • Reduced database load when processing osquery result logs by resolving scheduled query names in a single batch lookup instead of one query per result.
    • Added an "Inactive" status with an explanatory tooltip to the Users table for accounts that haven't been used for 30+ days. Regular users are inactive when they haven't logged in (or had session activity) for 30+ days; API-only users are inactive when their token has made no API requests for 30+ days. Fleet now records each user's last login time in a new last_login_at field, reports last session activity in a new last_activity_at field, and returns a server-computed status field (active, inactive, or no_access) from the users API.
    • Added an experimental WebSocket notification transport for fleetd agents (ADR-0011), disabled by default (enable with the websocket.transport_enabled server configuration): connected agents are pushed a "check now" notification when a live query targets them or when interval work (labels, policies, host vitals, refetch) is due, instead of polling distributed/read every 10 seconds.
    • Added conditional request (etag) support to the osquery config endpoint (/api/osquery/config), behind the osquery.config_etags server option (FLEET_OSQUERY_CONFIG_ETAGS, default off). When it's enabled, agents that send an etag field in the request body receive the minimal {"etag":"ok"} response when their configuration is unchanged, reducing agent config bandwidth; agents that don't send the field see no change. While it's off, every config request is served exactly as before.
    • Added an osquery.redis_config_etags server option (FLEET_OSQUERY_REDIS_CONFIG_ETAGS, default off, and requires osquery.config_etags): when both are enabled, config check-ins with a matching etag are answered directly from a Redis-backed ETag store, skipping the config build and its database reads entirely. Fleets with uniform configs share one ETag per fleet and platform; fleets with label-scoped reports use isolated per-host ETags invalidated whenever a host's label results are recorded. The short circuit fails open (any Redis error falls back to a full build) and is bypassed automatically for deployments with 2017 packs.
    • Windows user-scoped configuration profiles (./User/...) are now held in "Pending" until a user signs in, instead of failing during setup. On hosts enrolled by a user (Windows Autopilot, Entra ID) that user releases the hold; on hosts enrolled by installing fleetd, any signed-in user does, and Windows applies the settings to whoever is signed in. User-scoped profiles that already failed on an earlier Fleet version are not resent automatically: after upgrading, resend them once (or edit the profile) and Fleet will deliver them when a user is signed in.
    • Removing a Windows user-scoped configuration profile now waits for a signed-in user as well, instead of being reported as removed while the setting was still applied.
    • Windows configuration profiles now retry up to 3 times before being marked "Failed", matching Apple. Retries cover profiles the host rejects and profiles whose Fleet-proxied SCEP certificate never arrives. A profile stays "Pending" while Fleet retries.
    • Fleet no longer marks a configuration profile "Failed" when it briefly can't reach the NDES admin URL to fetch a SCEP challenge. The profile stays pending and Fleet tries again. Challenge failures that need an admin to act (invalid credentials, a full password cache, or an account without SCEP enroll permission) still fail the profile immediately with the same message as before.
    • Escaped values interpolated into the conditional access Apple configuration profile so a value containing markup is carried as literal text.
    • Fleet now clears dynamic labels and pending commands and software installs when an Android host re-enrolls. Manually assigned labels are preserved, and pending software installs are reported as failed. Past host activities for the host are also cleared unless preserve_host_activities_on_reenrollment is enabled.
    • Increased Android certificate delivery retries from 3 to 7 and added exponential backoff between attempts.
    • Improved SCIM user deactivation to more reliably deprovision the matching Fleet user.
    • Moved the host's OS settings table out of the "OS settings" modal into a dedicated Controls tab on Host details and My device.
    • Moved toast notifications to the bottom center of the screen so they no longer cover buttons in the bottom-right of pages and modals.
    • Updated the macOS enroll modal's "Company-owned" label and helper text to match iOS/iPadOS and Android ("Company-owned (fully-managed)").
    • Updated wipe modal for Apple and Windows hosts to call out deleting may remove the Wipe Pending status.
    • Updated the message end users see when they take too long to sign in during MDM enrollment to say their session may have timed out, instead of a generic error.
    • Added a descriptive message when a script produces empty standard output.
    • Improved fleetctl generate-gitops to emit software titles in name order instead of the default hosts_count order.
    • Improved the hosts report CSV export (GET /api/v1/fleet/hosts/report) so that exported cell values are treated as text by spreadsheet applications.
    • Changed duration fields in Fleet server logs (e.g. took) to render as human-readable strings with time units (e.g. "1.116187ms") instead of raw nanosecond numbers. Log pipelines that parse these fields numerically will need to be updated.
    • Changed requests denied by an API-only user's endpoint restrictions to return a distinct 403 message ("endpoint not permitted for this API-only user"), logged at info level with the route and denial reason, so they can be distinguished from role-based permission denials.
    • Enforced API-only endpoint restrictions on the debug routes so a restricted API-only token can no longer reach /debug/*.
    • Removed the unused jq binary from the fleetdm/fleet Docker image to reduce the image's attack surface and prevent SBOM scanners from flagging jq CVEs.
    • Deprecated osquery_max_log_write_body_size and osquery_max_distributed_write_body_size in favor of new configs.
    • Deprecated fleetdm/bomutils docker image. Starting in 4.90.0, fleetctl does not use fleetdm/bomutils to generate .pkg fleetd installers.
    • Updated the EPSS scores feed to download from its new canonical URL (epss.empiricalsecurity.com) instead of relying on the redirect from the old host (epss.cyentia.com).
    • Improved outbound address filtering to cover the unspecified addresses (0.0.0.0 and ::), the deprecated IPv4-compatible IPv6 form, and IPv4 addresses reached through a NAT64 prefix.
    • Made vulnerability host count updates recover automatically after an interrupted table swap.
    • Added support for sending blank APNS pings to Apple devices.
    • Improved parsing of Apple MachineInfo blobs during enrollment.
    • Improved validation of the order_key parameter when listing software, rejecting sort keys that aren't supported instead of passing them through to the query.
    • Improved validation of the order_key parameter on GET /api/v1/fleet/activities and GET /api/v1/fleet/hosts/{id}/activities, rejecting unsupported sort keys.
    • Added MDM profile counts (Apple, Windows, Android configuration profiles and Apple DDM declarations) to usage statistics for troubleshooting.
    • Added conditional config request support to osquery-perf simulated hosts, including stats for conditional requests and estimated bandwidth saved, for load-testing the above.
    • Added a useFormValidation hook as the single source of truth for the documented form validation behavior, and applied it to the new user and new API-only user forms.
    • Updated the DDM asset error message shown when the Authentication key is provided to explain that Fleet defaults to MDM authentication.
    • Removed mention of osquery when viewing a DDM profile that is verifying.
    • Removed the QR code from the "Add hosts" enrollment instructions for company-owned Android hosts, since fully-managed enrollment isn't done by scanning a code.
    • Disabled the Save button in the end user migration workflow while a request is in flight.
    • Documented why safari_extensions returns empty without Full Disk Access or a uid constraint (users JOIN/CROSS JOIN, or WHERE uid = ...), noted the /Applications-only scan limitation, fixed standard Safari inventory SQL to include a users CROSS JOIN, and replaced legacy .safariextz bash equivalents with modern Safari App/Web Extension paths.
    • Fleet now restores BitLocker protection on Windows hosts that are encrypted but whose protection is off, where disk encryption is enforced. This includes hosts that require a startup PIN but do not have one yet, and hosts where an admin, third-party software, or a previous MDM forbade the TPM-only protector Fleet needs, which Fleet now clears. Such a host shows "Enforcing" while Fleet repairs it, and "Action required" with the reason in its disk encryption details only once fleetd reports it cannot.
    • Fixed a Windows host's disk encryption status naming an action the end user cannot take. A host whose protection is off no longer asks them to create a BitLocker PIN, since Windows only offers PIN setup on a protected volume, and a repair waiting on a pending restart now asks for that restart on both the host details page and the end user's My device page.
    • Fixed an issue where a second user signing in to a Windows device that was already enrolled via Autopilot would get stuck on the "Account setup" Enrollment Status Page for up to 3 hours.
    • Fixed built-in and starter library Linux labels being too strict to match derived distributions, so hosts running Pop!_OS, Linux Mint, Zorin OS, Debian, older Fedora releases, Amazon Linux, and SUSE now appear in the Linux labels that apply to them.
    • Fixed an upgrade failure where a MySQL "Prepared statement needs to be re-prepared" error (1615) aborted a database migration instead of being retried.
    • Fixed osquery and orbit config endpoints returning HTTP 500 when a host references a recently deleted team by invalidating the Redis host cache on team deletion.
    • Fixed the dashboard "Hosts enrolled" chart drill-down including pending hosts in the filtered host list, by adding an "Enrolled hosts" status filter (status=enrolled on the list hosts and count hosts endpoints) that excludes hosts pending MDM enrollment.
    • Fixed pending hosts (Apple Business Manager, Windows Autopilot) showing a "Fetching fresh vitals" spinner and a "This host is offline. Please try refetching host vitals later." error on the host details page, even though nobody asked for a refetch.
    • Fixed "Turn off MDM" being available again after it succeeded, which let an offline host be sent duplicate unenroll commands.
    • Fixed an Apple configuration profile that was removed and then added back before the host came online being stripped from the host and reinstalled, instead of staying in place.
    • Fixed ACME certificates deployed via user-scoped profiles not showing on the macOS host details page, and recorded them under the enrolled user's scope instead of the system keychain.
    • Fixed an issue where a misleading detail was shown for pending/verifying DDM profiles.
    • Fixed iOS/iPadOS refetch getting blocked when an online device acknowledged a refetch command before Fleet finished recording the command as sent.
    • Fixed duplicate IdP device mapping ("2 users") shown for a host after it re-enrolled through ADE with end user authentication when its IdP username had previously been set manually. The enrollment now replaces the manually set mapping instead of adding a second one.
    • Fixed the host details Vitals card replacing Enrollment ID with an empty Serial number after a personal (BYOD) Android host is unenrolled.
    • Fixed Android MDM commands returning 500 instead of the actual error code from the Google Android Enterprise API.
    • Fixed an issue where Homebrew cask metadata for a Fleet-maintained app (macOS) could reach the generated install/uninstall scripts without being escaped for shell use. All cask-controlled values interpolated into generated scripts are now escaped, so shell metacharacters in the metadata are treated as literal text.
    • Fixed macOS Fleet-maintained apps with in-bundle login items or background helpers (e.g. 1Password's browser helper) always being detected as open. The Fleet-managed "app is open" check now matches only the app's own executable instead of any process running inside the app bundle.
    • Fixed Fleet-maintained apps selecting the wrong version to be active.
    • Fixed the Fleet-maintained app auto-update cron not updating install and uninstall scripts when it advances an app to a new version.
    • Fixed the Fleet-maintained apps auto-update cron job not updating scripts when they change in the manifest without a version change.
    • Fixed software search to match on bundle_identifier and custom display_name so admins and end users can find macOS custom packages by their visible name.
    • Fixed the transient empty state shown when changing Self-service search and category filters.
    • Fixed self-service reinstall and uninstall buttons remaining disabled after cancelling the uninstall confirmation modal.
    • Fixed the VPP install details modal retrying the command results request four times when the result isn't available yet and the API returns a 404.
    • Fixed activity feed rendering a blank actor for failed iPad VPP installs: auto-update terminal failures now attribute to Fleet, and any install whose initiating admin has since been deleted also renders "Fleet" instead of an empty name.
    • Fixed uninstalling .sh and .py script packages from macOS hosts, which was rejected even though installing them there is allowed. The rejection message for other platforms now names them the same way the install message does ("macOS and Linux" rather than "linux").
    • Fixed the "Advanced options" reveal button on the Edit software modal not expanding for .msix packages (e.g., Claude, Slack on Windows), which prevented users from viewing or editing install/uninstall scripts.
    • Fixed the error toast shown when selecting a custom package with an unsupported extension so the friendly message stays on the main line and the extension reason appears in the expandable raw-response panel.
    • Fixed the Save button never activating when adding a package from the software title page while GitOps mode is enabled.
    • Fixed the "Software" automation filter on the Policies page to no longer include patch policies. Added a dedicated "Patch" filter option.
    • Fixed the total number of retries of a failing software install automation across policy runs not being limited.
    • Fixed exclude-label-scoped policies running, and their automations firing, on newly enrolled hosts before the host had evaluated the label's membership.
    • Fixed an issue where label-scoped reports could run on hosts outside the target label (or be skipped for hosts inside it).
    • Fixed a race where a newly created or edited label-scoped query could briefly be delivered to every host (and out-of-scope results stored in its report) because the query row was committed before its labels.
    • Fixed built-in labels being overwritten, renamed, or deleted by supplying a label name that differs from the built-in name only in letter casing.
    • Fixed the modify label endpoint so that a dynamic label's membership can no longer be cleared by sending an empty hosts or host_ids list, which is now rejected like a non-empty one.
    • Fixed the label spec endpoints so that the host membership list only includes hosts the requesting user is authorized to see, preventing cross-team host ID disclosure through global manual labels.
    • Fixed an issue where disabled packs could still be applied to hosts in certain targeting configurations.
    • Fixed query (report) results submitted to /api/osquery/log so that they are only accepted when the query is actually scheduled for the submitting host, preventing an enrolled host from adding rows to reports it was never assigned or from streaming results for those queries to a log destination.
    • Fixed report descriptions so that newlines are preserved when the description is displayed, instead of being collapsed onto a single line.
    • Fixed the fleet and global schedule endpoints accepting reports that belong to a different fleet, and made them return the same "not found" response for a report outside the caller's access as for one that doesn't exist.
    • Fixed live query authorization so that an empty team selection is authorized like an omitted one.
    • Fixed policy result ingestion so a host can no longer report results for policies it is not assigned, preventing forged policy membership across fleet, platform, and label scopes.
    • Fixed an issue where an activity might not be created when an MDM command was enqueued via the API.
    • Fixed GET /api/v1/fleet/hosts/identifier/:identifier disclosing host details to GitOps users, who are denied on all other host read endpoints. Unlike GET /api/v1/fleet/hosts/:id, which returns an error for GitOps users, this endpoint still succeeds and returns the host's id (and nothing else), for backwards compatibility with the deprecated Puppet module.
    • Fixed authentication and enrollment tokens (including session, invite, email-change, MFA, host device, and MDM enrollment/installer tokens) so that case-mutated tokens are no longer accepted; these tokens are now matched case-sensitively.
    • Fixed deleting a certificate template that doesn't exist returning a 500 internal server error. Users authorized to manage certificate templates now get a 404, and users who aren't get a 403 whether or not the template exists.
    • Fixed getting a certificate template by ID disclosing whether templates a user can't access exist. Reading a template on another fleet now returns a 404, the same as a template that doesn't exist.
    • Fixed the add/edit certificate authority modals showing a generic "Please try again." error instead of the invalid URL error returned by the server. The error now names the certificate authority, for example "Invalid Hydrant URL. Please correct and try again."
    • Fixed editing only the username or only the password of an NDES SCEP certificate authority skipping validation against the NDES server. Fleet now verifies the credentials on save and returns an error if they're wrong, instead of saving a broken certificate authority whose misconfiguration only surfaced later as a profile failure on hosts.
    • Fixed editing only the SCEP URL of an NDES SCEP certificate authority failing with a "password" must be set when modifying an existing certificate authority error. The password field is now cleared when the SCEP URL changes, so it's re-entered and sent with the update.
    • Fixed an empty username or password being saved on an NDES SCEP certificate authority.
    • Fixed adding or editing a certificate authority with a bad NDES admin URL or credentials showing a generic "Please try again." message instead of "Invalid admin URL or credentials."
    • Fixed updating an NDES SCEP certificate authority with the masked password (********) returned by the GET endpoint sending the mask to the NDES server as the literal password and failing with a misleading "invalid credentials" error. The mask is now rejected with an invalid-password error, matching GitOps behavior.
    • Fleet now skips validating NDES credentials against the NDES server when an update leaves the admin URL, username, and password unchanged, so a no-op edit doesn't consume a slot in NDES's password cache.
    • Fixed an unreachable NDES admin URL (timeout, DNS failure, connection refused) being reported as "Invalid admin URL or credentials" when editing an NDES SCEP certificate authority. It's now reported as "Couldn't connect to admin URL."
    • Fixed the Save button staying enabled in the edit certificate authority modal after Fleet clears the unchanged NDES password, which let the form submit an empty password.
    • Fixed editing a Windows configuration profile so that uploading a replacement file with a different name updates the profile's name.
    • Fixed uploading a Windows configuration profile with a file name longer than 255 characters returning a database error.
    • Fixed a bug where Windows disk encryption showed a "Resend" action that always failed, since BitLocker enforcement isn't a configuration profile.
    • Fixed an issue where Observer, Observer+ and Technician could not see the managed account rotation banner.
    • Fixed the error returned when a free-tier request sets a premium-only field so that it names the field as it appears in the request payload (for example critical) instead of Fleet's internal Go field name (for example Critical).
    • Fixed a query returning a MySQL error if hit with unsupported platforms, by now returning an empty result.
    • Fixed an issue where stale fleet names could appear in mdm.apple_business after renaming a fleet.
    • Fixed false positive vulnerabilities reported for JetBrains teamcity-cli installed via Homebrew, which was incorrectly matched to the TeamCity CI server's CPE.
    • Fixed fleetctl gitops silently dropping ios_updates and ipados_updates when it creates a new fleet.
    • Fixed fleetctl generate-gitops failing with an unsupported Content-Type error when the org logo is an SVG.
    • Fixed fleetctl generate-gitops not using .sh and .ps1 extensions for install scripts.
    • Fixed an issue where deleting an ADE device after turning off Apple Business could leave orphaned rows.
    • Fixed form validation on the new/edit user and API-only user forms: field errors no longer appear before a field has been edited, clear as soon as the field is focused, and the "select at least one fleet" error now renders on the selector instead of as a toast.
    • Updated validation error copy on the new/edit user and API-only user forms to the standard wording (e.g. "Enter an email" instead of "Email field must be completed").
    • Fixed the fleet, role, and API access controls staying editable while a user was being saved on the new/edit user and API-only user forms.
    • Fixed error toasts showing an expandable "Raw response" panel containing an empty {} when the underlying error carried no details.
    • Fixed inconsistent spacing around the enrollment URL on the iOS & iPadOS tab of the Add hosts modal, so it now matches the macOS and Android tabs.
    • Fixed the confirmation checkbox on the "Clear passcode" host modal rendering in green instead of red, so it now matches the destructive "Clear passcode" button.
    • Fixed incorrect background color on authentication pages (login, SSO, registration) in dark mode.
    • Fixed autofilled inputs showing a white background in dark mode. The autofill style now uses theme colors instead of a hardcoded white, and covers Firefox via the standard :autofill selector.
    • Fixed label color for install/post-install/uninstall script fields in software package advanced options to match Fleet's standard form label color.
    • Fixed long unbreakable words (e.g. file paths in inline code) overflowing the table info side panel on the report and policy editor pages.
    • Matched the height of the host status and platform/label filter dropdowns on the Hosts page.
    • Fixed the "Collecting results..." empty state on the report details page reading "about about X hours".
    • Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade.

    Fleet's agent

    The following version of Fleet's agent (fleetd) support the latest changes to Fleet:

    • orbit-v1.61.0
    • fleet-desktop-v1.61.0 (included with Orbit)
    • osquery-5.23.1 (included with Orbit)
    • fleetd-chrome-v1.3.5
    • fleetd-android-v1.5.0

    While newer versions of fleetd still function with older versions of Fleet, old versions of fleetd and osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet.

    Upgrading

    Please visit our upgrade guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    e0d2b9afcf661dcdaea3f0c9c0bd8b2c51fd032e8fb771b9e625c3b4e6b81210 fleet_v4.92.0_linux.tar.gz
    69e2319abbecc5e8a4a9f4bbe4233895d338af681daaf18d5d8eba608d0b5439 fleetctl_v4.92.0_linux_amd64.tar.gz
    da77eef850a0f13cede3b551c8ac90b424e7864a4145ba310cc730639127d1c1 fleetctl_v4.92.0_linux_amd64.zip
    3a12324fb34e397f5de2aca24a172080e20c81e0a213c6cb567564893802a366 fleetctl_v4.92.0_linux_arm64.tar.gz
    5827c85e48ae6a0fb18b9b38894445aec343f08a8dc82ef043d8855ae381d962 fleetctl_v4.92.0_linux_arm64.zip
    e4d8ccbe4303e794c0efa322d537bd418d992ec4a13db5e79077987e9099dcc9 fleetctl_v4.92.0_macos.tar.gz
    7675d605b0ce3f13a2fa3556ac1d231af60b13002098736df59ae5d322783913 fleetctl_v4.92.0_macos.zip
    9499cecadcc20a10bf1f43dfd0c0b3f5318b87687f722cbe3faa622b910cc2d9 fleetctl_v4.92.0_windows_amd64.tar.gz
    3f0578afbaf4504c66fc7580acd608953cfc299f81d96b277db31a1fc2a773e0 fleetctl_v4.92.0_windows_amd64.zip
    bf081d6487b75680045466978201e5ed0051eb545896e404f6290904b9ca7b6b fleetctl_v4.92.0_windows_arm64.tar.gz
    e98531e5db88da8effae211f3cafa44fa84258af79048879f3d379ffb49949cf fleetctl_v4.92.0_windows_arm64.zip

    Original source
  • Sep 18, 2026
    • Date parsed from source:
      Sep 18, 2026
    • First seen by Releasebot:
      Sep 22, 2026
    Fleet logo

    Fleet

    v4.92.0

    Fleet adds changes for v4.92.0, bringing the latest product updates to users.

    Adding changes for Fleet v4.92.0 (#52270)

    Original source
  • Sep 14, 2026
    • Date parsed from source:
      Sep 14, 2026
    • First seen by Releasebot:
      Sep 15, 2026
    Fleet logo

    Fleet

    orbit-v1.61.0: Cherry-pick #53119: Bump macadmins/osquery-extension to v1.5.4 (#53137)

    Fleet ships a cherry-picked fix into the rc-minor-fleetd-v1.61.0 release candidate branch, resolving issue #51527 and carrying forward the tested Fleet Desktop and fleetd change from #53119.

    Cherry-pick of #53119 into the rc-minor-fleetd-v1.61.0 RC branch.

    Related issue: Resolves #51527

    Checklist for submitter

    Changes file added for user-visible changes in changes/, orbit/changes/ or ee/fleetd-chrome/changes.

    See Changes
    files
    for more information.

    Testing

    QA'd all new/changed functionality manually (in original PR #53119)

    AI

    AI: Claude Code (claude-fable-5-1)

    fleetd/orbit/Fleet Desktop

    Verified compatibility with the latest released version of Fleet (see Must rule)

    If the change applies to only one platform, confirmed that runtime.GOOS is used as needed to isolate changes

    Co-authored-by: Claude [email protected]

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    Fleet logo

    Fleet

    v4.91.1: Revert #51896 slow host software list query fix from 4.91.1 RC (#52944)

    Fleet reverts the slow host software list query fix from 4.91.1 to avoid database migration conflicts, keeping the release on the original schema path and removing the changelog entry for that patch.

    Related issue: #51896

    Checklist for submitter

    If some of the following don't apply, delete the relevant line.

    Input data is properly validated, SELECT * is avoided, SQL
    injection is prevented (using placeholders for values in statements), JS
    inline code is prevented especially for url redirects, and untrusted
    data interpolated into shell scripts/commands is validated against shell
    metacharacters.

    Details

    Reverts the cherry-pick of #52338 ("Fix slow host software list query",
    RC commit 99cceca) from the 4.91.1 release candidate, and removes its
    entry from the 4.91.1 changelog.

    Why: the fix carries a database migration
    (AddHostVPPAndInHouseInstallsHostIndexes, 20260902150237 on main).
    Shipping it in 4.91.1 requires re-timestamping it on the RC to sort
    before 4.92.0's first new migration (20260810192005), which in turn
    requires a matching re-timestamp PR on main before 4.92.0 ships — the
    ADD INDEX migration is not idempotent, so a timestamp mismatch would
    break 4.91.1 → 4.92.0 upgrades. Dropping the fix from 4.91.1 avoids the
    renumbering entirely; #51896 ships in 4.92.0 with its original migration
    timestamp.

    After this revert, 4.91.1 contains no new migrations relative to
    4.91.0, and no migration renumbering is needed on main.

    Verified:

    go build / go vet clean on server/datastore/mysql

    TestMigrations passes; migration chain ends at
    20260810160000_DedupeSoftwareChecksums (same as 4.91.0 + earlier
    picks)

    TestSoftware/ListHostSoftware passes against the restored query code
    schema.sql restored (seed list back to id 591, new indexes removed)

    Testing

    Added/updated automated tests (existing tests cover the restored
    code; the reverted commit's tests were removed with it)

    For unreleased bug fixes in a release candidate, one of:

    Confirmed that the fix is not expected to adversely impact load
    test results (restores the code that shipped in 4.91.0; note the #51896
    slow query remains present in 4.91.1, as in 4.91.0)

    Co-authored-by: test [email protected]

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    Fleet logo

    Fleet

    fleet-v4.91.1

    Fleet fixes several product issues across software inventory, host activity, Apple Business deletions, dashboard charts, MDM command timing, SCIM group updates, and script-only package labels, improving reliability and accuracy across the platform.

    Bug fixes

    Fixed software title details pages and the hosts list software status filter timing out for software with a large install history.

    Fixed host activity queue getting stuck due to database transactions not retrying when getting MySQL error 1615

    Fixed deleting a host that was released from Apple Business reporting success while the host record stayed in Fleet. Fleet now checks the assignment with Apple before deleting, and returns an error instead of reporting success if Apple can't be reached.

    Fixed "Hosts enrolled" chart on the dashboard page to exclude pending hosts from per-platform counts.

    Fixed an issue where VPP and In House Apps would backdate and sometimes fall outside of the MDM command queue.

    Fixed a bug where updating a SCIM group's members could silently remove members that the identity provider did not ask to remove.

    Fixed script-only packages (.sh/.ps1/.py) with an uninstall script showing "Run/Rerun" and "Ran" instead of "Install/Reinstall", "Uninstall", and "Installed" on the host details and self-service pages.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    e21743e6b43beb3b9bc53e4df2e6a9e6f1a6d8b532e1a92902b29677b0b9af8f fleet_v4.91.1_linux.tar.gz

    78461d0d90e797eeb0d01a533211d8b0baab253eb3488fc970dda9ec8f56739d fleetctl_v4.91.1_linux_amd64.tar.gz

    a9f4f8221405ca61320a02f19801b3e3d70cb3c4115a8048c763330f86025d06 fleetctl_v4.91.1_linux_amd64.zip

    d5619f6c169bd64fa4cc893cc0935dbef816bbe84f56af466608de3d5e609e1a fleetctl_v4.91.1_linux_arm64.tar.gz

    eb5d68800e147a7193d96f5aacfd7b6ddfc48a6296698b1e7f7d7adcf53030bb fleetctl_v4.91.1_linux_arm64.zip

    737f1312342b2440512624edd4db6a3ab978e9371330f70c86d37854ec168e8d fleetctl_v4.91.1_macos.tar.gz

    02b5e8c8da6d59e68cfdcab16864db9fee34f558476d4241a435576d99106b30 fleetctl_v4.91.1_macos.zip

    aaaad19522c5fd932650b496e9e6670b86fe2d273d58b524851e42a1031cb805 fleetctl_v4.91.1_windows_amd64.tar.gz

    2166e34a17cdb4c2da8ef76c030b957932c77509cd3a40229e774f752f068823 fleetctl_v4.91.1_windows_amd64.zip

    c594c1f486bd9b05514ffa962eca7a1a9bb5c6942bc9bdabf0d95ae7ebda2da0 fleetctl_v4.91.1_windows_arm64.tar.gz

    5c0285e2f87dc396bbe0206e6ab4b402d474175b07beba12d3fd8940575600c4 fleetctl_v4.91.1_windows_arm64.zip

    Original source
  • Sep 2, 2026
    • Date parsed from source:
      Sep 2, 2026
    • First seen by Releasebot:
      Sep 3, 2026
    Fleet logo

    Fleet

    Fleet 4.91.0 | Windows local admin accounts, Autopilot default fleets, and more...

    Fleet releases 4.91.0 with major Windows device management upgrades, including local admin accounts and default Autopilot fleet assignment, plus richer webhooks, smarter patching, broader script variables, Apple Business release actions, and OS update improvements.

    Fleet 4.91.0 is now available. See the complete changelog or read on for highlights. For upgrade instructions, visit the upgrade guide in the Fleet docs.

    Three of this release's highlights close gaps in Windows device management: a local admin account for troubleshooting, automatic fleet assignment for Autopilot-enrolled hosts, and clearer software inventory for Windows Store apps. Read on for those, plus updates to webhooks, patch policies, scripts, DDM, Apple Business Manager, and OS updates.

    Highlights

    • Windows: create a local admin account
    • Default fleet for Windows Autopilot-enrolled hosts
    • Webhooks for host activities
    • Patch policies: install when the app is closed
    • Built-in variables in scripts
    • Release a host from Apple Business
    • Apple hardware marketing names
    • OS updates: update to latest after a deadline

    Windows: create a local admin account

    Available in Fleet Premium

    IT admins can now create managed local admin accounts on Windows hosts. Turn on Create hidden admin for Windows under Controls > Setup experience > Users, or set windows_settings.enable_managed_local_account in GitOps. Fleet creates the account, hides it from the sign-in screen, and generates a unique, escrowed password for each host. All roles in Fleet can retrieve the password from Host details > Actions > Show managed account when IT needs a break-glass account for troubleshooting.

    On macOS, managed accounts are created only at enrollment time, and only for hosts that automatically enroll via Apple Business Manager. On Windows, they're created on every host with MDM turned on, including hosts that enrolled earlier.

    GitHub issue: #43488

    Default fleet for Windows Autopilot-enrolled hosts

    IT admins can now choose a default fleet for hosts that enroll through Windows Autopilot. New Autopilot-enrolled Windows hosts land in that fleet automatically, instead of sitting in "Unassigned" until an admin transfers them by hand. Only global admins can set the default, and it's available in GitOps as mdm.windows_automatic_enrollment.default_fleet.

    GitHub issue: #41787

    Webhooks for host activities

    Available in Fleet Premium

    IT Admins and Security Engineers can now send a webhook for every activity tied to a specific host, like a script run, software install, or configuration profile install. Configure a webhook URL per fleet from that fleet's Hosts page, or with webhook_settings.host_activities_webhook in GitOps, to feed a SIEM or trigger automations in a third-party automation tool (e.g. Tines).

    GitHub issue: #40493

    Patch policies: install when the app is closed

    Available in Fleet Premium

    Patch policies for Fleet-maintained apps can now wait until the app is closed before installing an update, instead of forcing the update while an end user is mid-task. Choose Patch only when app is closed when adding or editing a Fleet-maintained app, and Fleet skips the install (logged as "Install skipped") until the app quits, then installs it on the next automation run.

    GitHub issue: #39962

    Built-in variables in scripts

    Available in Fleet Premium

    Fleet's built-in variables, like $FLEET_VAR_HOST_END_USER_IDP_USERNAME, now work in shell, PowerShell, and Python script content on macOS, Windows, Linux hosts, not just configuration profiles. IT Admins can write one script that inserts a host's serial number, IdP username, or other host-specific values, instead of hardcoding a value per host. Fleet validates variable references when a script is uploaded, so a script referencing a variable that doesn't exist is rejected before it ever runs.

    GitHub issue: #46837

    Release a host from Apple Business

    Available in Fleet Premium

    IT admins can now release a host from Apple Business (ABM) directly from the Fleet UI or API, without signing into the ABM portal. Use the Release from Apple Business action on an eligible host's details page, or release multiple hosts at once via the API. Only Fleet users with admin role can release a host.

    GitHub issue: #47633

    Apple hardware marketing names

    Fleet now shows the Apple hardware marketing name, like "MacBook Pro 16-inch, M3, 2023," on the Hosts, Host details, and Fleet Desktop > My device pages, instead of the raw hardware model identifier (for example, "Mac15,9"). This makes it easier to tell which hardware a host is running without looking up the model identifier yourself.

    GitHub issue: #46818

    OS updates: update to latest after a deadline

    Available in Fleet Premium

    IT Admins managing macOS, iOS, and iPadOS OS updates can now set enforcement to always target the latest OS version, with a deadline measured in days after each release, instead of pinning to a specific version and a fixed calendar date. As Apple ships new OS versions, Fleet updates the enforced target automatically, so admins don't have to bump the minimum version by hand every time Apple releases an update.

    GitHub issue: #39085

    Changes

    IT Admins

    • Added the ability to create a managed local admin account on Windows hosts. Requires fleetd 1.60.0 or higher.
    • Added a default fleet for new Windows MDM enrollments (Fleet Premium). IT admins can pick the fleet that hosts enrolling through user-driven Windows MDM enrollment (Windows Autopilot, Entra join) are automatically assigned to. The fleet is assigned before the Autopilot Enrollment Status Page runs, so the default fleet's software, scripts, and configuration profiles apply during out-of-box setup.
    • Added the option to keep macOS, iOS, and iPadOS hosts on the latest OS version (Fleet Premium). Setting minimum_version to latest along with deadline_days tells Fleet to automatically track the newest version Apple publishes for each host's hardware and to set the update deadline that many days after the version has been released.
    • Added activity automations for fleets (Fleet Premium): a per-fleet webhook, configured from the Hosts page, that sends a request to a destination URL whenever an activity linked to one of the fleet's hosts is created.
    • Added a "Patch when closed" option for patch policies that only patches an app on a host if the app is not running.
    • Added support for Fleet's built-in variables (e.g. $FLEET_VAR_HOST_END_USER_IDP_USERNAME) in scripts, including software install, post-install, and uninstall scripts. Variables are resolved per host at execution time and require a Fleet Premium license.
    • Added Adobe plugins to software inventory: Fleet now detects Adobe Creative Cloud plugins (CEP and UXP extensions) on macOS and Windows hosts and lists them on the Software page and host details with the software type "Plugin (Adobe)", including version and host count.
    • Added 29 new iOS/iPadOS device vitals, such as battery level, accessibility settings, cellular technology, cloud backup status, organization info, MDM options, device attestation, and cellular service subscriptions, collected via the existing DeviceInformation MDM refetch and shown in the host API response and a new "View all" vitals modal on the host details page. Personal (BYOD) enrollments don't receive these new fields, to avoid exposing information about a device the organization doesn't own.
    • Added marketing name display for Apple devices (macOS, iOS, iPadOS) on the Hosts and Host details pages. The "Hardware model" field now shows human-readable names (e.g. "MacBook Pro (16-inch, 2021)") instead of raw identifiers (e.g. "MacBookPro18,1").
    • Added support for releasing devices from Apple Business inside Fleet.
    • Added the s3_software_installers_signed_url configuration option to serve software installer, in-house app, and bootstrap package downloads via GCS presigned URLs (the GCS counterpart to CloudFront URL signing), so clients download directly from object storage instead of streaming through the Fleet server.
    • Added support for custom host vitals ($FLEET_HOST_VITAL_) in Android configuration profiles and managed app configuration, including per-host value expansion at delivery and automatic resend when a host's value changes.
    • Added support for $FLEET_HOST_VITAL_ custom host vital variables in host name templates, including per-host resolution, validation of referenced vital IDs, and automatic re-delivery when a host's vital value changes.
    • Added support for nested groups in Entra in IdP vitals.
    • Added linux as a label platform option, which targets hosts on any Linux distribution.
    • Added a sortable "Added to Fleet" column to the hosts table, showing when each host last enrolled with Fleet.
    • Added support for enabling/disabling software inventory per-fleet via PATCH /api/v1/fleet/fleets/{id} with {"features": {"enable_software_inventory": }}. The key follows PATCH-merge semantics: when omitted, the stored value is unchanged.
    • Added a --bypass-end-user-auth flag to fleetctl package that configures the generated fleetd installer to skip the end-user authentication prompt during enrollment on Linux and Windows hosts (e.g. when the end user already authenticated via another MDM). Requires fleetd v1.60.0 or higher.
    • Added host_id and host_serial to the mdm_enrolled activity for Apple (macOS, iOS, iPadOS) enrollments, and the activity now appears on the host's activity timeline.
    • Added token_invalid to the ABM token API responses and dep_device_error (a human-readable message) to GET /hosts/:id/dep_assignment, to help identify why a host's Apple Business Manager device lookup or ABM token isn't returning expected data (e.g. a rejected or invalid-signature token, unsigned terms, a server-side error, or the device no longer being assigned to Fleet).

    Security Engineers

    • Changed Orbit enrollment to determine end user authentication requirements from server policy rather than client-advertised capabilities. The mdm.allow_orbit_end_user_auth_bypass server setting (enabled by default) controls whether hosts that do not complete end user authentication may enroll into a fleet that requires it; set it to false to strictly enforce end user authentication for all Orbit enrollments.
    • Added a user_mfa_requested activity, recorded when valid credentials are submitted for an MFA-enabled account and a verification email is sent.
    • Added created_setup_experience_script and deleted_setup_experience_script activities so that adding, replacing, or removing a setup experience script (via the API or GitOps) is recorded in the audit log.
    • Updated the macOS CIS benchmark policies to the latest CIS releases: macOS 14 Sonoma v3.1.0, macOS 15 Sequoia v2.1.0, and macOS 26 Tahoe v1.1.0.
    • Excluded Adobe plugins from vulnerability scanning, so no vulnerabilities are reported for them. No vulnerability data source maps an Adobe CEP or UXP extension to a CVE; Adobe files CVEs against the host application (Photoshop, Acrobat, and so on), which Fleet already scans.

    Bug fixes and improvements

    • Updated configuration profiles scoped by dynamic (query-based) labels to preserve a host's current profile state while the host's membership in a label is still unknown. Profile changes only happen after the label has been evaluated at the host's next refetch, so adding a new exclude-any (or include-all) label to a profile does not immediately remove it from hosts that have not run the label's query yet.
    • Improved the performance of the configuration profiles status summary (GET /api/latest/fleet/configuration_profiles/summary) for Windows hosts so it no longer times out on large fleets.
    • Reduced database load when software installed-path updates hit lock contention: the transaction now fails fast instead of retrying, and the host's next software report reconciles the paths.
    • Improved software ingestion performance at scale by batching host_software_installed_paths deletes (previously unbounded single statements).
    • Blocked host enrollment with empty or whitespace-only enroll secrets across all enrollment paths (osquery, Orbit, Apple MDM, Android), and removed any pre-existing empty enroll secrets.
    • Updated Windows SCEP profiles to fail with a clear message when the certificate authority challenge contains characters Windows doesn't support (ASN.1 PrintableString), instead of showing "Verified" while no certificate is installed.
    • Improved input validation for the Windows MDM enrollment flow.
    • Normalized LocURI values before validation in Windows profile handling.
    • Improved LocURI validation in Windows profile handling to canonicalize element content before checking.
    • Updated the macOS disk encryption banner on the Host details and My device pages to tell IT admins and end users that ADE-enrolled hosts escrow their FileVault key automatically on the next refetch, instead of asking the end user to log out.
    • Added a clear error message when adding both Mozilla Firefox and Firefox ESR (which share a bundle identifier) to the same fleet, so admins understand only one of them can be added instead of seeing a generic conflict error.
    • Added deduplication and out-of-order protection to the Android MDM Pub/Sub notification handler. Duplicate deliveries from Google Pub/Sub no longer re-run the setup experience or emit duplicate activities, and a stale device-deleted notification arriving after a re-enrollment no longer leaves the host stuck showing unenrolled.
    • Bounded the Android device reconciliation cron's Google API pagination so a malformed or cycling response can no longer cause an unbounded loop, and added periodic progress logging during pagination.
    • Bounded how much of a Google Workspace directory one IdP sync pass pulls, so a very large directory or a misbehaving response can no longer paginate indefinitely or grow server memory without limit. A sync that exceeds a limit fails with an error naming the limit (visible as the last IdP sync status) instead of ingesting a partial directory.
    • Clarified the failed-install modal copy on Android hosts to explain that the end user can retry via the Google Play Store in their work profile.
    • Added a disabled Refetch button with a tooltip on the Host details page for Android hosts, explaining that Android hosts sync data automatically and linking to how to sync manually.
    • Removed the misleading Self-service preview tab from the "Edit appearance" modal for Android apps. Android apps are installed from the Play Store rather than the Fleet self-service web view, and updating the appearance will not change anything in the Play Store.
    • Disabled the Android MDM "Connect" and "Turn off Android MDM" buttons with a GitOps tooltip when GitOps mode is enabled, matching the Windows MDM behavior.
    • Added software upload progress logging to fleetctl GitOps.
    • Added a diagnostic message when an install script can't be run (exit code -1), such as when the interpreter in its shebang is missing on the host, instead of reporting no output.
    • Allowed .py script-only packages to be assigned a setup_experience_platform (darwin or linux), matching .sh.
    • Added a software package maximum size error message in the UI to fix inconsistent errors across different browsers.
    • Normalized login responses for accounts with MFA enabled to follow authentication best practices.
    • Made MFA login token redemption atomic so a single one-time token can no longer be used to create more than one session under concurrent requests.
    • Ensured a password reset token can only be used once.
    • Added 255-character caps to additional user-supplied name and description inputs (API user, custom variable, certificate, label, pack, certificate authority forms) to prevent the same class of overflow bug.
    • Reworked the fleets dropdown to make the search input discoverable at 10+ fleets and added an "Add fleet" affordance for global admins.
    • Restricted deleting a fleet to global write permissions (global admin or GitOps), matching the existing restriction on creating one.
    • Restricted the manual MDM enrollment profile endpoint (GET /api/v1/fleet/enrollment_profiles/manual) to global and fleet-scoped admins and maintainers.
    • Clarified the Controls > OS updates empty state to say "Apple or Windows MDM must be turned on" and link to MDM settings, so it no longer implies MDM is off when only Android MDM is enabled.
    • Improved the Apple Business success toast shown after editing fleet assignments to name the organization.
    • Renamed the "Program (Windows)" software type to "Application (Windows)", which includes apps installed through the Windows app store.
    • Added tooltips to the "Agent", "Last restarted", and "Status" column headers on the Hosts page explaining which platforms are supported and why.
    • Updated the "Last opened" tooltip on the Host details Software table to explain why it's only supported for native macOS, Windows, and Linux apps and packages.
    • Removed the cellProps.rows.length === 1 workaround (which suppressed the tooltip whenever the table had exactly one row) by adding the correct CSS, fixing the tooltip overflowing when the host table has only one row.
    • Ranked "Select API endpoints" search results by relevance (exact match, then prefix, then whole-word, then substring, matched against both name and path) instead of leaving them in an unranked catalog order, and fixed a bug where the table's default sort silently discarded that ranking.
    • Removed pagination from the "Select API endpoints" search results table (Settings > Users > Add API-only user > Specific API endpoints), relying on the results dropdown's existing scrollbar instead.
    • Improved empty state copy on the software title detail page when the software is not found in the selected fleet.
    • Made the per-platform entries in the dashboard "Hosts enrolled" chart keyboard accessible: each platform with hosts is now focusable via Tab, activatable with Enter/Space, has a visible focus indicator, and exposes an accessible name (e.g. "macOS hosts").
    • Enforced API-only endpoint restrictions on chart endpoints.
    • Updated button styles across the Fleet UI to use the new bordered secondary and subdued button variants.
    • Aligned the configuration profiles empty state with the assets tab styling so admin and maintainer users see a consistent empty state.
    • Aligned the configuration profiles and assets empty states for technicians with the shared EmptyState styling.
    • Added a FLEET_DEV_SKIP_S3_CONFIG environment variable to skip applying local S3 dev defaults and creating test S3 buckets when running fleet serve --dev.
    • Added --since-commit and --commit flags to the migration-cleanup tool, allowing migration rename scans scoped to a commit range on main or a single commit, in addition to the existing --branch mode.
    • Split ListHostSoftware and ModifyAppConfig into smaller helpers so that those packages can be checked by the nilaway linter.
    • Removed an unneeded dependency that does not support Apple M chips.
    • Updated Go to 1.26.7.
    • Fixed an App Store or in-house app install that a device acknowledged but never verified leaving the host unable to run anything else. Fleet now fails such an install after 24 hours and releases the host's activity queue, so scripts, software installs, and uninstalls waiting behind it run. The wait is configurable with FLEET_SERVER_VPP_INSTALL_REAP_TIMEOUT. An install whose command has not reached the device yet is left alone until it can no longer be delivered.
    • Fixed Fleet holding on to an App Store app verification command after it had nothing left to verify on that host, which delayed verifying the next install on the same host by up to a day.
    • Fixed software (packages, App Store apps, and in-house apps) targeted with "exclude any" on a host vitals label being hidden from, and blocked for, every host instead of only the label's members.
    • Fixed duplicate software inventory entries (same name, version, and source with the same vulnerabilities but different host counts) that could appear on instances upgraded to Fleet v4.76.0 or later. Existing duplicate giflib (Homebrew) entries are merged during the database migration on upgrade.
    • Fixed a false-negative vulnerability report where Firefox Developer Edition on macOS was not matched to any CVEs because Fleet generated no CPE for it.
    • Fixed the SCEP proxy so that Windows profiles using a custom SCEP proxy certificate authority have their one-time Fleet challenge validated before a PKIOperation request is forwarded to the certificate authority. Requests with a missing, incorrect, or expired challenge are now rejected.
    • Fixed the SCEP proxy so that a Windows profile pending removal can no longer be used to relay SCEP requests to the configured certificate authority, and so that proxy error responses no longer include the certificate authority's URL.
    • Fixed a few edge cases for Apple profile reconciliation when devices respond with NotNow in certain scenarios.
    • Fixed an issue where re-enrolling an Apple device with a different type, e.g. Manual -> ADE, would not update the enrollment type correctly.
    • Fixed a bug where an Apple configuration profile (DDM declaration) could become undeletable if the set of allowed declaration types changed after the profile was added (for example, when a server configuration flag was toggled). Deleting a profile no longer re-runs upload-time validation.
    • Fixed Fleet storing an unusable disk encryption key and logging an escrow activity for macOS hosts that aren't enrolled in Fleet's MDM.
    • Fixed team-level BitLocker PIN enforcement never reaching Windows hosts when Apple MDM was not configured on the server: the "Create PIN" banner appeared on the My device page, but the queries and MDM command that enable PIN setup were never sent.
    • Fixed Windows software whose inventory name includes the version (e.g. "Granola 7.373.2") not matching the Fleet-maintained app's software title, which prevented the uninstall action from appearing and listed each version as its own software title. Applies to Fleet-maintained apps that have been added as an installer. Existing mismatched titles are merged when the app is added, shortly after server startup, and hourly thereafter.
    • Fixed a bug where a failed macOS Fleet-maintained app install could be reported as successfully installed because the install script did not check the exit code of the command that installed the app. This covers generated install scripts, the custom install scripts used by some apps (including Google Chrome, Zoom, Microsoft Edge, and Webex), and the already-published scripts of frozen apps.
    • Fixed the Docker Desktop macOS Fleet-maintained app not reporting an installed version or "Installed" status on hosts that already have Docker Desktop. The app matched on the embedded Electron bundle identifier (com.electron.dockerdesktop) instead of the identifier the installed app reports (com.docker.docker), and embedded bundles are excluded from software inventory. Existing Docker Desktop installers are re-pointed to the correct software title on upgrade.
    • Fixed a bug where the patch policy for the Windows Git Fleet-maintained app always returned "Pass", even on hosts running an outdated version, so update automations never triggered. The generated query matched programs.name LIKE 'Git %', but Git for Windows registers itself in the registry as exactly Git.
    • Fixed the macOS "Steam up to date" patch policy always failing on hosts that have the current version of Steam installed. Steam.app ships without a CFBundleShortVersionString, so the generated policy now compares CFBundleVersion, which agrees with the version Fleet reports in software inventory.
    • Fixed Fleet no longer recognizing hosts running Omarchy as Linux. Omarchy 4 ships its own /etc/os-release and reports platform=omarchy, where earlier versions inherited arch from Arch Linux and were covered by Fleet's Arch support. Host vitals and software inventory populate again, disk encryption and key escrow are available, policies and labels scoped to linux apply, and scripts can be run from the host's Actions menu. Omarchy hosts continue to roll up onto the "Arch Linux" / "rolling" row in Software > OS.
    • Fixed Android hosts staying stuck on a pending Lock, Wipe, or Clear passcode when Google never delivered the command's result to Fleet. Fleet now checks the command's outcome directly with Google once a day and updates the host, so the command can be re-issued.
    • Fixed the Hosts page so that managed Android hosts display their serial number instead of "Not supported" when one is reported.
    • Fixed an issue where GitOps could apply MDM SSO configuration values that were invalid.
    • Fixed an issue where generate-gitops would export an empty apple_business section if the AB default fleets had only been set via the UI.
    • Fixed the Google Calendar integration scheduling maintenance events over users' Focus Time and Out of office blocks.
    • Fixed the SCIM last request telemetry so that authorization failures (403 Forbidden) from unauthorized users are no longer persisted, preventing them from overwriting the admin-visible SCIM status.
    • Fixed an edge case where deactivating a SCIM user did not deprovision the matching Fleet user if the user's identifiers were changed in the same request.
    • Fixed the Helm chart's Deployment and fleet-vulnprocessing CronJob templates so empty/unset entries in environments (e.g. the default FLEET_SERVER_PRIVATE_KEY: "") are omitted from the rendered container env list instead of being emitted as an empty-string env var, which previously collided with the same key supplied via envsFrom and caused server-side apply to reject the object with a "duplicate entries for key" error.
    • Fixed password reset so that case-mutated reset tokens are no longer accepted; tokens are now matched case-sensitively.
    • Fixed an issue where an SSO-only invitation could be accepted with a password, creating a local password-authenticated account and bypassing SSO enforcement. The authentication mode is now derived solely from the invite.
    • Fixed the hosts list endpoint sometimes returning software title details that didn't match the applied filter.
    • Fixed the software title details response so that installer script contents and managed app configuration are only returned to users authorized to read the installer, and so that a request without a fleet is authorized against "No team" instead of skipping the scope check. This applies to GET /api/v1/fleet/software/titles/{id} and to the software_title included in GET /api/v1/fleet/hosts when filtering by software_title_id.
    • Fixed a software title request without a fleet so that it only resolves titles in fleets the requester can see. Previously a title reachable only through a software package, App Store app, or in-house app in another fleet was returned, which told the requester that software they have no access to exists.
    • Fixed device-authenticated ("My device") software uninstall so that it applies the same self-service and label-scope rules as the self-service install path, instead of accepting any package on the host's fleet.
    • Fixed the OS versions API (GET /api/latest/fleet/os_versions) to return a validation error for an unsupported platform filter and a "not found" error for an unknown OS version ID, instead of a successful but empty or null-filled response. Also corrected the max_vulnerabilities validation message so the >= character is no longer returned HTML-escaped.
    • Fixed the delete host endpoint returning inconsistent responses for a host outside the requester's fleet versus one that doesn't exist.
    • Fixed the host transfer activity (transferred_hosts) to only record host IDs that actually exist, so non-existent host IDs passed to POST /api/latest/fleet/hosts/transfer can no longer be injected into the audit trail. No activity is created when none of the requested hosts exist.
    • Fixed the policy automations table showing only one host for automation runs that cover multiple hosts.
    • Fixed query (report) responses so that pack metadata (ID, name, description) is only included when the requesting user is authorized to read packs, preventing cross-fleet pack metadata disclosure via query name collisions.
    • Fixed the live query results websocket stream returning a different error for a nonexistent campaign versus one owned by another user.
    • Fixed the self-service "Install all" button so its count and install target scope to the current search query. Previously, typing a search would filter the visible list while "Install all" still counted (and queued) every item in the selected category, including software the search had filtered out.
    • Fixed device-authenticated ("My device") endpoints so that host policies are returned in a device-safe representation that no longer exposes the policy author's name and email or the policy's raw SQL query.
    • Fixed a bug where a .sh or .py software package with Windows-style (CRLF) line endings was accepted at upload but failed to install on Linux hosts with a "No such file or directory" error. Line endings are now normalized to Unix-style before the script is stored.
    • Fixed a potential resource exhaustion issue in the MSI metadata parser.
    • Fixed a race condition that allowed a one-time software installer download token to be redeemed more than once when many requests raced concurrently, by making the token consumption atomic.
    • Fixed the "Add software" error for a file whose contents don't match a supported installer format: it no longer says "Couldn't edit software" on an add and no longer implies the file extension is the problem.
    • Fixed software installer validation errors reporting the wrong action verb (add vs. edit).
    • Fixed the install rejection message for .sh/.py script packages to say they can be installed on macOS and Linux hosts, rather than Linux only.
    • Fixed long fleet names overflowing the fleets table, fleet detail page header, teams dropdown, and manage enroll secrets modal. Fleet name inputs now cap at 255 characters (matching the database column), and the API and GitOps now return a clear validation error instead of a raw "Data too long" MySQL error when a longer name is submitted.
    • Fixed long label names overflowing the Labels card on the host details page.
    • Fixed a bug where modifying a label could silently persist a membership change without recording an audit activity when the label's metadata update failed (e.g. renaming to a name that already exists). Label metadata and membership are now saved in a single transaction, so a failed update rolls back both.
    • Fixed the Setup experience Users settings to default the account type to "Admin" for fleets whose config predates the setting, instead of showing no selection.
    • Fixed sort direction on the "Last seen" and "Last fetched" columns of the hosts table so that sort descending puts the oldest date (biggest "days ago" number) first, matching the visible duration rather than the underlying timestamp.
    • Fixed the "Last restarted" vital showing on ChromeOS hosts, where it's not actually collected.
    • Fixed the status-filter dropdown's selected-value icon (e.g. the disk encryption, bootstrap package, and policy status filters on the Hosts page) rendering near-black and barely visible in dark mode.
    • Fixed UI to show a direct button instead of a single-item dropdown on the Labels page (for users without edit/delete permissions) and the Integrations page (Jira/Zendesk).
    • Fixed styling issues with the gap between icons and text across the product.
    • Fixed the page content shifting left when opening a role dropdown near the bottom of the New user form (/settings/users/new/human). Dropdowns now flip upward when there's no room below the trigger.
    • Fixed the page content shifting left when opening the Actions dropdown on the last rows of a table (labels, users, fleets), and the resulting jump when a delete modal opened. The dropdown menu now flips upward when there's no room below the trigger.
    • Fixed an accessibility issue where the resend button would not show up when focused inside the OS settings modal.
    • Fixed tooltips wrapping icons or numeric values (like the Issues count on the host details page) showing a text (I-beam) cursor on hover, which made them look editable; those tooltips now use the default arrow cursor. Underlined-text tooltips are unchanged.
    • Fixed the My device > Self-service search bar not sitting flush right when the "Install all" button isn't rendered.
    • Fixed an empty summary card rendering above the Vitals section on the host details page for Fleet Free hosts with no summary content (Android, and iOS/iPadOS with no OS settings).
    • Fixed data table column headers stretching vertically when the table has no rows (e.g. while refetching from a zero-result search on the My device software page).
    • Fixed the misaligned icon in notify.success / notify.error toast notifications so it sits on the first line of the message on both single- and multi-line toasts.
    • Fixed low color contrast on the "Inherited" tag and unified the styling of tags (e.g. "Inherited," "API," "Patch," host filter chips, and host label pills) across the UI to match the design system.
    • Fixed helper text under checkboxes and radio buttons so it aligns with the label instead of the control.
    • Fixed misaligned app icons on the macOS setup experience "Setting up your device" screen.
    • Fixed an issue where the user-scoped icon wasn't showing for iOS and iPadOS hosts.
    • Fixed an issue where Fleet would show a turn on MDM banner before knowing the device state.
    • Fixed the script and query editors so that scrolling after a single click no longer selects text instead of scrolling.

    Ready to upgrade?

    Visit our Upgrade guide in the Fleet docs to update to Fleet 4.91.0.

    Manage all your devices like it's 2026

    Open MDM, patching, and vuln management for every OS.

    Original source
  • Sep 2, 2026
    • Date parsed from source:
      Sep 2, 2026
    • First seen by Releasebot:
      Sep 3, 2026
    Fleet logo

    Fleet

    v4.91.0

    Fleet adds changes in Fleet 4.91.0.

    Adding changes for Fleet 4.91.0

    Original source
  • Sep 2, 2026
    • Date parsed from source:
      Sep 2, 2026
    • First seen by Releasebot:
      Sep 3, 2026
    Fleet logo

    Fleet

    fleet-v4.91.0

    Fleet ships 4.91.0 with major IT admin upgrades, including managed local admin accounts on Windows, smarter Apple and Android device management, fleet-level automations, richer host vitals, expanded software inventory, and a broad set of security, performance, and UI fixes.

    Fleet 4.91.0 (Sep 2, 2026)

    IT Admins

    Added the ability to create a managed local admin account on Windows hosts. Requires fleetd 1.60.0 or higher.

    Added a default fleet for new Windows MDM enrollments (Fleet Premium). IT admins can pick the fleet that hosts enrolling through user-driven Windows MDM enrollment (Windows Autopilot, Entra join) are automatically assigned to. The fleet is assigned before the Autopilot Enrollment Status Page runs, so the default fleet's software, scripts, and configuration profiles apply during out-of-box setup.

    Added the option to keep macOS, iOS, and iPadOS hosts on the latest OS version (Fleet Premium). Setting minimum_version to latest along with deadline_days tells Fleet to automatically track the newest version Apple publishes for each host's hardware and to set the update deadline that many days after the version has been released.

    Added activity automations for fleets (Fleet Premium): a per-fleet webhook, configured from the Hosts page, that sends a request to a destination URL whenever an activity linked to one of the fleet's hosts is created.

    Added a "Patch when closed" option for patch policies that only patches an app on a host if the app is not running.

    Added support for Fleet's built-in variables (e.g. $FLEET_VAR_HOST_END_USER_IDP_USERNAME) in scripts, including software install, post-install, and uninstall scripts. Variables are resolved per host at execution time and require a Fleet Premium license.

    Added Adobe plugins to software inventory: Fleet now detects Adobe Creative Cloud plugins (CEP and UXP extensions) on macOS and Windows hosts and lists them on the Software page and host details with the software type "Plugin (Adobe)", including version and host count.

    Added 29 new iOS/iPadOS device vitals, such as battery level, accessibility settings, cellular technology, cloud backup status, organization info, MDM options, device attestation, and cellular service subscriptions, collected via the existing DeviceInformation MDM refetch and shown in the host API response and a new "View all" vitals modal on the host details page. Personal (BYOD) enrollments don't receive these new fields, to avoid exposing information about a device the organization doesn't own.

    Added marketing name display for Apple devices (macOS, iOS, iPadOS) on the Hosts and Host details pages. The "Hardware model" field now shows human-readable names (e.g. "MacBook Pro (16-inch, 2021)") instead of raw identifiers (e.g. "MacBookPro18,1").

    Added support for releasing devices from Apple Business inside Fleet.

    Added the s3_software_installers_signed_url configuration option to serve software installer, in-house app, and bootstrap package downloads via GCS presigned URLs (the GCS counterpart to CloudFront URL signing), so clients download directly from object storage instead of streaming through the Fleet server.

    Added support for custom host vitals ($FLEET_HOST_VITAL_<id>) in Android configuration profiles and managed app configuration, including per-host value expansion at delivery and automatic resend when a host's value changes.

    Added support for $FLEET_HOST_VITAL_<id> custom host vital variables in host name templates, including per-host resolution, validation of referenced vital IDs, and automatic re-delivery when a host's vital value changes.

    Added support for nested groups in Entra in IdP vitals.

    Added linux as a label platform option, which targets hosts on any Linux distribution.

    Added a sortable "Added to Fleet" column to the hosts table, showing when each host last enrolled with Fleet.

    Added support for enabling/disabling software inventory per-fleet via PATCH /api/v1/fleet/fleets/{id} with {"features": {"enable_software_inventory": <bool>}}. The key follows PATCH-merge semantics: when omitted, the stored value is unchanged.

    Added a --bypass-end-user-auth flag to fleetctl package that configures the generated fleetd installer to skip the end-user authentication prompt during enrollment on Linux and Windows hosts (e.g. when the end user already authenticated via another MDM). Requires fleetd v1.60.0 or higher.

    Added host_id and host_serial to the mdm_enrolled activity for Apple (macOS, iOS, iPadOS) enrollments, and the activity now appears on the host's activity timeline.

    Added token_invalid to the ABM token API responses and dep_device_error (a human-readable message) to GET /hosts/:id/dep_assignment, to help identify why a host's Apple Business Manager device lookup or ABM token isn't returning expected data (e.g. a rejected or invalid-signature token, unsigned terms, a server-side error, or the device no longer being assigned to Fleet).

    Security Engineers

    Changed Orbit enrollment to determine end user authentication requirements from server policy rather than client-advertised capabilities. The mdm.allow_orbit_end_user_auth_bypass server setting (enabled by default) controls whether hosts that do not complete end user authentication may enroll into a fleet that requires it; set it to false to strictly enforce end user authentication for all Orbit enrollments.

    Added a user_mfa_requested activity, recorded when valid credentials are submitted for an MFA-enabled account and a verification email is sent.

    Added created_setup_experience_script and deleted_setup_experience_script activities so that adding, replacing, or removing a setup experience script (via the API or GitOps) is recorded in the audit log.

    Updated the macOS CIS benchmark policies to the latest CIS releases: macOS 14 Sonoma v3.1.0, macOS 15 Sequoia v2.1.0, and macOS 26 Tahoe v1.1.0.

    Excluded Adobe plugins from vulnerability scanning, so no vulnerabilities are reported for them. No vulnerability data source maps an Adobe CEP or UXP extension to a CVE; Adobe files CVEs against the host application (Photoshop, Acrobat, and so on), which Fleet already scans.

    Bug fixes and improvements

    Updated configuration profiles scoped by dynamic (query-based) labels to preserve a host's current profile state while the host's membership in a label is still unknown. Profile changes only happen after the label has been evaluated at the host's next refetch, so adding a new exclude-any (or include-all) label to a profile does not immediately remove it from hosts that have not run the label's query yet.

    Improved the performance of the configuration profiles status summary (GET /api/latest/fleet/configuration_profiles/summary) for Windows hosts so it no longer times out on large fleets.

    Reduced database load when software installed-path updates hit lock contention: the transaction now fails fast instead of retrying, and the host's next software report reconciles the paths.

    Improved software ingestion performance at scale by batching host_software_installed_paths deletes (previously unbounded single statements).

    Blocked host enrollment with empty or whitespace-only enroll secrets across all enrollment paths (osquery, Orbit, Apple MDM, Android), and removed any pre-existing empty enroll secrets.

    Updated Windows SCEP profiles to fail with a clear message when the certificate authority challenge contains characters Windows doesn't support (ASN.1 PrintableString), instead of showing "Verified" while no certificate is installed.

    Improved input validation for the Windows MDM enrollment flow.

    Normalized LocURI values before validation in Windows profile handling.

    Improved LocURI validation in Windows profile handling to canonicalize element content before checking.

    Updated the macOS disk encryption banner on the Host details and My device pages to tell IT admins and end users that ADE-enrolled hosts escrow their FileVault key automatically on the next refetch, instead of asking the end user to log out.

    Added a clear error message when adding both Mozilla Firefox and Firefox ESR (which share a bundle identifier) to the same fleet, so admins understand only one of them can be added instead of seeing a generic conflict error.

    Added deduplication and out-of-order protection to the Android MDM Pub/Sub notification handler. Duplicate deliveries from Google Pub/Sub no longer re-run the setup experience or emit duplicate activities, and a stale device-deleted notification arriving after a re-enrollment no longer leaves the host stuck showing unenrolled.

    Bounded the Android device reconciliation cron's Google API pagination so a malformed or cycling response can no longer cause an unbounded loop, and added periodic progress logging during pagination.

    Bounded how much of a Google Workspace directory one IdP sync pass pulls, so a very large directory or a misbehaving response can no longer paginate indefinitely or grow server memory without limit. A sync that exceeds a limit fails with an error naming the limit (visible as the last IdP sync status) instead of ingesting a partial directory.

    Clarified the failed-install modal copy on Android hosts to explain that the end user can retry via the Google Play Store in their work profile.

    Added a disabled Refetch button with a tooltip on the Host details page for Android hosts, explaining that Android hosts sync data automatically and linking to how to sync manually.

    Removed the misleading Self-service preview tab from the "Edit appearance" modal for Android apps. Android apps are installed from the Play Store rather than the Fleet self-service web view, and updating the appearance will not change anything in the Play Store.

    Disabled the Android MDM "Connect" and "Turn off Android MDM" buttons with a GitOps tooltip when GitOps mode is enabled, matching the Windows MDM behavior.

    Added software upload progress logging to fleetctl GitOps.

    Added a diagnostic message when an install script can't be run (exit code -1), such as when the interpreter in its shebang is missing on the host, instead of reporting no output.

    Allowed .py script-only packages to be assigned a setup_experience_platform (darwin or linux), matching .sh.

    Added a software package maximum size error message in the UI to fix inconsistent errors across different browsers.

    Normalized login responses for accounts with MFA enabled to follow authentication best practices.

    Made MFA login token redemption atomic so a single one-time token can no longer be used to create more than one session under concurrent requests.

    Ensured a password reset token can only be used once.

    Added 255-character caps to additional user-supplied name and description inputs (API user, custom variable, certificate, label, pack, certificate authority forms) to prevent the same class of overflow bug.

    Reworked the fleets dropdown to make the search input discoverable at 10+ fleets and added an "Add fleet" affordance for global admins.

    Restricted deleting a fleet to global write permissions (global admin or GitOps), matching the existing restriction on creating one.

    Restricted the manual MDM enrollment profile endpoint (GET /api/v1/fleet/enrollment_profiles/manual) to global and fleet-scoped admins and maintainers.

    Clarified the Controls > OS updates empty state to say "Apple or Windows MDM must be turned on" and link to MDM settings, so it no longer implies MDM is off when only Android MDM is enabled.

    Improved the Apple Business success toast shown after editing fleet assignments to name the organization.

    Renamed the "Program (Windows)" software type to "Application (Windows)", which includes apps installed through the Windows app store.

    Added tooltips to the "Agent", "Last restarted", and "Status" column headers on the Hosts page explaining which platforms are supported and why.

    Updated the "Last opened" tooltip on the Host details Software table to explain why it's only supported for native macOS, Windows, and Linux apps and packages.

    Removed the cellProps.rows.length === 1 workaround (which suppressed the tooltip whenever the table had exactly one row) by adding the correct CSS, fixing the tooltip overflowing when the host table has only one row.

    Ranked "Select API endpoints" search results by relevance (exact match, then prefix, then whole-word, then substring, matched against both name and path) instead of leaving them in an unranked catalog order, and fixed a bug where the table's default sort silently discarded that ranking.

    Removed pagination from the "Select API endpoints" search results table (Settings > Users > Add API-only user > Specific API endpoints), relying on the results dropdown's existing scrollbar instead.

    Improved empty state copy on the software title detail page when the software is not found in the selected fleet.

    Made the per-platform entries in the dashboard "Hosts enrolled" chart keyboard accessible: each platform with hosts is now focusable via Tab, activatable with Enter/Space, has a visible focus indicator, and exposes an accessible name (e.g. "macOS hosts").

    Enforced API-only endpoint restrictions on chart endpoints.

    Updated button styles across the Fleet UI to use the new bordered secondary and subdued button variants.

    Aligned the configuration profiles empty state with the assets tab styling so admin and maintainer users see a consistent empty state.

    Aligned the configuration profiles and assets empty states for technicians with the shared EmptyState styling.

    Added a FLEET_DEV_SKIP_S3_CONFIG environment variable to skip applying local S3 dev defaults and creating test S3 buckets when running fleet serve --dev.

    Added --since-commit and --commit flags to the migration-cleanup tool, allowing migration rename scans scoped to a commit range on main or a single commit, in addition to the existing --branch mode.

    Split ListHostSoftware and ModifyAppConfig into smaller helpers so that those packages can be checked by the nilaway linter.

    Removed an unneeded dependency that does not support Apple M chips.

    Updated Go to 1.26.7.

    Fixed an App Store or in-house app install that a device acknowledged but never verified leaving the host unable to run anything else. Fleet now fails such an install after 24 hours and releases the host's activity queue, so scripts, software installs, and uninstalls waiting behind it run. The wait is configurable with FLEET_SERVER_VPP_INSTALL_REAP_TIMEOUT. An install whose command has not reached the device yet is left alone until it can no longer be delivered.

    Fixed Fleet holding on to an App Store app verification command after it had nothing left to verify on that host, which delayed verifying the next install on the same host by up to a day.

    Fixed software (packages, App Store apps, and in-house apps) targeted with "exclude any" on a host vitals label being hidden from, and blocked for, every host instead of only the label's members.

    Fixed duplicate software inventory entries (same name, version, and source with the same vulnerabilities but different host counts) that could appear on instances upgraded to Fleet v4.76.0 or later. Existing duplicate giflib (Homebrew) entries are merged during the database migration on upgrade.

    Fixed a false-negative vulnerability report where Firefox Developer Edition on macOS was not matched to any CVEs because Fleet generated no CPE for it.

    Fixed the SCEP proxy so that Windows profiles using a custom SCEP proxy certificate authority have their one-time Fleet challenge validated before a PKIOperation request is forwarded to the certificate authority. Requests with a missing, incorrect, or expired challenge are now rejected.

    Fixed the SCEP proxy so that a Windows profile pending removal can no longer be used to relay SCEP requests to the configured certificate authority, and so that proxy error responses no longer include the certificate authority's URL.

    Fixed a few edge cases for Apple profile reconciliation when devices respond with NotNow in certain scenarios.

    Fixed an issue where re-enrolling an Apple device with a different type, e.g. Manual -> ADE, would not update the enrollment type correctly.

    Fixed a bug where an Apple configuration profile (DDM declaration) could become undeletable if the set of allowed declaration types changed after the profile was added (for example, when a server configuration flag was toggled). Deleting a profile no longer re-runs upload-time validation.

    Fixed Fleet storing an unusable disk encryption key and logging an escrow activity for macOS hosts that aren't enrolled in Fleet's MDM.

    Fixed team-level BitLocker PIN enforcement never reaching Windows hosts when Apple MDM was not configured on the server: the "Create PIN" banner appeared on the My device page, but the queries and MDM command that enable PIN setup were never sent.

    Fixed Windows software whose inventory name includes the version (e.g. "Granola 7.373.2") not matching the Fleet-maintained app's software title, which prevented the uninstall action from appearing and listed each version as its own software title. Applies to Fleet-maintained apps that have been added as an installer. Existing mismatched titles are merged when the app is added, shortly after server startup, and hourly thereafter.

    Fixed a bug where a failed macOS Fleet-maintained app install could be reported as successfully installed because the install script did not check the exit code of the command that installed the app. This covers generated install scripts, the custom install scripts used by some apps (including Google Chrome, Zoom, Microsoft Edge, and Webex), and the already-published scripts of frozen apps.

    Fixed the Docker Desktop macOS Fleet-maintained app not reporting an installed version or "Installed" status on hosts that already have Docker Desktop. The app matched on the embedded Electron bundle identifier (com.electron.dockerdesktop) instead of the identifier the installed app reports (com.docker.docker), and embedded bundles are excluded from software inventory. Existing Docker Desktop installers are re-pointed to the correct software title on upgrade.

    Fixed a bug where the patch policy for the Windows Git Fleet-maintained app always returned "Pass", even on hosts running an outdated version, so update automations never triggered. The generated query matched programs.name LIKE 'Git %', but Git for Windows registers itself in the registry as exactly Git.

    Fixed the macOS "Steam up to date" patch policy always failing on hosts that have the current version of Steam installed. Steam.app ships without a CFBundleShortVersionString, so the generated policy now compares CFBundleVersion, which agrees with the version Fleet reports in software inventory.

    Fixed Fleet no longer recognizing hosts running Omarchy as Linux. Omarchy 4 ships its own /etc/os-release and reports platform=omarchy, where earlier versions inherited arch from Arch Linux and were covered by Fleet's Arch support. Host vitals and software inventory populate again, disk encryption and key escrow are available, policies and labels scoped to linux apply, and scripts can be run from the host's Actions menu. Omarchy hosts continue to roll up onto the "Arch Linux" / "rolling" row in Software > OS.

    Fixed Android hosts staying stuck on a pending Lock, Wipe, or Clear passcode when Google never delivered the command's result to Fleet. Fleet now checks the command's outcome directly with Google once a day and updates the host, so the command can be re-issued.

    Fixed the Hosts page so that managed Android hosts display their serial number instead of "Not supported" when one is reported.

    Fixed an issue where GitOps could apply MDM SSO configuration values that were invalid.

    Fixed an issue where generate-gitops would export an empty apple_business section if the AB default fleets had only been set via the UI.

    Fixed the Google Calendar integration scheduling maintenance events over users' Focus Time and Out of office blocks.

    Fixed the SCIM last request telemetry so that authorization failures (403 Forbidden) from unauthorized users are no longer persisted, preventing them from overwriting the admin-visible SCIM status.

    Fixed an edge case where deactivating a SCIM user did not deprovision the matching Fleet user if the user's identifiers were changed in the same request.

    Fixed the Helm chart's Deployment and fleet-vulnprocessing CronJob templates so empty/unset entries in environments (e.g. the default FLEET_SERVER_PRIVATE_KEY: "") are omitted from the rendered container env list instead of being emitted as an empty-string env var, which previously collided with the same key supplied via envsFrom and caused server-side apply to reject the object with a "duplicate entries for key" error.

    Fixed password reset so that case-mutated reset tokens are no longer accepted; tokens are now matched case-sensitively.

    Fixed an issue where an SSO-only invitation could be accepted with a password, creating a local password-authenticated account and bypassing SSO enforcement. The authentication mode is now derived solely from the invite.

    Fixed the hosts list endpoint sometimes returning software title details that didn't match the applied filter.

    Fixed the software title details response so that installer script contents and managed app configuration are only returned to users authorized to read the installer, and so that a request without a fleet is authorized against "No team" instead of skipping the scope check. This applies to GET /api/v1/fleet/software/titles/{id} and to the software_title included in GET /api/v1/fleet/hosts when filtering by software_title_id.

    Fixed a software title request without a fleet so that it only resolves titles in fleets the requester can see. Previously a title reachable only through a software package, App Store app, or in-house app in another fleet was returned, which told the requester that software they have no access to exists.

    Fixed device-authenticated ("My device") software uninstall so that it applies the same self-service and label-scope rules as the self-service install path, instead of accepting any package on the host's fleet.

    Fixed the OS versions API (GET /api/latest/fleet/os_versions) to return a validation error for an unsupported platform filter and a "not found" error for an unknown OS version ID, instead of a successful but empty or null-filled response. Also corrected the max_vulnerabilities validation message so the >= character is no longer returned HTML-escaped.

    Fixed the delete host endpoint returning inconsistent responses for a host outside the requester's fleet versus one that doesn't exist.

    Fixed the host transfer activity (transferred_hosts) to only record host IDs that actually exist, so non-existent host IDs passed to POST /api/latest/fleet/hosts/transfer can no longer be injected into the audit trail. No activity is created when none of the requested hosts exist.

    Fixed the policy automations table showing only one host for automation runs that cover multiple hosts.

    Fixed query (report) responses so that pack metadata (ID, name, description) is only included when the requesting user is authorized to read packs, preventing cross-fleet pack metadata disclosure via query name collisions.

    Fixed the live query results websocket stream returning a different error for a nonexistent campaign versus one owned by another user.

    Fixed the self-service "Install all" button so its count and install target scope to the current search query. Previously, typing a search would filter the visible list while "Install all" still counted (and queued) every item in the selected category, including software the search had filtered out.

    Fixed device-authenticated ("My device") endpoints so that host policies are returned in a device-safe representation that no longer exposes the policy author's name and email or the policy's raw SQL query.

    Fixed a bug where a .sh or .py software package with Windows-style (CRLF) line endings was accepted at upload but failed to install on Linux hosts with a "No such file or directory" error. Line endings are now normalized to Unix-style before the script is stored.

    Fixed a potential resource exhaustion issue in the MSI metadata parser.

    Fixed a race condition that allowed a one-time software installer download token to be redeemed more than once when many requests raced concurrently, by making the token consumption atomic.

    Fixed the "Add software" error for a file whose contents don't match a supported installer format: it no longer says "Couldn't edit software" on an add and no longer implies the file extension is the problem.

    Fixed software installer validation errors reporting the wrong action verb (add vs. edit).

    Fixed the install rejection message for .sh/.py script packages to say they can be installed on macOS and Linux hosts, rather than Linux only.

    Fixed long fleet names overflowing the fleets table, fleet detail page header, teams dropdown, and manage enroll secrets modal. Fleet name inputs now cap at 255 characters (matching the database column), and the API and GitOps now return a clear validation error instead of a raw "Data too long" MySQL error when a longer name is submitted.

    Fixed long label names overflowing the Labels card on the host details page.

    Fixed a bug where modifying a label could silently persist a membership change without recording an audit activity when the label's metadata update failed (e.g. renaming to a name that already exists). Label metadata and membership are now saved in a single transaction, so a failed update rolls back both.

    Fixed the Setup experience Users settings to default the account type to "Admin" for fleets whose config predates the setting, instead of showing no selection.

    Fixed sort direction on the "Last seen" and "Last fetched" columns of the hosts table so that sort descending puts the oldest date (biggest "days ago" number) first, matching the visible duration rather than the underlying timestamp.

    Fixed the "Last restarted" vital showing on ChromeOS hosts, where it's not actually collected.

    Fixed the status-filter dropdown's selected-value icon (e.g. the disk encryption, bootstrap package, and policy status filters on the Hosts page) rendering near-black and barely visible in dark mode.

    Fixed UI to show a direct button instead of a single-item dropdown on the Labels page (for users without edit/delete permissions) and the Integrations page (Jira/Zendesk).

    Fixed styling issues with the gap between icons and text across the product.

    Fixed the page content shifting left when opening a role dropdown near the bottom of the New user form (/settings/users/new/human). Dropdowns now flip upward when there's no room below the trigger.

    Fixed the page content shifting left when opening the Actions dropdown on the last rows of a table (labels, users, fleets), and the resulting jump when a delete modal opened. The dropdown menu now flips upward when there's no room below the trigger.

    Fixed an accessibility issue where the resend button would not show up when focused inside the OS settings modal.

    Fixed tooltips wrapping icons or numeric values (like the Issues count on the host details page) showing a text (I-beam) cursor on hover, which made them look editable; those tooltips now use the default arrow cursor. Underlined-text tooltips are unchanged.

    Fixed the My device > Self-service search bar not sitting flush right when the "Install all" button isn't rendered.

    Fixed an empty summary card rendering above the Vitals section on the host details page for Fleet Free hosts with no summary content (Android, and iOS/iPadOS with no OS settings).

    Fixed data table column headers stretching vertically when the table has no rows (e.g. while refetching from a zero-result search on the My device software page).

    Fixed the misaligned icon in notify.success/notify.error toast notifications so it sits on the first line of the message on both single- and multi-line toasts.

    Fixed low color contrast on the "Inherited" tag and unified the styling of tags (e.g. "Inherited," "API," "Patch," host filter chips, and host label pills) across the UI to match the design system.

    Fixed helper text under checkboxes and radio buttons so it aligns with the label instead of the control.

    Fixed misaligned app icons on the macOS setup experience "Setting up your device" screen.

    Fixed an issue where the user-scoped icon wasn't showing for iOS and iPadOS hosts.

    Fixed an issue where Fleet would show a turn on MDM banner before knowing the device state.

    Fixed the script and query editors so that scrolling after a single click no longer selects text instead of scrolling.

    Fleet-maintained app updates and vulnerability fixes are applied, whether or not you upgrade.

    Fleet's agent

    The following version of Fleet's agent (fleetd) support the latest changes to Fleet:

    • orbit-v1.59.0
    • fleet-desktop-v1.59.0 (included with Orbit)
    • osquery-5.23.1 (included with Orbit)
    • fleetd-chrome-v1.3.5
    • fleetd-android-v1.5.0

    Two features in this release (managed local admin accounts on Windows and the fleetctl package --bypass-end-user-auth flag) require fleetd 1.60.0, which will be released soon.

    While newer versions of fleetd still function with older versions of Fleet, old versions of fleetd and osquery may not function with new versions of Fleet. We do not actively test these scenarios, and we recommend deploying a minimum of the agent versions above before upgrading to this version of Fleet.

    Upgrading

    Please visit our upgrade guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    • a9b73e16a44770a2c58cb693a71208473c104083b755b2570147ab1b35f798a4 fleet_v4.91.0_linux.tar.gz
    • efddc73ed5b4c1f524603aad95d993743ffd36c7737bdc69a6a27c074da57c36 fleetctl_v4.91.0_linux_amd64.tar.gz
    • 09e9e7dbb00d4dae8e342d7b4c9bb391f966d4d476357901f7bae5bc82e3ee06 fleetctl_v4.91.0_linux_amd64.zip
    • c3a90037fc1083e76f955a7aca03303e336c2bebc7ffd649dc6f59171728be09 fleetctl_v4.91.0_linux_arm64.tar.gz
    • 8b55ec7f8410f2f49561ad56428ff3bbd7f37e883c5c44d035212f94abe82617 fleetctl_v4.91.0_linux_arm64.zip
    • 093b53445b379d8994d990e84fffe2655051e51949b287bdbd79982089ef0eb5 fleetctl_v4.91.0_macos.tar.gz
    • a8eb2c2ecb5bb1fe7eacfc88b9aa387ad75ca581a65f6cc86d9cce9e86880b73 fleetctl_v4.91.0_macos.zip
    • 5320601a3369170bdfa8b5bb42e5351e4564ed66b80774ec33a3ffd89845eefe fleetctl_v4.91.0_windows_amd64.tar.gz
    • 2f6d2cddea5c16dcad6a56155ca9c914f715549b81ff044a7483e137160334d1 fleetctl_v4.91.0_windows_amd64.zip
    • 2d05d4bab375f714d7d35b2011d57328c0754ced0f99cb9cc15dbb4c5f1214d2 fleetctl_v4.91.0_windows_arm64.tar.gz
    • 6b35b3d9d7ff3068982f04311538b0b25951a0463e8e40475121967b8b5bf2fb fleetctl_v4.91.0_windows_arm64.zip
    Original source
  • Sep 1, 2026
    • Date parsed from source:
      Sep 1, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    Fleet logo

    Fleet

    fleet-v4.90.2

    Fleet fixes large-scale automation load issues by adding a configurable release budget for Fleet-initiated activities, prioritizing user actions, and preventing policy edits and wipes from stalling result ingestion across the fleet.

    Bug fixes

    Added a release budget for Fleet-initiated activities (policy-automation software installs and scripts, and iOS/iPadOS scheduled app updates): they are now queued immediately but released to hosts at a configurable rate (FLEET_ACTIVITY_FLEET_INITIATED_RELEASE_PER_MINUTE, default 1000 hosts/minute, 0 = unlimited), spreading out the install-execution and result-ingestion load when an automation fires for many hosts at once. User-initiated activities (self-service installs, admin-run scripts, lock/unlock/wipe, setup experience) are unaffected and now take precedence over queued Fleet-initiated activities on the same host.

    Fixed editing a policy on a large fleet stalling policy and software install result ingestion fleet-wide. The policy_membership wipe now runs after the policy update commits instead of inside its transaction, so its row locks are no longer held for the whole wipe. An interrupted wipe is completed by the policy membership cron.

    Upgrading

    Please visit our update guide for upgrade instructions.

    Documentation

    Documentation for Fleet is available at fleetdm.com/docs.

    Binary Checksum

    SHA256

    88932d2bade4e9271c0482d1900c50c4a1dec5a16e812ed29112f095ab4d28d7 fleet_v4.90.2_linux.tar.gz
    99a6e6fe47860c4dff2d09b7a50674236616818e8d54f0cb07130e24ff2e026b fleetctl_v4.90.2_linux_amd64.tar.gz
    2c0e480d5767b71348fe884b4c7207a37703327107da380d8dcd6548f410aabb fleetctl_v4.90.2_linux_amd64.zip
    8445974427b04795f4bccd4b887d4782344c0266699a02cf9ab642117d3e7e6c fleetctl_v4.90.2_linux_arm64.tar.gz
    b50fe57b823f67ba21546327166cce7153d896b702775622eff1fe8f3b362996 fleetctl_v4.90.2_linux_arm64.zip
    1c911e660272a2092c96deeb89928c11ff17418f3ddea2132f3a3ec7825bb0cc fleetctl_v4.90.2_macos.tar.gz
    6e83dbb754073aabc6047ed9b83e2874ad89fe5f3ce269fcdb7f49bf821d13d2 fleetctl_v4.90.2_macos.zip
    99af91ec0541b12d1807ebc140428dfc7a0fec5228efaef0e9b531a2ac5a9e13 fleetctl_v4.90.2_windows_amd64.tar.gz
    85126063313ff0623145e863bbe4b35de8e9d000c261b1c51c8d2099a0bfffd7 fleetctl_v4.90.2_windows_amd64.zip
    ec3fac914ba29b342d43d71e759fb8962ea9620c505614e10ea9bbf7536db56f fleetctl_v4.90.2_windows_arm64.tar.gz
    b071b665700c153a3353545505a7c99fc8478b4cb5d0f9d61a8e1a4f65d4374c fleetctl_v4.90.2_windows_arm64.zip

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.