Commit Graph
23998 Commits
Author SHA1 Message Date
40a97beee8 Add blog article: One console to rule them all: The case for unified endpoint management (#43919)
## Summary

- Adds a new blog article by Ashish Kuthiala: "One console to rule them
all: The case for unified endpoint management"
- The article makes the case for consolidated endpoint management over
fragmented point solutions, covering efficiency, cost, risk, and
security visibility arguments
- Published date set to 2025-07-21, categorized under "articles"

## Changes

-
`articles/one-console-to-rule-them-all-the-case-for-unified-endpoint-management.md`
- New blog article

---

Built for [Ashish
Kuthiala](https://fleetdm.slack.com/archives/D0AG9JQ53GA/p1776806237491349)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: Ashish Kuthiala <53918208+akuthiala@users.noreply.github.com>
Co-authored-by: Dan Gordon <daniel@fleetdm.com>
2026-04-22 12:13:30 -05:00
johnjeremiah 718c5b0393 Updating link to old event handout (#43960)
Updating link
2026-04-22 12:13:07 -05:00
Dante Catalfamo 2d3a790a10 Don't resend pending certificates (#43820)
**Related issue:** Resolves #37556
2026-04-22 13:08:59 -04:00
Luke Heath ca679561e5 Potential fix for code scanning alert no. 1537: Incorrect conversion between integer types (#43918) 2026-04-22 11:57:03 -05:00
Scott Gress 75d8102922 Update class on exceptions field to fix padding (#43927) 2026-04-22 11:53:31 -05:00
Eric 8cd2da576b Website: update homepage hero (#43958)
Changes:
- Added a [comma](https://fleetdm.com/handbook/company/writing#commas)
to the homepage hero

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
  * Updated homepage headline text with improved grammar and clarity.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-22 11:27:13 -05:00
Eric 275e21bcda Website: Update partners form, update action input validation (#43954)
Changes:
- Updated the input validation and added an invalidEmailDomain exit to
the deliver-deal-registration-submission and
deliver-partner-registration-submission actions
- Updated the input validation in the
deliver-whitepaper-download-request and deliver-webinar-access-request
actions
- Added error messages to the forms on the partners page for the added
exits
- Updated the `bannedEmailDomainsForCSRSigning` and
`bannedEmailDomainsForWebsiteSubmissions` config values

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Blocked submissions from restricted email domains with a clear error
response and a prompt to use a work email.
* **Bug Fixes**
* Strengthened email-format and required-field validation across
registration and request forms.
  * Restricted partner registration type options to accepted values.
* **Chores**
  * Added a domain to the denylist used for website submissions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-22 11:02:06 -05:00
Martin AngersandCopilot 04c9abbdb6 Bugfix: fallback the script execution timeout from agent options to global if not set for team (#43911)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #40952 

# Checklist for submitter

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

See
https://drive.google.com/file/d/1lot6KmliWmTpJ-paKyT_aI8GYq8PO71L/view?usp=drive_link


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Script execution timeout now falls back to the global agent setting
when not explicitly defined at the team level, making timeout behavior
more predictable.

* **Tests**
* Added test coverage validating timeout resolution across various
team/global configuration scenarios to prevent regressions.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-04-22 12:00:58 -04:00
Allen Houchins 051bf05958 Add Fleet Desktop login item profile (#43956)
Introduce a new macOS configuration profile to register
/Applications/Fleet Desktop.app as a managed login item so Fleet Desktop
auto-launches. Adds
it-and-security/lib/macos/configuration-profiles/fleet-desktop-login-item.mobileconfig
and includes it in it-and-security/fleets/workstations.yml limited to
hosts labeled "Macs with Fleet Desktop installed".
2026-04-22 10:55:28 -05:00
Victor Lyuboslavsky d79dc50883 Remove Win MDM "Status on a Status" from osquery perf (#43940)
Estimate ~5% load improvement.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Fixed MDM command handling in the performance testing agent to
properly skip duplicate status responses.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-22 10:42:31 -05:00
Luke Heath 73925b22be Add permissions to e2e-agent workflow and remove Slack notification if retries remaining (#43917) 2026-04-22 10:29:19 -05:00
Luke Heath 409433ff81 Fix unreleased bug where workstations is not selected on controls page (#43893) 2026-04-22 10:19:05 -05:00
fleet-releaseandmostlikelee 993039e5f8 Update Fleet-maintained apps (#43949)
Automated ingestion of latest Fleet-maintained app data.

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2026-04-22 10:18:54 -05:00
Dan Gordon d457b69b99 Create IT-leaders-guide-to-Linux-device-management LP in French (#43946)
Create French version of the landing page for IT Leaders Guide to Linux
Device Management.

Currently points to English version of asset.

Some parts of pages are hard-coded in the page generation scripts as
English so still show as English.
2026-04-22 10:06:53 -05:00
melpike 96620f1c1f [Route] PSSO local account (#43781)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** #30674

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **New Features**
* Added a new shortlink route for accessing PSSO local account setup
experience guides, enabling users to reach setup documentation through a
simplified URL path.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-22 08:18:15 -06:00
3dab32657c Update h2 font-size from 1.25rem (20px) to 1rem (16px) in Fleet UI (#43054)
## Summary

- Reduces h2 `font-size` from `$medium` (1.25rem / 20px) to `$small`
(1rem / 16px) across 6 component stylesheets in the Fleet UI frontend.
- set side-nav__container to `align-items` `flex-start` so it's
consistent in **Controls** and **Admin** pages with same layout.

## QA

- Verify h2 headings render at 16px (1rem) across the affected pages:
  - Section headers (global component)
  - Host query report table
  - Device user "Setting up your device" page
  - Windows automatic enrollment settings page
  - Software vulnerability details page
  - Software title details edit icon modal

---

Built for
[Mel](https://fleetdm.slack.com/archives/D0AKX7DJFCN/p1775487801759869)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

---------

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
Co-authored-by: melpike <melpike.dev@gmail.com>
Co-authored-by: melpike <79950145+melpike@users.noreply.github.com>
2026-04-22 08:09:11 -06:00
kilo-code-bot[bot]andkiloconnect[bot] 7452677824 Close Sr. Customer Support Engineer position (#43942)
## Summary
- Comments out the "Sr. Customer Support Engineer" open position in
`handbook/company/open-positions.yml` to close the listing.

Built for [Isabell
Reedy](https://fleetdm.slack.com/archives/D0AEGJCGJR0/p1776864650512589)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-04-22 14:53:58 +01:00
Carloandjkatz01 39e4f616ea macOS managed local account foundations (#43381)
Implements both #42942 and #42943 

Co-authored-by: jkatz01 <yehonatankatz@gmail.com>
2026-04-22 09:05:07 -04:00
Juan Fernandez 0d8c8978ea Fix 'Reports' menu item navigation (#43934)
Resolves #43272 

Fixed bug with 'Reports' menu item navigation
2026-04-22 08:48:38 -04:00
johnjeremiah 73a046b9ba Blog post- A Lot Has changed (#43710)
Blog post supports the Closed Lost campaign.
2026-04-22 07:41:32 -04:00
Noah Talerman 436534d135 Update feature request template description (#43870)
We want contributors/customers to use the feature request template for
Fleet-maintained apps
2026-04-22 09:24:13 +01:00
Allen Houchins f35fad2703 Relaunch apps via open as console user (#43842)
This pull request updates the application quit and relaunch logic in the
Homebrew ingester scripts to more robustly detect valid GUI user
sessions and improve how applications are relaunched after installation.
The main improvements ensure that actions are only attempted when a real
user is logged in, and that relaunching applications works reliably in
the correct user context, especially when running as root.

**User session validation:**
* The checks for a valid GUI session in `quit_application`,
`quit_and_track_application`, and `relaunch_application` have been
expanded to skip actions if the console user is empty, `root`, or
`loginwindow`, preventing attempts to interact with the GUI when no real
user is logged in.
[[1]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97L546-R546)
[[2]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97L590-R590)
[[3]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97L637-R663)

**Application relaunch improvements:**
* The `relaunch_application` logic now uses `launchctl asuser` with
`sudo -u` to launch the application in the correct user's GUI session,
ensuring that the app appears in the user's Dock and GUI, even when the
script runs as root. This replaces the previous approach of using
`osascript`, which could fail in root contexts.
[[1]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97R624-R628)
[[2]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97L637-R663)
* Additional comments were added to explain why these changes are
necessary and how the new approach works.
[[1]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97R624-R628)
[[2]](diffhunk://#diff-a9df2db484fcbb560d62c43f94c4bcc2d26dcf68066c9e7cc2bffad6f124ce97L637-R663)

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* More reliable app relaunch after installations, reducing failures when
GUI apps are reinstalled.
* Avoids attempting to quit or relaunch when no active console user is
present (including the system login window), preventing unintended
actions.
* Uses a more robust method to launch apps in the user GUI session and
reports success based on the launcher outcome for clearer results.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 20:51:40 -05:00
fleet-releaseandmostlikelee 53d01eb0b9 Update Fleet-maintained apps (#43920)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated macOS package metadata for Connect Fonts (version 28.1.3),
Discord (version 0.0.387), and Zotero (version 9.0.1).

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: mostlikelee <16102903+mostlikelee@users.noreply.github.com>
2026-04-21 20:50:54 -05:00
Magnus Jensen fd0488a5f6 Update input action buttons app wide (#43906)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #41147 

See comment for images of all changes:
https://github.com/fleetdm/fleet/issues/41147#issuecomment-4291447286

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

- [x] Input data is properly validated, `SELECT *` is avoided, SQL
injection is prevented (using placeholders for values in statements), JS
inline code is prevented especially for url redirects, and untrusted
data interpolated into shell scripts/commands is validated against shell
metacharacters.
- [x] Timeouts are implemented and retries are limited to avoid infinite
loops
- [x] If paths of existing endpoints are modified without backwards
compatibility, checked the frontend/CLI for any necessary changes

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually


<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Style**
* Standardized and restyled action buttons (copy, show/hide secret,
etc.) across the app for consistent appearance, sizing, hover states and
keyboard focus outlines.
* Improved input and textarea layouts so action buttons align neatly,
copy/confirmation messages display correctly, and spacing adapts when
actions are present.

* **Documentation**
* Added a changelog entry documenting the action-button styling and
layout updates.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 17:54:05 -06:00
Juan Fernandez baba593e61 Make labels on the host detail page render horizontally (#43933)
**Related issue:** Resolves #43914 

Make labels on the host detail page render horizontally.
2026-04-21 19:47:10 -04:00
EricandCopilot 562b1978e6 Website: update remediate page for windows users (#43932)
Closes: https://github.com/fleetdm/fleet/issues/39986

Changes:
- Updated the /remediate page to show a different step 1 for Windows
users.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Platform-aware remediation UI: the first remediation step now shows
system-tray instructions and a Windows-specific image for Windows
clients, while non-Windows users continue to see the original menu-bar
instructions and image.
* The page now detects Windows clients and surfaces the appropriate
guidance automatically.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->

---------

Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
2026-04-21 18:07:07 -05:00
Eric 28473e7c5f Website: add webinar article, update embedded webinar styles (#43902)
Closes: https://github.com/fleetdm/confidential/issues/15353

Changes:
- Added a new webinar article
- Updated the styling of embedded webinar videos

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Style**
* Improved embedded video display with updated aspect ratio handling and
refined positioning for better visual presentation on webinar pages.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 17:37:02 -05:00
kilo-code-bot[bot]andkiloconnect[bot] 4b71c1673b Add 'Why no optional attendees?' to Why this way handbook page (#43931)
## Summary

- Adds a new "Why no optional attendees?" section to the "Why this way?"
handbook page (`handbook/company/why-this-way.md`).
- Explains why Fleet doesn't use the "optional attendees" feature in
calendar invites for internal meetings: it creates ambiguity, muddies
the attendee list, and causes confusion about who to expect.
- Clarifies that invited attendees are mandatory, anyone else can join
non-"[no shadows]" meetings by adding themselves, and every internal
meeting is inherently optional if it's not a good use of time to help
the company.

Built for
[mikermcneil](https://fleetdm.slack.com/archives/C02A8BRABB5/p1776810106895019?thread_ts=1770388050.769139&cid=C02A8BRABB5)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-04-21 17:33:16 -05:00
Eric 7f6c2e908e Website: update build-static-content script to be compatible with Node versions under 20 (#43930)
Changes:
- Updated the `URL.parse` in build-static-content to be
`require('URL').parse()`

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Improved webinar video URL parsing for greater reliability. Existing
behavior remains: parse failures still produce errors and video links
containing query strings are rejected.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 17:31:30 -05:00
Jake Stenger 0f07001a8d more Windows solutions (#43925) 2026-04-21 18:15:19 -04:00
Scott Gress 91d9b25924 Allow conditional downloads across fleets (#43679)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #43417

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [X] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
done in https://github.com/fleetdm/fleet/pull/42216

## Testing

- [X] Added/updated automated tests
- [X] QA'd all new/changed functionality manually
- Using a local fileserver, added the same software to two fleets and
ran `fleetctl gitops`. Verified that the first fleet downloaded the
file, the second fleet used the cache, and both fleet showed the
software installer in the UI.

## Summary by CodeRabbit

* **Chores**
* Updated software installer lookup mechanism to support optional
team-scoped searches, enabling fallback to cross-team installer cache
when team-specific installers are unavailable.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 17:06:23 -05:00
johnjeremiah 087ba3ff80 Contact source change for webinar and gated doc (#43838)
Updating the contact source value for webinars and gated docs to match
the new sfdc values



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Corrected CRM contact-source classification so webinar access requests
and whitepaper downloads are categorized separately from general contact
form submissions.

* **Chores**
* Expanded accepted contact-source values in the CRM integration to
include distinct labels for webinars and gated documents.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 17:03:41 -05:00
Victor Lyuboslavsky 1f6e556818 Improved Windows MDM performance (#43912)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #43875

`POST /api/mdm/microsoft/management` is the hot endpoint for any
Windows-MDM-enrolled
fleet. Every enrolled host hits it twice per check-in interval. At 40k
hosts that's a
four-figure sustained queries-per-second rate on the database reader
pool, dominated
by one expensive query plus a handful of redundant
`MDMWindowsGetEnrolledDeviceWithDeviceID`
lookups on the same row.

This PR cuts that load by:

1. Short-circuiting the pending-commands query when the device's queue
is empty (the
overwhelming common case). Replaces a 3-table join plus anti-join with a
cheap
   primary-key probe.
2. Loading the enrolled device exactly once in `isTrustedRequest` and
threading it
through to every downstream consumer instead of re-fetching it three
times.

No behavior change to the protocol, no schema change. Also filed a
related issue: https://github.com/fleetdm/fleet/issues/43897

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:

- [x] Alerted the release DRI if additional load testing is needed



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved Windows MDM server performance at scale by reducing database
queries during device check-ins.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 16:52:36 -05:00
dependabot[bot] 5cc283c258 Bump follow-redirects from 1.15.11 to 1.16.0 in /tools/fleet-slackbot (#43730) 2026-04-21 16:04:37 -05:00
dependabot[bot] 1cef0d0be7 Bump hono from 4.12.12 to 4.12.14 in /tools/fleet-slackbot (#43653) 2026-04-21 16:04:07 -05:00
dependabot[bot] 3269a1b481 Bump follow-redirects from 1.15.11 to 1.16.0 in /tools/fleetctl-npm (#43561) 2026-04-21 16:03:41 -05:00
kilo-code-bot[bot]andkiloconnect[bot] 4047c20e32 Update Steven Palmesano's title from CSA to CSE (#43913)
## Summary

- Moved Steven Palmesano from the Customer Solutions Architect (CSA) row
to the Customer Support Engineer (CSE) row in the customer success
handbook team table.

## Changes

- `handbook/customer-success/README.md`: Removed Steven Palmesano from
the CSA listing and added him to the CSE listing.

---

Built for [Isabell
Reedy](https://fleetdm.slack.com/archives/D0AEGJCGJR0/p1776804449377809)
by [Kilo for Slack](https://kilo.ai/features/slack-integration)

Co-authored-by: kiloconnect[bot] <240665456+kiloconnect[bot]@users.noreply.github.com>
2026-04-21 22:02:45 +01:00
Victor Lyuboslavsky c378e27d82 Fixed Android pubsub panic when host was deleted (#43788)
<!-- Add the related story/sub-task/bug number, like Resolves #123, or
remove if NA -->
**Related issue:** Resolves #42494 

# Checklist for submitter

If some of the following don't apply, delete the relevant line.

- [x] Changes file added for user-visible changes in `changes/`,
`orbit/changes/` or `ee/fleetd-chrome/changes`.
See [Changes
files](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/guides/committing-changes.md#changes-files)
for more information.

## Testing

- [x] Added/updated automated tests
- [x] QA'd all new/changed functionality manually

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Prevented a server panic (HTTP 502) when Android pubsub status reports
arrive for hosts deleted from Fleet by validating re-enrollment before
processing.
* Improved Android host creation to avoid creating duplicate hosts when
an Orbit-only enrollment already exists.

* **Tests**
* Added unit tests for the re-enrollment flow for deleted hosts and
deduplication between Orbit and Android enrollments.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 16:01:51 -05:00
fleet-releaseandallenhouchins c2379eaaff Update Fleet-maintained apps (#43891)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
  * Updated Granola macOS app configuration to version 7.147.1
* Updated Microsoft Outlook macOS installation configuration to the
latest installer build

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-04-21 15:05:22 -05:00
Konstantin Sykulev ba7720f7de Use UTC time for osv processing (#43889)
**Related issue:** Resolves #39900

## Testing
- [x] QA'd all new/changed functionality manually

For unreleased bug fixes in a release candidate, one of:
- [x] Confirmed that the fix is not expected to adversely impact load
test results
- [x] Alerted the release DRI if additional load testing is needed



<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Bug Fixes**
* Improved timestamp handling for OS vulnerability data synchronization
to use UTC timezone when synchronization is enabled, ensuring consistent
timing behavior across different system configurations.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 14:42:16 -05:00
Tim Lee e0d7e0c6b8 Add RHEL support to osv-processor (#43277) 2026-04-21 13:39:22 -06:00
fleet-releaseandallenhouchins 4bba50faf8 Update Fleet-maintained apps (#43867)
Automated ingestion of latest Fleet-maintained app data.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Updated Android Studio macOS installer metadata to patch version
2025.3.4.6 with corresponding checksum verification.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->

Co-authored-by: allenhouchins <32207388+allenhouchins@users.noreply.github.com>
2026-04-21 13:58:04 -05:00
Eric 50a7dac9d2 Website: queries » reports (#43871)
Closes: https://github.com/fleetdm/fleet/issues/43578

Changes:
- Renamed the /query-library page to be /report-library, and added a
redirect
- Renamed the query-detail template page to report-details, and added
redirects for the query pages.
- Updated the docs nav to link to the "reports"  page instead of queries
- Updated mentions of query/queries to be "report/reports"
- Renamed the query generator to be the report generator, and added a
redirect
- Updated the sitemap to use the new URLs for report-related pages

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **New Features**
* Added dedicated "Reports" library and details pages and client
bundles.

* **Refactor**
* Renamed "Queries" to "Reports" across UI, routes, page headings, and
labels (legacy redirects added).
* Updated generator branding from "Query robot" to "Report robot" and
updated tooltips/messages.

* **Chores**
* Updated sitemap and navigation to reference /reports and report detail
URLs.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 13:42:32 -05:00
Ashish Kuthiala 5313643a4c Add whitepapers section and update marketing assets (#43879)
Added new section for whitepapers including downloadable PDFs for lead
generation and executive education. Updated existing sections with new
assets and descriptions.
2026-04-21 13:40:57 -05:00
Allen Houchins 83dca8ce79 Fix display name formatting for Touch ID script (#43882)
<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Chores**
* Minor configuration formatting adjustment to improve consistency and
standardization.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 13:39:26 -05:00
Allen Houchins f07e101986 Update enable-touch-id-sudo.sh (#43880) 2026-04-21 13:31:27 -05:00
johnjeremiahandAshish Kuthiala 3ea751c300 Fixing Sentence Case Typos (#43725)
Co-authored-by: Ashish Kuthiala <53918208+akuthiala@users.noreply.github.com>
2026-04-21 13:18:15 -05:00
Jonathan Katz 915ba8a45c 🤖 Ignore DEP premium filters on Fleet Free tier (#43865)
## Summary

Fixes #43826.

Adds code to silently ignore `dep_profile_error` and
`dep_assign_profile_response` query parameters similar to other premium
only parameters on the list hosts endpoint. This PR does _NOT_ include
filtering out the `dep_profile_error` field from the host details object
since it doesn't seem like a common pattern to filter out individual
fields from a response object, but that can be changed if needed.


# Checklist for submitter

## Testing

- [x] Added/updated automated tests
- [ ] Where appropriate, [automated tests simulate multiple hosts and
test for host
isolation](https://github.com/fleetdm/fleet/blob/main/docs/Contributing/reference/patterns-backend.md#unit-testing)
(updates to one hosts's records do not affect another)

- [x] QA'd all new/changed functionality manually

### Before fix

On premium:
- UI: can see "AB issue" card 
- UI: can see MDM status with Profile assignment error: failed
- API: can curl `/fleet/hosts?dep_profile_error=true` and get the host
- API: can curl `/fleet/hosts` and see `"dep_profile_error":true` for
the failed host
- API: can curl `/fleet/hosts/7` and see `"dep_profile_error": true`
- API: can curl `/fleet/hosts?dep_assign_profile_response=FAILED`

On free:
- UI: can't see "AB issue" card
- UI: can see MDM status pending but no details, api response has
`"dep_profile_error": true`
- API: can curl `/fleet/hosts?dep_profile_error=true` and get the host
- API: can curl `/fleet/hosts` and see `"dep_profile_error":true` for
the failed host
- API: can curl `/fleet/hosts?dep_assign_profile_response=FAILED`


### After fix

On free:
- API: curl `/fleet/hosts?dep_profile_error=true` and the filter gets
ignored
- API: curl `/fleet/hosts?dep_assign_profile_response=FAILED` or other
statuses and the filter gets ignored
- API: can curl `/fleet/hosts` to show all hosts and it shows
`"dep_profile_error":true` since it is not filtered at the host details
level
- API: can curl `/fleet/hosts/7` and see dep_profile_error since it is
not filtered at the host details level

```
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts?dep_assign_profile_response=FAILED'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  8878    0  8878    0     0   144k      0 --:--:-- --:--:-- --:--:--  146k
       5
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts?dep_profile_error=true'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  8879    0  8879    0     0   298k      0 --:--:-- --:--:-- --:--:--  298k
       5
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  8879    0  8879    0     0   283k      0 --:--:-- --:--:-- --:--:--  289k
       5
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts?dep_profile_error=true&dep_assign_profile_response=FAILED'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  8879    0  8879    0     0   311k      0 --:--:-- --:--:-- --:--:--  321k
       5
```

On premium:
- Everything works as expected, filters work

```
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts?dep_assign_profile_response=FAILED'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  1696    0  1696    0     0  58681      0 --:--:-- --:--:-- --:--:-- 60571
       1
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts?dep_profile_error=true'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  1696    0  1696    0     0  59613      0 --:--:-- --:--:-- --:--:-- 60571
       1
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  9055    0  9055    0     0   355k      0 --:--:-- --:--:-- --:--:--  368k
       5
jonathan@jonathans-macbook-pro:~/fleet$ curl -k -X GET 'https://localhost:8080/api/v1/fleet/hosts?dep_profile_error=true&dep_assign_profile_response=FAILED'   -H "Authorization: Bearer $TOKEN" | wc -l
  % Total    % Received % Xferd  Average Speed   Time    Time     Time  Current
                                 Dload  Upload   Total   Spent    Left  Speed
100  1696    0  1696    0     0  60845      0 --:--:-- --:--:-- --:--:-- 62814
       1
```

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->
## Summary by CodeRabbit

* **Bug Fixes**
* Host listing and counts now ignore premium-only filters on non-premium
licenses, ensuring consistent results for free-tier users.

* **Tests**
* Added tests validating that host listing and counting behave
differently between free and premium license tiers when premium filters
are used.
<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-04-21 14:14:25 -04:00
Noah Talerman b5183aad8e Roadmap blogpost: Add links to issues (#43720)
- @danbgordon: Add issues links could encourage community involvement
and collaboration.
2026-04-21 10:38:52 -07:00
Noah Talerman 885be0a987 Fleet server config reference: Declarations are device-scoped only (for now) (#43866)
Context:
https://fleetdm.slack.com/archives/C0891RE11SP/p1776730793467669
2026-04-21 12:30:59 -05:00