Cherry-pick #48451: Adding changes for Fleet v4.89.0 - #49379
Conversation
There was a problem hiding this comment.
Warning
- Copilot's review of this pull request may be incomplete because some of the changed files are excluded by your Copilot content exclusion settings. See Excluding content from Copilot for details.
Pull request overview
Cherry-pick of the v4.89.0 release bookkeeping into main, updating the Fleet release changelog and bumping version/image references across packaging and deployment artifacts.
Changes:
- Added the Fleet 4.89.0 section to
CHANGELOG.md. - Bumped Fleet version/image tags to
v4.89.0in fleetctl’s npm package, Helm chart values/metadata, and dogfood Terraform. - Added a Trivy secret-scanning allow-rule for a UI placeholder string in the Google Workspace integration section.
Reviewed changes
Copilot reviewed 7 out of 112 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
| tools/fleetctl-npm/package.json | Bumps fleetctl npm installer version to v4.89.0. |
| security/code/trivy-secret.yaml | Adds allow-rule for a known UI placeholder string to avoid false-positive secret findings. |
| infrastructure/dogfood/terraform/gcp/variables.tf | Updates dogfood GCP image default to v4.89.0. |
| infrastructure/dogfood/terraform/aws/variables.tf | Updates dogfood AWS image default to v4.89.0. |
| charts/fleet/values.yaml | Updates Helm default imageTag to v4.89.0. |
| charts/fleet/Chart.yaml | Bumps chart version and appVersion for the v4.89.0 release. |
| CHANGELOG.md | Adds Fleet 4.89.0 release notes. |
| changes/* (excluded by policy) | Release-note changes/ cleanup/additions were part of the cherry-pick but are excluded from this review context. |
Files excluded by content exclusion policy (105)
- changes/16279-cross-team-label-membership
- changes/16288-conditional-access-authz
- changes/16291-policy-query-id-authz
- changes/16292-password-reset-clear-sessions
- changes/16691-cross-team-user-list-teams-authz
- changes/21818-fleetctl-sso-warning
- changes/30871-default-byod-fleet
- changes/33441-policies-include-exclude-targets
- changes/35694-device-software-cvss-filter
- changes/36774-cert-template-all-idp-vars
- changes/38504-auto-update-pin-rollback-fma
- changes/38670-policy-status-page
- changes/38928-navigate-to-report-after-saving
- changes/39017-mydevice-macos-applications-query-param
- changes/39323-positive-language-checkboxes
- changes/40502-fix-select-all-matching-hosts-count
- changes/41910-throttle-AMAPI
- changes/41968-android-profile-fleet-variables
- changes/42435-calendar-events-next-business-day
- changes/42441-live-query-redis-scaling
- changes/42445-firefox-esr-shared-bundle-identifier
- changes/42797-script-only-advanced-options
- changes/42915-google-workspace-idp-host-vitals
- changes/43310-policy-report-details-flash
- changes/43667-macos-script-only-setup-experience
- changes/43673-my-device-sort-by-display-name
- changes/43770-missing-fma-generate-gitops-bug
- changes/44109-vulns-not-supported
- changes/44153-enable-managed-local-account-update-fleet
- changes/44188-compress-windows-mdm-responses
- changes/44272-fix-scrollbar-always-showing
- changes/44325-gitops-mode-tooltip-label
- changes/44617-install-activity-premium-error
- changes/44629-optimize-orbit-mdm-connection-check
- changes/44645-self-service-update-button
- changes/44710-fix-spaces-in-script-package-name
- changes/44746-collect-and-filter-more-cves
- changes/44746-more-filtering-in-vulns-chart
- changes/44746-set-vuln-filters-in-gitops
- changes/45309-setup-experience-policy-checks
- changes/45353-android-var-software-configs
- changes/45368-track-mobile-devices-for-hosts-online
- changes/45635-windows-batched-reconciler
- changes/45635-windows-per-host-reconcile-on-enroll
- changes/45639-improve-error-messages
- changes/45640-apple-windows-mdm-command-activities
- changes/45661-fix-gitops-relative-paths
- changes/45947-fix-macos-profiles-stuck-verifying
- changes/45948-windows-esp-continue-anyway
- changes/45984-macos-update-new-hosts-default
- changes/46005-fleet-mcp-live-query-observer-plus
- changes/46243-join-mdm-for-missing-status
- changes/46291-ndes-retry-wipe
- changes/46299-live-report-remove-host
- changes/46300-orbit-reenroll-eua
- changes/46322-filter-os-versions-correctly
- changes/46641-sso-callback-subpath-duplication
- changes/46642-subpath-email-links
- changes/46824-gitops-vpp-all-fleets
- changes/46920-tooltips-for-fleets-and-roles
- changes/46921-improve-software-tooltips
- changes/46982-windows-scep-profile-validation-panic
- changes/46993-windows-batch-remove-async
- changes/47019-script-batch-back-button
- changes/47246-policy-selection-pagination-reset
- changes/47259-windows-mdm-redeliver-fleetd-after-wipe
- changes/47343-idp-cookie
- changes/47348-dont-delete-host_software_installs-rows
- changes/47412-render-command-line-flags-as-is
- changes/47475-fleet-maintained-apps-pagination
- changes/47492-windows-scep-challenge-printable-characters
- changes/47498-bump-x-image-cve-2026-33813
- changes/47508-toast-notifications
- changes/47543-android-staggered-job-queuing
- changes/47573-signoz-dashboards-deployment-environment
- changes/47605-hosts-enrolled-percentage
- changes/47629-gitops-scriptonly-macos-setup-experience
- changes/47685-activity-outline
- changes/47784-better-error-missing-private-key
- changes/47811-update-chart-styles-for-current-and-future
- changes/47839-software-title-summary-timeout
- changes/47947-script-only-gitops-url
- changes/47981-gitops-category-collation
- changes/47989-copied-badge
- changes/48042-resend-managed-config-on-var-change
- changes/48192-refetch-report-results
- changes/48297-fix-mdm-command-list-custom-label
- changes/48368-setup-experience-install-order-tooltip
- changes/48594-recovery-lock-byod-personal-enrollment
- changes/48633-profile-reconcile-duplicate-host
- changes/48805-byod-idp-enroll
- changes/48879-vpp-manual-byod-device-install
- changes/48917-command-details-modal-reenrolled-host
- changes/add-support-software-category
- changes/batch-script-team-check
- changes/fix-condaccess-scep-validation
- changes/fix-s3-carve-cleanup-hang
- changes/fix-team-member-authorization.md
- changes/improve-batch-script-exec-perms
- changes/improve-mdm-results-validation
- changes/scep-renewal-validation
- changes/software-detail-pending-activity-dropout
- changes/software-title-scope-validation
- changes/ssrf-transport-ip-blocking
- changes/update-go-1.26.5
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| - Windows configuration profiles are now queued immediately when a host enrolls in Windows MDM, instead of waiting for the next profile reconciliation cron pass. | ||
| - Improved query validation logic around policy creation. | ||
| - Updated the "installed during setup" tooltip on Controls > Setup experience > Install software to clarify that installation order depends on software name (0-9, then A-Z), and that software without a policy is installed before software with a policy. | ||
| - Navigate back to the report details page after saving changes to a report. |
| - Fixed a bug where a script executed in a scheduled batch would still execute on hosts that had been transferred to a different fleet between the time the batch was scheduled and the time it later executed | ||
| - Fixed a bug where the MDM command results endpoint might not return hostnames for all returned hosts |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Path: .coderabbit.yaml Review profile: CHILL Plan: Pro Run ID: ⛔ Files ignored due to path filters (2)
📒 Files selected for processing (110)
💤 Files with no reviewable changes (104)
WalkthroughPrepares the Fleet v4.89.0 release by updating Helm chart metadata, container image references, Terraform defaults, and the fleetctl npm package version. Selected change entries are removed or revised, including notes covering policy targeting, Windows and macOS enrollment behavior, vulnerability status, GitOps, notifications, and chart styling. A Trivy suppression rule is added for a Google Workspace placeholder. Possibly related issues
Possibly related PRs
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Related issue: NA
Cherry-pick of #48451 ("Adding changes for Fleet v4.89.0") from
rc-minor-fleet-v4.89.0intomain.This brings the v4.89.0 CHANGELOG entry and the corresponding
changes/cleanup into main. The CHANGELOG conflict was resolved by placing the 4.89.0 section above the existing 4.88.1 section (keeping main's 4.88.1 date of Jul 10, 2026).Checklist for submitter
changes/,orbit/changes/oree/fleetd-chrome/changes.Summary by CodeRabbit
New Features
Bug Fixes