Skip to content

Device Guard Pilot 0.5.2

Pre-release
Pre-release

Choose a tag to compare

@ShalomMaman ShalomMaman released this 16 Aug 00:15
7a0c45a

Device Guard Pilot 0.5.2 advances the public managed-device pilot with verified maintenance restoration, system controls, kiosk profiles, and a compact-device administration experience.

Highlights

  • Verified timed access to application stores: a maintenance window makes approved stores visible, keeps unrelated escape surfaces blocked, and restores the hidden state only after Android confirms it.
  • Complete system-application inventory with explicit safety tiers, administrator risk acceptance for unknown OEM components, and support for both blocklist and strict allowlist policies.
  • Optional single-application and single-site kiosk profiles with fail-closed navigation and exit verification.
  • Verified Android system-policy controls, including developer options and ADB, USB transfer, unknown-source installation, accounts, VPN, network settings, Safe Boot, factory reset, and application-control settings.
  • Compact-screen inventory UX: the explanation, search, and filters scroll away with the list, while the smaller save bar preserves the selected-system count and labelled action.
  • Signed self-update support for existing pilot devices. This artifact is build 12 so that devices running the unpublished 0.5.2 build 11 can update automatically.
  • Complete English and Hebrew localization with LTR/RTL support and automated locale-parity checks.

Verification

  • The explicit pilotChannelRelease gate passed: unit tests, Android lint, release build, APK identity, version, signer, embedded manifest URL, and P-256 metadata-key fingerprint.
  • The offline signed-update drill passed from both published Pilot 0.5.1 and the unpublished hardware Pilot 0.5.2 build 11 to this build.
  • GitHub CI and CodeQL status are recorded on the linked pull request.

Pilot warning

This remains a public pilot prerelease, not a production customer artifact. The pilot identity and Android debug-compatible signing certificate are retained only for in-place compatibility with already enrolled test devices. Production deployments require the separate production identity, externally managed APK signing key, completed hardware matrix, and documented recovery exercise.

סיכום בעברית

גרסת הפיילוט 0.5.2 משפרת את פתיחת החנות לזמן מוגבל ואת השחזור המאומת שלה, מוסיפה ניהול רכיבי מערכת ומצבי קיוסק, ומשפרת את הגלילה במסכים קטנים. build 12 מאפשר גם למכשיר שכבר קיבל build פנימי 11 להתעדכן אוטומטית. זו עדיין גרסת פיילוט ציבורית ולא חבילת Production ללקוחות.