Releases: jermainewalkes/patchwalker
Release list
PatchWalker 1.20.7
PatchWalker 1.20.7
- Clearer update checks. A check in progress is now shown across the console — a machine reads "Checking" while it runs, on its own page, in the machine list and in its group. Checks keep running on the Controller if you move to another page, and the result appears against the machine when you return.
- Groups stay live. Machine status on the Groups page updates on its own after a check or install, with no reload.
- More resilient status. A machine's known state is preserved if a check is interrupted, so a scan that is cut short never leaves the machine showing the wrong status.
- Interface refinements. Machine names display consistently in upper case, the update worklist keeps its context when you return to it and several small display issues have been corrected.
SHA-256: 0b0d8462b6ea48d687f604599674835c776b892946e91591241dde0269761654
Source commit: 25b58b9
PatchWalker 1.20.5
PatchWalker 1.20.5 rolls up everything since 1.20.2 - a security and correctness hardening pass plus a batch of new capability.
New
- Update approvals / KB blocklist - decline or defer specific updates across the whole fleet.
- Repair Windows Update - reset a machine's update components remotely to clear a corrupt update store (errors like 0x8024200B).
- Chat notifications - Microsoft Teams, Slack or a generic JSON webhook, alongside email.
- Reboot (Notify) install option - gives logged-in users a grace-period warning before a restart.
- Update classification - Security / Critical / Feature / Driver / Definition shown in the worklist.
- Offline error-code explanations - plain-English cause and fix for common Windows Update, MSI and Linux package errors, with no internet required.
- Stale-machine reporting - surface machines not checked in for a set number of days, with CSV export.
- openSUSE / zypper support.
- History retention controls - prune old activity so the database does not grow without bound.
Improved
- Accessibility: keyboard-reorderable dashboard widgets and cleaner screen-reader navigation.
- Scheduled update checks now run through the job queue for more reliable, non-overlapping runs.
Fixed
- Machines with a name longer than 15 characters now enrol with their full hostname, fixing a Kerberos/WinRM connection failure.
- Linux installs now apply exactly the packages you select (previously upgraded everything).
- Per-update install results are recorded accurately in history.
- Maintenance windows are now a hard deadline for scheduled installs.
SHA-256: a88204c8bf81fd3fa4139024e6ce45113cba282e9fb33e3b1fb9f97cac783ea6
Source commit: d7b17ba
PatchWalker 1.20.2
PatchWalker 1.20.2
Recommended for all Domain / gMSA installs. This is a focused stability fix.
Fixed
- Machine key-store ACL corruption on gMSA upgrades. On a Domain (gMSA) Controller, the installer's certificate-import grant modified the shared, OS-protected
MachineKeysfolder with an inheritable ACL and re-applied it on every upgrade. On some machines this stripped SYSTEM and Administrators from the folder, making machine private keys unreadable and breaking the host's Remote Desktop (its listener certificate key). The grant now re-asserts SYSTEM and Administrators Full Control and no longer applies the damaging inheritable permission, while still allowing the service to import a TLS certificate from the web console. Standalone (LocalSystem) installs were never affected. - Recovery tool for already-affected machines. A repair script is installed at
<install dir>\scripts\Repair-MachineKeysAcl.ps1. If an earlier version left a machine's key-store ACLs damaged, run it once from an elevated PowerShell to restore SYSTEM/Administrators access to the key files, then restart the Remote Desktop service (or reboot). - Seal-key permission grant is now idempotent - it no longer accumulates a duplicate entry on the TPM-sealed key each upgrade.
Install
Download PatchWalkerSetup-1.20.2.exe below and run it on the Controller. It upgrades in place over a running install and restarts the service. gMSA Controllers upgrading from an earlier version have SYSTEM/Administrators access to the machine key store re-asserted automatically as part of the upgrade.
SHA-256: f2b25f3494a855cf628ed9efbbfe43747ca5de29bff05843363276e66ecf0ef4
PatchWalker 1.20.1
PatchWalker 1.20.1
Highlights
- Idle session timeout. After a configurable quiet period (Settings > Session, default 15 minutes, with on/off) the console shows a 60-second countdown, then signs the user out. While enabled, the sign-in cookie's lifetime is tightened to match - an abandoned or closed session also expires server-side, while active operators are kept signed in automatically. Activity in any open console tab keeps the session alive.
- The Controller identifies itself. The machine running PatchWalker is marked with an automatic Controller badge on the Machines list, its detail page and the update worklist - including Controllers registered by IP address.
- Safe Controller self-patching. Installing updates on the Controller - reboot included - is now safe end to end: the install and reboot are recorded before the shutdown is sent, an interrupted reboot command is never re-sent after a restart (on any machine), and the console warns before actions that will take it down. The console reconnects automatically once the Controller is back.
- Upgrades refresh cleanly. Stylesheets and scripts are version-stamped, so the console never renders with a stale cached stylesheet after an upgrade. (One final hard refresh may be needed when upgrading TO this version.)
- Activity log on the Updates page persists while checks or installs are running - navigate away and back without losing the live log; completed outcomes surface as notifications.
Install
Download PatchWalkerSetup-1.20.1.exe below and run it on the Controller. It upgrades in place over a running install and restarts the service.
SHA-256: cc6aadb2e6f22883929376a0ee7fc4d3f157044a053434b9cfe6bb654003ac6c
PatchWalker 1.18.0
PatchWalker 1.18.0
Highlights
- Job-completion notifications. Installs, reboots and connection tests now report their outcome as a notification (toast and bell history) whichever page you are on - batch installs produce one summary naming any machines that failed. Notifications throughout now say exactly what they acted on.
- Verified reboots. Reboot commands are error-checked, and a reboot job watches the machine go down and come back before reporting success - a blocked shutdown now fails with the reason instead of pretending it worked. The "Reboot needed" state clears as soon as the machine returns.
- Self-healing re-enrolment. Re-running the enrolment script on an already-enrolled machine now updates its record automatically: the Controller verifies the new certificate against the live machine before accepting it, so the changed-pin protection still blocks spoofed enrolments.
- Editable roles. Custom roles can now be edited after creation. The Roles page summarises each role's access as compact counts, with a cleaner add/edit dialog.
- Reliability fixes from a code review: a page-crash race in the Updates worklist's background refresh; dashboards no longer count machines awaiting a restart as up to date; a check's update list and counts are stored atomically; connection tests no longer probe a disabled mirror; Standalone installs on workgroup machines get a working web-console address.
Install
Download PatchWalkerSetup-1.18.0.exe below and run it on the Controller. It upgrades in place over a running install and restarts the service.
SHA-256: a14d9e14636ab27d416aee11a717b3df1bada6aa863dc641b09b147a23b33df2
PatchWalker 1.17.0
PatchWalker 1.17.0
Highlights
- Controller address auto-resolves to its FQDN. The manual "Mirror Hostname" field has been removed; app and software deployment, the package mirror and the Ubuntu Pro contracts proxy now always use the Controller's own fully-qualified name. This fixes application deployments failing with "Unable to connect to the remote server" on Controllers with no Linux mirror configured.
- In-app update check. About → Check for Updates asks GitHub for a newer release; Download to Controller fetches the installer and verifies its SHA-256. An optional daily auto-check shows an "Update available" badge in the top bar. The installer is never run automatically — an admin applies it on the Controller.
- Update worklist visibility. Machines being checked now show a "Checking" indicator, checks and installs survive navigating away, and in-progress installs are shown clearly.
- Dashboard accuracy. Severity tiles now reflect currently pending updates and clear to zero once installed.
Install
Download PatchWalkerSetup-1.17.0.exe below and run it on the Controller. It upgrades in place over a running install and restarts the service.
SHA-256: f8a5fa786f44991a074717cb7713627c8a8d7983fd08659b6cd99dff5be21611
PatchWalker 1.15.1
PatchWalker 1.15.1. SHA-256: b701235b3ed28bf3b4bfb0d7e91709344e4c6d78added99f20502b2dd65d4f91