Release notes for public versions. Every download is on GitHub Releases.
1.20.7
Clearer update checks. A check in progress is now shown across the console — a machine reads “Checking” while it runs, on its own page, in the machine list and in its group. Checks keep running on the Controller if you move to another page, and the result appears against the machine when you return.
Groups stay live. Machine status on the Groups page updates on its own after a check or install, with no reload.
More resilient status. A machine's known state is preserved if a check is interrupted, so a scan that is cut short never leaves the machine showing the wrong status.
Interface refinements. Machine names display consistently in upper case, the update worklist keeps its context when you return to it and several small display issues have been corrected.
1.20.5
Update approvals. Decline or defer specific updates across the whole fleet by KB number or title — the lever to hold a bad patch back everywhere at once.
Repair Windows Update. Reset a machine's update components remotely, straight from its page in the console, to clear a corrupt update store.
Chat notifications. Send alerts to Microsoft Teams, Slack or a custom endpoint alongside email.
Reboot with notice. A new install option gives signed-in users a grace-period warning before a restart.
Clearer updates. Each update shows its classification (security, critical, feature or driver), and common update and installer errors now come with a plain-English explanation.
New reporting. A report lists machines not checked in for a set number of days, and activity history can be pruned on a schedule.
Wider Linux support including openSUSE (zypper); selective Linux installs now apply exactly the packages you choose.
Enrolment fix. Machines with a name longer than 15 characters now enrol with their full hostname, resolving a connection failure on those hosts.
Accessibility improvements to the console, more reliable scheduled checks, and a security and correctness hardening pass across the codebase.
1.20.2
Important fix for Domain / gMSA Controllers. An earlier installer could damage the machine key-store permissions during an upgrade, which on some machines broke the host's Remote Desktop. This release corrects the permission grant and ships a repair tool for any affected machine. Standalone installs were not affected.
1.20
Idle session timeout. After a configurable quiet period the console shows a 60-second countdown, then signs the user out; the sign-in cookie's lifetime is tightened to match, while active operators stay signed in automatically.
The Controller identifies itself with an automatic badge, and patching it — reboot included — is safe end to end: outcomes are recorded before the shutdown, interrupted reboot commands are never re-sent, and the console reconnects once the Controller is back.
Upgrades refresh cleanly — stylesheets are version-stamped so the console never renders with a stale cached stylesheet after an upgrade.
The Updates activity log persists across navigation while work is running.
1.18
Job-completion notifications. Installs, reboots and connection tests report their outcome wherever you are in the console, with batch installs summarised in one notification; messages now say exactly what they acted on.
Verified reboots. A reboot job confirms the machine actually went down and came back before reporting success, and a blocked shutdown fails with the reason.
Self-healing re-enrolment. Re-running the enrolment script on a known machine updates its record automatically after the Controller verifies the new certificate against the live machine.
Editable roles with a cleaner permissions dialog, plus reliability fixes across the dashboard, update worklist and connection tests.
1.17
Simpler Controller addressing. The Controller’s address is now resolved automatically from its fully-qualified name; the manual hostname field is gone. Application and software deployment work out of the box without configuring a mirror.
In-app update check. The Controller can check GitHub for a newer release, download the installer and verify its SHA-256, with an optional daily check and an “update available” badge. Updates are always applied manually on the Controller.
Clearer update progress in the worklist, with checks and installs that continue while you navigate elsewhere, and a dashboard that reflects only currently outstanding updates.
1.15 — initial public release
The first publicly available build. Highlights of what PatchWalker does at launch:
Agentless management of Windows (WinRM over HTTPS) and Linux (SSH) from one Controller.
OS, application and software updates, with per-machine and bulk install.
Install schedules targeting OS updates, software updates, or both, with maintenance windows and reboot policy.
Dashboard, reporting and exports, plus scheduled compliance emails.
Air-gapped Ubuntu Pro / ESM via a built-in package mirror and contracts proxy.
Role-based access, Microsoft Entra SSO and a break-glass administrator.
Encrypted, scheduled backups to a local or network folder.
Looking for a specific version or older download? They’re all listed on
GitHub Releases, each with its SHA-256 checksum.