August 2026 preview update

VersionGopher 0.7.16 watches a whole fleet drift apart, not just one machine.

The big deal: managed Windows endpoints that scan on a schedule, and a fleet cohesion gradient that turns red as machines diverge.

Since the forensic discovery cockpit shipped, VersionGopher has grown a managed Windows endpoint you deploy through Microsoft Intune, a fleet view of every enrolled machine, and cross-sectional drift detection that answers the question every fleet operator actually has: my machines were built to be identical, so how far have they drifted from each other? The evidence-gated CVE matcher is now in production, and the collector and supply-chain paths are hardened.

Major outcomes

What customers should notice first

Managed endpoints

Windows machines scan themselves on a schedule.

A signed Windows endpoint service runs the collector on a schedule and uploads verified results to your hosted instance, so managed machines stay inventoried without hands-on scans.

Intune deployment

Deploy the fleet through Microsoft Intune.

Package the endpoint as an .intunewin, assign it to a device group, and enroll each machine with a one-use bootstrap token. A non-Intune admin can enroll from the configuration tray, no PowerShell required.

Fleet drift

See when a fleet drifts apart.

Fleet cohesion measures how identical your machines really are, on a green-to-red gradient, and names the machines that have diverged, so bad patch management and configuration drift surface early.

Fleet management

The Fleet view manages the whole estate.

See every enrolled endpoint with its state, last scan, and identity; run bulk actions; retire or clean up devices; and keep per-organization scope on every fleet operation.

CVE accuracy

The evidence-gated matcher is in production.

The skeptical, evidence-gated CVE matcher shipped to production: weak identities require corroboration, and visible vulnerabilities are separated from needs-verification and audit-only decisions.

Supply chain

npm installation is hardened.

Front-end dependency installation is locked down with an enforced npm supply-chain policy and check, reducing the blast radius of a poisoned or unexpected package during setup.

Collector hardening

Hostile files are handled safely.

Product-banner reads, malformed ELF notes, self-referential PE resources, and version-scoring work are all bounded, with generated malformed-file regressions proving the fixes.

Feed reliability

Advisory feeds resume cleanly.

OSV incremental updates read the documented columns, resume from a stored watermark in bounded batches, and retry transient failures without losing catalog state.

Why it matters

A fleet that was built identical rarely stays that way.

New machines get imaged the same, deployed, and then quietly diverge: one misses a patch cycle, another keeps a leftover agent, a third picks up software nobody approved. By the time it shows up in an audit, the fleet is all over the place. VersionGopher now measures that divergence directly and shows it as a single gradient, so drift is something you watch trend, not something you discover after the fact.

The signal is deliberately robust. Rather than comparing version strings, which real Windows systems fragment into thousands of side-by-side components, fleet cohesion compares the overlap of each machine's file-hash sets. A freshly imaged fleet scores near the top; as machines fall to different patch levels or accumulate unique software, the score falls toward red and the outlier machines are named.

Drift detection is scoped honestly. It applies only to managed host-tracking endpoints, because a machine has to be compared with its own fleet, not with unrelated uploads. Snapshots accrue over time, and an alert fires when a fleet slides from its own recent baseline, before it reaches the red band.

Alongside the fleet work, the evidence-gated CVE matcher favors defensible decisions over broad matches, the collector is hardened against hostile files, and front-end dependency installation follows an enforced supply-chain policy.

vCISO and security leadershipWatch a managed fleet's cohesion trend and get alerted when machines drift apart.
IT and MSPsDeploy scanning to Windows fleets through Intune and see which machines fell behind.
Incident responseStill scan the boxes agents cannot reach, now with fleet context around them.
Analyst workflowVisible CVEs stay split into actionable and needs-verification lanes with suppressed decision traces kept for audit.
Visual proof

The analytics view turns a fleet into a gradient.

The collector stays lightweight and the deeper analysis lives in the hosted workflow: the Fleet view, fleet cohesion and drift, ML/AI Insights, CVE evidence lanes, package risk, binary forensic signals, search, and assessment reports.

Deploy managed endpoints with Intune Understand groups, similarity, and drift Read the CVE evidence decision guide Open help and setup notes
VersionGopher dashboard overview VersionGopher package risk dashboard

Bring a real fleet to the preview.

Start with one Windows endpoint group, firmware image, storage estate, inherited environment, or embedded platform.