# Release Notes

## Current version

Every file is a release asset in [octetproof/octet-browser](https://github.com/octetproof/octet-browser), under [v1.3.0](https://github.com/octetproof/octet-browser/releases/tag/v1.3.0). All versions and their changelogs are on the [releases page](https://github.com/octetproof/octet-browser/releases).

| Asset | What it is |
|---|---|
| `octet-collector.js` | The collector, as a script that defines the global `octet`. Serve it from your own origin. |
| `octet-collector.js.sri` | The Subresource Integrity hash of `octet-collector.js`, for the `integrity` attribute. |
| `octet-collector.mjs` | The collector as an ES module. |
| `octetproof-collector-1.3.0.tgz` | The collector as an npm package, `@octetproof/collector`, with TypeScript types. |
| `octet-edge-linux-amd64` | The edge, for Linux on x86-64. |
| `octet-edge-linux-arm64` | The edge, for Linux on 64-bit ARM. |
| `SHA256SUMS` | SHA-256 checksums of the files above. |
| `SHA256SUMS.sig`, `SHA256SUMS.pem` | The cosign signature over `SHA256SUMS`, and its certificate. |

Use the collector and the edge from the same release. To check your downloads, see [Deploy the Edge](/docs/browser/integration/deploy-edge/#1-download-and-verify-the-binary).

## Collector support

Octet accepts collections from a collector release for 12 months after the release that replaces it. When a new release comes out, its entry below gives the date the previous collector stops being accepted. After that date, the old collector's sessions get `400` with `unknown_seal_key`.

## Browser support

The collector is built for ECMAScript 2020, which every current version of Chrome, Edge, Firefox and Safari supports, on desktop and mobile. It needs `fetch` and a secure (HTTPS) page. In browsers that lack WebRTC or WebSockets, or where they are turned off, the collector still works and the verdict is weaker.

## v1.3.0

**Breaking:** update the collector and the edge together. From this release, Octet accepts only sealed collections and only edges with a client certificate. A v1.2.0 collector gets `400` with `unsealed_bundle`, and a v1.2.0 edge without a client certificate gets `401` with `client_cert_required`. The v1.2.0 collector is not covered by the 12-month support window, because it doesn't seal its collections.

- The collector encrypts each collection to Octet before it leaves the browser. Your edge forwards it without being able to read it, and Octet can tell if it was changed on the way. See [Integrity and Audit](/docs/browser/concepts/integrity/).
- Octet refuses a copy of a collection it accepted recently, through any edge, with `409` and `replayed_bundle`.
- The collector keeps a device key in the browser's IndexedDB, in a database named `octet` on your origin. See [Privacy and Data](/docs/browser/concepts/privacy/#data-stored-in-the-browser).
- The collector needs a secure (HTTPS) page. On a plain `http://` page it fails at once with a clear error.
- The published collector files are scrambled, which makes them harder to read. It doesn't make the collector's data trustworthy. The script is about 100 KB, or about 36 KB gzipped, and still needs no `unsafe-eval`.
- The edge connects to Octet only over mutual TLS, with a client certificate for your license. It refuses to start without one. You issue the certificate yourself in your license's **Edge certificates** tab in the Octet portal, and can revoke a single certificate there. See [Deploy the Edge](/docs/browser/integration/deploy-edge/#4-install-the-client-certificate).
- New reason codes: `client_cert_required`, `client_cert_licence_mismatch`, `client_cert_revoked`, `unsealed_bundle`, `unknown_seal_key`, `bad_seal` and `replayed_bundle`. See [Errors](/docs/browser/reference/errors/#reasons-octet-gives-your-edge).
- Octet uses only network timings that Octet's servers or your edge measure.
- Sessions through iCloud Private Relay keep the user's own country, and aren't treated as masked.
- In `full` mode, `ready()` can take up to about 4.5 s on a connection tunnelled to an exit far from the user.
- New pages: [Integrity and Audit](/docs/browser/concepts/integrity/) and [Keep Verdicts for Audit](/docs/browser/integration/keep-verdicts/).

## v1.2.0

The first public release of Octet Browser.

- The collector's `start()` and `ready()` split collection from the moment of action: start at page load, and wait at the moment of action.
- Three collection modes, `full`, `lite` and `passive`. Every host the collector contacts is run by you or by Octet.
- Each verdict carries a signed token, verifiable against Octet's published key set.
- Per-license read tokens for fetching verdicts, created and revoked by you in the Octet portal.
- The edge terminates TLS itself, and returns Octet's status and reason code when Octet refuses a session.
- Static edge binaries for Linux on `amd64` and `arm64`.
- The collector starts a Web Worker from a `blob:` URL. Allow `worker-src blob:` in your Content Security Policy for the best results. See [Network and CSP](/docs/browser/reference/network/).
