Skip to content

v3.0.0

Choose a tag to compare

@github-actions github-actions released this 03 Aug 21:14
· 337 commits to main since this release
d00b5ee

Features

  • add env that allowing write log to file (13f17e2)
  • bypass sec-fetch-dest gated on server (d96eab8)
  • collections prune (2fb614a)
  • CSP pre-flight detection to skip doomed shadow worker spawn (b610751)
  • daemon now print warnings when running as root (13127fd)
  • data worker batch handler (c609413)
  • default hardening is off (4e85ff8)
  • default report level blocking is off (50b3391)
  • default workerSpawnMode to blob on MV2 (f8d7018)
  • fail fast to NM when header CSP blocks workers on MV3 (b6529c2)
  • handle shadow-url edge cases (e88623b)
  • i18n + a11y for picker, popup, settings (13b6104)
  • in-page WT (e1f3729)
  • isSecureContext check & allow requestDevice in console (8729d26)
  • migrate storage to IndexedDB + per-key settings (2b151ae)
  • move root daemon to abstract socket (01c1b2e)
  • mv2 support (52c07bc)
  • mv2 support (firefox 58+) (0297ea5)
  • permission policy (d3cbec6)
  • report check when write (1fe1678)
  • report-level blocking (8de34a6)
  • rewrite meta-tag CSP via StreamFilter, cache TT policy (3b70028)
  • rich text i18n support (811f1e1)
  • sec-fetch-dest check (99bf49d)
  • security hardening (a434282)
  • theme sync (6f221c0)
  • TLV binary packing for DeviceInfo.collections (128f40a)
  • trusted type now working properly (03e9488)
  • WebTransport (9c4ff18)
  • worker polyfill impl (21faed1)
  • worker polyfill stub (c74f1bd)
  • worker spawn fallback mode (blob + CSP rewrite) (404c429)
  • wt in-page now fully handle hotpath (83cd2d0)
  • WT without worker (3a36c92)

Bug Fixes

  • 8 spec compliance fixes across daemon and polyfill (a8a64c2)
  • add back gate for unix (0d5f156)
  • better use strict handler (283c34c)
  • clippy lint (ecbb3d6)
  • constant-time WS auth compare (0aec2fb)
  • cross platform build errors (5278bd7)
  • CSP rewrite for blob mode + test fixes (a198736)
  • current benchmark not parity with docs (partial fix) (341fcc2)
  • data worker ack on init message (e2c4978)
  • dataplane_mode per session instead of per device (17d86b7)
  • event double fire (36e5ced)
  • js/ts lint (c5c5f92)
  • logger env (8b4c447)
  • now the worker performance match benchmark.md (0d90e4b)
  • origin check for sandbox iframe (7983ed4)
  • page xss vulnerability (tt factory exposed) (995faaf)
  • report level block list now work properly (792751a)
  • report level blocking now match 1:1 with chromium source (c6607d4)
  • requestDevice cancel now return empty array instead of throwing (5e6a47e)
  • resolve all addons-linter warnings (0bbc4ed)
  • review fixes for worker spawn fallback (4ed0a10)
  • rust code smell (aa92690)
  • settings behavior (dddd587)
  • shadowdom picker consent bypass (a2fe259)
  • some bugs (d42bce3)
  • some more security hardening (274aec8)
  • strict_min_version lint (c7e83c3)
  • sync MV2 manifest and injector script lists with MV3 (04c3a1e)
  • throw on success (6e9cccd)
  • warning in wrong branch (6d5ed22)
  • windows build error (cf2e1cc)
  • wire protocol drift (4b1ba28)
  • wrong path (5812e0e)