Skip to content

BearBrowser v150.0.7 — surface polish + self-heal architecture

Latest

Choose a tag to compare

@mdheller mdheller released this 04 Aug 22:24
b0be6da

BearBrowser v150.0.7 — surface polish + self-heal architecture

Second release cut through the promotion gate. Info.plist = 150.0.7 (matches
the tag, verified locally + will be verified by promotion-gate.yml on
publish).

User-facing changes

  • BearTrap + BearWall dedicated surface — a new page at
    resource://bearstart/beartrap.html shows every fingerprint probe, every
    blocked vendor request, and every canary-token exfiltration the browser has
    caught this session. Three tabs, live polling of the loopback sidecar, empty-
    state explainers. Reachable from the hamburger menu's BearBrowser section.
  • URL-bar counter chiclet — the nav-bar BearNet button now shows live
    per-kind counts of caught probes/blocked hosts/canary hits in its tooltip.
  • 11 shipped strings cleaned of leaked upstream product names (Firefox
    150 fork, LibreWolf-mirror, Firefox ETP strict, Firefox Downloads).
  • Canary channel — set bearbrowser.update.channel = canary to receive
    latest-canary.json updates 24-72h before promotion to stable.

Release-safety infrastructure landed

Every one of these fires on PR-time or a schedule; none are advisory.

  • promotion-gate.yml re-verifies the actual release artifact before
    publish-latest-json fires
  • gate-of-the-gate (test_promotion_gate.py) unit-tests the gate's own
    logic (12 assertions) — would have caught both v150.0.6 gate false-negatives
  • watchdog-latest-release hourly re-verifies /latest
  • main-branch-red-watchdog issues on any workflow red > 6h
  • cockpit-boot-integration xvfb + headless nav to the cockpit URL
  • signing-rehearsal adhoc mac + self-signed Windows — proves the pipeline
    works end-to-end before real certs arrive
  • upstream-toolchain-drift weekly HEAD-check of pinned Firefox tarball +
    cbindgen crate — issues before a nightly loses a day
  • brand-string-sweep guards against reintroduction of the 11 leaks
  • rs-mirror-preflight PR-time WIF + gs list + write smoke
  • packaging-and-update-tests covers patches.py alpha-sort + sweep NameError
    • pref line round-trip + semver -rc suffix + update-fetch hygiene

Every release from now on runs the gauntlet.

Verifiable

  • Package gate: 15/15 static assertions on the shipped artifact (local
    pre-verify + promotion-gate CI).
  • Info.plist CFBundleShortVersionString == 150.0.7 == release tag.
  • Update-fetch hygiene keywords colocated on the same call.
  • beartrap.html + bearbrowser.svg staged in the shipped resource dir.

SHA256

  • BearBrowser-150.0.7-macos.dmg 9e42e4333b70d43da882d478b4ca15f6ba874cbfb4fc6573a08ca3961c1e94a7
  • BearBrowser-150.0.7-linux-x86_64.tar.xz c6a87689ec06e108037500a41883540f815a51fb2d553b350401e311b4ba1f9f