Releases: bayraktarozcan/Brave-Omega-Project
Release list
v2.8.1.1 - ExpandString reporting fix, stale ADMX policy removal
v2.8.1.1 — ExpandString reporting fix, stale ADMX policy removal
ExpandString registry type reporting fixed, and two dead Brave-only policies removed from the ADMX/ADML templates.
Summary
v2.8.1.1 closes a reporting gap: the startup summary and the console report counted and displayed only three registry value types, silently omitting ExpandString — the type used by DownloadDirectory, the one policy in the registry that is neither DWord, String, nor MultiString. The policy catalog additionally carried stale EN/TR source headers.
Separately, BraveLocalAIEnabled and PsstEnabled were removed from admx/brave.admx and admx/brave.adml: both are inactive in Brave and do not function, and both had survived earlier script-level removals inside the shipped templates, so the ADMX kept advertising controls the project does not manage. No policy or registry value changed: totals remain 151 across 5 tiers; the cumulative chain remains 24 → 51 → 83 → 123 → 151, and the true type distribution is 124 DWord / 7 String / 19 MultiString / 1 ExpandString.
| Metric | Before (v2.8.1.0) | After (v2.8.1.1) |
|---|---|---|
| Hardening levels | 5 | 5 |
| Total policies | 151 | 151 (no change) |
| Cumulative chain | 24→51→83→123→151 | 24→51→83→123→151 |
| Script version | v2.8.1.0 | v2.8.1.1 |
| Validated Brave | 1.96.59 | 1.96.59 (unchanged) |
| Validated Chromium | 154.0.8037.58 | 154.0.8037.58 (unchanged) |
| Registry types reported | 3 (DWord, String, MultiString) | 4 (DWord, String, MultiString, ExpandString) |
| ADMX policy entries | 766 | 764 (two dead policies removed) |
ADMX warnings from admx-validate.ps1 |
2 | 0 |
Removed
BraveLocalAIEnabled—<policy>block, both string resources and the<presentation id="BraveLocalAIEnabled"/>reference deleted from the ADMX/ADML. An Origin-only policy (Brave PR #37357) already removed fromBraveOmega.ps1in v2.2.0.1 and re-introduced to the template by a later upstream refresh in v2.5.0.0; v2.8.1.1 removes it for good.PsstEnabled— same treatment. This Privacy Settings Tuning Tool switch was never managed byBraveOmega.ps1,config.jsonor any profile, so it applied no hardening while advertising a non-functional control.Wiki/Rejected-Policies.md—BraveLocalAIEnabledentry extended;PsstEnabledadded as a new record. The ledger now holds 35 rejected/removed policies with the "Unrecognized by Brave" bucket at 12.
Fixed
- BraveOmega.ps1 —
$ScriptVersion→v2.8.1.1; the EN/TR$SummaryTypesformats carry a fourth field; the type counter now initialises"ExpandString" = 0; the summary call passes the fourth counter; the registry type parser acceptsExpandString. - docs/policy-catalog.md —
DownloadDirectorydocumented asExpandStringin both the EN and TR tables; the type-distribution line and the per-type tables report the fourth type; the stale TR source header corrected. - Version surfaces — README, SECURITY, index.html, the Wiki pages,
AGENTS.md,enterprise/levels.json, and the affected test expectations aligned tov2.8.1.1. - Tests — new
Tests/TypeDistribution.Tests.ps1derives the distribution from the data layer and asserts the 151-policy total, the four supported types, the runtime counters, and every catalog row. - Registry payloads and policy values are unchanged —
.regoutput stays byte-identical.
Full details in CHANGELOG.
v2.8.1.0 - Brave 1.96.59 compatibility validation
v2.8.1.0 — Brave 1.96.59 compatibility validation
Brave 1.96.59 (Chromium 154.0.8037.58) validated; no policy changes.
Summary
v2.8.1.0 validates the configuration against Brave 1.96.59 (Chromium 154.0.8037.58), released September 24, 2026. Brave 1.95.104 (Chromium 153.0.8010.53) remains supported. No policies changed: totals remain 151 across 5 tiers; cumulative chain remains 24 → 51 → 83 → 123 → 151.
| Metric | Before (v2.8.0.0) | After (v2.8.1.0) |
|---|---|---|
| Hardening levels | 5 | 5 |
| Total policies | 151 | 151 (no change) |
| Cumulative chain | 24→51→83→123→151 | 24→51→83→123→151 |
| Script version | v2.8.0.0 | v2.8.1.0 |
| Validated Brave | 1.95.104 | 1.96.59 |
| Validated Chromium | 153.0.8010.53 | 154.0.8037.58 |
Changed
- BraveOmega.ps1 —
$ScriptVersion→v2.8.1.0;$ValidatedBrave→1.96.59;$ValidatedChromium→154; header changelog, version context, and channel warning updated. - ADMX artifacts —
admx/brave.admx+admx/brave.adml+admx/VERSION_BRAVE_ADMXrefreshed to official 154.1.98.28 policy templates;PsstEnabledandBraveLocalAIEnabledare now correctly cross-referenced (reported as intentional warnings — candidates for a future feature release). - Version matrices and catalog — README, SECURITY, index.html, Wiki compatibility matrix, and regenerated
levels.jsonupdated;.regartifacts byte-identical (no policy drift).
Full details in CHANGELOG.
v2.8.0.0 - Data-layer refactor
v2.8.0.0 — Data-layer refactor
All 151 policy definitions lifted out of the script body into a validated, machine-readable data layer.
Summary
v2.8.0.0 lifts all 151 policy definitions out of the script body into a validated, machine-readable data layer: Brave Omega/config.json (registry targets + level order) and Brave Omega/profiles/*.json (one file per tier). BraveOmega.ps1 now loads policies at runtime through Import-OmegaPolicyData into a single $OmegaState, producing byte-identical registry output.
The Pester suite, the ADMX cross-reference validator, and the policy-catalog generator read the same data layer, making it the single source of truth for build, test, and docs. No policies changed: totals remain 151 across 5 tiers; cumulative chain remains 24 → 51 → 83 → 123 → 151.
| Metric | Before (v2.7.3.0) | After (v2.8.0.0) |
|---|---|---|
| Hardening levels | 5 | 5 |
| Total policies | 151 | 151 (no change) |
| Cumulative chain | 24→51→83→123→151 | 24→51→83→123→151 |
| Script version | v2.7.3.0 | v2.8.0.0 |
| Validated Brave | 1.95.104 | 1.95.104 |
| Validated Chromium | 153.0.8010.53 | 153.0.8010.53 |
Changed
- BraveOmega.ps1 —
$ScriptVersion→v2.8.0.0; policy definitions moved out of the script into the data layer; runtime loads policies viaImport-OmegaPolicyData(single$OmegaState). - Data layer — new
Brave Omega/config.json+Brave Omega/profiles/<Tier>.json, now the single source of truth; ADMX validator, Pester suite, and catalog generator all read the same data. - Tests & CI — TestHelper and tests re-pointed to the data layer; Pester job in
quality.ymlnow also emits a CodeCoverage report (informational). - Version matrices and catalog — README, SECURITY, index.html, Wiki compatibility matrix, and regenerated
levels.jsonbumped;.regartifacts byte-identical (no policy drift).
Full details in CHANGELOG.
v2.7.3.0 - Brave 1.95.104 compatibility validation
v2.7.3.0 — Brave 1.95.104 compatibility validation
Validated against the latest stable Brave. Zero policy changes.
Summary
v2.7.3.0 validates the configuration against Brave 1.95.104 (Chromium 153.0.8010.53), released September 18, 2026. Brave 1.95.102 (Chromium 153.0.8010.48) remains supported. No policies changed: totals remain 151 across 5 tiers (chain 24 → 51 → 83 → 123 → 151).
| Metric | Before (v2.7.2.0) | After (v2.7.3.0) |
|---|---|---|
| Total policies | 151 | 151 (no change) |
| Validated Brave | 1.95.102 | 1.95.104 |
| Validated Chromium | 153.0.8010.48 | 153.0.8010.53 |
Changed
BraveOmega.ps1:$ScriptVersion→v2.7.3.0, validated-version constants, header changelog and channel warning.- Version matrices and catalog bumped (README, SECURITY, index.html, Wiki);
.regartifacts byte-identical.
Full details in CHANGELOG.
[DEPRECATED] v2.7.2.0 - Brave 1.95.102 compatibility validation
v2.7.2.0 — Brave 1.95.102 compatibility validation
Validated against the latest stable Brave. Zero policy changes.
Summary
v2.7.2.0 validates the configuration against Brave 1.95.102 (Chromium 153.0.8010.48), released September 16, 2026. Brave 1.95.101 (Chromium 153.0.8010.37) remains supported. No policies changed: totals remain 151 across 5 tiers (chain 24 → 51 → 83 → 123 → 151).
| Metric | Before (v2.7.1.0) | After (v2.7.2.0) |
|---|---|---|
| Total policies | 151 | 151 (no change) |
| Validated Brave | 1.95.101 | 1.95.102 |
| Validated Chromium | 153.0.8010.37 | 153.0.8010.48 |
Changed
BraveOmega.ps1:$ScriptVersion→v2.7.2.0, validated-version constants, header changelog and channel warning.- Version matrices and catalog bumped (README, SECURITY, index.html, Wiki);
.regartifacts byte-identical.
Full details in CHANGELOG.
[DEPRECATED] v2.7.1.0 - Brave 1.95.101 compatibility validation
v2.7.1.0 — Brave 1.95.101 compatibility validation
Validated against the latest stable Brave. Zero policy changes.
Summary
v2.7.1.0 validates the configuration against Brave 1.95.101 (Chromium 153.0.8010.37), released September 11, 2026. Brave 1.94.121 (Chromium 152.0.7977.83) remains supported. No policies changed: totals remain 151 across 5 tiers (chain 24 → 51 → 83 → 123 → 151).
| Metric | Before (v2.7.0.0) | After (v2.7.1.0) |
|---|---|---|
| Total policies | 151 | 151 (no change) |
| Validated Brave | 1.94.121 | 1.95.101 |
| Validated Chromium | 152.0.7977.83 | 153.0.8010.37 |
Changed
BraveOmega.ps1:$ScriptVersion→v2.7.1.0, validated-version constants, header changelog and channel warning.- Version matrices and catalog bumped (README, SECURITY, index.html, Wiki);
.regartifacts byte-identical.
Full details in CHANGELOG.
[DEPRECATED] v2.7.0.0 - Unified bilingual script
v2.7.0.0 — Unified bilingual script
One script, two languages, zero policy changes.
Summary
v2.7.0.0 merges BraveOmega-EN.ps1 and BraveOmega-TR.ps1 into a single BraveOmega.ps1 with a 108-key EN/TR strings table. First launch asks Press 1 for English / Türkçe için 2'ye basın, or pin the language with -Language EN|TR|Auto (TR aliases -Seviye, -Sifirla, -SenkronizasyonaIzinVer, -Dil kept). Brave Omega/ now holds exactly one script. No policies changed: totals remain 151 across 5 tiers (chain 24 → 51 → 83 → 123 → 151); validated Brave stays 1.94.121 (Chromium 152.0.7977.83).
| Metric | Before (v2.6.2.0) | After (v2.7.0.0) |
|---|---|---|
| Script files | 2 (EN + TR) | 1 (unified bilingual) |
| Total policies | 151 | 151 (no change) |
| Validated Brave | 1.94.121 | 1.94.121 |
Added
- Unified bilingual script (
$Stringstable +$LevelDisplayNames, bilingual startup prompt). - Gitleaks secret-scan CI (pinned v8.30.1, full history).
Fixed
- Latent TR bug: the S/MIME install notice never displayed in Turkish runs (canonical
$Levelfixes it; regression test added).
Changed
- EN/TR wrappers removed; tests, ADMX validator, workflows, docs, and Wiki updated to the wrapper-free layout.
Full details in CHANGELOG.
[DEPRECATED] v2.6.2.0 - Brave 1.94.121 compatibility validation
Brave 1.94.121 compatibility validation
v2.6.2.0 validates the configuration against Brave 1.94.121 (Chromium 152.0.7977.83), released September 4, 2026. Brave 1.94.117 (Chromium 152.0.7977.64) remains supported.
Summary
| Metric | Before (v2.6.1.1) | After (v2.6.2.0) |
|---|---|---|
| Hardening levels | 5 | 5 |
| Total policies | 151 | 151 (no change) |
| Essential policies | 27 | 27 (no change) |
| Cumulative chain | 24→51→83→123→151 | 24→51→83→123→151 |
| Script version | v2.6.1.1 | v2.6.2.0 |
| Validated Brave | 1.94.117 | 1.94.121 |
| Validated Chromium | 152.0.7977.64 | 152.0.7977.83 |
Changed
- BraveOmega-EN.ps1 / BraveOmega-TR.ps1 —
$ScriptVersion/$BetikSurum→v2.6.2.0;$ValidatedBrave/$DogrulananBrave→1.94.121; header changelog and channel warning updated. - Documentation mirrored across README, SECURITY, CHANGELOG, Wiki, and index.html.
Assets
BraveOmega-EN.ps1— English installerBraveOmega-TR.ps1— Turkish installer
[DEPRECATED] v2.6.1.1 — S/MIME documentation correction
Patch Release — 2026-09-06
S/MIME documentation correction
The S/MIME extension entry (maafgiompdekodanheihhgilkjchcakm) in the allow-list is configured via brave-extension://, NOT as a force-install. Brave silently blocks force-installed CRX files from outside the Chrome Web Store, so the extension requires a one-time manual acceptance per profile.
Changes
- No policy changes — totals remain 151 across all 5 tiers.
- All
v2.6.1.0→v2.6.1.1version references updated in both scripts, CHANGELOG.md, README.md, SECURITY.md, full Wiki, and index.html. - Backfilled the missing
v2.6.1.0Release History section and addedv2.6.1.1in Wiki/Changelog.md (EN + TR). - Removed the now-obsolete
release-notes/directory.
Compatible
| Brave | Chromium | OS |
|---|---|---|
| 1.94.117 | 152.0.7977.64 | Windows 10/11 |
[DEPRECATED] v2.6.1.0 - Patch release - removes the ChromeOS-only DeviceAttributesAllowedForOrigins policy
v2.6.1.0 — Policy Cleanup: Remove Unsupported DeviceAttributesAllowedForOrigins
Patch release — removes the ChromeOS-only DeviceAttributesAllowedForOrigins policy.
Summary
v2.6.1.0 removes DeviceAttributesAllowedForOrigins from the Essential tier. This ChromeOS-only Device Attributes API policy is not supported by Brave on Windows: registry enforcement returned an unknown-policy error at runtime. Removing it reduces the Essential tier from 28 to 27 policies and the total from 152 to 151. Consequently the cumulative chain drops to 24 → 51 → 83 → 123 → 151. No functional hardening is lost on Windows. Brave version is unchanged (1.94.117 / Chromium 152.0.7977.64) — this is a policy and scripting patch release, not a Brave bump.
| Metric | Before (v2.6.0.0) | After (v2.6.1.0) |
|---|---|---|
| Hardening levels | 5 | 5 |
| Total policies | 152 | 151 (−1) |
| Essential policies | 28 | 27 (−1) |
| Cumulative chain | 24→52→84→124→152 | 24→51→83→123→151 |
| Script version | v2.6.0.0 | v2.6.1.0 |
| Validated Brave | 1.94.117 | 1.94.117 |
| Validated Chromium | 152.0.7977.64 | 152.0.7977.64 |
Removed
DeviceAttributesAllowedForOrigins→ removed from Essential — ChromeOS-only Device Attributes API policy unsupported by Brave on Windows (runtime enforcement returns an unknown-policy error); no Windows hardening impact.
Changed
- Script version →
v2.6.1.0(EN + TR) - Tier counts: Essential 28 → 27, total 152 → 151; cumulative chain now 24→51→83→123→151 (BraveOnly 24, Essential 27, Balanced 32, Advanced 40, Strict 28)
BraveOmega-EN.ps1/BraveOmega-TR.ps1—$ScriptVersion/$BetikSurum→v2.6.1.0, definition + reset-list entries for the removed policy dropped, header and changelog updated- ADMX validation —
$knownAdmxExceptionsemptied;admx-validate.ps1, ADMXCrossReference, PolicyDefinitions and PolicyMerge tests updated to the 151-policy baseline - Documentation & tests — README, Wiki, SECURITY.md,
docs/policy-catalog.md, index.html and the Pester test suite updated to 151 policies
Files
BraveOmega-EN.ps1— English scriptBraveOmega-TR.ps1— Turkish scriptdocs/policy-catalog.md— Regenerated policy catalog (151 policies, exact match to the actual policy set)index.html— Interactive policy configurator