# Release Notes

## Current version

Every file ships as an asset of the [v1.2.0 release](https://github.com/octetproof/octet-browser/releases/tag/v1.2.0) of [octetproof/octet-browser](https://github.com/octetproof/octet-browser). All versions and their changelogs are on the [releases page](https://github.com/octetproof/octet-browser/releases).

| Asset | What it is |
|---|---|
| `octet-collector.js` | The collector, as a script that defines the global `octet`. Serve it from your own origin. |
| `octet-collector.js.sri` | The Subresource Integrity hash of `octet-collector.js`, for the `integrity` attribute. |
| `octet-collector.mjs` | The collector as an ES module. |
| `octetproof-collector-1.2.0.tgz` | The collector as an npm package, `@octetproof/collector`, with TypeScript types. |
| `octet-edge-linux-amd64` | The edge, for Linux on x86-64. |
| `octet-edge-linux-arm64` | The edge, for Linux on 64-bit ARM. |
| `SHA256SUMS` | SHA-256 checksums of the files above. |
| `SHA256SUMS.sig`, `SHA256SUMS.pem` | The cosign signature over `SHA256SUMS`, and its certificate. |

Use the collector and the edge from the same release. To check your downloads, see [Deploy the Edge](/docs/browser/integration/deploy-edge/#1-download-and-verify-the-binary).

## Browser support

The collector is built for ECMAScript 2020, which every current version of Chrome, Edge, Firefox and Safari supports, on desktop and mobile. It needs `fetch` and a secure (HTTPS) page. In browsers that lack WebRTC or WebSockets, or where they are turned off, the collector still works and the verdict is weaker.

## v1.2.0

The first public release of Octet Browser.

- The collector's `start()` and `ready()` split collection from the moment of action: start at page load, and wait at the moment of action.
- Three collection modes, `full`, `lite` and `passive`. No mode contacts a host that Octet or you don't run.
- Each verdict carries a signed token, verifiable against Octet's published key set.
- Per-license read tokens for fetching verdicts, minted and revoked by you in the Octet portal.
- The edge terminates TLS itself, and returns Octet's status and reason code when Octet refuses a session.
- Static edge binaries for Linux on `amd64` and `arm64`.
- The collector starts a Web Worker from a `blob:` URL. Allow `worker-src blob:` in your Content Security Policy for the best results. See [Network and CSP](/docs/browser/reference/network/).
