Última actualización: 3 de octubre de 2026.
Registro de cambios
Qué cambió en cada versión del motor, del CLI y sus plugins, y en cada actualización de la nube y del panel. Lo más reciente primero.
Lo que viene después está en el roadmap. ¿Has encontrado un fallo? Repórtalo en GitHub.
Las notas de versión se publican en inglés.
0.2.2
ÚltimaCorrectness fixes and engine 0.2.3
Añadido
- Plugins
The plugins and the CLI tell the engine when your build output is ES modules, from the bundler's output format or, in the CLI, from
.mjsfiles and<script type="module">in your built HTML. The newsourceTypeoption overrides it. - Documentación
A new Semantic contract page lists what obfuscated output keeps the same and the few deliberate differences. Diagnostics, Presets and Directives cover engine 0.2.3 behavior.
Cambiado
- Motor
A build that cannot reach its complexity target because a transform is turned off or a region directive limits it now fails with
DIAG_TARGET_NOT_REACHED, naming the file and lines. Before, it shipped weaker output. - Motor
Pro:
transforms.selfIntegrityon a build with no code atmediumor above now fails withDIAG_SELF_INTEGRITY_INERTinstead of shipping without the check. - Motor
minifynow only renames identifiers and compresses the code. It no longer rewrites syntax. - Motor
Loops are no longer rewritten into callback helpers at
minifyandlight, which removes the 2-5x slowdown those helpers caused in hot loops.At
light, property and global names still go through encoded constants, which has some cost in very hot code. - Motor
lightoutput is smaller: about 30% less gzipped on real bundles, most of all on string-heavy files such as translation tables. - Motor
The engine is smaller:
@afterpack/wasmdownloads about 17% fewer gzipped bytes. - CLI
The Protection Map shows coverage: each region lists the transforms applied to it and why any code stays readable. It no longer shows a resistance percentage.
- Nube
Pro builds now run engine 0.2.3.
Corregido
- Motor
Fixed cases where obfuscated code could behave differently from the original, at every preset. Most date back to 0.1, so rebuild with this release.
Each engine release is now checked against real libraries and multi-script pages before it ships. The items below list the fixes; the new Semantic contract page lists what output keeps the same and the few deliberate differences.
- Motor
Classic scripts keep their top-level functions and variables on the global object, so other scripts on the page can still use them, and references to globals declared elsewhere behave as in the original.
- Motor
An ES module with no
importorexportis no longer read as a classic script when a plugin, the CLI or thesourceTypeoption says the output is ES modules, so its top-level names stay offwindow.With none of those, the engine still tells the kind from the syntax, and a file without
importorexportis read as a classic script. - Motor
Values inside template literals are converted to text the way the original does, so objects such as dates format correctly.
- Motor
Functions your code later constructs, through
extends, aProxy, a stored reference or an export, stay constructible. - Motor
Class fields are defined the way native fields are, so a field over an inherited accessor works, as in custom elements, and a class called without
newthrows. - Motor
A function that refers to itself keeps one identity, so an event listener that removes itself is removed.
- Motor
BigIntarithmetic no longer throws or returns wrong values atmediumand above, a regression in 0.2. - Motor
At
mediumand above, arithmetic converts each object operand once, as the original does, and output no longer breaks when another script changesvalueOfortoStringon shared objects. - Motor
Direct
evalandwithkeep their scope: the code around them stays as written, and the build reports it withDIAG_DYNAMIC_SCOPE_NATIVE. - Motor
Classes and constructors keep their original name when your code reads
this.constructor.nameornew.target.name, so custom error classes report their own name. - Motor
Also fixed:
asyncordering, acatch (e)block that declaresvar e, optional calls in parentheses such as(o?.m)(),deletein strict code, nested loops that multiplied output size atmediumand above, and constant**results that could differ from the browser in the last digit. - Motor
An explicit
inflation.maxnow checks the finished file and fails the build withDIAG_SIZE_CAP_REACHEDwhen output reaches it. String encoding always completes first.In earlier versions, a tight
inflation.maxcould stop string encoding early and leave some strings readable, reported only as an Info diagnostic. If you setinflation.max, rebuild with this release. - Motor
Free builds no longer refuse a directive that only lowers protection, such as a transform mask or a lower preset. Like other directives on Free, it is ignored.
Security scanner
Corregido
- Nube
Security scanner and
afterpack audit: scans now read scripts that load late or that redirect the page. A scan that could not read a site's own code, or found none, is now "Not graded" instead of scored.Before this fix, such a scan could give a site a perfect score. The README badge now shows the host's latest graded scan.
CSS source maps, Parcel receipts and engine 0.2.2
Añadido
- Plugins
Parcel builds now get a protection receipt, so
afterpack verifyworks for them. Add--reporter @afterpack/parcel-optimizer/reporterto yourparcel buildcommand.
Cambiado
- Motor
Engine 0.2.2 is a build-only release: its output is the same as 0.2.1. Pro builds run it too.
Corregido
- Plugins
@afterpack/nextnow deletes CSS source maps from.next/staticalong with the JavaScript ones, and strips the comments that point to them.Earlier versions removed only JavaScript maps, so with
productionBrowserSourceMapson, your original stylesheets could be served with the site. The webpack, Rollup and Vite plugins now also drop CSS maps when your build ships no source maps.
Per-token presets and engine 0.2.1 (breaking)
Cambiado
- Motor
Presets are recalibrated for per-token protection:
medium,hardandextremenow apply their complexity target (7, 12 and 25) to every token, where 0.1 targeted an average across the file.Output at these presets is considerably larger than in 0.1, and presets no longer cap output size. If you set
complexityyourself, review the value, because it is now a per-token target.light, the default, adds no structural layers: it encodes strings, renames identifiers and rewrites syntax, and its output is about the same size as in 0.1. - Plugins
The Protection Map now shades each token by how much transformation it received and lists the declarations the engine rewrote, in local reports and in the dashboard.
- Plugins
The CLI and plugins now require engine 0.2 or newer and refuse an older one.
preset=directives resolve on the new scale. - Plugins
The CLI and plugins no longer edit your project's
.gitignore, because.afterpack/now carries its own. In CI, the Protection Map is off by default unless you setprotectionMap.enabled. - Nube
Pro builds now run engine 0.2.1, and builds from 0.2 packages get up to 4 minutes in the cloud (was 90 seconds).
If you use a Pro key, update the CLI or plugin too. A 0.1 package with no preset set, or with
preset=directives, sends values on the old scale, so its cloud builds come out heavier than intended. - Documentación
Docs and package READMEs are updated for 0.2, including the preset scale, the Protection Map, and where each integration runs in your build.
Corregido
- Motor
Fixed a miscompile in which code inside a rewritten
switch, a?.or??expression, or a class with private fields could read the wrong variable.It depended on the build seed and on a variable's name, original or renamed, matching one the engine uses internally. Affected code could throw or return wrong values.
- Motor
Functions stored on objects now stay constructible. 0.1 could turn them into arrow functions, which broke feature detection in polyfill libraries such as core-js.
- Motor
obfuscate()andobfuscateAll()in@afterpack/coreand@afterpack/wasmnow draw a fresh seed for each build when you don't pass one. In 0.1, every build of the same source came out identical. The CLI and plugins were not affected. - Motor
Input nested too deeply to process safely now fails with a clear diagnostic instead of crashing
@afterpack/wasm. A long-running@afterpack/wasminstance also no longer grows its memory with every file.
Cloud and dashboard
Añadido
- Nube
A Pro build that fails because of a problem on our side is credited back automatically, and the dashboard shows the file it stopped on.
Cambiado
- Nube
Security scanner: scoring now measures how much readable first-party code a site ships.
Reports list findings for each file, show evidence from exposed source maps, and preview a sample of the site's code protected by AfterPack. A site whose scripts are verified as protected can show a "Protected by AfterPack" badge.
Corregido
- Nube
Pro builds now honor
paths.excludeand glob patterns inidentifiers.reserved, which the cloud previously ignored. - Nube
If the engine cannot produce valid output for a file in a Pro build, that file now fails the build. Before, it came back unprotected.
CLI, framework plugins and engine
Añadido
- CLI
npx afterpackprotects a build directory or a single file in place.verifychecks a build against its protection receipt before deploy,restoreundoes the last run, andauditscans a live site. - Plugins
Plugins for Vite, Next.js, webpack, Rollup, esbuild, Astro, Svelte, SvelteKit, Vue, Nuxt, Angular, Electron and Parcel.
- Motor
@afterpack/coreruns locally on macOS, Linux (x64 and arm64, glibc and musl) and Windows x64.@afterpack/wasmruns the same engine in Cloudflare Workers and Node. - Plugins
The Protection Map is a local HTML report that shows what each part of your code went through. It is written to
.afterpack/when your build has source maps. - Documentación
The CLI and plugins are open source under Apache-2.0. The engine is free to use under the AfterPack Engine License.
Cloud, dashboard and docs
Añadido
- Documentación
The docs are now available in Chinese, Spanish, Hindi and Ukrainian.
Cambiado
- Nube
Pro builds with an invalid configuration are refused before they start and no longer count toward usage.
- Panel
Billed amounts under 1 MB now show in KB, based on exact byte counts.
Cloud, dashboard and Ask AfterPack
Cambiado
- Panel
When you invite someone who already has an account, they are added to the workspace right away.
- Documentación
Ask AfterPack keeps your conversation across page reloads. It points you to GitHub for bug reports and feature requests, and to email support for account questions.
Corregido
- Nube
Pro builds run an updated engine. Among its fixes: a minified function whose parameter shares the function's name (
function e(e){…}) could throw at runtime. - Nube
A file that crashed the engine during a Pro build no longer makes later Pro builds fail.
Accounts, dashboard and Pro
Añadido
- Panel
Accounts and the dashboard: workspaces and projects, team invites, API keys, cloud builds with their Protection Maps, usage and billing.
- Nube
AfterPack Pro: builds with a Pro key run in AfterPack's cloud, with per-region directives and Protection Maps kept in the dashboard.
- Documentación
Ask AfterPack, an assistant that answers questions from the docs.