Останнє оновлення: 3 жовтня 2026 р.

Журнал змін

Що змінилося в кожному релізі рушія, CLI та його плагінів і в кожному оновленні хмари та дашборду. Найновіше вгорі.

Що буде далі — на дорожній карті. Знайшли помилку? Повідомте на GitHub.

Нотатки до релізів публікуються англійською.

0.2.2

Останній

Correctness fixes and engine 0.2.3

Додано

  • Плагіни

    The plugins and the CLI tell the engine when your build output is ES modules, from the bundler's output format or, in the CLI, from .mjs files and <script type="module"> in your built HTML. The new sourceType option overrides it.

    sourceType

  • Документація

    A new Semantic contract page lists what obfuscated output keeps the same and the few deliberate differences. Diagnostics, Presets and Directives cover engine 0.2.3 behavior.

Змінено

  • Рушій

    A build that cannot reach its complexity target because a transform is turned off or a region directive limits it now fails with DIAG_TARGET_NOT_REACHED, naming the file and lines. Before, it shipped weaker output.

  • Рушій

    Pro: transforms.selfIntegrity on a build with no code at medium or above now fails with DIAG_SELF_INTEGRITY_INERT instead of shipping without the check.

  • Рушій

    minify now only renames identifiers and compresses the code. It no longer rewrites syntax.

    Presets

  • Рушій

    Loops are no longer rewritten into callback helpers at minify and light, which removes the 2-5x slowdown those helpers caused in hot loops.

    At light, property and global names still go through encoded constants, which has some cost in very hot code.

  • Рушій

    light output is smaller: about 30% less gzipped on real bundles, most of all on string-heavy files such as translation tables.

  • Рушій

    The engine is smaller: @afterpack/wasm downloads about 17% fewer gzipped bytes.

  • CLI

    The Protection Map shows coverage: each region lists the transforms applied to it and why any code stays readable. It no longer shows a resistance percentage.

    Protection Map

  • Хмара

    Pro builds now run engine 0.2.3.

Виправлено

  • Рушій

    Fixed cases where obfuscated code could behave differently from the original, at every preset. Most date back to 0.1, so rebuild with this release.

    Each engine release is now checked against real libraries and multi-script pages before it ships. The items below list the fixes; the new Semantic contract page lists what output keeps the same and the few deliberate differences.

    Semantic contract

  • Рушій

    Classic scripts keep their top-level functions and variables on the global object, so other scripts on the page can still use them, and references to globals declared elsewhere behave as in the original.

  • Рушій

    An ES module with no import or export is no longer read as a classic script when a plugin, the CLI or the sourceType option says the output is ES modules, so its top-level names stay off window.

    With none of those, the engine still tells the kind from the syntax, and a file without import or export is read as a classic script.

  • Рушій

    Values inside template literals are converted to text the way the original does, so objects such as dates format correctly.

  • Рушій

    Functions your code later constructs, through extends, a Proxy, a stored reference or an export, stay constructible.

  • Рушій

    Class fields are defined the way native fields are, so a field over an inherited accessor works, as in custom elements, and a class called without new throws.

  • Рушій

    A function that refers to itself keeps one identity, so an event listener that removes itself is removed.

  • Рушій

    BigInt arithmetic no longer throws or returns wrong values at medium and above, a regression in 0.2.

  • Рушій

    At medium and above, arithmetic converts each object operand once, as the original does, and output no longer breaks when another script changes valueOf or toString on shared objects.

  • Рушій

    Direct eval and with keep their scope: the code around them stays as written, and the build reports it with DIAG_DYNAMIC_SCOPE_NATIVE.

    Diagnostics

  • Рушій

    Classes and constructors keep their original name when your code reads this.constructor.name or new.target.name, so custom error classes report their own name.

    Semantic contract

  • Рушій

    Also fixed: async ordering, a catch (e) block that declares var e, optional calls in parentheses such as (o?.m)(), delete in strict code, nested loops that multiplied output size at medium and above, and constant ** results that could differ from the browser in the last digit.

  • Рушій

    An explicit inflation.max now checks the finished file and fails the build with DIAG_SIZE_CAP_REACHED when output reaches it. String encoding always completes first.

    In earlier versions, a tight inflation.max could stop string encoding early and leave some strings readable, reported only as an Info diagnostic. If you set inflation.max, rebuild with this release.

    inflation.max

  • Рушій

    Free builds no longer refuse a directive that only lowers protection, such as a transform mask or a lower preset. Like other directives on Free, it is ignored.

    Free builds

Оновлення хмари

Security scanner

Виправлено

  • Хмара

    Security scanner and afterpack audit: scans now read scripts that load late or that redirect the page. A scan that could not read a site's own code, or found none, is now "Not graded" instead of scored.

    Before this fix, such a scan could give a site a perfect score. The README badge now shows the host's latest graded scan.

0.2.1

CSS source maps, Parcel receipts and engine 0.2.2

Додано

  • Плагіни

    Parcel builds now get a protection receipt, so afterpack verify works for them. Add --reporter @afterpack/parcel-optimizer/reporter to your parcel build command.

Змінено

  • Рушій

    Engine 0.2.2 is a build-only release: its output is the same as 0.2.1. Pro builds run it too.

Виправлено

  • Плагіни

    @afterpack/next now deletes CSS source maps from .next/static along with the JavaScript ones, and strips the comments that point to them.

    Earlier versions removed only JavaScript maps, so with productionBrowserSourceMaps on, your original stylesheets could be served with the site. The webpack, Rollup and Vite plugins now also drop CSS maps when your build ships no source maps.

    Next.js guide

0.2.0

Per-token presets and engine 0.2.1 (breaking)

Змінено

  • Рушій

    Presets are recalibrated for per-token protection: medium, hard and extreme now apply their complexity target (7, 12 and 25) to every token, where 0.1 targeted an average across the file.

    Output at these presets is considerably larger than in 0.1, and presets no longer cap output size. If you set complexity yourself, review the value, because it is now a per-token target. light, the default, adds no structural layers: it encodes strings, renames identifiers and rewrites syntax, and its output is about the same size as in 0.1.

    Presets

  • Плагіни

    The Protection Map now shades each token by how much transformation it received and lists the declarations the engine rewrote, in local reports and in the dashboard.

    Protection Map

  • Плагіни

    The CLI and plugins now require engine 0.2 or newer and refuse an older one. preset= directives resolve on the new scale.

  • Плагіни

    The CLI and plugins no longer edit your project's .gitignore, because .afterpack/ now carries its own. In CI, the Protection Map is off by default unless you set protectionMap.enabled.

  • Хмара

    Pro builds now run engine 0.2.1, and builds from 0.2 packages get up to 4 minutes in the cloud (was 90 seconds).

    If you use a Pro key, update the CLI or plugin too. A 0.1 package with no preset set, or with preset= directives, sends values on the old scale, so its cloud builds come out heavier than intended.

    Pro

  • Документація

    Docs and package READMEs are updated for 0.2, including the preset scale, the Protection Map, and where each integration runs in your build.

Виправлено

  • Рушій

    Fixed a miscompile in which code inside a rewritten switch, a ?. or ?? expression, or a class with private fields could read the wrong variable.

    It depended on the build seed and on a variable's name, original or renamed, matching one the engine uses internally. Affected code could throw or return wrong values.

  • Рушій

    Functions stored on objects now stay constructible. 0.1 could turn them into arrow functions, which broke feature detection in polyfill libraries such as core-js.

  • Рушій

    obfuscate() and obfuscateAll() in @afterpack/core and @afterpack/wasm now draw a fresh seed for each build when you don't pass one. In 0.1, every build of the same source came out identical. The CLI and plugins were not affected.

    seed

  • Рушій

    Input nested too deeply to process safely now fails with a clear diagnostic instead of crashing @afterpack/wasm. A long-running @afterpack/wasm instance also no longer grows its memory with every file.

    Workers

Оновлення хмари

Cloud and dashboard

Додано

  • Хмара

    A Pro build that fails because of a problem on our side is credited back automatically, and the dashboard shows the file it stopped on.

Змінено

  • Хмара

    Security scanner: scoring now measures how much readable first-party code a site ships.

    Reports list findings for each file, show evidence from exposed source maps, and preview a sample of the site's code protected by AfterPack. A site whose scripts are verified as protected can show a "Protected by AfterPack" badge.

Виправлено

  • Хмара

    Pro builds now honor paths.exclude and glob patterns in identifiers.reserved, which the cloud previously ignored.

    paths.exclude

  • Хмара

    If the engine cannot produce valid output for a file in a Pro build, that file now fails the build. Before, it came back unprotected.

0.1.0

CLI, framework plugins and engine

Додано

  • CLI

    npx afterpack protects a build directory or a single file in place. verify checks a build against its protection receipt before deploy, restore undoes the last run, and audit scans a live site.

    CLI

  • Плагіни

    Plugins for Vite, Next.js, webpack, Rollup, esbuild, Astro, Svelte, SvelteKit, Vue, Nuxt, Angular, Electron and Parcel.

    Framework guides

  • Рушій

    @afterpack/core runs locally on macOS, Linux (x64 and arm64, glibc and musl) and Windows x64. @afterpack/wasm runs the same engine in Cloudflare Workers and Node.

    Workers

  • Плагіни

    The Protection Map is a local HTML report that shows what each part of your code went through. It is written to .afterpack/ when your build has source maps.

    Protection Map

  • Документація

    The CLI and plugins are open source under Apache-2.0. The engine is free to use under the AfterPack Engine License.

    License

Оновлення хмари

Cloud, dashboard and docs

Додано

  • Документація

    The docs are now available in Chinese, Spanish, Hindi and Ukrainian.

    Docs

Змінено

  • Хмара

    Pro builds with an invalid configuration are refused before they start and no longer count toward usage.

  • Дашборд

    Billed amounts under 1 MB now show in KB, based on exact byte counts.

Оновлення хмари

Cloud, dashboard and Ask AfterPack

Змінено

  • Дашборд

    When you invite someone who already has an account, they are added to the workspace right away.

  • Документація

    Ask AfterPack keeps your conversation across page reloads. It points you to GitHub for bug reports and feature requests, and to email support for account questions.

Виправлено

  • Хмара

    Pro builds run an updated engine. Among its fixes: a minified function whose parameter shares the function's name (function e(e){…}) could throw at runtime.

  • Хмара

    A file that crashed the engine during a Pro build no longer makes later Pro builds fail.

Оновлення хмари

Accounts, dashboard and Pro

Додано

  • Дашборд

    Accounts and the dashboard: workspaces and projects, team invites, API keys, cloud builds with their Protection Maps, usage and billing.

  • Хмара

    AfterPack Pro: builds with a Pro key run in AfterPack's cloud, with per-region directives and Protection Maps kept in the dashboard.

    Pro

  • Документація

    Ask AfterPack, an assistant that answers questions from the docs.