1.2.0Current2026-08-19
- The published checksum list is now signed. Until now those checksums came from the same host as the downloads they described, which catches a corrupted file but could never catch a tampered one — anyone able to replace a binary could replace its checksum in the same motion.
- The Windows installer checks the download's Authenticode signature and refuses one published by anybody else, rather than trusting the checksum alone.
- On Linux and macOS the installer verifies the signature over the checksum list. On an upgrade it asks the agent already on the machine to do it, because that agent carries the key from software you already chose to trust.
- The agent can verify a release itself: simpletag-agent --verify <file> <SHA256SUMS> <SHA256SUMS.sig>.
simpletag-agent-linux 6c5b2b08180ca7f518b8894b1b3d0cc483c94ab90eb11bd09eb917390fcc18c6
simpletag-agent.exe 0bfbc989cc2730c87980397686e3786661429b148c10c6d280584665bd2b783b
simpletag-agent.js 36434460f4ff43524b5d99f90260feb6e4888c81c3bbff2d590b7d3859571c8b
simpletag-setup.exe 80ca4efc8a87597130660ed596f80293e8930b1116a7ae4ecafcf6cfbef6b615
This list is signed. The installers check the signature against a key built into the agent, not just the numbers above — a checksum served by the same host as the file it describes catches a bad download and nothing else.
1.1.02026-08-18
- Signed. Both binaries now carry an Authenticode signature with an RFC-3161 timestamp, so Windows names a publisher instead of warning about an unknown one.
- The installer carries the Simpletag mark — an icon, a header and a welcome panel where before it shipped with stock NSIS artwork.
- The agent reports how each disk is attached (SATA, NVMe, USB). It is what makes a disposal certificate able to say that an erase claimed over a USB bridge may not have reached the drive.
simpletag-agent-linux 85e3bad9e67b6e43b05fe38de2f0a8e6ed952b85a643ec340ad3f8dff3cd5334
simpletag-agent.exe 6ce668a83833b51baafdcf5c505b966794e9d6da53e39e28c49b90448722d389
simpletag-agent.js 978a2d011c957099b05fc35818ea08af118cfc4f75621b638c590648b05db15c
simpletag-setup.exe 0ac27da7cd3fd147cd77cb80de4c769dda0b5386236228099f4fca92d3b53cd3
This list is signed. The installers check the signature against a key built into the agent, not just the numbers above — a checksum served by the same host as the file it describes catches a bad download and nothing else.