simpletagASSET TRACKING

Agent releases

Every version of the agent and the Windows installer, what changed in it, and the SHA-256 you should see. The installer checks these itself before it installs anything — they are published so that you can check too.

Machines upgrade by re-running the same install command; enrolment is kept. Nothing here is pushed to a machine — the agent cannot be told to update itself, which is the same reason it cannot be told to do anything else.

1.2.0Current2026-08-19
  • The published checksum list is now signed. Until now those checksums came from the same host as the downloads they described, which catches a corrupted file but could never catch a tampered one — anyone able to replace a binary could replace its checksum in the same motion.
  • The Windows installer checks the download's Authenticode signature and refuses one published by anybody else, rather than trusting the checksum alone.
  • On Linux and macOS the installer verifies the signature over the checksum list. On an upgrade it asks the agent already on the machine to do it, because that agent carries the key from software you already chose to trust.
  • The agent can verify a release itself: simpletag-agent --verify <file> <SHA256SUMS> <SHA256SUMS.sig>.
simpletag-agent-linux 6c5b2b08180ca7f518b8894b1b3d0cc483c94ab90eb11bd09eb917390fcc18c6 simpletag-agent.exe 0bfbc989cc2730c87980397686e3786661429b148c10c6d280584665bd2b783b simpletag-agent.js 36434460f4ff43524b5d99f90260feb6e4888c81c3bbff2d590b7d3859571c8b simpletag-setup.exe 80ca4efc8a87597130660ed596f80293e8930b1116a7ae4ecafcf6cfbef6b615

This list is signed. The installers check the signature against a key built into the agent, not just the numbers above — a checksum served by the same host as the file it describes catches a bad download and nothing else.

1.1.02026-08-18
  • Signed. Both binaries now carry an Authenticode signature with an RFC-3161 timestamp, so Windows names a publisher instead of warning about an unknown one.
  • The installer carries the Simpletag mark — an icon, a header and a welcome panel where before it shipped with stock NSIS artwork.
  • The agent reports how each disk is attached (SATA, NVMe, USB). It is what makes a disposal certificate able to say that an erase claimed over a USB bridge may not have reached the drive.
simpletag-agent-linux 85e3bad9e67b6e43b05fe38de2f0a8e6ed952b85a643ec340ad3f8dff3cd5334 simpletag-agent.exe 6ce668a83833b51baafdcf5c505b966794e9d6da53e39e28c49b90448722d389 simpletag-agent.js 978a2d011c957099b05fc35818ea08af118cfc4f75621b638c590648b05db15c simpletag-setup.exe 0ac27da7cd3fd147cd77cb80de4c769dda0b5386236228099f4fca92d3b53cd3

This list is signed. The installers check the signature against a key built into the agent, not just the numbers above — a checksum served by the same host as the file it describes catches a bad download and nothing else.

1.0.02026-08-15
  • First release. A read-only agent for Windows, Linux and macOS that reports what a machine is, who is signed in, and what is installed — and cannot be told to change anything.
  • Windows installer with an enrolment code carried in its own filename, so there is nothing to type.
  • Every download is checksum-verified before anything is installed.

Checksums for this build were not recorded.