Changelog
What's new.
Every release since the ledger began — written down where you can check it. Versioned, dated, and gated; each entry traces to a real release id.
Latest releases
Shipped, in order.
Newest first. Every row here corresponds to a release the deploy gate signed off — the dates are UTC.
- 2026-10-01 r2026.10.01-2 Client
Transfers that pick up where they left off
A brief connection drop no longer ends a transfer. Both sides reconnect on their own and pick up exactly where they left off — nothing that already arrived is sent twice, and the file still lands byte-for-byte identical.
- 2026-10-01 r2026.10.01-1 Site
Two lanes, honest names
The two transfer modes now say what they guarantee: "End-to-end" — sealed on your device before sending, the relay only forwards ciphertext — and "Transport-only", the faster lane where the relay carries the bytes. Same behavior, honest labels across the app, docs and chat.
- 2026-10-01 r2026.10.01-1 Client
Bigger pieces on the relay path
Transfers carried through the relay now move in bigger pieces — 8 MiB chunks — cutting round-trips and overhead, under a tightened stream budget that keeps the relay steady under load.
- 2026-10-01 r2026.10.01-1 Client
Transfers that hold steady
The transfer engine got sturdier under load and at the edges: receivers that fall behind recover smoothly, gaps are repaired and re-sent instead of stalling a run, and staged writes drain fully before the final check.
- 2026-09-30 r2026.09.30-8 Site
Who builds this site
The footer and a new About colophon now say it plainly: Tallow is built and operated by AI agents working under human oversight.
- 2026-09-30 r2026.09.30-5 Site
Status page, steadied
The status page got a small accessibility pass: keyboard and screen-reader visitors now jump straight to the content, and the page reserves space for its service rows so nothing shifts around while it loads.
- 2026-09-30 r2026.09.30-4 Pages
The page source, tidied
The served pages got a quiet tidiness pass: internal development annotations and stray comments no longer travel in the page source. Nothing visible changed — the source is simply cleaner.
- 2026-09-30 r2026.09.30-2 Pages
The blog steps back
The blog left the public surface: its draft posts are retired for an editorial pass, and search engines are asked to drop both routes. Nothing else on the site moved.
- 2026-09-29 r2026.09.29-2 Client
Fallbacks, sized for the lane
When a transfer has to fall back to the relay lane, its pieces are now sized for that lane: large fallback transfers that used to drop on their opening piece complete normally.
- 2026-09-29 r2026.09.29-1 Client
Big transfers, faster
The transfer engine got a speed pass: its flow-control loop keeps acknowledgements moving instead of waiting on itself, idle waits wake the moment data arrives, and fast device-to-device links carry larger pieces at a time. In this round's checks a 512 MiB transfer completed in about 45 seconds, verified byte for byte.
- 2026-09-27 r2026.09.27-2 Client
Interrupted transfers clean up after themselves
If a transfer dies before finishing, its temporary browser data no longer lingers: every visit sweeps what an interrupted session left behind — protected by a lock, so anything still in use is never touched — and the docs were corrected to describe exactly what is kept.
- 2026-09-27 r2026.09.27-2 ClientSecurity
Archive metadata is capped and contained
Compressed data that arrives attached to a file is now read under strict caps — entry count, declared sizes, and compression ratio — and anything over the caps is rejected safely rather than unpacked. The verification-code screen got its own cap too.
- 2026-09-26 r2026.09.27-1 Security
Dependencies, cleared to zero
The site's JavaScript dependencies were refreshed until the audit came back clean — every advisory resolved, 27 down to zero.
- 2026-09-26 r2026.09.27-1 PagesInfra
The service now watches itself
A real transfer runs against the live service every six hours — verified end to end, byte for byte — with a matching chat check beside it. The status page grew two live rows for the effort: Transfers and Chat.
- 2026-09-26 r2026.09.26-3 Client
A dropped transfer picks itself back up
If the connection drops while a chat transfer is running, both sides now reconnect on their own and the file batch is re-sent — up to two recoveries per session — instead of the transfer failing and the room going quiet.
- 2026-09-26 r2026.09.26-2 Client
Chat no longer breaks on a second file batch
Sending a second batch of files in a chat could end the room — the receiver stalled and the sender sat on “Sending…”. The cause was a stale completion frame from the previous batch; batches now carry their own fresh transfer scope, and a cross-batch encryption nonce reuse went with it.
- 2026-09-26 r2026.09.26-1 SecurityDocs
An audit against reality — claims, docs, and edges aligned
A ten-lane audit of the live product landed its fixes: feature claims re-scoped to what the site and service actually do, FAQ answers tightened, security edges hardened (response headers, log hygiene, the relay metrics surface), and docs swept for references that no longer match.
- 2026-09-25 r2026.09.25-6 ChromeLanding
One header everywhere — and a quieter homepage
The desktop header and the phone menu now carry the same five destinations in the same order: About, Docs, FAQ, Security, Whitepaper. The homepage shed its cryptography band (that evidence lives on /security), and this ledger is now complete back to its first entry.
- 2026-09-25 r2026.09.25-5 MobilePages
A menu built for thumbs — and two new pages
The phone menu is now a full-screen sheet: Docs, About, Security, FAQ and the whitepaper one tap away, with the appearance switch built in. Two new pages ship with it — /status, and the page you are reading.
- 2026-09-25 r2026.09.25-4 Landing
Comparison, rebuilt for app-first senders
The “How Tallow differs” table now lines up against LocalSend and Blip — the tools you actually switch from — including a row for what a receiver needs, and the rows where they win.
- 2026-09-25 r2026.09.25-3 Security
Security opens with evidence
The verification story now leads /security: what the relay can’t see, what we prove, and how to check the client you are running.
- 2026-09-25 r2026.09.25-2 Landing
How it works, and honest answers
A short walkthrough of the transfer path, plus an eight-question FAQ, now sit directly below the transfer module.
- 2026-09-25 r2026.09.25-1 Trust
The trust surface, sharpened
A verifiable-transfer card, precise retention language, and an honest-loss row in the comparison.
- 2026-09-24 r2026.09.24-2 Chrome
A quieter header and footer
The header is down to About and Docs; utility links moved to the footer, and the landing page lost two dead sections.
- 2026-09-24 r2026.09.24-1 Accessibility
Accessibility, wave one
A theme pass, focus and hit-target fixes, and clearer announcements through the transfer flow — the first wave of the site-wide accessibility remediation.
- 2026-09-23 r2026.09.23-7 Docs
Docs, reconciled with reality
Swept the last onion-relay references out of the docs and archives — what you read now matches what runs.
- 2026-09-23 r2026.09.23-6 Client
One gigabyte, enforced everywhere
The 1 GiB transfer limit is now enforced the same way in the picker, in chat, and at both ends of the wire.
- 2026-09-23 r2026.09.23-5 SecurityInfra
Crypto hardening and a relay rotation
Downgrade gating and KEM binding in the handshake; relay credentials rotated, with the old ones dead.
- 2026-09-23 r2026.09.23-4 Chrome
Every setting within reach
The half-height mobile settings sheet scrolls now, so no option hides below the fold — caught on a real phone and fixed the same day.
- 2026-09-23 r2026.09.23-3 Chrome
Navigation internals, trimmed
Removed a dead navigation layer — 528 lines down to 251 — and pinned the cleanup with a test that asserts it stays gone.
- 2026-09-23 r2026.09.23-2 Accessibility
Focus lands where you expect
Skip-link focus target fixed and header focus retained — keyboard navigation reads cleanly from the first Tab.
- 2026-09-23 r2026.09.23-1 Releases
Releases become verifiable
Every deploy now carries its own identity — version.json and an x-release meta tag — behind a nine-step gate.
Release ids follow rYYYY.MM.DD-N — the UTC date plus the day's sequence. They are never reused. The ledger's first dated record is r2026.09.23-1; earlier deploys are backfilled in the operations record.
Also
Not everything is a release.
- Reproducible builds
Each deploy carries its own identity: version.json, an x-release meta tag, and a verifiable chain.
Reproducible builds → - Audit
Independent review status, and what is still pending.
Audit status → - Status
What is up right now, and how the checks work.
/status →