Skip to content

Veil

v1.3.1 Feature

This release adds 2 notable features for engineering teams evaluating rollout.

✓ No known CVEs patched
Read the diff → Tool health → What is this tool? →

✓ No known CVEs patched in this version

Topics

ai-agents anti-detection automation browser-automation cdp chrome-devtools-protocol
+4 more
mcp stealth-browser typescript web-scraping

Summary

AI summary

Updates Verified, https://github.com/acunningham-ship-it/veilbrowser/releases/tag/python-v1.3.1, and Python across a mixed release.

Full changelog

Published to npm as @achamm/[email protected]. The Python front end ships in the companion release python-v1.3.1.

Added

  • A Python front end (python/) — see python-v1.3.1.
  • CHROME_FLAGS_LEAD / CHROME_FLAGS_TAIL and FINGERPRINT_STEALTH_BODY are now exported, so the launch flags and the injected stealth body have one definition shared by both front ends instead of a copy in each.

Fixed

  • The injected scripts are now pure ASCII, and a test enforces it. Bun's transpiler escapes non-ASCII to \uXXXX, which is value-preserving in a normal template but not in String.raw, where the raw text is the value. Measured: String.raw`a—b` is 3 characters under node and 8 under bun, with the literal characters \ u 2 0 1 4 ending up in the script served to the page. Veil runs under bun, so the em dashes in the stealth patch's comments were reaching pages as escape sequences.

    All seven occurrences were inside // comments, so nothing was broken — but one non-ASCII character inside a string value would have silently changed what the patch does, differently per runtime. Keeping these templates ASCII removes the class of bug, and it's what makes byte-parity with Python possible at all.

  • veilbrowser (Python) no longer needs websockets just to build a stealth script — the import moved into CDP.connect(), where it's actually used. This failed the 1.3.0 release in CI, so v1.3.0 was tagged but never published; npm goes 1.2.0 → 1.3.1.

Verified

  • 204/204 bun tests (197 before this release + 7 new parity tests)
  • 21/21 Python checks against a real Chrome, run from the installed wheel outside the source tree
  • node, bun and Python emit byte-identical stealth scripts for all four presets

Weekly OSS security release digest.

The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.

No spam, unsubscribe anytime.

Share this release

Track Veil

Get notified when new releases ship.

Sign up free

Beta — feedback welcome: [email protected]