SDK changelog
What changed in each version of the SofAds TV SDK, newest first. This page is generated from the SDK's own changelog when the site is built.
Your app always runs the SDK version you shipped: the copy bundled in your package, or the pinned version your hosted site loads (https://sdk.sofadsrv.com/v1.0.0/sofads.min.js, never "latest"). Server-side changes, such as new demand, need no SDK update. Upgrade when a version below brings something you want, and test it with test ads first. Your app's version is in the debug overlay and in SofAds.getInfo().
Unreleased
Added
- On packaged Tizen apps the SDK reads
config.xmlonce at init, in the background, and logs one console warning listing the exact lines to add. It checks for<access origin="*" subdomains="true"></access>,<tizen:allow-navigation>*</tizen:allow-navigation>(an empty element or a single host counts as missing) and the four base privileges (internet, adinfo, productinfo, tv.inputdevice). The Google PAL privileges (system, telephony, network.public) are checked too when the bootstrap enablesgoogle_palon Tizen. The debug overlay shows the same warning. Hosted apps (pages served over http or https) are not checked. CHANGELOG.md(this file), andnpm run version:bump, which updatespackage.json,package-lock.jsonand the version insrc/config.tsand moves "Unreleased" into a dated version entry; it refuses to bump past a version that was never released.
Changed
- Tizen access rules follow the revised set:
access origin="*"plustizen:allow-navigation(for hosted apps), the four base privileges, and the Google PAL block. This replaces the old allowlist that only covered*.sofadsrv.comand the list of Google hosts. Protection now lives in the SDK. - The test-mode console line now ends with
Why: https://sofads.com/docs/troubleshooting#test-mode(a stable URL) instead of the test-ads page. - The Tizen privilege table covers all seven privileges by short name (
internet,adinfo,productinfo,tv_inputdevice,system,telephony,network_public).
Security
- HTML ad iframes use the sandbox
allow-scriptsonly (HTML_AD_SANDBOX). That means noallow-top-navigation, noallow-top-navigation-by-user-activation, no popups and no same-origin access. A real-browser test shows that a creative tryingwindow.top.location = …,top.location.href = …orwindow.open(…, '_top')is blocked and the app stays on its page. A static test makes sure the SDK itself never navigates the top-level page.
1.0.0 - not released yet
The history up to round 14, reconstructed from the commits between 2026-10-06 and 2026-10-08.
Added
- Core SDK (2026-10-06):
SofAds.init,showInterstitial,showRewarded, the QR card format, VAST video with wrapper resolution, house/direct prefetch, batched events withsendBeacon, the install ID, and the bootstrap config with kill switches. Everything uses XHR, so it works fromfile://. The SDK never throws and never blocks the app. - Ad screen for the 10-foot UI: scan-to-reward with "Reward unlocked" and Continue, an opaque end panel, and screenshots of every ad state.
SofAds.previewand a demo gallery mode. - Three-owner ad screen (round 6): advertiser creative, publisher reward (an amount plus an icon, overridable in code) and the SofAds frame. Frame translations come as one file per language (EN, NL, DE, FR, ES, IT, PL, PT), and the frame renders in the creative's language.
- Targeting signals:
device.utc_offsetand a lower-caseddevice.make. - Google skippable-ads standard (round 7): a "You can skip in X s" countdown, then a focused "Skip ad" button. Arabic is added and the layout works right to left. A "Test ad" label.
- Signal providers (round 7), with Google PAL (
google_pal) as the first one: nonce generation at init and per session, a TCF__tcfapishim that never reports consent by default, and playback, click and touch hooks. The README includes a guide to writing a provider. - Tizen integration checks (round 7): when
webapis.jsis missing or a privilege throws aSecurityError, the SDK falls back to the install ID, logs one console warning and setswebapis_missing/privilege_missinginsession_start. A test-mode console line, and a debug overlay with the install ID as text and as a QR code. - Recorded Google IMA sample-tag fixtures, and VAST
<Icons>(AdChoices) rendering. - Titan OS: device info via
TitanSDK.deviceInfo.getDeviceInfo(). - Stable docs URLs (round 9): one
docs_base_url, and every printed docs link comes from the stable list. - Made for children (round 11):
features.child_directedis honored. The SDK reads no OS ID, sends no IFA, runs no signal providers and never sends the install ID asppid. Partner fills play without a QR. - Typed public event hooks (
SofAds.on/SofAds.off) for the live demo's log (round 14).
Changed
- Round 12: partner fills carry no QR code (
qr_suppressedis removed). - The OS advertising ID is read only after a bootstrap says the app is not made for children (review round 11).
Removed
- The init option
rewarded.scanAutoCloseSeconds. - Dead exports. The build now enables
noUnusedLocalsandnoUnusedParameters.
Keep reading
- SDK reference: every call, option and event in the current version.
- Release checklist: what to check before you ship an update.