Skip to content
Devix Open Source

Changelog

Every release of Cookie Consent, newest first. Breaking changes are flagged.

v1.0.0

12 Sep 2026

First release.

Added

  • Real blocking: <script type="text/plain" data-cc="analytics">, data-cc-src on iframes and images, several categories on one tag (data-cc="analytics marketing"), single services (data-cc="analytics/ga4"), and a nonce copied onto everything we unblock for strict CSP pages.
  • Withdrawing consent takes an embed off the page immediately, and reloadOnWithdraw covers scripts that have already run.
  • Google Consent Mode v2: consentModeDefaults() for the <head> and an automatic consent update with all seven signals, wait_for_update, ads_data_redaction and optional url_passthrough.
  • Regimes — GDPR/UK, UAE PDPL and the GCC, Brazil's LGPD, and the US opt-out states — deciding whether anything may run before a choice, with your own regimes accepted too.
  • Global Privacy Control and Do Not Track recorded as a refusal, without anyone being asked.
  • A consent record with an id, both timestamps, categories, refused categories, services, version, regime, language, a notice hash and a revision number — handed to report() for your server log.
  • Categories and services with descriptions, provider links, cookie tables, service dependencies (needs), and autoClear cookies that are deleted whenever a category is refused.
  • Every label, description and word takes { en: '…', ar: '…' }, so service labels translate too.
  • A notice that is a labelled dialog, a preferences screen on a native <dialog>, switches that are real checkboxes, a configurable heading tag, and a refusal button exactly as prominent as the acceptance.
  • [data-cc-open] on any element opens the preferences, so a footer link needs no code.
  • Theming through CSS variables, classNames on every part, theme: 'auto', a @layer devix stylesheet, and box, bar and centre layouts.
  • React, Vue, Svelte, <dx-cookie-consent> and a DOM-free @devix-labs/cookie-consent/core.