Verify your download
Every release is published with its SHA-256 checksum. If the checksum of the file you downloaded matches, the file is byte-for-byte the one we released and has not been damaged or tampered with on the way.
- Download
DiffScope-1.0.1-win-x64.zipfrom the download page. Only download DiffScope from this website: we do not publish it anywhere else. - Open PowerShell or Command Prompt in the folder that contains the zip and run one of these commands:
Get-FileHash .\DiffScope-1.0.1-win-x64.zip -Algorithm SHA256certutil -hashfile DiffScope-1.0.1-win-x64.zip SHA256The result must match this SHA-256 exactly (upper or lower case does not matter):
ee57ff27e5a2ee1db9b45608ddc4c4f476599f63d7232be61a462b28528688ffIf the hash does not match
Do not extract or run the file. Delete it and download it again from this website. If it still does not match, please report it (see below).
Why DiffScope.exe is not code-signed
Windows programs can be signed with a code-signing certificate that names the publisher. DiffScope’s executable is not signed yet, because a certificate is not in place. This has two visible effects:
- Microsoft Defender SmartScreen shows “Windows protected your PC” the first time you run it. Click More info › Run anyway.
- The file properties show no digital signature, and Windows names the publisher as “Unknown”.
A signature would tell you who published the file. Until DiffScope is signed, the SHA-256 checksum above is how you confirm that your copy is exactly the file published on this website. When code signing is added, it will be announced in the changelog and this page will be updated.
How the app is built
DiffScope reads the files you give it, shows the differences and writes only the files you save. It is designed to do nothing else.
No network access
The app contains no networking code: no telemetry, no update checks, no crash reporter, no licence server. It works the same on an air-gapped machine.
Locked-down window
The user interface runs in Chromium’s sandbox with context isolation on and Node.js integration off. It can only reach the app through a small, fixed set of functions.
Strict content policy
A strict Content Security Policy allows only the app’s own scripts and styles and blocks every network connection, so file content can never load or run outside code.
Files and settings
Files are only written when you save. Settings are kept locally in %APPDATA%\DiffScope. No admin rights, services or registry entries are needed.
Security fixes, including updates of the bundled Electron runtime, are listed in the changelog.
Supported versions
Security fixes are made in the latest release only. Please keep DiffScope up to date by checking the changelog from time to time; the app does not check for updates itself, because it never goes online.
| Version | Security fixes |
|---|---|
| Latest release (currently 1.0.1) | Yes |
| Older releases | No, please update |
Reporting a vulnerability
If you believe you have found a security problem in DiffScope or this website, please report it privately rather than posting it publicly, so that it can be fixed before others can misuse it.
Private reports
A contact address is coming soon. Until it is published here, please keep the details private.
A useful report includes:
- the DiffScope version (
.\DiffScope.exe --version | Write-Output) and your Windows version; - a description of the problem and its impact;
- steps or sample files to reproduce it, with nothing confidential in them;
- whether you would like to be credited when the fix is released.
Please do not access other people’s data, disrupt the website or download service, or run automated scans against it.
Bug bounty
DiffScope is free software and there is no bug bounty programme: we cannot offer payment for reports. With your permission, we are happy to thank you by name in the release notes of the fix.
