v0.16.0
This release updates the Go API and configuration model, improves automation and PDF validation, and includes processing fixes and security hardening.
- Protect image buffer allocations against integer overflow and enforce resource limits before decoding each TIFF page.
- Fix default-configuration handling (#1492): synchronize access to the cached default configuration and return independent clones to callers.
This release includes fixes covered by six security advisories.
- Integer overflow in image buffer allocation
- Traditional cross-reference tables bypass configured XRef limits
- Packed RGB image samples can cause an index-out-of-range panic during image extraction
- Missing BitsPerComponent can cause a nil-pointer panic during image extraction
- Integer overflow in XRef stream /W array can cause denial of service
- Off-by-one revision mapping weakens PDF signature modification reporting
- Updated Go API — Explicit contexts for long-running operations, optional progress reporting, and reusable caller-owned configuration.
- Configuration redesign — Schema-aware loading, explicit initialization and reset, plus read-only and stateless operation.
- Automation and container preparation — Signal cancellation, safer output replacement, password-file inputs, and verified execution under arbitrary user IDs.
- Stronger PDF validation — Improved malformed-input handling, graph-traversal safeguards, and compatibility warnings for selected relaxed-validation decisions.
- Clearer signature validation — Separate reporting of document integrity, certificate trust, revocation, and timestamp evidence.
- PDF processing fixes — Improved resize orientation, rotated watermarks, form appearances, image handling, and LZW decoding.
- Smaller Go module — Approximately 94% smaller in the original packaging comparison. Samples and test fixtures remain in Git but are excluded from module downloads.
Go applications require Go 1.26 or later and updates to affected API calls. Existing file-backed configurations from v0.15 or earlier require an explicit configuration reset.
go get github.com/pdfcpu/pdfcpu@v0.16.0
Existing v0.15 and older config.yml files do not contain the new configuration schema identifier. pdfcpu preserves the file and reports that a reset is required instead of rewriting it automatically.
If the configuration is not customized, run:
pdfcpu config reset
pdfcpu config validate
For an explicit configuration root, use the same root for every command:
pdfcpu --conf /srv/pdfcpu config reset
pdfcpu --conf /srv/pdfcpu config validate
pdfcpu --conf /srv/pdfcpu config inspect
Before resetting, back up any customized config.yml. After resetting, reapply your settings. Installed user fonts and trusted certificates are preserved.
New installations and stateless operation with --conf disable need no migration.
See the v0.16 configuration upgrade guide.
| Change | Required action |
|---|---|
Long-running operations require a context.Context |
Pass the request or job context, or context.Background() when cancellation is not needed. Nil contexts are rejected. |
Validation and optimization operations take a final *api.ProgressOptions |
Pass nil when progress events are not needed. |
LoadConfiguration() now takes options and returns an error |
Call api.LoadConfiguration(api.ConfigurationOptions{}) and handle the error. |
Context-free and interim WithContext/WithOptions variants were consolidated |
Use the canonical operation name. |
Configurations supplied by an application remain caller-owned and can be reused after an operation. Clone a configuration before applying different settings for another job; do not mutate it concurrently while operations use it. Passing nil loads the default configuration and may initialize files on disk. For stateless applications, explicitly load api.ConfigurationModeStateless and pass the returned configuration.
See API installation and usage and the v0.16 migration guide for before/after examples.
- Automatic discovers or initializes file-backed configuration for normal CLI and API use.
- Read-only loads a prepared configuration tree without modifying it.
- Stateless uses built-in settings and the 14 core PDF fonts without accessing configuration files, user fonts or the local certificate store.
The CLI selects stateless mode with --conf disable.
Applications select a mode through api.ConfigurationOptions.
Configuration root precedence is the explicit flag, PDFCPU_CONFIG_ROOT, then the operating-system default.
Normal CLI PDF commands have no read-only-mode flag: prepare the complete tree first and mount it read-only.
Go applications can select api.ConfigurationModeReadOnly to load existing configuration without modifying files.
The new commands are:
pdfcpu config init
pdfcpu config list
pdfcpu config inspect [--json]
pdfcpu config validate
pdfcpu config reset
Use pdfcpu config inspect for configuration paths and effective policy.
The CLI responds to Ctrl+C, SIGINT and SIGTERM. The first signal requests a clean stop; a second signal terminates immediately. Go callers control cancellation through the context passed to the operation.
Cancellation is cooperative, so a large operation may take a moment to reach a safe stopping point. File-producing operations stage output before publication. When cancellation or an ordinary write failure occurs before publication, an existing destination is preserved and unfinished temporary output is removed.
Stdin PDF input and merged form multi-fill output to stdout use the operating-system temporary directory. Replacement files are staged beside their destination. On supported Unix systems, replacement preserves the destination group or fails before publication.
Use --upw-file or --opw-file wherever the corresponding literal password flag is accepted. Supply a password either directly or through a file, not both. Password files cannot use stdin.
One trailing LF or CRLF is ignored. Other spaces and line endings remain part of the password. An empty file supplies an empty password, except where a non-empty owner password is required.
Password changes can replace their positional old/new password pair with:
| Command | Old password | New password |
|---|---|---|
changeupw |
--upwold-file |
--upwnew-file |
changeopw |
--opwold-file |
--opwnew-file |
Both file options for a password change must be supplied together.
maxInputBytesoptionally limits each PDF input, including stdin spooling. Zero remains unlimited.maxObjectBytesexposes the existing per-object reader buffer limit. Its default remains 64 MiB.- Offline mode now consistently covers remote images, link validation and live CRL/OCSP requests.
- Outbound image and revocation requests reject loopback, private, link-local, multicast, unspecified and selected special-purpose destinations by default. Trusted private revocation hosts can be configured explicitly.
These settings limit individual inputs or operations; they are not a total memory, disk or job-time budget.
Compatibility-warning coverage has substantially expanded. Relaxed validation reports selected conditions that strict validation would reject, indicating whether content was accepted, skipped or repaired in memory. These warnings are available through the CLI and structured API reports; --quiet suppresses CLI warnings.
Go callers can obtain the same ordered report through ValidateWithReport, ValidateFileWithReport and ValidateContextWithReport. Existing error-only validation APIs remain available.
Warning coverage is partial and will expand over time. Some relaxed-validation fallbacks produce no notice, so silence does not imply strict validation.
Strict validation describes the checks pdfcpu currently implements; it does not certify complete ISO 32000 compliance or prove that no bounded low-level reader recovery occurred.
Stronger validation and safer handling of malformed PDFs, including improved bounds checks, cycle detection and error reporting. Relaxed mode adds targeted compatibility exceptions while strict validation retains its requirements.
Signature validation now clearly separates integrity, certificate trust, revocation and timestamp evidence from the overall local assessment. See the signature-validation guide for output examples, supported checks and current limitations.
The Go module now excludes samples and test fixtures while retaining all runtime resources (#1449).
This release prepares pdfcpu for container deployment; an official image is planned for v0.17.
- Existing v0.15 and older file-backed configuration requires an explicit reset.
- Long-running Go APIs require a non-nil context under their canonical names.
- Validation and optimization APIs listed above require the final progress argument.
- Strict validation may reject malformed structures that earlier releases did not check.
- Relaxed compatibility warnings do not yet cover every pre-existing fallback.
- Cancellation takes effect at checkpoints, so some operations may not stop immediately.
#1407, #1444, #1449, #1457, #1460, #1461, #1465, #1466, #1467, #1470, #1472, #1473, #1474, #1477, #1479, #1484, #1485, #1487, #1492.
v4.16.0
Security
This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.
- Request scheme:
Context.Scheme()now uses theX-Forwarded-Proto,X-Forwarded-Protocol,X-Forwarded-SslandX-Url-Schemeheaders only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could sendX-Forwarded-Proto: httpsover plain HTTP and skipHTTPSRedirect. WhenX-Forwarded-Protois present, only it is used (its last value), and the scheme is returned in lowercase. the newEcho#SchemeExtractorfield selects the strategy:ExtractSchemeFromHeaders(...TrustOption)(default),ExtractSchemeDirect()orLegacySchemeExtractor(). The Secure middleware now sets HSTS based onContext.Scheme(). The Proxy middleware always setsX-Forwarded-ProtofromContext.Scheme()and removesX-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemebefore forwarding. GHSA-2ffq-g2xg-c22p - JSONP:
Context.JSONPandContext.JSONPBlobaccept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits,_and$). Any other callback returns a 400 Bad Request error that wraps the newErrInvalidJSONPCallback, and nothing is written. JSONP responses now carryX-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g - MethodOverride: a POST can no longer be overridden to
GET,HEAD,OPTIONS,TRACEorCONNECT. Before this, with theMethodFromFormorMethodFromQuerygetter and MethodOverride registered withUsebefore the CSRF middleware,_method=GETskipped the CSRF check. Register MethodOverride withEcho#Pre. GHSA-r7w9-592q-9vg4 - Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this,
/%09/evil.example/redirected browsers toevil.example. GHSA-v753-g4cw-jm48 - Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so
/admin%2Fsecret.txtor/%61dmin/secret.txtcan no longer reach a file under a guarded/admin/*route. GHSA-375p-5qhx-8wq4 The Static middleware andStaticDirectoryHandler(used byEcho.Static,Echo.StaticFS,Group.StaticandGroup.StaticFS) no longer serve paths with a.,..or empty segment, such as/assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr - Dependencies: update
golang.org/x/textto v0.40.0 (GO-2026-5970).
Client IP address (no code change in v4)
Without Echo#IPExtractor, Context.RealIP() in v4 trusts the X-Forwarded-For and X-Real-IP headers from any client, so the rate limiter can be bypassed and the Proxy middleware forwards a spoofed X-Real-IP (GHSA-246p-cpwv-v3jq, GHSA-99jh-6h7p-pp36). Changing this default in v4 would put all clients behind a proxy into one rate-limit bucket, so v4 keeps it. Set an extractor that matches your deployment:
e.IPExtractor = echo.ExtractIPDirect() // no proxy in front of the app
e.IPExtractor = echo.ExtractIPFromXFFHeader() // behind proxies in private networks that set X-Forwarded-For
// behind a proxy with public addresses (e.g. a CDN), also trust its ranges:
// e.IPExtractor = echo.ExtractIPFromXFFHeader(echo.TrustIPRange(cdnRange))
v5 uses the direct peer address by default since v5.1.0.
Behavior changes to check before upgrading
- Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or
100.64.0.0/10) address, itsX-Forwarded-Protois now ignored:HTTPSRedirectredirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16,130.211.0.0/22), and networks that use100.64.0.0/10(such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes._, gclb1, _ := net.ParseCIDR("35.191.0.0/16") _, gclb2, _ := net.ParseCIDR("130.211.0.0/22") e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
echo.LegacySchemeExtractor()restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that setRemoteAddrto the client's address also makeX-Forwarded-Protoignored (or, if they take it from a header, spoofable). - Trusted proxies must set
X-Forwarded-Proto. A proxy on a trusted address that passes the client'sX-Forwarded-Protothrough (for example nginx withoutproxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalidX-Forwarded-Protovalue now results inhttpinstead of falling back to the other scheme headers. - Your own tests.
httptest.NewRequestsetsRemoteAddrto192.0.2.1:1234, which is not trusted, so tests that setX-Forwarded-Protonow seehttp. Setreq.RemoteAddr = "10.0.0.1:1234"or usee.SchemeExtractor = echo.LegacySchemeExtractor()in such tests. - Proxy middleware headers.
X-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemeare no longer forwarded to the upstream;X-Forwarded-Protocarries the scheme. - MethodOverride. Overriding a POST to
GET(for example withX-HTTP-Method-Override: GETto send a long query in a POST body) is no longer done; such requests keep the POST method. - Static files. Paths with a double slash or dot segment (for example
/assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example%2C,%40or lowercase hex like%c3%a9) unlessStaticConfig.EnablePathUnescapingis set;Echo.Statichas behaved this way since v4.15.4. WithStaticConfig.EnablePathUnescapingorEcho#EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control. - JSONP.
Context.JSONPreturns an error for callbacks that are not JavaScript identifiers.
Documentation
- Static middleware: when registered with
Echo#Useit runs before route and group middleware, so route guards do not protect the files it serves.
v5.4.0
Security
This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.
- Request scheme:
Context.Scheme()now uses theX-Forwarded-Proto,X-Forwarded-Protocol,X-Forwarded-SslandX-Url-Schemeheaders only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could sendX-Forwarded-Proto: httpsover plain HTTP and skipHTTPSRedirect. WhenX-Forwarded-Protois present, only it is used (its last value), and the scheme is returned in lowercase.Echo#SchemeExtractor(andConfig.SchemeExtractor) selects the strategy:ExtractSchemeFromHeaders(...TrustOption)(default),ExtractSchemeDirect()orLegacySchemeExtractor(). The Secure middleware now sets HSTS based onContext.Scheme(). The Proxy middleware always setsX-Forwarded-ProtofromContext.Scheme()and removesX-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemebefore forwarding. GHSA-2ffq-g2xg-c22p - Proxy middleware: always sets
X-Real-IPfromContext.RealIP(), so a client can no longer pass a spoofedX-Real-IPto the upstream. GHSA-99jh-6h7p-pp36 - JSONP:
Context.JSONPandContext.JSONPBlobaccept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits,_and$). Any other callback returns a 400 Bad Request error that wraps the newErrInvalidJSONPCallback, and nothing is written. JSONP responses now carryX-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g - MethodOverride: a POST can no longer be overridden to
GET,HEAD,OPTIONS,TRACEorCONNECT. Before this, with theMethodFromFormorMethodFromQuerygetter and MethodOverride registered withUsebefore the CSRF middleware,_method=GETskipped the CSRF check. Register MethodOverride withEcho#Pre. GHSA-r7w9-592q-9vg4 - Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this,
/%09/evil.example/redirected browsers toevil.example. GHSA-v753-g4cw-jm48 - Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so
/admin%2Fsecret.txtor/%61dmin/secret.txtcan no longer reach a file under a guarded/admin/*route. GHSA-375p-5qhx-8wq4 The Static middleware andStaticDirectoryHandler(used byEcho.Static,Echo.StaticFS,Group.StaticandGroup.StaticFS) no longer serve paths with a.,..or empty segment, such as/assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr
Behavior changes to check before upgrading
- Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or
100.64.0.0/10) address, itsX-Forwarded-Protois now ignored:HTTPSRedirectredirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16,130.211.0.0/22), and networks that use100.64.0.0/10(such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes._, gclb1, _ := net.ParseCIDR("35.191.0.0/16") _, gclb2, _ := net.ParseCIDR("130.211.0.0/22") e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
echo.LegacySchemeExtractor()restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that setRemoteAddrto the client's address also makeX-Forwarded-Protoignored (or, if they take it from a header, spoofable). - Trusted proxies must set
X-Forwarded-Proto. A proxy on a trusted address that passes the client'sX-Forwarded-Protothrough (for example nginx withoutproxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalidX-Forwarded-Protovalue now results inhttpinstead of falling back to the other scheme headers. - Your own tests.
httptest.NewRequestsetsRemoteAddrto192.0.2.1:1234, which is not trusted, so tests that setX-Forwarded-Protonow seehttp. Setreq.RemoteAddr = "10.0.0.1:1234"or usee.SchemeExtractor = echo.LegacySchemeExtractor()in such tests. - Proxy middleware headers.
X-Real-IPsent to the upstream is now alwaysContext.RealIP(). In a chain like nginx → Echo Proxy → upstream, configureEcho#IPExtractor(for exampleecho.ExtractIPFromRealIPHeader()) to pass the client address on.X-Forwarded-Ssl,X-Forwarded-ProtocolandX-Url-Schemeare no longer forwarded;X-Forwarded-Protocarries the scheme. - MethodOverride. Overriding a POST to
GET(for example withX-HTTP-Method-Override: GETto send a long query in a POST body) is no longer done; such requests keep the POST method. - Static files. Paths with a double slash or dot segment (for example
/assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example%2C,%40or lowercase hex like%c3%a9) unlessStaticConfig.EnablePathUnescapingis set;Echo.Statichas behaved this way since v5.2.1. WithStaticConfig.EnablePathUnescapingorConfig.EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control. - JSONP.
Context.JSONPreturns an error for callbacks that are not JavaScript identifiers.
Documentation
IPExtractordocs: corrected the description of the default (the direct peer address has been used since v5.1.0).- Static middleware: when registered with
Echo#Useit runs before route and group middleware, so route guards do not protect the files it serves.
Version 1.61.1 (2026-09-27)
- fix(protocol): add tagged field to alter configs config entries by @prestona in https://github.com/IBM/sarama/pull/3773
- fix(producer): number idempotent batches at flush by @dnwe in https://github.com/IBM/sarama/pull/3762
- fix: several correctness bugs in the txnmgr compared with Java by @dnwe in https://github.com/IBM/sarama/pull/3764
- fix(producer): keep resent batches muted on retry by @dnwe in https://github.com/IBM/sarama/pull/3765
- fix(producer): bump idempotent epoch once per batch by @dnwe in https://github.com/IBM/sarama/pull/3768
- fix(consumer): notify before releasing on abort by @dnwe in https://github.com/IBM/sarama/pull/3771
- fix(consumer): recheck closed after taking lock by @dnwe in https://github.com/IBM/sarama/pull/3772
- fix(client): metadata and broker lifecycle races by @dnwe in https://github.com/IBM/sarama/pull/3774
- fix: only abandon the current broker worker by @dnwe in https://github.com/IBM/sarama/pull/3777
- fix(consumer): fetch stable offsets for read_committed by @dnwe in https://github.com/IBM/sarama/pull/3779
- fix(txn): retry every retriable transaction error by @dnwe in https://github.com/IBM/sarama/pull/3783
- fix(txn): epoch bump follow-ups by @dnwe in https://github.com/IBM/sarama/pull/3766
- fix(txn): commit transactional offsets correctly by @dnwe in https://github.com/IBM/sarama/pull/3780
- fix(broker): enforce MaxOpenRequests before writing by @dnwe in https://github.com/IBM/sarama/pull/3782
- fix(consumer): keep member id across cooperative rejoin by @dnwe in https://github.com/IBM/sarama/pull/3763
- fix(consumer): cooperative rejoin and coordinator move by @dnwe in https://github.com/IBM/sarama/pull/3769
- fix(consumer): preferred read replica fallbacks by @dnwe in https://github.com/IBM/sarama/pull/3785
- fix(deps): update module github.com/klauspost/compress to v1.20.1 - autoclosed by @renovate[bot] in https://github.com/IBM/sarama/pull/3786
- chore(deps): update dependency golangci/golangci-lint to v2.14.0 by @renovate[bot] in https://github.com/IBM/sarama/pull/3776
- fix(deps): update module github.com/pierrec/lz4/v4 to v4.1.31 by @renovate[bot] in https://github.com/IBM/sarama/pull/3788
- docs(consumer): commit before revoke without autocommit by @dnwe in https://github.com/IBM/sarama/pull/3784
- test(functional): cover admin AlterConfig by @dnwe in https://github.com/IBM/sarama/pull/3775
- test(admin): answer FindCoordinator on both brokers by @dnwe in https://github.com/IBM/sarama/pull/3778
Full Changelog: https://github.com/IBM/sarama/compare/v1.61.0...v1.61.1
Wails v3.0.0-beta.26
- Watcher applies HTTP readiness checks to frontend dev server in PR by @atterpac
- Recover from WebView2 process failures instead of leaving a blank window in PR by @taliesin-ai
🤖 This is an automated nightly release generated from the latest changes on master.
Installation:
go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-beta.26
v5.5.2
lego is an independent, free, and open-source project, if you value it, consider supporting it! ❤️
Everybody thinks that the others will donate, but in the end, nobody does.
So if you think that lego is worth it, please consider donating.
For key updates, see the changelog.
Wails v3.0.0-beta.25
- Stop
wails3 devand its background processes when the primary application exits (#6048)
🤖 This is an automated nightly release generated from the latest changes on master.
Installation:
go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-beta.25
Version 1.61.0 (2026-09-22)
- feat(consumer): support cooperative rebalancing by @dnwe in https://github.com/IBM/sarama/pull/3696
- feat: support KIP-848 ConsumerGroupDescribe API by @shilohlee98 in https://github.com/IBM/sarama/pull/3748
- examples: add cooperative-sticky assignor to consumergroup by @dnwe in https://github.com/IBM/sarama/pull/3760
- fix(client): only deregister the broker registered under that ID by @hsdfat in https://github.com/IBM/sarama/pull/3752
- fix(consumer): stop roundrobin balancer looping on an unsubscribed topic by @lenamonj in https://github.com/IBM/sarama/pull/3740
- fix(producer): drain pending responses immediately once channel closes by @navi89mai in https://github.com/IBM/sarama/pull/3729
- fix: prevent race in asyncProducer retryHandler by @dloebl in https://github.com/IBM/sarama/pull/3733
- fix(protocol): return ErrUnsupportedVersion for absent broker API keys by @wxldonnaBJ in https://github.com/IBM/sarama/pull/3741
- chore(deps): update dependency golangci/golangci-lint to v2.13.2 by @renovate[bot] in https://github.com/IBM/sarama/pull/3732
- chore(deps): bump github.com/klauspost/compress from 1.19.2 to 1.20.0 by @dependabot[bot] in https://github.com/IBM/sarama/pull/3743
- chore(deps): bump github.com/pierrec/lz4/v4 from 4.1.29 to 4.1.30 by @dependabot[bot] in https://github.com/IBM/sarama/pull/3751
- chore(deps): update dependency vearutop/teststat to v0.1.29 by @renovate[bot] in https://github.com/IBM/sarama/pull/3730
- chore(deps): bump the golang-x group across 1 directory with 3 updates by @dependabot[bot] in https://github.com/IBM/sarama/pull/3749
- chore(deps): update docker/bake-action action to v7.4.0 - autoclosed by @renovate[bot] in https://github.com/IBM/sarama/pull/3756
- chore(deps): update docker/setup-buildx-action action to v4.4.1 by @renovate[bot] in https://github.com/IBM/sarama/pull/3757
- fix(test): capture logs without replacing the global Logger by @official-burak in https://github.com/IBM/sarama/pull/3737
- test(functional): cover cooperative Java interoperability by @dnwe in https://github.com/IBM/sarama/pull/3754
- docs: clarify producer batching configuration by @krvladislav in https://github.com/IBM/sarama/pull/3712
- @shilohlee98 made their first contribution in https://github.com/IBM/sarama/pull/3748
- @hsdfat made their first contribution in https://github.com/IBM/sarama/pull/3752
- @lenamonj made their first contribution in https://github.com/IBM/sarama/pull/3740
- @navi89mai made their first contribution in https://github.com/IBM/sarama/pull/3729
- @krvladislav made their first contribution in https://github.com/IBM/sarama/pull/3712
- @dloebl made their first contribution in https://github.com/IBM/sarama/pull/3733
- @official-burak made their first contribution in https://github.com/IBM/sarama/pull/3737
- @wxldonnaBJ made their first contribution in https://github.com/IBM/sarama/pull/3741
Full Changelog: https://github.com/IBM/sarama/compare/v1.60.2...v1.61.0
v2.14.0
This release contains new features, improvements and bug fixes.
- US-1698 Image compression API for DOCX:
Document.CompressImages(targetDPI, jpegQuality), the equivalent of Word's "Compress Pictures" - US-1749
XLOOKUP,XMATCH,SWITCHandTEXTSPLITfor the spreadsheet formula engine - US-1750 Statistical functions for the spreadsheet formula engine: the
STDEV/VARfamily,NORM.DIST,NORM.INV,BINOM.DIST,PERCENTILE,QUARTILE,CORREL,FORECASTandLINEST - US-1783 Presentation text formatting and slide property API: italic, underline, strike, caps, character spacing, kerning, superscript/subscript, language, line spacing, margins, indents and tab stops, plus
Slide.SetHidden/Hidden,SlideSize.SetType/TypeandPresentation.NotesSize/SetNotesSize
- US-1658 XLSX to PDF conversion honoring print areas, including multi-range lists, whole-column and whole-row references
- US-1665 DOCX to PDF rendering of Word section formatting: multi-column layout, page borders, line numbering and page-number formats
- US-1761 UniPDF dependency update to v5.1.0
- US-1699 CI/CD pipeline gating convert render output against committed baselines, with stale-baseline detection and pixel-diff artifacts on failure
- US-1729 Table of contents not generated for content wrapped in a Structured Document Tag (SDT) fix
- US-1749
INDEXpanicking out of bounds when the column argument equals the row width fix - US-1658 XLSX to PDF fixes for the page size table (missing Quarto and Envelope 9 codes, swapped Envelope B5 dimensions, incorrect Monarch width), charts duplicating series data from both live and cached values, mis-sized merged cells, and page-break artifacts in row borders and trailing pages
- US-1761 The minimum supported Go version is now 1.25.0, raised by the UniPDF v5.1.0 dependency. Projects building UniOffice with Go 1.24 or earlier need to upgrade their toolchain.