1 days ago
pdfcpu

v0.16.0

v0.16.0

This release updates the Go API and configuration model, improves automation and PDF validation, and includes processing fixes and security hardening.

Changes since v0.16.0-rc.1

  • Protect image buffer allocations against integer overflow and enforce resource limits before decoding each TIFF page.
  • Fix default-configuration handling (#1492): synchronize access to the cached default configuration and return independent clones to callers.

Security advisories

This release includes fixes covered by six security advisories.

Highlights

  • Updated Go API — Explicit contexts for long-running operations, optional progress reporting, and reusable caller-owned configuration.
  • Configuration redesign — Schema-aware loading, explicit initialization and reset, plus read-only and stateless operation.
  • Automation and container preparation — Signal cancellation, safer output replacement, password-file inputs, and verified execution under arbitrary user IDs.
  • Stronger PDF validation — Improved malformed-input handling, graph-traversal safeguards, and compatibility warnings for selected relaxed-validation decisions.
  • Clearer signature validation — Separate reporting of document integrity, certificate trust, revocation, and timestamp evidence.
  • PDF processing fixes — Improved resize orientation, rotated watermarks, form appearances, image handling, and LZW decoding.
  • Smaller Go module — Approximately 94% smaller in the original packaging comparison. Samples and test fixtures remain in Git but are excluded from module downloads.

Requirements and installation

Go applications require Go 1.26 or later and updates to affected API calls. Existing file-backed configurations from v0.15 or earlier require an explicit configuration reset.

go get github.com/pdfcpu/pdfcpu@v0.16.0

Before upgrading

Reset legacy file-backed configuration

Existing v0.15 and older config.yml files do not contain the new configuration schema identifier. pdfcpu preserves the file and reports that a reset is required instead of rewriting it automatically.

If the configuration is not customized, run:

pdfcpu config reset
pdfcpu config validate

For an explicit configuration root, use the same root for every command:

pdfcpu --conf /srv/pdfcpu config reset
pdfcpu --conf /srv/pdfcpu config validate
pdfcpu --conf /srv/pdfcpu config inspect

Before resetting, back up any customized config.yml. After resetting, reapply your settings. Installed user fonts and trusted certificates are preserved.
New installations and stateless operation with --conf disable need no migration.

See the v0.16 configuration upgrade guide.

Update Go API callers

Change Required action
Long-running operations require a context.Context Pass the request or job context, or context.Background() when cancellation is not needed. Nil contexts are rejected.
Validation and optimization operations take a final *api.ProgressOptions Pass nil when progress events are not needed.
LoadConfiguration() now takes options and returns an error Call api.LoadConfiguration(api.ConfigurationOptions{}) and handle the error.
Context-free and interim WithContext/WithOptions variants were consolidated Use the canonical operation name.

Configurations supplied by an application remain caller-owned and can be reused after an operation. Clone a configuration before applying different settings for another job; do not mutate it concurrently while operations use it. Passing nil loads the default configuration and may initialize files on disk. For stateless applications, explicitly load api.ConfigurationModeStateless and pass the returned configuration.

See API installation and usage and the v0.16 migration guide for before/after examples.

Configuration and runtime

Explicit configuration modes

  • Automatic discovers or initializes file-backed configuration for normal CLI and API use.
  • Read-only loads a prepared configuration tree without modifying it.
  • Stateless uses built-in settings and the 14 core PDF fonts without accessing configuration files, user fonts or the local certificate store.

The CLI selects stateless mode with --conf disable.
Applications select a mode through api.ConfigurationOptions.
Configuration root precedence is the explicit flag, PDFCPU_CONFIG_ROOT, then the operating-system default.
Normal CLI PDF commands have no read-only-mode flag: prepare the complete tree first and mount it read-only.
Go applications can select api.ConfigurationModeReadOnly to load existing configuration without modifying files.

The new commands are:

pdfcpu config init
pdfcpu config list
pdfcpu config inspect [--json]
pdfcpu config validate
pdfcpu config reset

Use pdfcpu config inspect for configuration paths and effective policy.

Cancellation and transactional output

The CLI responds to Ctrl+C, SIGINT and SIGTERM. The first signal requests a clean stop; a second signal terminates immediately. Go callers control cancellation through the context passed to the operation.

Cancellation is cooperative, so a large operation may take a moment to reach a safe stopping point. File-producing operations stage output before publication. When cancellation or an ordinary write failure occurs before publication, an existing destination is preserved and unfinished temporary output is removed.

Stdin PDF input and merged form multi-fill output to stdout use the operating-system temporary directory. Replacement files are staged beside their destination. On supported Unix systems, replacement preserves the destination group or fails before publication.

Password files

Use --upw-file or --opw-file wherever the corresponding literal password flag is accepted. Supply a password either directly or through a file, not both. Password files cannot use stdin.

One trailing LF or CRLF is ignored. Other spaces and line endings remain part of the password. An empty file supplies an empty password, except where a non-empty owner password is required.

Password changes can replace their positional old/new password pair with:

Command Old password New password
changeupw --upwold-file --upwnew-file
changeopw --opwold-file --opwnew-file

Both file options for a password change must be supplied together.

Resource and network policy

  • maxInputBytes optionally limits each PDF input, including stdin spooling. Zero remains unlimited.
  • maxObjectBytes exposes the existing per-object reader buffer limit. Its default remains 64 MiB.
  • Offline mode now consistently covers remote images, link validation and live CRL/OCSP requests.
  • Outbound image and revocation requests reject loopback, private, link-local, multicast, unspecified and selected special-purpose destinations by default. Trusted private revocation hosts can be configured explicitly.

These settings limit individual inputs or operations; they are not a total memory, disk or job-time budget.

Validation

Compatibility warnings

Compatibility-warning coverage has substantially expanded. Relaxed validation reports selected conditions that strict validation would reject, indicating whether content was accepted, skipped or repaired in memory. These warnings are available through the CLI and structured API reports; --quiet suppresses CLI warnings.

Go callers can obtain the same ordered report through ValidateWithReport, ValidateFileWithReport and ValidateContextWithReport. Existing error-only validation APIs remain available.

Warning coverage is partial and will expand over time. Some relaxed-validation fallbacks produce no notice, so silence does not imply strict validation.

Strict validation describes the checks pdfcpu currently implements; it does not certify complete ISO 32000 compliance or prove that no bounded low-level reader recovery occurred.

Expanded validation and malformed-input handling

Stronger validation and safer handling of malformed PDFs, including improved bounds checks, cycle detection and error reporting. Relaxed mode adds targeted compatibility exceptions while strict validation retains its requirements.

Signature-validation evidence

Signature validation now clearly separates integrity, certificate trust, revocation and timestamp evidence from the overall local assessment. See the signature-validation guide for output examples, supported checks and current limitations.

Distribution and constrained environments

The Go module now excludes samples and test fixtures while retaining all runtime resources (#1449).
This release prepares pdfcpu for container deployment; an official image is planned for v0.17.

Compatibility summary

  • Existing v0.15 and older file-backed configuration requires an explicit reset.
  • Long-running Go APIs require a non-nil context under their canonical names.
  • Validation and optimization APIs listed above require the final progress argument.
  • Strict validation may reject malformed structures that earlier releases did not check.
  • Relaxed compatibility warnings do not yet cover every pre-existing fallback.
  • Cancellation takes effect at checkpoints, so some operations may not stop immediately.

Fixed issues

#1407, #1444, #1449, #1457, #1460, #1461, #1465, #1466, #1467, #1470, #1472, #1473, #1474, #1477, #1479, #1484, #1485, #1487, #1492.

2 days ago
echo

v4.16.0

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. the new Echo#SchemeExtractor field selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr
  • Dependencies: update golang.org/x/text to v0.40.0 (GO-2026-5970).

Client IP address (no code change in v4)

Without Echo#IPExtractor, Context.RealIP() in v4 trusts the X-Forwarded-For and X-Real-IP headers from any client, so the rate limiter can be bypassed and the Proxy middleware forwards a spoofed X-Real-IP (GHSA-246p-cpwv-v3jq, GHSA-99jh-6h7p-pp36). Changing this default in v4 would put all clients behind a proxy into one rate-limit bucket, so v4 keeps it. Set an extractor that matches your deployment:

e.IPExtractor = echo.ExtractIPDirect()        // no proxy in front of the app
e.IPExtractor = echo.ExtractIPFromXFFHeader() // behind proxies in private networks that set X-Forwarded-For
// behind a proxy with public addresses (e.g. a CDN), also trust its ranges:
// e.IPExtractor = echo.ExtractIPFromXFFHeader(echo.TrustIPRange(cdnRange))

v5 uses the direct peer address by default since v5.1.0.

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded to the upstream; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v4.15.4. With StaticConfig.EnablePathUnescaping or Echo#EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.
2 days ago
echo

v5.4.0

Security

This release fixes several security issues. Upgrading is recommended. Some fixes change behavior; read "Behavior changes to check before upgrading" below.

  • Request scheme: Context.Scheme() now uses the X-Forwarded-Proto, X-Forwarded-Protocol, X-Forwarded-Ssl and X-Url-Scheme headers only when the request comes directly from a loopback, link-local or private network address or a unix socket. Before this, any client could send X-Forwarded-Proto: https over plain HTTP and skip HTTPSRedirect. When X-Forwarded-Proto is present, only it is used (its last value), and the scheme is returned in lowercase. Echo#SchemeExtractor (and Config.SchemeExtractor) selects the strategy: ExtractSchemeFromHeaders(...TrustOption) (default), ExtractSchemeDirect() or LegacySchemeExtractor(). The Secure middleware now sets HSTS based on Context.Scheme(). The Proxy middleware always sets X-Forwarded-Proto from Context.Scheme() and removes X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme before forwarding. GHSA-2ffq-g2xg-c22p
  • Proxy middleware: always sets X-Real-IP from Context.RealIP(), so a client can no longer pass a spoofed X-Real-IP to the upstream. GHSA-99jh-6h7p-pp36
  • JSONP: Context.JSONP and Context.JSONPBlob accept only a callback that is empty, a JavaScript identifier or a dot-separated path of identifiers (ASCII letters, digits, _ and $). Any other callback returns a 400 Bad Request error that wraps the new ErrInvalidJSONPCallback, and nothing is written. JSONP responses now carry X-Content-Type-Options: nosniff. JSONP lets any website read the response with the user's cookies, so do not use it for data that needs authentication. GHSA-h9g5-28mm-hx3g
  • MethodOverride: a POST can no longer be overridden to GET, HEAD, OPTIONS, TRACE or CONNECT. Before this, with the MethodFromForm or MethodFromQuery getter and MethodOverride registered with Use before the CSRF middleware, _method=GET skipped the CSRF check. Register MethodOverride with Echo#Pre. GHSA-r7w9-592q-9vg4
  • Redirects: the trailing slash middlewares and the static directory redirect percent-encode control characters in the redirect path. Before this, /%09/evil.example/ redirected browsers to evil.example. GHSA-v753-g4cw-jm48
  • Static files: with the default settings, the Static middleware resolves files from the same form of the path that the router matched, so /admin%2Fsecret.txt or /%61dmin/secret.txt can no longer reach a file under a guarded /admin/* route. GHSA-375p-5qhx-8wq4 The Static middleware and StaticDirectoryHandler (used by Echo.Static, Echo.StaticFS, Group.Static and Group.StaticFS) no longer serve paths with a ., .. or empty segment, such as /assets/../admin/secret.txt, also after path unescaping. GHSA-3pmx-cf9f-34xr

Behavior changes to check before upgrading

  • Proxies or load balancers with public IP addresses. If a proxy connects to your app from a public (or 100.64.0.0/10) address, its X-Forwarded-Proto is now ignored: HTTPSRedirect redirects in a loop and the Secure middleware stops sending HSTS. This affects, for example, Cloudflare, CloudFront and Azure Front Door connecting to a public origin, the GCP external HTTP(S) load balancer including GKE Ingress (35.191.0.0/16, 130.211.0.0/22), and networks that use 100.64.0.0/10 (such as Alibaba Cloud SLB or EKS custom networking). Trust the proxy's address ranges:
    _, gclb1, _ := net.ParseCIDR("35.191.0.0/16")
    _, gclb2, _ := net.ParseCIDR("130.211.0.0/22")
    e.SchemeExtractor = echo.ExtractSchemeFromHeaders(echo.TrustIPRange(gclb1), echo.TrustIPRange(gclb2))
    Proxies on the same host, in a private network (AWS ALB, in-cluster ingress controllers such as ingress-nginx or Traefik, most PaaS routers) or on a unix socket keep working without changes. echo.LegacySchemeExtractor() restores the old behavior but is not safe unless every request passes through a proxy that sets these headers. Serverless adapters or middleware that set RemoteAddr to the client's address also make X-Forwarded-Proto ignored (or, if they take it from a header, spoofable).
  • Trusted proxies must set X-Forwarded-Proto. A proxy on a trusted address that passes the client's X-Forwarded-Proto through (for example nginx without proxy_set_header X-Forwarded-Proto $scheme;) still lets the client choose the scheme. An invalid X-Forwarded-Proto value now results in http instead of falling back to the other scheme headers.
  • Your own tests. httptest.NewRequest sets RemoteAddr to 192.0.2.1:1234, which is not trusted, so tests that set X-Forwarded-Proto now see http. Set req.RemoteAddr = "10.0.0.1:1234" or use e.SchemeExtractor = echo.LegacySchemeExtractor() in such tests.
  • Proxy middleware headers. X-Real-IP sent to the upstream is now always Context.RealIP(). In a chain like nginx → Echo Proxy → upstream, configure Echo#IPExtractor (for example echo.ExtractIPFromRealIPHeader()) to pass the client address on. X-Forwarded-Ssl, X-Forwarded-Protocol and X-Url-Scheme are no longer forwarded; X-Forwarded-Proto carries the scheme.
  • MethodOverride. Overriding a POST to GET (for example with X-HTTP-Method-Override: GET to send a long query in a POST body) is no longer done; such requests keep the POST method.
  • Static files. Paths with a double slash or dot segment (for example /assets//app.js) now return 404; in HTML5 mode the index is still served. The Static middleware no longer finds file names that the client sends with non-default escaping (for example %2C, %40 or lowercase hex like %c3%a9) unless StaticConfig.EnablePathUnescaping is set; Echo.Static has behaved this way since v5.2.1. With StaticConfig.EnablePathUnescaping or Config.EnablePathUnescapingStaticFiles, encoded dots (%2e%2e) no longer traverse directories, but encoded slashes are still decoded, so do not combine these options with route-based access control.
  • JSONP. Context.JSONP returns an error for callbacks that are not JavaScript identifiers.

Documentation

  • IPExtractor docs: corrected the description of the default (the direct peer address has been used since v5.1.0).
  • Static middleware: when registered with Echo#Use it runs before route and group middleware, so route guards do not protect the files it serves.
2 days ago
sarama

Version 1.61.1 (2026-09-27)

What's Changed

🐛 Fixes

📦 Dependency updates

📝 Documentation

➕ Other Changes

Full Changelog: https://github.com/IBM/sarama/compare/v1.61.0...v1.61.1

4 days ago
wails

Wails v3.0.0-beta.26

Wails v3 Beta Release - v3.0.0-beta.26

Added

  • Watcher applies HTTP readiness checks to frontend dev server in PR by @atterpac

Fixed

  • Recover from WebView2 process failures instead of leaving a blank window in PR by @taliesin-ai

🤖 This is an automated nightly release generated from the latest changes on master.

Installation:

go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-beta.26

⚠️ Beta Warning: This is pre-release software. The API is stable, but you may still encounter issues before the final 3.0 release.

6 days ago
lego

v5.5.2

lego is an independent, free, and open-source project, if you value it, consider supporting it! ❤️

Everybody thinks that the others will donate, but in the end, nobody does.

So if you think that lego is worth it, please consider donating.

For key updates, see the changelog.

Changelog

7 days ago
wails

Wails v3.0.0-beta.25

Wails v3 Beta Release - v3.0.0-beta.25

Fixed

  • Stop wails3 dev and its background processes when the primary application exits (#6048)

🤖 This is an automated nightly release generated from the latest changes on master.

Installation:

go install github.com/wailsapp/wails/v3/cmd/wails3@v3.0.0-beta.25

⚠️ Beta Warning: This is pre-release software. The API is stable, but you may still encounter issues before the final 3.0 release.

8 days ago
sarama

Version 1.61.0 (2026-09-22)

What's Changed

🎉 New Features / Improvements

🐛 Fixes

📦 Dependency updates

🔧 Maintenance

📝 Documentation

New Contributors

Full Changelog: https://github.com/IBM/sarama/compare/v1.60.2...v1.61.0

8 days ago
unioffice

v2.14.0

Release notes - UniOffice v2.14.0

This release contains new features, improvements and bug fixes.

New Features

  • US-1698 Image compression API for DOCX: Document.CompressImages(targetDPI, jpegQuality), the equivalent of Word's "Compress Pictures"
  • US-1749 XLOOKUP, XMATCH, SWITCH and TEXTSPLIT for the spreadsheet formula engine
  • US-1750 Statistical functions for the spreadsheet formula engine: the STDEV/VAR family, NORM.DIST, NORM.INV, BINOM.DIST, PERCENTILE, QUARTILE, CORREL, FORECAST and LINEST
  • US-1783 Presentation text formatting and slide property API: italic, underline, strike, caps, character spacing, kerning, superscript/subscript, language, line spacing, margins, indents and tab stops, plus Slide.SetHidden/Hidden, SlideSize.SetType/Type and Presentation.NotesSize/SetNotesSize

Improvements

  • US-1658 XLSX to PDF conversion honoring print areas, including multi-range lists, whole-column and whole-row references
  • US-1665 DOCX to PDF rendering of Word section formatting: multi-column layout, page borders, line numbering and page-number formats
  • US-1761 UniPDF dependency update to v5.1.0
  • US-1699 CI/CD pipeline gating convert render output against committed baselines, with stale-baseline detection and pixel-diff artifacts on failure

Bug Fixes

  • US-1729 Table of contents not generated for content wrapped in a Structured Document Tag (SDT) fix
  • US-1749 INDEX panicking out of bounds when the column argument equals the row width fix
  • US-1658 XLSX to PDF fixes for the page size table (missing Quarto and Envelope 9 codes, swapped Envelope B5 dimensions, incorrect Monarch width), charts duplicating series data from both live and cached values, mis-sized merged cells, and page-break artifacts in row borders and trailing pages

Breaking Changes

  • US-1761 The minimum supported Go version is now 1.25.0, raised by the UniPDF v5.1.0 dependency. Projects building UniOffice with Go 1.24 or earlier need to upgrade their toolchain.