Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: py-pdf/pypdf
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: 6.18.0
Choose a base ref
...
head repository: py-pdf/pypdf
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 6.18.1
Choose a head ref
  • 16 commits
  • 27 files changed
  • 9 contributors

Commits on Sep 7, 2026

  1. Configuration menu
    Copy the full SHA
    d8fe3e7 View commit details
    Browse the repository at this point in the history

Commits on Sep 8, 2026

  1. BUG: Use font color for FreeText default appearance (#4051)

    FreeText already stores font_color in /DS, but its /DA entry was generated from border_color. Use font_color for /DA so viewers do not render text with the border color and border_color=None no longer leaves the default appearance empty.
    
    Add regression coverage for different text and border colors as well as annotations without a border.
    
    Refs #2084.
    Refs #2433.
    
    AI assistance: OpenAI ChatGPT (GPT-5.6 Pro) assisted with repository research, implementation, and validation. The final diff was checked against the current code, issue history, and repository contribution policy.
    
    Guard /DA color conversion with font_color while keeping it independent of the border color. Cover 12 text/border color combinations, no-border width, and write/read preservation.
    
    Validation: the exact changed annotation module and selected regression tests passed 13 isolated checks on Python 3.13.5, using installed pypdf 5.9.0 supporting types. The three empty-string cases fail before the guard is restored. git diff --check and Python 3.9 syntax parsing pass. The full repository suite and Ruff were not run locally due to unavailable repository downloads/dependencies; repository CI remains the integration check.
    
    AI assistance: OpenAI ChatGPT (GPT-6 Astra Pro).
    Yuki9814 authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    2316987 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    948c9b5 View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    3f37f47 View commit details
    Browse the repository at this point in the history
  4. ROB: Fix CFF handling with supplements for fonttools < 4.58.0 (#4059)

    Before fonttools/fonttools@1394c64, CFF font files with supplements threw a `NotImplementedError`, thus breaking text extraction. Allow this error as a valid one to not enforce too recent *fonttools* versions.
    stefan6419846 authored Sep 8, 2026
    Configuration menu
    Copy the full SHA
    431f76d View commit details
    Browse the repository at this point in the history

Commits on Sep 9, 2026

  1. TST: Replace FDA download URL (#4063)

    The old URL proved to regularly be unreliable.
    stefan6419846 authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    376d7d4 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    7bb71dd View commit details
    Browse the repository at this point in the history
  3. ROB: Fix compatibility for fonttools < 4.57.0 (#4050)

    ---------
    
    Co-authored-by: Stefan <96178532+stefan6419846@users.noreply.github.com>
    MeggyCal and stefan6419846 authored Sep 9, 2026
    Configuration menu
    Copy the full SHA
    d80ccfc View commit details
    Browse the repository at this point in the history

Commits on Sep 10, 2026

  1. Configuration menu
    Copy the full SHA
    3f7bc19 View commit details
    Browse the repository at this point in the history
  2. BUG: Repeat the letter for /S /A and /S /a page labels past Z (#4065)

    number2uppercase_letter implemented bijective base-26 - the Excel column
    sequence - so the 28th page of a section labelled /S /A came out as "AB".
    The module docstring quotes the numbering the PDF specification defines:
    
        A       Uppercase letters (A to Z for the first 26 pages,
                                   AA to ZZ for the next 26, and so on)
    
    "AA to ZZ for the next 26" is 26 labels, which only holds if the letter is
    repeated: AA, BB, CC, ..., ZZ. Bijective base-26 spends AA..AZ on those 26
    pages and does not reach ZZ until 702.
    
    Emit the same letter repeated instead. The two conventions agree on 1..27,
    so only a letter-numbered section longer than 27 pages changes.
    
    The existing case (28, "ab") in test_number2lowercase_letter pinned the old
    answer and is updated to "bb".
    youdie006 authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    c38feda View commit details
    Browse the repository at this point in the history
  3. Configuration menu
    Copy the full SHA
    808a318 View commit details
    Browse the repository at this point in the history
  4. BUG: Use current text matrix for visitor_text (#4062)

    Closes #2932.
    
    ---------
    
    Co-authored-by: r-kamei <r-kamei@sixsquare.co.jp>
    r-kamei and ssjkamei authored Sep 10, 2026
    Configuration menu
    Copy the full SHA
    735d284 View commit details
    Browse the repository at this point in the history

Commits on Sep 11, 2026

  1. SEC: Limit allowed length of tokens in parse_bfchar (#4071)

    Additionally, we introduce further length validation checks while we are
    at it to better deal with malformed inputs.
    stefan6419846 authored Sep 11, 2026
    Configuration menu
    Copy the full SHA
    319d0b8 View commit details
    Browse the repository at this point in the history
  2. Configuration menu
    Copy the full SHA
    0fb26eb View commit details
    Browse the repository at this point in the history
  3. SEC: Further restrict FlateDecode recovery (#4073)

    Previously, we would only count invalid bytes which could not be decoded
    in `/FlateDecode` recovery. This avoids excessive iteration for the
    completely broken data we tested with, as every input byte fails to
    decode here.
    
    For actual padded data, this would still be a performance bottleneck, as
    this is a very inefficient and slow byte-by-byte decoding approach.
    Given a GZIP file for example, which is a zlib/flate data stream
    prefixed by some file header bytes, it was possible to trigger the slow
    path without the recovery limit ever kicking in.
    
    Please note that some persons might see this as a breaking change, for
    example because some software would use GZIP for compression in
    zlib/flate streams (for whatever reason). As this violates the PDF
    specification, a more efficient fallback handling has not been
    implemented for now. If this really is a concern for some use cases,
    either increasing the limit (for the slow variant) or providing a
    corresponding fix (as a fast variant) are still possible.
    stefan6419846 authored Sep 11, 2026
    Configuration menu
    Copy the full SHA
    d9d38cf View commit details
    Browse the repository at this point in the history
  4. REL: 6.18.1

    ## What's new
    
    ### Security (SEC)
    - Further restrict FlateDecode recovery (#4073) by @stefan6419846
    - Limit entry count for TrueType and Type1 font `/Widths` (#4072) by @stefan6419846
    - Limit allowed length of tokens in parse_bfchar (#4071) by @stefan6419846
    
    ### Bug Fixes (BUG)
    - Use current text matrix for visitor_text (#4062) by @r-kamei
    - Repeat the letter for /S /A and /S /a page labels past Z (#4065) by @youdie006
    - Use font color for FreeText default appearance (#4051) by @Yuki9814
    
    ### Robustness (ROB)
    - Fix compatibility with fonttools < 4.58.0 (#4050, #4059) by @MeggyCal and @stefan6419846
    
    ### Documentation (DOC)
    - Use combined matrix in visitor examples (#4066) by @r-kamei
    
    [Full Changelog](6.18.0...6.18.1)
    stefan6419846 committed Sep 11, 2026
    Configuration menu
    Copy the full SHA
    caf8cde View commit details
    Browse the repository at this point in the history
Loading