Skip to content

Feat/node 26 support - #2699

Merged
GCHQDeveloper581 merged 4 commits into
gchq:masterfrom
alleria173:feat/node-26-support
Aug 18, 2026
Merged

GCHQDeveloper581 merged 4 commits into
gchq:masterfrom
alleria173:feat/node-26-support

Conversation

@alleria173

Copy link
Copy Markdown
Contributor

Add Node 26 support alongside Node 24

Closes #2397

Summary

Adds Node.js 26 compatibility ahead of it becoming the active LTS release in November 2026, per the phased approach suggested in #2397: Node 24 remains the officially supported version, with Node 26 added to the CI test matrix. A follow-up change can make Node 26 official once it reaches LTS.

Branch: feat/node-26-support (commit a182fe74, based on upstream master @ c56dd233)

Diagnostics performed

The full toolchain was run under Node 26.5.0 (and re-verified under 24.18.0 as a baseline):

Check Node 24 Node 26 (before fix) Node 26 (after fix)
npm ci (incl. postinstall grunt tasks) ✅ ✅ ✅
npm test (2280 operation + 272 Node API tests) ✅ all pass ❌ 4 failures + 1 error ✅ all pass
npm run lint ✅ ✅ ✅
npm run build (webpack prod) ✅ — ✅
npm run node + grunt testnodeconsumer (CJS + ESM) ✅ — ✅
npm run testui not run locally (needs Chrome/xvfb) — covered by CI on both matrix legs

Static analysis of the dependency tree found:

  • No native addons anywhere in the tree (zero binding.gyp), so no NODE_MODULE_VERSION/ABI concerns. Heavy dependencies are WASM-based (argon2-browser, libyara-wasm, libbzip2-wasm, jq-web, tesseract.js).
  • No dependency caps Node below 26 in its engines field.
  • No usage of Node 26 semver-major removals in CyberChef source: _stream_* core modules (only present inside self-contained bundled copies of readable-stream), http.Server.writeHeader(), module.register(). The Temporal global being enabled by default causes no conflicts.
  • The --openssl-legacy-provider flag used by npm test still works on Node 26 (OpenSSL 3.5.x retains the legacy provider). Note: this is a future risk when Node moves to OpenSSL 4.

The one incompatibility found: cbor

All five test failures were in the CBOR Encode operation. Outputs were truncated to the first CBOR byte, e.g. encoding "Text" produced 64 instead of 64 54 65 78 74.

Root cause: Node 26 includes the semver-major change "stream: readable read one buffer at a time" (nodejs/node#60441). cbor@10's synchronous encoder (Encoder._encodeAll) pipes the encoder stream into a NoFilter and performs a single bs.read(), assuming it returns the entire concatenated encoding. On Node 26 that read returns only the first buffered chunk.

Alternatives evaluated:

  1. Upgrade nofilter — nofilter@6 has an incompatible API (NoFilter is not a constructor from cbor's CJS require); cbor@10 pins nofilter@^3.
  2. Switch to Cbor.encodeAsync() — works (collects 'data' events instead of a sync read), but keeps an effectively unmaintained dependency with a latent stream bug.
  3. ✅ Replace cbor with cbor2 — same author's actively maintained successor (cbor2@2.3.0, engines >=20), pure data API with no Node stream dependency, works in browsers and Node identically.

Output equivalence verified byte-for-byte against the old package, including RFC 8949 canonical form:

  • encode(input, {sortKeys: sortCoreDeterministic}) reproduces encodeCanonical's length-first key ordering (b sorts before aa) — the default cbor2 encode does not sort keys, so the explicit sort option is required.
  • Primitives, half-precision floats (1.5 → f9 3e 00), maps, lists, integers, booleans, and null all match.
  • Decode path verified against the same vectors.

Changes

  • package.json / package-lock.json
    • engines: ">=24 <25" → ">=24 <27"
    • Dependency swap: cbor@10.0.12 → cbor2@2.3.0 (pinned exact, matching the previous pin convention)
  • src/core/operations/CBOREncode.mjs — use cbor2's encode with sortCoreDeterministic key sorting
  • src/core/operations/CBORDecode.mjs — use cbor2's decode on the raw Uint8Array (drops the old hex-string round-trip)
  • .github/workflows/master.yml, pull_requests.yml — node-version becomes a matrix [24, 26] with fail-fast: false; artefact upload and GitHub Pages deploy are gated to the Node 24 leg so they run exactly once. releases.yml intentionally unchanged (npm publish stays on the officially supported Node 24 until Phase B).
  • .github/dependabot.yml — removed the now-stale cbor >=10 ignore entry
  • README.md / AGENTS.md — Node.js support notes updated

Testing

  • Regression coverage: the existing CBOR operation tests fail on Node 26 before the fix and pass after it (they also continue to pass on Node 24).
  • Full non-UI suite green on both Node 24.18.0 and 26.5.0.
  • Production build and Node consumer (CJS/ESM) tests green on Node 26.
  • UI tests will run on both matrix legs in CI.

Follow-up (Phase B — when Node 26 reaches LTS, ~Nov 2026)

  • engines → ">=26 <27"; CI node-version: 26 everywhere including releases.yml
  • Dockerfile → node:26-alpine@sha256:... — note dependabot was told to ignore this major version for the Docker node image when PR Bump node from 24-alpine to 26-alpine #2381 was closed, so this must be done manually
  • .devcontainer/devcontainer.json → javascript-node:26-*
  • README/AGENTS.md, browserslist node >= 26, CHANGELOG entry, version bump via npm run minor

AI disclosure
Compatibility and testing done with Github Copilot with Claude Fable.

- Widen engines range to >=24 <27
- Test against Node 24 and 26 in CI (build/deploy artefacts remain on 24)
- Replace unmaintained 'cbor' dependency with 'cbor2': the cbor package's
  synchronous encode relies on a single stream read() returning the whole
  encoding, which breaks on Node 26 where readable streams return one
  buffer at a time
- Remove stale dependabot ignore for the removed cbor package
- Update Node.js support notes in README and AGENTS
@alleria173
alleria173 marked this pull request as ready for review July 28, 2026 14:00

@GCHQDeveloper581 GCHQDeveloper581 left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good!

Thanks for your contribution.

@GCHQDeveloper581
GCHQDeveloper581 merged commit 2fc915b into gchq:master Aug 18, 2026
4 checks passed
@GCHQDeveloper581

Copy link
Copy Markdown
Contributor

(note - any PRs to be merged after this merge will require a merge from master as the workflows required has changed from "main" -> ("main (24)", "main (26)")

gabrielcosi pushed a commit to gabrielcosi/home-ops that referenced this pull request Aug 18, 2026
…) (#439)

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/gchq/cyberchef](https://github.com/gchq/CyberChef) | minor | `11.3.0` → `11.4.0` |

---

### Release Notes

<details>
<summary>gchq/CyberChef (ghcr.io/gchq/cyberchef)</summary>

### [`v11.4.0`](https://github.com/gchq/CyberChef/blob/HEAD/CHANGELOG.md#1140---2026-08-18)

[Compare Source](gchq/CyberChef@v11.3.0...v11.4.0)

This release includes a security fix

- Security: patch XSS in Regular expression module \[[@&#8203;Ne0re0](https://github.com/Ne0re0)]
- chore (deps): bump [@&#8203;codemirror/view](https://github.com/codemirror/view) from 6.43.8 to 6.43.9 in the patch-updates group  | \[[#&#8203;2731](gchq/CyberChef#2731)]
- chore (deps): bump [@&#8203;codemirror/commands](https://github.com/codemirror/commands) from 6.10.4 to 6.11.0 in the minor-updates group  | \[[#&#8203;2732](gchq/CyberChef#2732)]
- Add XPRESS (MS-XCA) decompression operations \[[@&#8203;MP-GOWTHAM](https://github.com/MP-GOWTHAM)] | \[[#&#8203;2722](gchq/CyberChef#2722)]
- Feat/node 26 support \[[@&#8203;alleria173](https://github.com/alleria173)] | \[[#&#8203;2699](gchq/CyberChef#2699)]
- chore(root): update allowlist \[[@&#8203;evenstensberg](https://github.com/evenstensberg)] | \[[#&#8203;2713](gchq/CyberChef#2713)]
- chore (deps): bump the patch-updates group across 1 directory with 7 updates  | \[[#&#8203;2730](gchq/CyberChef#2730)]
- chore (deps): bump the minor-updates group across 1 directory with 9 updates  | \[[#&#8203;2729](gchq/CyberChef#2729)]
- chore (deps): bump docker/login-action from 4.5.2 to 4.6.0 in the actions-dependencies group  | \[[#&#8203;2716](gchq/CyberChef#2716)]
- chore (deps): bump node from `a0b9bf0` to `d32cdf6` in the docker-dependencies group  | \[[#&#8203;2723](gchq/CyberChef#2723)]
- docs(root): improve docs a bit \[[@&#8203;evenstensberg](https://github.com/evenstensberg)] | \[[#&#8203;2718](gchq/CyberChef#2718)]
- fix: use js-yaml for both JSON to YAML and YAML to JSON \[[@&#8203;bartvanandel](https://github.com/bartvanandel)] | \[[#&#8203;2710](gchq/CyberChef#2710)]
- chore (deps): bump the patch-updates group across 1 directory with 6 updates  | \[[#&#8203;2712](gchq/CyberChef#2712)]
- chore (deps): bump the minor-updates group across 1 directory with 3 updates  | \[[#&#8203;2705](gchq/CyberChef#2705)]
- chore (deps): bump the actions-dependencies group with 2 updates  | \[[#&#8203;2703](gchq/CyberChef#2703)]
- fix: replace `shasum` / `sha256sum` / `sed` calls with node built-ins \[[@&#8203;bartvanandel](https://github.com/bartvanandel)] | \[[#&#8203;2019](gchq/CyberChef#2019)]
- chore (deps): bump fast-uri from 3.1.4 to 3.1.5  | \[[#&#8203;2709](gchq/CyberChef#2709)]
- chore (deps): bump ip-address from 10.2.0 to 10.4.0  | \[[#&#8203;2708](gchq/CyberChef#2708)]
- fix: stop Parse QR Code from participating in Magic ([#&#8203;2610](gchq/CyberChef#2610)) \[[@&#8203;Sanjays2402](https://github.com/Sanjays2402)] | \[[#&#8203;2613](gchq/CyberChef#2613)]
- Restrict A1Z26 Magic checks to valid ranges \[[@&#8203;vetrovk](https://github.com/vetrovk)] | \[[#&#8203;2644](gchq/CyberChef#2644)]
- feat: Extend automated ingredient validation to include argSelector ingredients ([#&#8203;2641](gchq/CyberChef#2641)) \[[@&#8203;mansiverma897993](https://github.com/mansiverma897993)] | \[[#&#8203;2643](gchq/CyberChef#2643)]
- Add Modular Exponentiation operation \[[@&#8203;p-leriche](https://github.com/p-leriche)] | \[[#&#8203;2149](gchq/CyberChef#2149)]
- Add npm allowScripts policy for npm v12 \[[@&#8203;zainnadeem786](https://github.com/zainnadeem786)] | \[[#&#8203;2682](gchq/CyberChef#2682)]
- chore (deps): bump assorted vulnerable dependencies \[[@&#8203;GCHQDeveloper581](https://github.com/GCHQDeveloper581)] | \[[#&#8203;2689](gchq/CyberChef#2689)]
- chore (deps): bump shell-quote from 1.8.4 to 1.10.0  | \[[#&#8203;2690](gchq/CyberChef#2690)]
- chore (deps): bump the patch-updates group across 1 directory with 9 updates  | \[[#&#8203;2686](gchq/CyberChef#2686)]
- chore (deps): bump the actions-dependencies group across 1 directory with 2 updates  | \[[#&#8203;2685](gchq/CyberChef#2685)]
- chore (deps): bump nginxinc/nginx-unprivileged from `fd3314e` to `44e3633` in the docker-dependencies group  | \[[#&#8203;2684](gchq/CyberChef#2684)]

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Berlin)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about these updates again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMC4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUvY29udGFpbmVyIiwidHlwZS9taW5vciJdfQ==-->

Reviewed-on: https://git.xcd.dev/gabrielcosi/home-ops/pulls/439
@alleria173
alleria173 deleted the feat/node-26-support branch August 19, 2026 14:15
dgalanberasaluce pushed a commit to dgalanberasaluce/infra-personal that referenced this pull request Sep 6, 2026
This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [ghcr.io/alam00000/bentopdf-simple](https://github.com/alam00000/bentopdf) | patch | `2.8.7` → `2.8.8` |
| [ghcr.io/gchq/cyberchef](https://github.com/gchq/CyberChef) | minor | `11.3.0` → `11.4.0` |
| [jgraph/drawio](https://www.drawio.com) ([source](https://github.com/jgraph/docker-drawio)) | minor | `31.1.8` → `31.4.2` |
| [plantuml/plantuml-server](https://github.com/plantuml/plantuml-server) | patch | `v1.2026.6` → `v1.2026.8` |

---

### Release Notes

<details>
<summary>alam00000/bentopdf (ghcr.io/alam00000/bentopdf-simple)</summary>

### [`v2.8.8`](https://github.com/alam00000/bentopdf/releases/tag/v2.8.8): Text Editing In BentoPDF! and many more - v2.8.8

[Compare Source](alam00000/bentopdf@v2.8.8...v2.8.8)

##### Dad Joke Of the Release

What do you call a bee that can't make up its mind? A maybe 🤣

##### The Biggest Release of BentoPDF yet!

**This is the biggest release of BentoPDF**. BentoPDF can now edit text, image, shapes in BentoPDF and there are two new engines **Kura** and **Hyper Compress**. Detailed Explanation is below.

##### PDF Text Editing

BentoPDF can now edit the actual text inside a PDF.  You can click any paragraph and type. Text reflows live, fonts and styling are preserved, and everything runs entirely in your browser, as always.

- **Edit in place** with live reflow, real font matching, and word wrap that follows the original layout
- **Full styling**: bold, italic, underline, strikethrough, superscript, subscript, font family and size, text colour, outline colour and width, character and line spacing
- **Paragraph control**: left / centre / right / justify alignment, bulleted and numbered lists with indent levels, and left-to-right and right-to-left text
- **Find & replace** across the document, plus **spell-check** with a personal dictionary and per-language switching
- **Images**: add, replace in place, or export a PNG, edit it in any app, and have your saved changes re import automatically
- **Objects**: align, distribute, rotate, flip, duplicate, and reorder front to back. Even commercial software like Apryse and Nutrient do not support this
- **Accessibility**: alt text for tagged PDFs, and reading-order text export
- Undo / redo, document properties, page navigation, zoom presets

This was arguably the hardest feature I had built so far. Given the complex nature of PDFs and the different ways it can be produced, you might encounter certain bugs.

##### Note

Local fonts access is only available on chromium based browsers such as Chrome and Edge. Other browsers have a limitation of not having the font access API.

##### Hyper Compress is the best open source PDF compression engine

[hyper.bentopdf.com](https://hyper.bentopdf.com) · [github.com/alam00000/bentopdf-hyper-compress](https://github.com/alam00000/bentopdf-hyper-compress)

Hyper is a High fidelity, content preserving PDF compressor that preserves PDF conformance.

- **Monotonic**: Hyper never returns a larger file. If compression does not save space, you get the original back untouched. This makes it useful for workflows so you can have a predicctable output.
- **True lossless mode**, with no quality loss
- **Verified output**: transformations that can affect visual fidelity are checked and rolled back when a page cannot be reproduced faithfully. **0.39% corruption rate, the lowest of any engine measured**
- **Benchmarked** against Ghostscript, MuPDF and qpdf across 2,104 real-world PDFs and 27,352 engine runs, with fidelity measured by an independent renderer:

| Tier     | Hyper                  | Ghostscript   | MuPDF         | qpdf         |
| -------- | ---------------------- | ------------- | ------------- | ------------ |
| Lossless | **22.4% @&#8203; SSIM 1.000** | 21.1% @&#8203; 0.997 | 4.7% @&#8203; 1.000  | 6.3% @&#8203; 1.000 |
| 300 dpi  | **52.3% @&#8203; 1.000**      | 19.1% @&#8203; 0.996 | 14.0% @&#8203; 1.000 | n/a          |
| 150 dpi  | **58.2% @&#8203; 0.999**      | 42.4% @&#8203; 0.994 | 19.4% @&#8203; 1.000 | n/a          |
| 72 dpi   | **64.8% @&#8203; 0.996**      | 53.9% @&#8203; 0.990 | 28.0% @&#8203; 0.999 | n/a          |

- Ships as a CLI, Node SDK, C API, self-hosted service, and a WebAssembly build for the browser

##### Kura is a PDF standards and preflight engine

[kura.bentopdf.com](https://kura.bentopdf.com) · [github.com/alam00000/bentopdf-kura](https://github.com/alam00000/bentopdf-kura)

Kura turns everyday PDFs into archival, print and accessible ones, from a single engine.

- **Supports every standard**: all 11 PDF/A levels, PDF/UA-1 and UA-2, PDF/X-1a through X-6, PDF/E-1 and PDF/VT, plus Factur-X, ZUGFeRD, XRechnung and Order-X e-invoices
- **Print preflight built in**: 396 bundled profiles covering hairlines, rich black, image resolution, overprint, transparency, page boxes, fonts and colour, with repairs where a repair exists, and your own profiles in JSON or the XML dialect you already use
- **Validates clean**: 0 red on the veraPDF corpus, Isartor 204/204, BFO 34/34, Ghent Output Suite 5.0 69/69, PDF/UA Reference Suite 10/10, Cal Poly PDF/VT 24/24
- **Proven on real files**: 30,677 real-world PDFs converted, **zero crashes**, zero timeouts, 0.05 s median
- Also Ships as a CLI, C library, npm package, Docker image, and a WebAssembly build that runs entirely in the browser

##### Note

Both Kura and Hyper are not yet integrated into BentoPDF. I need to do some further tests and optimizations after which they will be ready to be integrated. However they are stable and you can try them out

##### 🐛 Bug Fixes

1. Webpage strings fail to render on self-hosted simple version on some browsers [#&#8203;833](alam00000/bentopdf#833)
2. Service Worker not precaching assets [#&#8203;830](alam00000/bentopdf#830)
3. PDF To Tiff OOM bug [#&#8203;829](alam00000/bentopdf#829)
4. Bug In PDF commenting where the cursor moved to EOL [#&#8203;809](alam00000/bentopdf#809)
5. URL redirection issue [#&#8203;796](alam00000/bentopdf#796)
6. WASM Initialization timeout error [#&#8203;324](alam00000/bentopdf#324)

##### New Features & Improvements

1. Author names can now be changed in PDF Editor - [#&#8203;707](alam00000/bentopdf#707)
2. Github API Call is optional - [#&#8203;269](alam00000/bentopdf#269)
3. Korean, CJK, Indic and other Non Latin Texts were not supported in PDF Editor when added as text. this has now been fixed. Also the text is now written into the content stream, its searchable and selectable . - [#&#8203;404](alam00000/bentopdf#404)
4. BentoPDF live website now has removed Simple Analytics. It used to track anonymous visit count only. But as a pledge to complete privacy both BentoPDF live website and self hosted tools have 0 analytics.
5. New Duplex sort tool by [@&#8203;r0ckarong](https://github.com/r0ckarong) - [#&#8203;752](alam00000/bentopdf#752)  ❤️
6. A polyfill fix for pdf.js which caused rendering crashes in older browsers by [@&#8203;mvanhorn](https://github.com/mvanhorn)  - [#&#8203;795](alam00000/bentopdf#795) ❤️
7. Translations and other fixes by [@&#8203;PeterDaveHello](https://github.com/PeterDaveHello) and [@&#8203;Stephan-P](https://github.com/Stephan-P) ❤️

##### What's More

- build(deps): bump dompurify from 3.4.11 to 3.4.12 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;805](alam00000/bentopdf#805)
- build(deps): bump PDF engine and viewer to [`7ffa16f`](alam00000/bentopdf@7ffa16f9c5cd) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;838](alam00000/bentopdf#838)
- Fix broken star history chart in README by [@&#8203;OctoBored](https://github.com/OctoBored) in [#&#8203;835](alam00000/bentopdf#835) ❤️
- Update nl/tools.json by [@&#8203;Stephan-P](https://github.com/Stephan-P) in [#&#8203;824](alam00000/bentopdf#824) ❤️
- build(deps): bump postcss from 8.5.16 to 8.5.26 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;823](alam00000/bentopdf#823)
- build(deps): bump nanoid from 3.3.15 to 3.3.18 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;832](alam00000/bentopdf#832)
- build(deps): bump mermaid from 11.16.0 to 11.16.1 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;821](alam00000/bentopdf#821)
- build(deps-dev): bump brace-expansion from 2.1.2 to 2.1.4 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;822](alam00000/bentopdf#822)
- Correct grammar, wording, branding, and metadata inconsistencies by [@&#8203;PeterDaveHello](https://github.com/PeterDaveHello) in [#&#8203;790](alam00000/bentopdf#790) ❤️
- fix: polyfill Map.prototype.getOrInsertComputed to stop PDF.js render crash by [@&#8203;mvanhorn](https://github.com/mvanhorn) in [#&#8203;795](alam00000/bentopdf#795)
- build(deps): bump PDF engine and viewer to [`b9854c1`](alam00000/bentopdf@b9854c1098fc) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;841](alam00000/bentopdf#841)
- (Feature) Add Duplex sort / collate documents (Fixes [#&#8203;220](alam00000/bentopdf#220)) by [@&#8203;r0ckarong](https://github.com/r0ckarong) in [#&#8203;752](alam00000/bentopdf#752)
- build(deps): bump PDF engine and viewer to [`f486379`](alam00000/bentopdf@f48637921bf4) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;843](alam00000/bentopdf#843)
- build(deps): bump PDF engine and viewer to [`8ff5002`](alam00000/bentopdf@8ff5002c6cd5) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;844](alam00000/bentopdf#844)

##### New Contributors

- [@&#8203;github-actions](https://github.com/github-actions)\[bot] made their first contribution in [#&#8203;838](alam00000/bentopdf#838)
- [@&#8203;OctoBored](https://github.com/OctoBored) made their first contribution in [#&#8203;835](alam00000/bentopdf#835) ❤️
- [@&#8203;mvanhorn](https://github.com/mvanhorn) made their first contribution in [#&#8203;795](alam00000/bentopdf#795) ❤️
- [@&#8203;r0ckarong](https://github.com/r0ckarong) made their first contribution in [#&#8203;752](alam00000/bentopdf#752) ❤️

##### A Note From Dev

Thank you so much for your continued support of BentoPDF. ❤️

Unfortunately, I broke my hand a couple of weeks ago, so this release was originally planned to include several more features, including Measurement, an Acrobat Parity Comparison Tool, Print Production, and Accessibility. I wasn't able to get them ready in time, but once I'm fully recovered, I'll be working on bringing them to BentoPDF as soon as possible.

I really look forward to hearing what you think of this release! If you run into any bugs or issues, please don't hesitate to report them.

Have a wonderful weekend, and thank you again for all your support! ❤️

**Full Changelog**: <alam00000/bentopdf@v2.8.7...v2.8.8>

### [`v2.8.8`](https://github.com/alam00000/bentopdf/releases/tag/v2.8.8): Text Editing In BentoPDF! and many more - v2.8.8

[Compare Source](alam00000/bentopdf@v2.8.7...v2.8.8)

##### Dad Joke Of the Release

What do you call a bee that can't make up its mind? A maybe 🤣

##### The Biggest Release of BentoPDF yet!

**This is the biggest release of BentoPDF**. BentoPDF can now edit text, image, shapes in BentoPDF and there are two new engines **Kura** and **Hyper Compress**. Detailed Explanation is below.

##### PDF Text Editing

BentoPDF can now edit the actual text inside a PDF.  You can click any paragraph and type. Text reflows live, fonts and styling are preserved, and everything runs entirely in your browser, as always.

- **Edit in place** with live reflow, real font matching, and word wrap that follows the original layout
- **Full styling**: bold, italic, underline, strikethrough, superscript, subscript, font family and size, text colour, outline colour and width, character and line spacing
- **Paragraph control**: left / centre / right / justify alignment, bulleted and numbered lists with indent levels, and left-to-right and right-to-left text
- **Find & replace** across the document, plus **spell-check** with a personal dictionary and per-language switching
- **Images**: add, replace in place, or export a PNG, edit it in any app, and have your saved changes re import automatically
- **Objects**: align, distribute, rotate, flip, duplicate, and reorder front to back. Even commercial software like Apryse and Nutrient do not support this
- **Accessibility**: alt text for tagged PDFs, and reading-order text export
- Undo / redo, document properties, page navigation, zoom presets

This was arguably the hardest feature I had built so far. Given the complex nature of PDFs and the different ways it can be produced, you might encounter certain bugs.

##### Note

Local fonts access is only available on chromium based browsers such as Chrome and Edge. Other browsers have a limitation of not having the font access API.

##### Hyper Compress is the best open source PDF compression engine

[hyper.bentopdf.com](https://hyper.bentopdf.com) · [github.com/alam00000/bentopdf-hyper-compress](https://github.com/alam00000/bentopdf-hyper-compress)

Hyper is a High fidelity, content preserving PDF compressor that preserves PDF conformance.

- **Monotonic**: Hyper never returns a larger file. If compression does not save space, you get the original back untouched. This makes it useful for workflows so you can have a predicctable output.
- **True lossless mode**, with no quality loss
- **Verified output**: transformations that can affect visual fidelity are checked and rolled back when a page cannot be reproduced faithfully. **0.39% corruption rate, the lowest of any engine measured**
- **Benchmarked** against Ghostscript, MuPDF and qpdf across 2,104 real-world PDFs and 27,352 engine runs, with fidelity measured by an independent renderer:

| Tier     | Hyper                  | Ghostscript   | MuPDF         | qpdf         |
| -------- | ---------------------- | ------------- | ------------- | ------------ |
| Lossless | **22.4% @&#8203; SSIM 1.000** | 21.1% @&#8203; 0.997 | 4.7% @&#8203; 1.000  | 6.3% @&#8203; 1.000 |
| 300 dpi  | **52.3% @&#8203; 1.000**      | 19.1% @&#8203; 0.996 | 14.0% @&#8203; 1.000 | n/a          |
| 150 dpi  | **58.2% @&#8203; 0.999**      | 42.4% @&#8203; 0.994 | 19.4% @&#8203; 1.000 | n/a          |
| 72 dpi   | **64.8% @&#8203; 0.996**      | 53.9% @&#8203; 0.990 | 28.0% @&#8203; 0.999 | n/a          |

- Ships as a CLI, Node SDK, C API, self-hosted service, and a WebAssembly build for the browser

##### Kura is a PDF standards and preflight engine

[kura.bentopdf.com](https://kura.bentopdf.com) · [github.com/alam00000/bentopdf-kura](https://github.com/alam00000/bentopdf-kura)

Kura turns everyday PDFs into archival, print and accessible ones, from a single engine.

- **Supports every standard**: all 11 PDF/A levels, PDF/UA-1 and UA-2, PDF/X-1a through X-6, PDF/E-1 and PDF/VT, plus Factur-X, ZUGFeRD, XRechnung and Order-X e-invoices
- **Print preflight built in**: 396 bundled profiles covering hairlines, rich black, image resolution, overprint, transparency, page boxes, fonts and colour, with repairs where a repair exists, and your own profiles in JSON or the XML dialect you already use
- **Validates clean**: 0 red on the veraPDF corpus, Isartor 204/204, BFO 34/34, Ghent Output Suite 5.0 69/69, PDF/UA Reference Suite 10/10, Cal Poly PDF/VT 24/24
- **Proven on real files**: 30,677 real-world PDFs converted, **zero crashes**, zero timeouts, 0.05 s median
- Also Ships as a CLI, C library, npm package, Docker image, and a WebAssembly build that runs entirely in the browser

##### Note

Both Kura and Hyper are not yet integrated into BentoPDF. I need to do some further tests and optimizations after which they will be ready to be integrated. However they are stable and you can try them out

##### 🐛 Bug Fixes

1. Webpage strings fail to render on self-hosted simple version on some browsers [#&#8203;833](alam00000/bentopdf#833)
2. Service Worker not precaching assets [#&#8203;830](alam00000/bentopdf#830)
3. PDF To Tiff OOM bug [#&#8203;829](alam00000/bentopdf#829)
4. Bug In PDF commenting where the cursor moved to EOL [#&#8203;809](alam00000/bentopdf#809)
5. URL redirection issue [#&#8203;796](alam00000/bentopdf#796)
6. WASM Initialization timeout error [#&#8203;324](alam00000/bentopdf#324)

##### New Features & Improvements

1. Author names can now be changed in PDF Editor - [#&#8203;707](alam00000/bentopdf#707)
2. Github API Call is optional - [#&#8203;269](alam00000/bentopdf#269)
3. Korean, CJK, Indic and other Non Latin Texts were not supported in PDF Editor when added as text. this has now been fixed. Also the text is now written into the content stream, its searchable and selectable . - [#&#8203;404](alam00000/bentopdf#404)
4. BentoPDF live website now has removed Simple Analytics. It used to track anonymous visit count only. But as a pledge to complete privacy both BentoPDF live website and self hosted tools have 0 analytics.
5. New Duplex sort tool by [@&#8203;r0ckarong](https://github.com/r0ckarong) - [#&#8203;752](alam00000/bentopdf#752)  ❤️
6. A polyfill fix for pdf.js which caused rendering crashes in older browsers by [@&#8203;mvanhorn](https://github.com/mvanhorn)  - [#&#8203;795](alam00000/bentopdf#795) ❤️
7. Translations and other fixes by [@&#8203;PeterDaveHello](https://github.com/PeterDaveHello) and [@&#8203;Stephan-P](https://github.com/Stephan-P) ❤️

##### What's More

- build(deps): bump dompurify from 3.4.11 to 3.4.12 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;805](alam00000/bentopdf#805)
- build(deps): bump PDF engine and viewer to [`7ffa16f`](alam00000/bentopdf@7ffa16f9c5cd) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;838](alam00000/bentopdf#838)
- Fix broken star history chart in README by [@&#8203;OctoBored](https://github.com/OctoBored) in [#&#8203;835](alam00000/bentopdf#835) ❤️
- Update nl/tools.json by [@&#8203;Stephan-P](https://github.com/Stephan-P) in [#&#8203;824](alam00000/bentopdf#824) ❤️
- build(deps): bump postcss from 8.5.16 to 8.5.26 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;823](alam00000/bentopdf#823)
- build(deps): bump nanoid from 3.3.15 to 3.3.18 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;832](alam00000/bentopdf#832)
- build(deps): bump mermaid from 11.16.0 to 11.16.1 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;821](alam00000/bentopdf#821)
- build(deps-dev): bump brace-expansion from 2.1.2 to 2.1.4 by [@&#8203;dependabot](https://github.com/dependabot)\[bot] in [#&#8203;822](alam00000/bentopdf#822)
- Correct grammar, wording, branding, and metadata inconsistencies by [@&#8203;PeterDaveHello](https://github.com/PeterDaveHello) in [#&#8203;790](alam00000/bentopdf#790) ❤️
- fix: polyfill Map.prototype.getOrInsertComputed to stop PDF.js render crash by [@&#8203;mvanhorn](https://github.com/mvanhorn) in [#&#8203;795](alam00000/bentopdf#795)
- build(deps): bump PDF engine and viewer to [`b9854c1`](alam00000/bentopdf@b9854c1098fc) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;841](alam00000/bentopdf#841)
- (Feature) Add Duplex sort / collate documents (Fixes [#&#8203;220](alam00000/bentopdf#220)) by [@&#8203;r0ckarong](https://github.com/r0ckarong) in [#&#8203;752](alam00000/bentopdf#752)
- build(deps): bump PDF engine and viewer to [`f486379`](alam00000/bentopdf@f48637921bf4) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;843](alam00000/bentopdf#843)
- build(deps): bump PDF engine and viewer to [`8ff5002`](alam00000/bentopdf@8ff5002c6cd5) by [@&#8203;github-actions](https://github.com/github-actions)\[bot] in [#&#8203;844](alam00000/bentopdf#844)

##### New Contributors

- [@&#8203;github-actions](https://github.com/github-actions)\[bot] made their first contribution in [#&#8203;838](alam00000/bentopdf#838)
- [@&#8203;OctoBored](https://github.com/OctoBored) made their first contribution in [#&#8203;835](alam00000/bentopdf#835) ❤️
- [@&#8203;mvanhorn](https://github.com/mvanhorn) made their first contribution in [#&#8203;795](alam00000/bentopdf#795) ❤️
- [@&#8203;r0ckarong](https://github.com/r0ckarong) made their first contribution in [#&#8203;752](alam00000/bentopdf#752) ❤️

##### A Note From Dev

Thank you so much for your continued support of BentoPDF. ❤️

Unfortunately, I broke my hand a couple of weeks ago, so this release was originally planned to include several more features, including Measurement, an Acrobat Parity Comparison Tool, Print Production, and Accessibility. I wasn't able to get them ready in time, but once I'm fully recovered, I'll be working on bringing them to BentoPDF as soon as possible.

I really look forward to hearing what you think of this release! If you run into any bugs or issues, please don't hesitate to report them.

Have a wonderful weekend, and thank you again for all your support! ❤️

**Full Changelog**: <alam00000/bentopdf@v2.8.7...v2.8.8>

</details>

<details>
<summary>gchq/CyberChef (ghcr.io/gchq/cyberchef)</summary>

### [`v11.4.0`](https://github.com/gchq/CyberChef/blob/HEAD/CHANGELOG.md#1140---2026-08-18)

[Compare Source](gchq/CyberChef@v11.3.0...v11.4.0)

This release includes a security fix

- Security: patch XSS in Regular expression module \[[@&#8203;Ne0re0](https://github.com/Ne0re0)]
- chore (deps): bump [@&#8203;codemirror/view](https://github.com/codemirror/view) from 6.43.8 to 6.43.9 in the patch-updates group  | \[[#&#8203;2731](gchq/CyberChef#2731)]
- chore (deps): bump [@&#8203;codemirror/commands](https://github.com/codemirror/commands) from 6.10.4 to 6.11.0 in the minor-updates group  | \[[#&#8203;2732](gchq/CyberChef#2732)]
- Add XPRESS (MS-XCA) decompression operations \[[@&#8203;MP-GOWTHAM](https://github.com/MP-GOWTHAM)] | \[[#&#8203;2722](gchq/CyberChef#2722)]
- Feat/node 26 support \[[@&#8203;alleria173](https://github.com/alleria173)] | \[[#&#8203;2699](gchq/CyberChef#2699)]
- chore(root): update allowlist \[[@&#8203;evenstensberg](https://github.com/evenstensberg)] | \[[#&#8203;2713](gchq/CyberChef#2713)]
- chore (deps): bump the patch-updates group across 1 directory with 7 updates  | \[[#&#8203;2730](gchq/CyberChef#2730)]
- chore (deps): bump the minor-updates group across 1 directory with 9 updates  | \[[#&#8203;2729](gchq/CyberChef#2729)]
- chore (deps): bump docker/login-action from 4.5.2 to 4.6.0 in the actions-dependencies group  | \[[#&#8203;2716](gchq/CyberChef#2716)]
- chore (deps): bump node from `a0b9bf0` to `d32cdf6` in the docker-dependencies group  | \[[#&#8203;2723](gchq/CyberChef#2723)]
- docs(root): improve docs a bit \[[@&#8203;evenstensberg](https://github.com/evenstensberg)] | \[[#&#8203;2718](gchq/CyberChef#2718)]
- fix: use js-yaml for both JSON to YAML and YAML to JSON \[[@&#8203;bartvanandel](https://github.com/bartvanandel)] | \[[#&#8203;2710](gchq/CyberChef#2710)]
- chore (deps): bump the patch-updates group across 1 directory with 6 updates  | \[[#&#8203;2712](gchq/CyberChef#2712)]
- chore (deps): bump the minor-updates group across 1 directory with 3 updates  | \[[#&#8203;2705](gchq/CyberChef#2705)]
- chore (deps): bump the actions-dependencies group with 2 updates  | \[[#&#8203;2703](gchq/CyberChef#2703)]
- fix: replace `shasum` / `sha256sum` / `sed` calls with node built-ins \[[@&#8203;bartvanandel](https://github.com/bartvanandel)] | \[[#&#8203;2019](gchq/CyberChef#2019)]
- chore (deps): bump fast-uri from 3.1.4 to 3.1.5  | \[[#&#8203;2709](gchq/CyberChef#2709)]
- chore (deps): bump ip-address from 10.2.0 to 10.4.0  | \[[#&#8203;2708](gchq/CyberChef#2708)]
- fix: stop Parse QR Code from participating in Magic ([#&#8203;2610](gchq/CyberChef#2610)) \[[@&#8203;Sanjays2402](https://github.com/Sanjays2402)] | \[[#&#8203;2613](gchq/CyberChef#2613)]
- Restrict A1Z26 Magic checks to valid ranges \[[@&#8203;vetrovk](https://github.com/vetrovk)] | \[[#&#8203;2644](gchq/CyberChef#2644)]
- feat: Extend automated ingredient validation to include argSelector ingredients ([#&#8203;2641](gchq/CyberChef#2641)) \[[@&#8203;mansiverma897993](https://github.com/mansiverma897993)] | \[[#&#8203;2643](gchq/CyberChef#2643)]
- Add Modular Exponentiation operation \[[@&#8203;p-leriche](https://github.com/p-leriche)] | \[[#&#8203;2149](gchq/CyberChef#2149)]
- Add npm allowScripts policy for npm v12 \[[@&#8203;zainnadeem786](https://github.com/zainnadeem786)] | \[[#&#8203;2682](gchq/CyberChef#2682)]
- chore (deps): bump assorted vulnerable dependencies \[[@&#8203;GCHQDeveloper581](https://github.com/GCHQDeveloper581)] | \[[#&#8203;2689](gchq/CyberChef#2689)]
- chore (deps): bump shell-quote from 1.8.4 to 1.10.0  | \[[#&#8203;2690](gchq/CyberChef#2690)]
- chore (deps): bump the patch-updates group across 1 directory with 9 updates  | \[[#&#8203;2686](gchq/CyberChef#2686)]
- chore (deps): bump the actions-dependencies group across 1 directory with 2 updates  | \[[#&#8203;2685](gchq/CyberChef#2685)]
- chore (deps): bump nginxinc/nginx-unprivileged from `fd3314e` to `44e3633` in the docker-dependencies group  | \[[#&#8203;2684](gchq/CyberChef#2684)]

</details>

<details>
<summary>jgraph/docker-drawio (jgraph/drawio)</summary>

### [`v31.4.2`](jgraph/docker-drawio@v31.4.1...v31.4.2)

[Compare Source](jgraph/docker-drawio@v31.4.1...v31.4.2)

### [`v31.4.1`](jgraph/docker-drawio@v31.3.2...v31.4.1)

[Compare Source](jgraph/docker-drawio@v31.3.2...v31.4.1)

### [`v31.3.2`](jgraph/docker-drawio@v31.3.1...v31.3.2)

[Compare Source](jgraph/docker-drawio@v31.3.1...v31.3.2)

### [`v31.3.1`](jgraph/docker-drawio@v31.1.8...v31.3.1)

[Compare Source](jgraph/docker-drawio@v31.1.8...v31.3.1)

</details>

<details>
<summary>plantuml/plantuml-server (plantuml/plantuml-server)</summary>

### [`v1.2026.8`](plantuml/plantuml-server@v1.2026.6...v1.2026.8)

[Compare Source](plantuml/plantuml-server@v1.2026.6...v1.2026.8)

</details>

---

### Configuration

📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://github.com/renovatebot/renovate/discussions) if that's undesired.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My43My4yIiwidXBkYXRlZEluVmVyIjoiNDMuNzMuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=-->

Reviewed-on: https://forgejo.internal/forgejo_admin/infra-personal/pulls/137
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Feature request: Update to Node 26

2 participants