pdfcpu

pdfcpu·pdfcpu.pdfcpu

A PDF processor written in Go.

winget install --id pdfcpu.pdfcpu --exact --source winget

Latest 0.15.0·August 11, 2026

Release Notes

pdfcpu v0.15.0

This release is a focused follow-up to v0.14.0 improving diagnostics and observability for validating large PDF corpora. It also includes PDF processing hardening, CJK text wrapping for watermarks, and clearer signature-validation behavior.

v0.15.0 follows v0.14.0 by only one week because post-release corpus testing made an existing operational gap clear: large wildcard-driven validation runs delayed failure diagnostics until the full input set completed and provided no quiet-mode indication of the file currently being processed.

The changes are targeted and immediately useful to corpus testers, so holding them for a later feature release would unnecessarily delay feedback. The short interval is intentional and does not establish a weekly release routine.

Corpus validation diagnostics

Multi-file CLI validation now reports each failed input as soon as the failure is detected, continues with the remaining inputs, and exits nonzero with a compact summary:

validation failed: 66 of 463 files invalid

The new --progress flag identifies the active input during quiet validation runs. This is useful when a long-running corpus job stalls on a particular file:

pdfcpu validate -q --progress "**/*.pdf"

The quotes are intentional. They pass the recursive pattern to pdfcpu for internal expansion instead of asking the shell to expand thousands of paths into one command line, which may exceed the operating system's argument-size limit.

With -q --progress, progress and validation failures are written to standard error while standard output remains clean:

validating(mode=relaxed) path/to/input.pdf ...
validate path/to/input.pdf: validation error: ...

Corpus testing and issue reports

There is a new Corpus Validation guide documenting quick assessment, progress monitoring, logging, validation modes, result interpretation, and focused issue reporting.

A failed corpus run is diagnostic input, not an issue backlog. Public reports must isolate one manually verified and independently reproduced problem with the smallest shareable PDF. Include the relevant error and final summary, and attach large logs as compressed files instead of pasting them into an issue.

AI-generated, bulk-generated, or mechanically reformatted corpus reports will be closed immediately without investigation. Corpus-wide analysis, failure classification, confidential-file investigation, and scheduled remediation are separate engineering work and may require a paid engagement.

Limited corpus investigation and remediation work may be available by arrangement.

PDF validation and processing hardening

Malformed and inconsistent PDF structures now produce more contextual errors across reading, dereferencing, validation, optimization, fonts, forms, and XObjects. Integer conversion and encryption handling have been tightened, and additional guards reduce the risk of panics while processing damaged input.

This work is backed by expanded malformed-input, error-path, and optimization regression coverage.

CJK watermark text wrapping

Text watermarks now support automatic wrapping for CJK text, including long runs without spaces. Oversized text is wrapped to the configured width instead of forcing unintended font-size reduction. This resolves issue #1427 and includes expanded CJK wrapping and layout coverage.

Digital signatures

Signature validation output is clearer for legacy and unsupported cases. Evidence handling, PKCS#1 and PKCS#7 processing, and related error classification have also been tightened.

Compatibility notes

The pkg/api multi-file validation contract is unchanged: API callers continue to receive joined errors after processing. The CLI now streams individual multi-file validation failures and returns a final summary, so scripts that compare complete stderr strings should be updated to rely on exit status and stable error classification instead.

Existing non-quiet validation already reports the active input. --progress extends that visibility to quiet corpus runs without duplicating normal progress output.

Changelog

  • f2686555086a2e76dc19f602ea1897f6e3baae4d bump version
  • dcc168d28225f7f3266836668483a3cdaced729a update issue reporting guidelines
  • f5f3edf37f9642c4403300db88109521085006f2 harden PDF validation and add progress reporting
  • afc357e23773c32d61b8c18601f77aa8ffcb6dab clarify signature validation output and legacy handling
  • c9c07d0fcd19439f967cfff96203ebe41a1e8327 harden crypto integer conversions
  • 198382701afee53f783aaf425cc240ee26170ae4 upgrade gh workflows
  • 4e5f3aba056aebb721d7334032b378aeba1708b8 harden crypto integer conversions
  • b57300b5f79f9139a7a6534fce7cbc96633ae025 clean up for #1427
  • a2c33719c6aa55593d0316e50247388a3763b5f2 add CJK auto-wrap support for text watermarks (#1427)

Installer type: zip

x865638F02DAF759E2AAE019DDAEEE19907681AB807C6114B1EE916DB0F1466016E
x649809A70EE60BA78252628CC9738B284FBEBF22BC2616AE903FB89B807E75A8A6

Details

Homepage
https://github.com/pdfcpu/pdfcpu
License
Apache-2.0
Publisher
pdfcpu
Support
https://github.com/pdfcpu/pdfcpu/issues

Tags

gogolanggolang-librarypdfpdf-filespdf-libpdf-processorpdflibprocessor

Older versions (1)

0.11.1
x8637EA74CBC25626581930D4156B091EF3B9A6EB6108C49F660D8BF7653693D1F5
x64B728436D173C6278286DF5FEB6EBF39E9FABCA0951CA106C6E8678C7AF14E9A8