This release fixes the CSP errors introduced in v2.8.3 Fixes: #671 #670
Full changelog
This release fixes the CSP errors introduced in v2.8.3
Fixes: #671 #670
Full Changelog: https://github.com/alam00000/bentopdf/compare/v2.8.3...v2.8.4
A privacy‑first, client‑side PDF toolkit that lets you manipulate, edit, merge and process PDFs entirely in the browser with no server‑side processing.
This release fixes the CSP errors introduced in v2.8.3 Fixes: #671 #670
This release fixes the CSP errors introduced in v2.8.3
Fixes: #671 #670
Full Changelog: https://github.com/alam00000/bentopdf/compare/v2.8.3...v2.8.4
[!WARNING]
This release addresses the security vulnerabilityGHSA-6vh8-4frx-647fwhich affects all versions including and prior to v2.8.2.
All users of BentoPDF are recommended to upgrade immediately to the latest version 2.8.3
A huge thank you to @Astaruf for discovering this vulnerability and reporting it to us through responsible disclosure. Independent security researchers like Lorenzo are what keep open source software trustworthy, and we are genuinely grateful for the care and professionalism shown throughout the process. This is exactly how coordinated vulnerability disclosure should work, and BentoPDF is safer today because of it. Thank you. ❤️
BentoPDF is maintained by a single developer. While every effort is made to ensure the codebase is reviewed, scanned, and hardened before each release, the reality of a solo-maintained project is that comprehensive security coverage is not achievable without external input. The surface area of a modern document-processing tool is substantial, and no individual reviewer can reasonably cover all of it alone.
This disclosure has been a humbling reminder that no codebase is perfect, and that security is a process and not a milestone. Going forward, BentoPDF will be putting more active investment into security hardening: stricter reviews for anything touching untrusted input, expanded automated scanning in CI, and faster turnaround on reports.
If you find something that looks off like a bug, a misconfiguration, an edge case that feels risky then please tell us. Report privately through GitHub Security Advisories or email [email protected]. You do not need a working exploit, proof of impact, or a perfectly written report. A description and a hint is enough, and we will take it from there. Every report genuinely helps, and every reporter gets credited.
Thank you for using BentoPDF, and thank you for helping us make it safer.
Full Changelog: https://github.com/alam00000/bentopdf/compare/v2.8.2...v2.8.3
Fixed Docker container startup failure due to permission issues preventing proper operation.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Beta — feedback welcome: [email protected]