Skip to content

build(deps): bump github.com/pdfcpu/pdfcpu from 0.15.0 to 0.16.0 - #988

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/pdfcpu/pdfcpu-0.16.0
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/github.com/pdfcpu/pdfcpu-0.16.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps github.com/pdfcpu/pdfcpu from 0.15.0 to 0.16.0.

Release notes

Sourced from github.com/pdfcpu/pdfcpu's releases.

v0.16.0

This release updates the Go API and configuration model, improves automation and PDF validation, and includes processing fixes and security hardening.

Changes since v0.16.0-rc.1

  • Protect image buffer allocations against integer overflow and enforce resource limits before decoding each TIFF page.
  • Fix default-configuration handling (#1492): synchronize access to the cached default configuration and return independent clones to callers.

Security advisories

This release includes fixes covered by six security advisories.

Highlights

  • Updated Go API — Explicit contexts for long-running operations, optional progress reporting, and reusable caller-owned configuration.
  • Configuration redesign — Schema-aware loading, explicit initialization and reset, plus read-only and stateless operation.
  • Automation and container preparation — Signal cancellation, safer output replacement, password-file inputs, and verified execution under arbitrary user IDs.
  • Stronger PDF validation — Improved malformed-input handling, graph-traversal safeguards, and compatibility warnings for selected relaxed-validation decisions.
  • Clearer signature validation — Separate reporting of document integrity, certificate trust, revocation, and timestamp evidence.
  • PDF processing fixes — Improved resize orientation, rotated watermarks, form appearances, image handling, and LZW decoding.
  • Smaller Go module — Approximately 94% smaller in the original packaging comparison. Samples and test fixtures remain in Git but are excluded from module downloads.

Requirements and installation

Go applications require Go 1.26 or later and updates to affected API calls. Existing file-backed configurations from v0.15 or earlier require an explicit configuration reset.

go get github.com/pdfcpu/pdfcpu@v0.16.0

Before upgrading

Reset legacy file-backed configuration

Existing v0.15 and older config.yml files do not contain the new configuration schema identifier. pdfcpu preserves the file and reports that a reset is required instead of rewriting it automatically.

If the configuration is not customized, run:

</tr></table> 

... (truncated)

Commits
  • d4effbd bump version
  • bf56803 fix #1492
  • f098cdd prevent integer overflow in image buffer allocations
  • 4d0e9ff fix Windows configuration test portability
  • 3335af5 bump version, update dependencies, clean up
  • 4641614 add evidence-based signature validation reporting
  • 12d153d report selected relaxed validation fallbacks
  • 265f908 enforce xref limits for traditional xref tables
  • 71f0ff7 fix #1485
  • 65a34f5 enforce resources dict
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [github.com/pdfcpu/pdfcpu](https://github.com/pdfcpu/pdfcpu) from 0.15.0 to 0.16.0.
- [Release notes](https://github.com/pdfcpu/pdfcpu/releases)
- [Commits](pdfcpu/pdfcpu@v0.15.0...v0.16.0)

---
updated-dependencies:
- dependency-name: github.com/pdfcpu/pdfcpu
  dependency-version: 0.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies for dependabot :) label Oct 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies for dependabot :)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants