Format: Keep a Changelog.
[Unreleased]
[1.0.0] - 2026-10-07
Added
-
Archive limits on
read()—docx.read,pptx.readandxlsx.readacceptmaxParts,maxUncompressedandmaxRatioand forward them toopc.read; the defaults are unchanged and0disables a check. Thexlsx.readcell caps stay in the same options object. Committeddist/**bundles regenerated. -
ooxmlShared.wordRootAttrs(nodes)— the root attributes of a WordprocessingML part:wandralways;mc,w15andmc:Ignorable="w15"when aw15:element is present. The story-part parse functions (docxHeaders.parse,docxFootnotes.parseFootnotes/parseEndnotes,docxComments.parse) accept a parsed root. -
read()lists the parts a re-write drops —docx.read,xlsx.readandpptx.readreturnunmodelledParts: the package parts the model does not carry, whichwrite()does not reproduce ([{ partName, contentType }], sorted,[]when nothing is dropped). The record is computed by the newooxmlShared.trackUnmodelledParts(pkg, consume), which runs the read over an access-tracking view ofpkg.parts; the returnedpackagestays the plain object. Committeddist/**bundles regenerated. -
markupCompatibility.processoptionkeepElements— a list of qualified element names kept wherever they appear, even when their prefix is ignorable;mc:AlternateContentandmc:*attributes inside them are still resolved. Absent or not an array, nothing changes. -
Read-limit boundary tests — every
opc.readandxlsx.readlimit has an at-boundary, an over-boundary and a0(disabled) test. -
Typed table cell margins —
docxPropertiestypes<w:tblCellMar>astblPr.cellMargins(six edges:top,start,left,bottom,end,right, each a{ w, type }width; any other child verbatim incellMargins._extras), on tables and table styles alike, so a composer can pad table cells without hand-authoring XML.renderTablePropertieskeeps the schema order: the_extrasthat followtblCellMar(tblLook,tblCaption,tblDescription,tblPrChange) render after it, every other extra before it, so a schema-ordered<w:tblPr>round-trips unchanged.wmlTablePropertieskeeps its shape (it re-parses the core-rendered element). Committeddist/**docx bundles regenerated. -
Typed table properties —
docxPropertiesgainsparseTableProperties/renderTablePropertiesfor<w:tblPr>(style,width,borderswith six edges; everything else verbatim in_extras);docxStructuretypestblPron the table node anddocxStyleson a style (read + write, round-trip), so a composer can border a table without hand-authored XML. A table or style with notblPrrenders byte-identically to before. The opt-inwmlTablePropertiesextension re-derives its own fulltblPrshape from the core-typed bag (read shape and write bytes unchanged; pinned by parity tests). ABordercarries every attribute beyondval/sz/space/color(w:themeColor,w:themeTint,w:shadow,w:frame, ...) verbatim inextraAttrs, so atblBordersround trip is lossless with or without the extension. Committeddist/**docx bundles regenerated. -
Core surface — Open Packaging Conventions (
opcPackage,opcContentTypes,opcRelationships, ECMA-376 part 2) read/write ZIP-based packages with full[Content_Types].xml+.relsresolution. WordprocessingML (ECMA-376 §17) —docxorchestrator + part-level modules (properties,structure,styles,numbering,settings,comments,footnotes,headers,drawing,customXml,docx-walker,docx-text) covering paragraphs, runs, tables, sections, hyperlinks, bookmarks, ins/del, footnote/endnote/comment refs, header/footer parts, inline images, DrawingML shapes, custom XML data binding, OMML math. SpreadsheetML (ECMA-376 §18) —xlsxorchestrator + part-level modules (styles,tables,conditionalFormatting,comments,threadedComments,drawings,xlsx-walker) covering rows/cells, formulas, merges, columns, sheet views, auto-filter, hyperlinks, data validations, tables, conditional formatting + dxfs, comments (classic + threaded 2018+), drawings with charts and anchored images. PresentationML (ECMA-376 §19) —pptxorchestrator + part-level modules (theme,slide,picture,table,chart,pptx-walker) covering slides/layouts/masters, typed placeholders, text bodies, theme, inline pictures, tables, charts. DrawingML (ECMA-376 §20) —drawingml,drawingmlChart,drawingmlShape, the shared graphics surface used by all three formats. Office Math (ECMA-376 §22.1) —ooxmlMath(OMML parser/renderer). Markup Compatibility (ECMA-376 part 3) —markupCompatibilitystrips/preservesmc:AlternateContentblocks for Office 2010+ compatibility. XML parsing/serialization is delegated to@awacloud/fw/io/codec/xml.js(modulexml) — the package ships no local XML parser (see Changed). -
Typed errors — the
ooxmlErrorsfactory exposesOoxmlError,ParseError,RenderError,ContractError; everythrowin the package uses these classes with a stable, namespacedcodeand a structuredcontext. Consume viaruntime.resolve('ooxmlErrors')orooxmlErrors.factory(). -
Shared helper factory
ooxmlShared— canonical namespace map (NS.{W,A,R,SS,P,C,M,MC,WP,PIC,XDR,DS,TC,ACTIVEX}), relationship types (REL_TYPE.{DOC,HYPERLINK,IMAGE,STYLES,NUMBERING,SETTINGS,COMMENTS, FOOTNOTES,ENDNOTES,HEADER,FOOTER,CUSTOM_XML,CUSTOM_XML_PROPS,CHART, PACKAGE,DRAWING,TABLE,SHEET,SHARED_STRINGS,VML_DRAWING, THREADED_COMMENT,PERSON,SLIDE,SLIDE_LAYOUT,SLIDE_MASTER,THEME}), content types (CT.{DOCUMENT,STYLES_W,STYLES_X,NUMBERING,SETTINGS, COMMENTS_W,COMMENTS_X,FOOTNOTES,ENDNOTES,HEADER,FOOTER,WORKBOOK,SHEET, SHARED_STRINGS,DRAWING,TABLE,CHART,EMBEDDED_XLSX,PRESENTATION,SLIDE, SLIDE_LAYOUT,SLIDE_MASTER,THEME,VML_DRAWING,CUSTOM_XML_PROPS}), EMU conversion (EMU_PER_INCH,EMU_PER_CM,EMU_PER_PT,EMU_PER_PX_96,toEmu,inchesToEmu,cmToEmu,ptToEmu), boolean-attribute helpers (readBoolAttr/writeBoolAttr),partExt,lookupCT, a singleton-backed UTF-8 codec (encodeText/decodeText), and a stateful relationship-id allocatorcreateRidAllocator({ prefix, start, existing })(next/peek/reset/usedIds/claim/register, independent per-instance closure state — no shared global state). Color codec builders:createDmlColorCodec(xml)(DrawingML color parse/render with an opt-inwithModsflag reconciling thedml-effectstransforms-preserving semantics and thedml-fills-advancedflat-reference semantics; also backsdrawingml'ssrgbClrbuilder) andcreateXlsxColorCodec(xml)(union semantics overrgb/theme/tint/indexed/auto, emittingautoonly when truthy; consumed byxlsx/stylesandxlsx/conditionalFormatting).ModuleRuntimeconsumers getooxmlSharedinjected automatically wherever declared as a dependency. -
Coverage extras (opt-in, 36 modules under
src/extra/) reach 100% of the ECMA-376 strict surface with no load cost for the core: WordprocessingML (8 phase + misc —wml-run-formatting,wml-paragraph-formatting,wml-table-properties,wml-numbering-details,wml-settings,wml-fields,wml-tracked-changes,wml-vml-legacy,wml-misc), SpreadsheetML (5 phase + misc —sml-pivot-tables,sml-calculation,sml-sheet-config,sml-workbook-config,sml-form-controls,sml-misc), PresentationML (4 phase + misc —pml-animations,pml-transitions,pml-notes,pml-layouts-typed,pml-misc), DrawingML chart (5 phase + misc —dml-chart-data-labels,dml-chart-trendlines,dml-chart-axes-advanced,dml-chart-3d,dml-chart-other-types,dml-chart-misc), DrawingML main (3 phase + misc —dml-effects,dml-fills-advanced,dml-shapes-advanced,dml-main-misc), DrawingML positioning (dml-wp-positioning,dml-xdr-advanced), Math (math-advanced,math-misc), legacy/transitional (transitional— ECMA-376 part 4,legacy-vml— standalone VML). Each declares its own dependencies and is worker-safe (factory.toString()rehydration). -
Bundles —
docx-large/docx-full,xlsx-large/xlsx-full,pptx-large/pptx-full: pure fw module descriptors ({ name, dependencies, factory }) combining the core orchestrator with its P0/P1 extras (*-large, ~95% real-world usage) or the full P0–P2+misc+transitional+legacy-VML set (*-full, 100% strict coverage). Consumed exclusively viaModuleRuntime.register(...)+resolve('docxLargeBundle')etc.; all six descriptors are re-exported frommain.js. -
Extension hook
.use(...)ondocx/xlsx/pptx— afterread(), the walker offers each visitedrPr/pPr/tcPr/table/row/settings/workbook/sheetnode to extensions implementing the matchinghydrate*hook; beforewrite(), the symmetricaldehydrate*hook runs. Idempotent registration (.use()ignores an already-registered instance);docxWalkerpre-indexes hooks by name for O(N_hits) dispatch. -
Pre-built single-factory bundles — two-surface
dist/.tools/generate-bundles.mjs(bun run gen:bundles, a thin wrapper around@awacloud/tool-prebuild-generator) emits, per assembly root (9:docx/docx-large/docx-fulland the same forxlsx,pptx), two path-discriminated surfaces side by side underdist/:dist/standalone/<root>.{js,min.js,meta.json}(dependencies: [], every fw + ooxml-local factory inlined, zero runtime registration) anddist/build/<root>.{js,min.js,meta.json}(declares the 7 fw modules —xml,bitstream,huffman,lz77,deflate,zip,crc32— as dependencies, inlines only the ooxml-local factories, smallest payload). Each.jshas a minified.min.jstwin and a.meta.jsonsidecar (fwDependencies, sourcemodules, byte sizes);dist/build/ index.jsis a barrel re-exporting the whole@awacloud/ooxmlnamespace for bulk registration on an@awacloud/fwruntime. Both surfaces expose a single factory call returning the same enriched core orchestrator as the legacy declarative bundles, under the resolve keys<root>Bundled(standalone) /<root>Package(build) — e.g.docxLargeBundled/docxLargePackage.package.jsonexposes./build/*and./standalone/*. Documented indocs/api/bundles/prebuilt/README.md. Output is deterministic (see Changed — Dist). -
Documentation —
docs/README.mdtop-level index;docs/api/one page per source module (core,extra/opt-in,bundles/), following thedoc-format.mdconvention (YAML frontmatter — module/category/ dependencies/returns/worker-safe/status — metadata line, API table, examples, Notes, See also);docs/guide/user guides —getting-started,read-write-docx,read-write-xlsx,read-write-pptx,extending,performance(Web Worker integration recipe and resource-bound options),coverage,opc-overview;docs/api/errors.md— full catalog of error codes by namespace. -
Tests + integration — unit tests co-located per module; roundtrip integration test wiring all three formats through fw's
ModuleRuntime(tests/roundtrip.integration.test.js); fuzz/malformed-input test asserting a typed error on garbage/empty/corrupt input, including XXE and billion-laughs (tests/fuzz.test.js);tests/package-exports.test.jsverifying everypackage.json#exportssub-path resolves with at least one named export; a seeded random-attribute roundtrip pass over eachextra/misccatalog (src/extra/misc.test.js); shared test helpers (tests/_helpers/build.js—buildXml,buildDocxProps,buildOpc,buildDocxStack). -
Architecture — strict ECMA-376 coverage by default, transitional variants surfaced via the dedicated
extra/transitionalmapper; layered architecture (stable core delegates parsing depth to per-element extras opted in by the consumer, unknown elements kept in_extrasarrays for roundtrip fidelity); factory pattern ({ name, dependencies, factory }) compatible with@awacloud/fwModuleRuntimeDI; worker-safe (every factory is a self-contained closure, no closure on mutable module-level state — see Changed); browser-only (Uint8Array,TextEncoder,TextDecoderonly); zero external dependency beyond@awacloud/fw(workspace). -
Package surface —
package.jsonexposes:. src/main.js all modules + modules[] ./docx src/docx/docx.js core WordprocessingML ./docx-large src/bundles/docx-large.js ./docx-full src/bundles/docx-full.js ./xlsx src/xlsx/xlsx.js core SpreadsheetML ./xlsx-large src/bundles/xlsx-large.js ./xlsx-full src/bundles/xlsx-full.js ./pptx src/pptx/pptx.js core PresentationML ./pptx-large src/bundles/pptx-large.js ./pptx-full src/bundles/pptx-full.js ./opc src/opc/package.js ./drawingml src/drawingml/drawingml.js ./errors src/errors.js ./extra/* src/extra/*.js 36 opt-in modules ./bundles/* src/bundles/*.js 6 compositions ./build/* dist/build/* two-surface prebuilt (fw-DI variant) ./standalone/* dist/standalone/* two-surface prebuilt (framework-free)awa.maturity: "L4"(the initial core surface shipped at L2, then progressed L2 → L3 → L4 with the legal-metadata hygiene).
Changed
- API reference and source comments describe each opt-in module by what it
covers — internal milestone labels are removed from the
extra/pages and module comments, and thedocx/structuresource documentation now lists the hyperlink model'stargetandexternalfields. docx.writerejects a hyperlinkrIdit cannot resolve (breaking, pre-1.0) — it throwsContractErrordocx/hyperlink-unresolved-rid(context.rId,context.story) for a hyperlink whoserIdhas no relationship in its part, including a body node whoserIdis not a key of a suppliedopts.hyperlinks(that option still replaces the derived map). Thedocx/hyperlink-missing-ridcheck now also covers footnotes, endnotes and comments.docx.writefails explicitly instead of losing content (breaking, pre-1.0) — it throwsContractErrordocx/hyperlink-missing-ridfor a hyperlink with a target and norId, anddocx/numbering-missingfor list references (pPr.numPr) written withoutopts.numbering, instead of silently writing a lost target or dangling list references. Both checks run before any part is rendered and leave the input model untouched.opc.writeoutput is byte-reproducible — every entry is stamped 1980-01-01 00:00 by default (overridable withopts.mtime, aDateor a number), so.docx/.xlsx/.pptxoutput is byte-reproducible.- Generated ids need Web Crypto (security) — generated custom-XML store
ids and threaded-comment ids use
crypto.getRandomValuesonly; without it they throwdocx/no-random-source/xlsx/no-random-sourceinstead of falling back toMath.random. Pass the ids explicitly where Web Crypto is unavailable. - Coverage claims qualified — the coverage pages define "full" as every schema element typed or preserved as a passthrough (not a conformance measurement), no longer print unreproducible benchmark figures, and state the extras naming rule.
- Round-trip claims — the README, guides and API pages say what is preserved (elements inside the parts the model carries) and what is not (whole parts outside the model); the three read result shapes are documented.
- Source comments — translated to English; references to an internal audit page removed.
- Dist — dist regenerated with the licence banner: every committed
dist/**/*.js/.min.jsopens with the package's/*! … */legal block, each*.meta.jsonbytesentry is measured on the final bytes, and thebuiltAttimestamp is gone —bun run gen:bundlesis byte-deterministic. - Package contents — the npm tarball now ships
NOTICE(dual licence + third-party attributions) next toLICENSE. - Worker-safe factories — every ooxml factory is a self-contained
closure: nothing the factory body references is declared at module
scope. Module-level constants relocated into the owning factory body
(
DEFAULT_LIMITS/LEADING_SLASH_REinopc/package.js,HOOK_NAMESindocx/docx-walker.js,VML_ATTRS/VML_TAGSinextra/legacy-vml.js,NS_MAP/TRANSITIONAL_ELEMENTSinextra/transitional.js); the error classes (ParseError/RenderError/ContractError) are no longer imported from../errors.js: every factory that throws typed errors receives theooxmlErrorsinstance as its first dependency.factory.toString()produces JS that rehydrates inside a Web Worker without resolving any external module symbol. xml— the package's local XML parser (and its tests) is retired; every module now consumesxmlfrom@awacloud/fw/io/codec/xml.js(module namexml). Breaking for any external import of the formerooxmlXmlexport — acceptable pre-publication. Everydocs/reference toooxmlXml(dependency names, runtime resolves, imports) realigned to the canonicalxmlmodule name.- Namespaces, relationship types, content-types, EMU and
boolean-attribute helpers consolidated into
ooxmlShared(see Added) — ~250 LOC removed from consumers. The following factories gained'ooxmlShared'as an additional dependency and receive the shared instance as their last constructor argument (breaking for directfactory(...)callers; transparent forModuleRuntime.resolve(...)consumers, which inject it automatically):docx,docxStyles,docxNumbering,docxSettings,docxComments,docxFootnotes,docxHeaders,docxCustomXml,docxDrawing,xlsx,xlsxStyles,xlsxTables,xlsxComments,xlsxThreadedComments,xlsxDrawings,xlsxConditionalFormatting,pptx,pptxSlide,pptxTheme,pptxPicture,pptxTable,pptxChart,drawingml,drawingmlChart,drawingmlShape.opcPackagegained'ooxmlShared'as its 5th dependency (factory(errors, zip, contentTypes, rels, shared), up from 4 args).dmlEffects/dmlFillsAdvancedgained'ooxmlShared'as a second dependency (factory(xml, shared)). - UTF-8 codec and rId allocation consolidated in
ooxmlShared— theTextEncoder/TextDecoderpair instantiated locally in 22 worker-safe factories (opc/package;docx/{docx, comments, customXml, footnotes, headers, numbering, settings, styles};xlsx/{xlsx, styles, tables, comments, threadedComments, drawings};pptx/{pptx, slide, theme};drawingml/chart) is replaced byshared.encodeText/decodeText(bit-identical to the native Web APIs). The bespoke rId counter/collision-loop reimplemented at 5 sites is replaced byshared.createRidAllocator(...):docx.jsdocument rels (claimRid), image rels (collectImages.nextRId, prefixrImg), chart rels (collectCharts.nextRId, prefixrChart);xlsx.jshyperlink rIds (prefixrIdH);pptx.jspicture/chart/ layout rIds (see Fixed for the collision bug this last site's consolidation also closed). Every site's allocation sequence is byte-for-byte identical to the pre-refactor loop it replaced (createRidAllocatoryieldsprefix+start, prefix+(start+1), …skipping registered ids, matching the historicalwhile (… some(r => r.Id === id)) n++contracts) — exceptpptx.js, whose sequence changed as a side effect of fixing the collision bug (see Fixed). lookupCT(pkg, partName)consolidated intoooxmlShared(override > extension-default lookup,nullon no match);docx.js/pptx.jsconsume it instead of a duplicated local helper.opc/contentTypes.lookup(types, partName)keeps its complementary signature (flattypesobject rather than apkg).- Errors — granular namespaced kebab-case codes (
docx/missing-body,opc/zip-bomb,xlsx/limit-exceeded, etc.) replace the placeholder strings'ooxml/parse-error'/'ooxml/render-error'/'ooxml/contract-error'(catalog indocs/api/errors.md); every typed error carries a structuredcontext(partName,elementName,limit,cause, …); XML-parse/zip failures are re-thrown as typed errors withcausepreserved (e.g.docx/invalid-xml,opc/invalid-zip);docx.write/xlsx.write/pptx.writereject non-object models / wrong-typedbody/sheets/slideswithContractErrorinstead of a rawTypeError. - Internals —
docx.walkAllDrawingsnow descends intonode.txbxContentandnode.altContentso images nested in DrawingML textboxes / MC fallback are no longer dropped on write; the@typedef Drawingformalises the shape exchanged between thedocx/xlsx/pptxorchestrators anddrawingml*; text-extraction helpers (toText,textOfParagraph,textOfRun,textOfTable) extracted todocx/docx-text.js(factorydocxText, now adocxdependency) to shrink the orchestrator — public API unchanged; module-scopedRegExphoisted inopc/package.jshot paths. - Packaging —
awa.maturityprogressedL2→L3→L4;package.jsongaineddescription,keywords,engines,sideEffects: false, and the./errorssub-path export; the legal metadata (license,author,copyright,repository,bugs,homepage) is set andLICENSEcarries the AGPL-3.0-only text.
Removed
- The development playground (
playground/), never part of the published package. - The legacy
prebuilt/descriptors (the 18 single-surface generated descriptors that lived under the bundles source directory) and thetools/generate-prebuilds.mjsgenerator (bun run gen:prebuilds) — retired in favour of the two-surfacedist/build/+dist/standalone/convention (see Added). Exported factory names and resolve keys are unchanged; only the on-disk location and generator moved (tools/generate-bundles.mjs/bun run gen:bundles). - Imperative bundle builders
buildDocxLarge,buildDocxFull,buildXlsxLarge,buildXlsxFull,buildPptxLarge,buildPptxFull— bundles are now minimal fw descriptors consumed exclusively viaModuleRuntime.register(...)/resolve(...)(see Added — Bundles). - Named re-exports of extras from bundle entry points (e.g.
docxLarge.wmlRunFormatting,xlsxLarge.smlPivotTables) — import extras from@awacloud/ooxml(root) or@awacloud/ooxml/extra/*directly. - Top-level error class exports (
OoxmlError,ParseError,RenderError,ContractError) from@awacloud/ooxml/@awacloud/ooxml/errors— migrate toruntime.resolve('ooxmlErrors')orooxmlErrors.factory(). - Duplicated inline literal
…/relationships/imageinxlsx/xlsx.js(replaced byREL_TYPE.IMAGE) and a redundant localfindChildinextra/wml-numbering-details.js(replaced byxml.findChild).
Fixed
-
Story parts are namespace-well-formed — header, footer, footnotes, endnotes and comments parts are read through markup compatibility (as
word/document.xmlalready was) and written with the namespace declarations they use (w15andmc:Ignorablewhen needed;w:commentsnow declaresr), so a re-written story part declares every prefix it uses. Committeddist/**bundles regenerated. -
Hyperlinks are kept by
write(read(x).document, …)—read()copies a resolvable hyperlink'starget/externalonto the node, andwrite()emits the hyperlink relationships of headers, footers, footnotes, endnotes and comments in each part's own relationship table, so every resolvable link is kept by a re-write. -
word/settings.xmldeclares the prefixes it uses — settings re-written from a Word document declare every prefix the tree uses (m,o,v,w14,w15, …), withmc:Ignorablelisting the Office extension ones; a prefix with no known namespace throwsRenderErrordocx/settings-unknown-prefix(context.prefix). -
Documentation states measured facts — the transitional page and the
docx-fullbundle page no longer claim that the core reads Strict names or that the bundle rewrites namespaces; the docx guide's read-result sketch gives the real image and hyperlink entry shapes; the pptx and xlsx bundle pages give the full read envelope (unmodelledPartsincluded); round-trip claims say "re-emitted on write", name the whole-part caveat and make no percentage claim. -
xlsx.readcell cap fires (security) —maxCellsPerSheetcounted nothing. The row and cell caps are now checked on a pre-scan of each sheet before it is parsed and again while rows are mapped, and they bound the empty cells inserted for column gaps, so a far column reference cannot materialise an unbounded row. -
Repeating-section content controls are read from and written in the Word 2012 (
w15) namespace, with their title anddoNotAllowInsertDeleteSection; the legacyw:form is still read. Thew15declarations are added to the document root only when the body holds such an element. Built from the specification, and verified by a read / write / re-read round trip of a document saved by Microsoft Word 16.0 (a published third-party test file, MIT-licensed, vendored undertests/_fixtures/). -
docx.writedocuments itsimagesandcustomXmloptions. -
docxNumbering.bulletList()bullet glyph — the bullet level no longer forcesrPr: { font: 'Symbol' }:Symbolis a symbol-encoded font with no glyph at U+2022, so Word drew a hollow box.lvlTextstays•(U+2022) and renders with the paragraph font in Word and LibreOffice. The numbering model is unchanged (parse/serializestill round-trip a caller-suppliedrPr.font). Committeddist/**docx bundles regenerated. -
Documentation links resolve from the npm tarball. Links that pointed outside the package, or at files the tarball does not ship, now point at the public repository at this release's tag, so they resolve from the tarball; references to sources that are not published are plain-text citations, and a See also entry naming a page that exists nowhere is removed.
-
pptx rId allocator — historic uniqueness bug. Before the rId-allocator consolidation (see Changed),
pptx.js's picture path (shape.embedRef || 'rId' + nextRid++) never registered a preferred rId (shape.image.rId/shape.embedRef) with the counter, sonextRid++could re-emit an rId already used by an earlier relationship — producing a.relspart with two entries sharing the sameId(corrupt per OPC, silently tolerated by PowerPoint and undetected by the pre-existing roundtrip tests).createRidAllocator .claim(preferred)now registers every preferred id, closing the collision class; the no-opwhile (slideRels.some(...)) {}loop and the localparseRidNum/ensureUniquehelpers (15 LOC) were removed as dead code. The rId sequence emitted for pptx files whose pictures carry a preferred id may differ from previous versions — the new sequence is guaranteed collision-free; the public API (pptx.read/pptx.write) and roundtrip semantics (a free preferred rId is preserved) are unchanged. 3 regression tests added.
Security
opc.read(bytes, opts?)enforces three default bounds to prevent ZIP-bomb DoS:maxParts(1024),maxUncompressed(256 MiB),maxRatio(200). A breach raisesParseError('opc/zip-bomb', ...)withcontext.limitset; pass0per option to disable a given check.xlsx.read(bytes, opts?)boundsmaxSheets(64),maxRowsPerSheet(200k),maxCellsPerSheet(5M). A breach raisesParseError('xlsx/limit-exceeded', ...).- No DTD / no external entity policy is documented and pinned by
regression tests in
tests/fuzz.test.js(XXE + billion-laughs).
Documentation
- Documentation pass. The README now follows the published-package
layout (installation, quick start, package-specific sections, a sub-path
table with one row per
exportskey, maturity, licence and project links) and every quick-start snippet was executed. Registration snippets across the README and the guides now registerfw_require(the@awacloud/fwmodules the package consumes) beforemodules; without itresolvefails withModule not found. The guides open with a purpose and prerequisites, the coverage guide states what the*-miscpassthroughs do and do not model, and the hook tables of the extending guide match what the xlsx and pptx walkers pass to a hook. Four reference pages were added for modules that had none (docxWalker,docxText,xlsxWalker,pptxWalker), the French@fileoverviewprose of the three orchestrators is now English, and the package-local working notes (a TODO list and three audit pages) no longer live in the package or its tarball.