Skip to content

Security And Vendored Dependencies

MuhammaraJS compiles the WebAssembly target from vendored C and C++ source under packages/native-with-source/src/deps/. Those directories are not installed or kept current automatically by npm or another package manager. The versions below describe the source currently in this repository.

Vendor Inventory

Vendored directory Upstream baseline Source and tracking
PDFWriter PDF-Writer v4.9.1 Source and issues
FreeType 2.14.3 Source and issues
LibAesgm Unversioned Brian Gladman AES snapshot (copyright 1998-2013) Source
LibJpeg IJG JPEG 10 Source
LibPng 1.6.59 Source and issues
LibTiff 4.7.2 Source and issues
Zlib 1.3.1 Source and issues

The PDFWriter tag is the vendored tree's upstream baseline. MuhammaraJS carries changes on top of it, so packages/native-with-source/src/deps/PDFWriter is not necessarily byte-for-byte identical to that tag. The other version identifiers come from the vendored source headers; LibAesgm does not declare an upstream release version.

The WebAssembly build deliberately does not link OpenSSL: browsers have no OpenSSL runtime, and OpenSSL-backed encryption is excluded from this target.

Reporting A Defect

For a suspected defect in the PDF processing engine, first check the PDF-Writer issue tracker and report it upstream when it belongs there. Include a minimal input and expected behavior, and link the upstream report from the corresponding MuhammaraJS issue when the WebAssembly integration or local patches are relevant.

Use the same approach for FreeType, libpng, libtiff, zlib, and the other vendored libraries: report a library defect to its upstream project where it can be maintained, and use a MuhammaraJS issue for effects specific to @muhammara/wasm.

Updating A Vendor

An available newer upstream version is useful information. Open a MuhammaraJS issue requesting a dependency update when it includes a relevant security fix, bug fix, or compatibility improvement. Include the current inventory version, the proposed upstream version or immutable revision, the upstream release or advisory link, and any expected build or behavior impact. Maintainers can then evaluate, test, and review the vendor update independently.