Security And Vendored Dependencies
MuhammaraJS compiles the WebAssembly target from vendored C and C++ source under
packages/native-with-source/src/deps/. Those directories are not installed or
kept current automatically by npm or another package manager. The versions
below describe the source currently in this repository.
Vendor Inventory
| Vendored directory | Upstream baseline | Source and tracking |
|---|---|---|
PDFWriter |
PDF-Writer v4.9.1 | Source and issues |
FreeType |
2.14.3 | Source and issues |
LibAesgm |
Unversioned Brian Gladman AES snapshot (copyright 1998-2013) | Source |
LibJpeg |
IJG JPEG 10 | Source |
LibPng |
1.6.59 | Source and issues |
LibTiff |
4.7.2 | Source and issues |
Zlib |
1.3.1 | Source and issues |
The PDFWriter tag is the vendored tree's upstream baseline. MuhammaraJS carries
changes on top of it, so packages/native-with-source/src/deps/PDFWriter is not
necessarily byte-for-byte identical to that tag. The other version identifiers
come from the vendored source headers; LibAesgm does not declare an upstream
release version.
The WebAssembly build deliberately does not link OpenSSL: browsers have no OpenSSL runtime, and OpenSSL-backed encryption is excluded from this target.
Reporting A Defect
For a suspected defect in the PDF processing engine, first check the PDF-Writer issue tracker and report it upstream when it belongs there. Include a minimal input and expected behavior, and link the upstream report from the corresponding MuhammaraJS issue when the WebAssembly integration or local patches are relevant.
Use the same approach for FreeType, libpng, libtiff, zlib, and the other
vendored libraries: report a library defect to its upstream project where it
can be maintained, and use a MuhammaraJS issue for effects specific to
@muhammara/wasm.
Updating A Vendor
An available newer upstream version is useful information. Open a MuhammaraJS issue requesting a dependency update when it includes a relevant security fix, bug fix, or compatibility improvement. Include the current inventory version, the proposed upstream version or immutable revision, the upstream release or advisory link, and any expected build or behavior impact. Maintainers can then evaluate, test, and review the vendor update independently.