PDFFence 1.18 adds rule to flag stale PDF signature byte-range coverage
PDFFence 1.18.0, a PDF static-analysis tool, introduces an opt-in rule called PFP010 that flags cases where a PDF's signature byte-range coverage does not extend to the current end of file. The update complements the existing PFP009 rule, which detects regressions in signature coverage across document revisions. A new benchmark scenario demonstrates a case where a baseline PDF already has a stale byte-range boundary, and an appended revision leaves aggregate coverage counts at zero, making PFP010 the sole triggered policy. The release passed 235 tests and scored all 155 benchmark pairs, with both packages building reproducibly under Python 3.12 and 3.13. PDFFence explicitly does not validate cryptographic signatures, certificates, or trust chains, and only reports fixed aggregate counts and static findings.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in