Skip to content

Releases: ClassicMiniDIY/WireViz

v1.1.0 — upstream issue fixes: include, twisted pairs, shorts, sheet PDF

Choose a tag to compare

@SomethingNew71 SomethingNew71 released this 03 Oct 17:10
1ea1a6f

Fixes for open issues in the original wireviz/WireViz repository. Triage: docs/plans/2026-10-02-upstream-issue-triage.md.

Security

  • Untrusted mode: image.scale was written without escaping into the generated <img> tag, which let markup hide a second image that Graphviz then read into PNG/PDF output. scale now accepts only false, true, width, height or both.
  • Untrusted mode: a bare > in a value such as gauge or a color (in SHORT color mode) could end a Graphviz HTML label early. All label values are escaped, image.width/height must be numbers, and every generated label is checked to be well-formed with balanced angle brackets before Graphviz runs.
  • Untrusted mode: supplied image files must be .png, .jpg, .gif or .webp, and their content must match the extension (Pillow no longer probes other decoders such as EPS).

Bug fixes

  • A wire number beyond the cable's wire count, or an unknown wire label, gives a clear error (#208). An unknown label used to be drawn as the shield.
  • Unquoted NO, NC, ON, Yes and similar words stay text in labels: YAML is read with YAML 1.2 booleans (#305). Boolean attributes still accept yes/no/on/off.
  • A connector or cable with no attributes, an empty input file, and a comment-only file give clear errors (#426, #342).
  • Designators that contain : render (#487).
  • &, < and > in text no longer break the render; Graphviz tags (<b>, <br/>, <font>, ...) and HTML entities still work, while text such as <VBAT> is shown as written (#230, #266).
  • Using wire s on a cable without a shield is an error. Quoted numeric labels ('10') can be used in connections.
  • ignore_in_bom also hides the component's additional components; the diagram then lists them in full (#300). Behavior change: to keep a part such as a crimp terminal in the BOM under a hidden connector, set ignore_in_bom: false on that additional component.
  • colors: DIN and other list attributes given as a single value give a clear error (#265).
  • image: file.png works as a short form of image: {src: file.png} (#292).
  • Loops accept pin labels (#432); loops on non-sequential pin numbers have a regression test (#465).

Behavior changes

  • A cable named alone in a connection set (- B1) now uses wires 1 to n instead of wire 1 n times (#508). Autogenerated cables (- W.) are unchanged.
  • Errors in the input name the connection set (connection set 2 (X1 → W1 → X2): ...) and the CLI prints them as one line with exit code 1; --debug shows the traceback (#505, #207). Library callers can catch wireviz.wv_errors.WireVizError (a ValueError).

New features

  • Print-ready sheet PDF: -f D / output_formats="sheet" writes <name>.sheet.pdf, the HTML page (frame, diagram, BOM, title block) on one page at the template's sheet size. Needs pip install "wireviz[pdf]" (WeasyPrint 70 or later, Python 3.10 or later); WeasyPrint may load only the inline data: images, never a file or URL, and in untrusted mode it runs in a child process with the render timeout. The din-6771 template no longer lets the diagram overlap the BOM and title block, prints at the right page size, and defaults to A4; the simple template fits the diagram to the page when printed. New <!-- %date% --> placeholder (#32, #304).

  • Connector shorts: [[1, 2, 3], {YE: [N, AUX]}] shows internal shorts and jumpers as a bar in the pin table; shorted pins count as populated (#350).

  • Cable twisted: [[RD, BK], {wires: [3, 4], rate: 20/m}] shows twisted pairs, triads and groups as framed groups in the cable box (#3, #353).

  • include: merges shared connector/cable libraries from other files; -I/--include-path adds search directories (#220). Not allowed in untrusted mode.

  • A cable with no wirecount or colors takes its wire count from the wire numbers used in the connections (#508).

  • CSV BOM output: -f c / output_formats="csv" writes <name>.bom.csv (#98).

  • Loop colors: loops: [{RD: [VCC, SENSE]}] (#457).

  • options.show_title: true draws metadata.title above the diagram in PNG, SVG and PDF (#460).

  • --disable-key KEY (CLI) and parse(disable_keys=...) drop an attribute such as image from all components, or X1.image from one (#410).

  • Cable show_box: false hides the cable box and draws each wire straight from connector to connector (#212, #453).

  • CSS/HTML color names such as lightgreen or tomato (#135, #271).

  • .webp images are converted to PNG before rendering (#202).

  • Embedded images: image: data:image/png;base64,... (#188, #322). This also works in untrusted mode, which allows no file paths.

  • options.terminology replaces "pin", "wire" and "shield" in the diagram and BOM (#331).

  • Connector strip: {sleeve: 10, insulation: 2.5} shows stripping lengths in the diagram (#296).

v1.0.0 — security hardening and audit fixes

Choose a tag to compare

@SomethingNew71 SomethingNew71 released this 02 Oct 18:04
44a374b

Security hardening and bug fixes from the October 2026 audit. First stable release of the fork. Design and threat model: docs/plans/2026-10-02-october-2026-audit.md.

Security

  • SVG/HTML output no longer inlines arbitrary local files. Graphviz copies options.fontname and <font face> text into the SVG unescaped, so a YAML file could inject an <image> that pointed at any file (~/.ssh/id_rsa), which the embed step then base64-inlined. Only the images declared through image.src are embedded now, and fontname must be a plain font name.
  • Memory limits: pin/wire ranges and pincount/wirecount are capped at 10 000, and YAML alias trees in pin lists are refused (a few hundred bytes of YAML could allocate gigabytes).
  • PNG YAML embed and extract work on raw PNG chunks. No pixel decode, so no decompression bomb, and large renders no longer fail with DecompressionBombError.
  • New parse(..., untrusted=True) for servers that render YAML from other people (the wireviz-gui sidecar): string input is never read as a path, input is capped at 1 MB, images must be relative and inside image_paths, template names must be bare names, tweak is refused, SVG and HTML output are sanitized, and Graphviz runs with a 30 s timeout.

Bug fixes

  • options.output_dpi defaults to unset again. The 0.5.0 default of 96 made SVG and PDF output 1.33x too large; PNG output is unchanged.
  • parse() no longer keeps image search paths between calls (mutable default argument).
  • parse(): source_path resolves relative images for string/dict input; a Path input is always a file; non-UTF-8 files raise instead of being parsed as their own path; .png paths load the embedded YAML; output_formats="svg" works; dict input holding Path values works; return_types="png" embeds the YAML like file output.
  • Empty metadata:, options:, tweak: and additional_bom_items: sections no longer crash.
  • YAML aliases (*name) in connections no longer crash.
  • Missing output directories are created again (regression in 0.5.0).
  • Informational messages no longer go to stdout, where they corrupted -O - output.
  • CLI: cat x.yml | wireviz -f s -O name - writes name.svg; cat x.yml | wireviz - gives a usage error instead of a traceback; -f "" is a usage error; stdin/stdout are UTF-8 on every platform; --prepend is ignored (with a warning) when re-rendering a PNG; image search order is deterministic.
  • Wires with no color are as thick as other single-color wires when multi-color wires are present.
  • show_equiv: true without a gauge no longer crashes (upstream #497, port of upstream #498); gauge 1.0 finds its AWG equivalent.
  • Tweak override values containing backslashes (\N, \l) or characters such as # render correctly.
  • Image paths containing & render.
  • Mates (-->) accept pin labels, as cable connections do (upstream #510).

Requirements

  • Python 3.9 or later (3.7 and 3.8 are end-of-life). CI tests 3.9-3.14.
  • Minimum versions: click 8.0, pyyaml 5.4, pillow 10.3, graphviz (Python package) 0.20.

v0.5.0 — first ClassicMiniDIY release

Choose a tag to compare

@SomethingNew71 SomethingNew71 released this 05 May 12:27

First release of the ClassicMiniDIY/WireViz fork. Pulls in seven open upstream PRs that had been sitting unmerged for years, lays an automated test suite, and fixes a handful of bugs surfaced along the way.

Headline features

Feature Source
stdin/stdout streaming upstream #321
YAML embedded in PNG (round-trip editing) upstream #234
PDF output upstream #367
Custom template directory -t upstream #444
options.output_dpi upstream #379
Per-node tweak with placeholder substitution upstream #357
<!-- %revision% --> HTML template placeholder upstream #492

Bug fixes

  • Loopback rendering — loop-only connectors silently dropped, all loops forced onto a single side, loop edge ports referenced pin numbers instead of pin positions (upstream #496)
  • Hex RGB wire-thickness padding bug (upstream #495)
  • Custom HTML templates not resolvable against the YAML source directory (upstream #473)
  • SVG MIME type fix (upstream #443)
  • parse() no longer mutates dict inputs in place
  • All CLI errors now use click.UsageError (clean error messages instead of Python tracebacks)
  • Python 3.13+ compatibility (re.sub positional count deprecation)
  • Loop-only template no longer phantom-instantiated when used via Template.Designator

Testing

  • 134-test pytest suite covering the full API surface (parse, CLI, harness, dataclasses, colors, BOM, regressions, round-trip)
  • Runs in ~5 seconds
  • New Tests GitHub Actions workflow runs across Python 3.7-3.12 in parallel with the existing Create Examples workflow

Compatibility

API-compatible with WireViz 0.4.1 — existing YAML files render identically. New parameters on wireviz.parse() (source_path, template_dir, embed_yaml) are all keyword-only and default to behavior matching 0.4.1.

See docs/CHANGELOG.md for the full list of fixes and internal changes.