Repository navigation
Releases: ClassicMiniDIY/WireViz
Release list
v1.1.0 — upstream issue fixes: include, twisted pairs, shorts, sheet PDF
Fixes for open issues in the original wireviz/WireViz repository. Triage: docs/plans/2026-10-02-upstream-issue-triage.md.
Security
- Untrusted mode:
image.scalewas written without escaping into the generated<img>tag, which let markup hide a second image that Graphviz then read into PNG/PDF output.scalenow accepts onlyfalse,true,width,heightorboth. - Untrusted mode: a bare
>in a value such asgaugeor a color (inSHORTcolor mode) could end a Graphviz HTML label early. All label values are escaped,image.width/heightmust be numbers, and every generated label is checked to be well-formed with balanced angle brackets before Graphviz runs. - Untrusted mode: supplied image files must be
.png,.jpg,.gifor.webp, and their content must match the extension (Pillow no longer probes other decoders such as EPS).
Bug fixes
- A wire number beyond the cable's wire count, or an unknown wire label, gives a clear error (#208). An unknown label used to be drawn as the shield.
- Unquoted
NO,NC,ON,Yesand similar words stay text in labels: YAML is read with YAML 1.2 booleans (#305). Boolean attributes still acceptyes/no/on/off. - A connector or cable with no attributes, an empty input file, and a comment-only file give clear errors (#426, #342).
- Designators that contain
:render (#487). &,<and>in text no longer break the render; Graphviz tags (<b>,<br/>,<font>, ...) and HTML entities still work, while text such as<VBAT>is shown as written (#230, #266).- Using wire
son a cable without a shield is an error. Quoted numeric labels ('10') can be used in connections. ignore_in_bomalso hides the component's additional components; the diagram then lists them in full (#300). Behavior change: to keep a part such as a crimp terminal in the BOM under a hidden connector, setignore_in_bom: falseon that additional component.colors: DINand other list attributes given as a single value give a clear error (#265).image: file.pngworks as a short form ofimage: {src: file.png}(#292).- Loops accept pin labels (#432); loops on non-sequential pin numbers have a regression test (#465).
Behavior changes
- A cable named alone in a connection set (
- B1) now uses wires 1 to n instead of wire 1 n times (#508). Autogenerated cables (- W.) are unchanged. - Errors in the input name the connection set (
connection set 2 (X1 → W1 → X2): ...) and the CLI prints them as one line with exit code 1;--debugshows the traceback (#505, #207). Library callers can catchwireviz.wv_errors.WireVizError(aValueError).
New features
-
Print-ready sheet PDF:
-f D/output_formats="sheet"writes<name>.sheet.pdf, the HTML page (frame, diagram, BOM, title block) on one page at the template's sheet size. Needspip install "wireviz[pdf]"(WeasyPrint 70 or later, Python 3.10 or later); WeasyPrint may load only the inlinedata:images, never a file or URL, and in untrusted mode it runs in a child process with the render timeout. Thedin-6771template no longer lets the diagram overlap the BOM and title block, prints at the right page size, and defaults to A4; the simple template fits the diagram to the page when printed. New<!-- %date% -->placeholder (#32, #304). -
Connector
shorts: [[1, 2, 3], {YE: [N, AUX]}]shows internal shorts and jumpers as a bar in the pin table; shorted pins count as populated (#350). -
Cable
twisted: [[RD, BK], {wires: [3, 4], rate: 20/m}]shows twisted pairs, triads and groups as framed groups in the cable box (#3, #353). -
include:merges shared connector/cable libraries from other files;-I/--include-pathadds search directories (#220). Not allowed in untrusted mode. -
A cable with no
wirecountorcolorstakes its wire count from the wire numbers used in the connections (#508). -
CSV BOM output:
-f c/output_formats="csv"writes<name>.bom.csv(#98). -
Loop colors:
loops: [{RD: [VCC, SENSE]}](#457). -
options.show_title: truedrawsmetadata.titleabove the diagram in PNG, SVG and PDF (#460). -
--disable-key KEY(CLI) andparse(disable_keys=...)drop an attribute such asimagefrom all components, orX1.imagefrom one (#410). -
Cable
show_box: falsehides the cable box and draws each wire straight from connector to connector (#212, #453). -
CSS/HTML color names such as
lightgreenortomato(#135, #271). -
.webpimages are converted to PNG before rendering (#202). -
Embedded images:
image: data:image/png;base64,...(#188, #322). This also works in untrusted mode, which allows no file paths. -
options.terminologyreplaces "pin", "wire" and "shield" in the diagram and BOM (#331). -
Connector
strip: {sleeve: 10, insulation: 2.5}shows stripping lengths in the diagram (#296).
v1.0.0 — security hardening and audit fixes
Security hardening and bug fixes from the October 2026 audit. First stable release of the fork. Design and threat model: docs/plans/2026-10-02-october-2026-audit.md.
Security
- SVG/HTML output no longer inlines arbitrary local files. Graphviz copies
options.fontnameand<font face>text into the SVG unescaped, so a YAML file could inject an<image>that pointed at any file (~/.ssh/id_rsa), which the embed step then base64-inlined. Only the images declared throughimage.srcare embedded now, andfontnamemust be a plain font name. - Memory limits: pin/wire ranges and
pincount/wirecountare capped at 10 000, and YAML alias trees in pin lists are refused (a few hundred bytes of YAML could allocate gigabytes). - PNG YAML embed and extract work on raw PNG chunks. No pixel decode, so no decompression bomb, and large renders no longer fail with
DecompressionBombError. - New
parse(..., untrusted=True)for servers that render YAML from other people (the wireviz-gui sidecar): string input is never read as a path, input is capped at 1 MB, images must be relative and insideimage_paths, template names must be bare names,tweakis refused, SVG and HTML output are sanitized, and Graphviz runs with a 30 s timeout.
Bug fixes
options.output_dpidefaults to unset again. The 0.5.0 default of 96 made SVG and PDF output 1.33x too large; PNG output is unchanged.parse()no longer keeps image search paths between calls (mutable default argument).parse():source_pathresolves relative images for string/dict input; aPathinput is always a file; non-UTF-8 files raise instead of being parsed as their own path;.pngpaths load the embedded YAML;output_formats="svg"works; dict input holdingPathvalues works;return_types="png"embeds the YAML like file output.- Empty
metadata:,options:,tweak:andadditional_bom_items:sections no longer crash. - YAML aliases (
*name) inconnectionsno longer crash. - Missing output directories are created again (regression in 0.5.0).
- Informational messages no longer go to stdout, where they corrupted
-O -output. - CLI:
cat x.yml | wireviz -f s -O name -writesname.svg;cat x.yml | wireviz -gives a usage error instead of a traceback;-f ""is a usage error; stdin/stdout are UTF-8 on every platform;--prependis ignored (with a warning) when re-rendering a PNG; image search order is deterministic. - Wires with no color are as thick as other single-color wires when multi-color wires are present.
show_equiv: truewithout a gauge no longer crashes (upstream #497, port of upstream #498); gauge1.0finds its AWG equivalent.- Tweak override values containing backslashes (
\N,\l) or characters such as#render correctly. - Image paths containing
&render. - Mates (
-->) accept pin labels, as cable connections do (upstream #510).
Requirements
- Python 3.9 or later (3.7 and 3.8 are end-of-life). CI tests 3.9-3.14.
- Minimum versions: click 8.0, pyyaml 5.4, pillow 10.3, graphviz (Python package) 0.20.
v0.5.0 — first ClassicMiniDIY release
First release of the ClassicMiniDIY/WireViz fork. Pulls in seven open upstream PRs that had been sitting unmerged for years, lays an automated test suite, and fixes a handful of bugs surfaced along the way.
Headline features
| Feature | Source |
|---|---|
| stdin/stdout streaming | upstream #321 |
| YAML embedded in PNG (round-trip editing) | upstream #234 |
| PDF output | upstream #367 |
Custom template directory -t |
upstream #444 |
options.output_dpi |
upstream #379 |
| Per-node tweak with placeholder substitution | upstream #357 |
<!-- %revision% --> HTML template placeholder |
upstream #492 |
Bug fixes
- Loopback rendering — loop-only connectors silently dropped, all loops forced onto a single side, loop edge ports referenced pin numbers instead of pin positions (upstream #496)
- Hex RGB wire-thickness padding bug (upstream #495)
- Custom HTML templates not resolvable against the YAML source directory (upstream #473)
- SVG MIME type fix (upstream #443)
parse()no longer mutates dict inputs in place- All CLI errors now use
click.UsageError(clean error messages instead of Python tracebacks) - Python 3.13+ compatibility (
re.subpositionalcountdeprecation) - Loop-only template no longer phantom-instantiated when used via
Template.Designator
Testing
- 134-test pytest suite covering the full API surface (parse, CLI, harness, dataclasses, colors, BOM, regressions, round-trip)
- Runs in ~5 seconds
- New
TestsGitHub Actions workflow runs across Python 3.7-3.12 in parallel with the existingCreate Examplesworkflow
Compatibility
API-compatible with WireViz 0.4.1 — existing YAML files render identically. New parameters on wireviz.parse() (source_path, template_dir, embed_yaml) are all keyword-only and default to behavior matching 0.4.1.
See docs/CHANGELOG.md for the full list of fixes and internal changes.