Repository navigation
v1.0.0 — security hardening and audit fixes
Security hardening and bug fixes from the October 2026 audit. First stable release of the fork. Design and threat model: docs/plans/2026-10-02-october-2026-audit.md.
Security
- SVG/HTML output no longer inlines arbitrary local files. Graphviz copies
options.fontnameand<font face>text into the SVG unescaped, so a YAML file could inject an<image>that pointed at any file (~/.ssh/id_rsa), which the embed step then base64-inlined. Only the images declared throughimage.srcare embedded now, andfontnamemust be a plain font name. - Memory limits: pin/wire ranges and
pincount/wirecountare capped at 10 000, and YAML alias trees in pin lists are refused (a few hundred bytes of YAML could allocate gigabytes). - PNG YAML embed and extract work on raw PNG chunks. No pixel decode, so no decompression bomb, and large renders no longer fail with
DecompressionBombError. - New
parse(..., untrusted=True)for servers that render YAML from other people (the wireviz-gui sidecar): string input is never read as a path, input is capped at 1 MB, images must be relative and insideimage_paths, template names must be bare names,tweakis refused, SVG and HTML output are sanitized, and Graphviz runs with a 30 s timeout.
Bug fixes
options.output_dpidefaults to unset again. The 0.5.0 default of 96 made SVG and PDF output 1.33x too large; PNG output is unchanged.parse()no longer keeps image search paths between calls (mutable default argument).parse():source_pathresolves relative images for string/dict input; aPathinput is always a file; non-UTF-8 files raise instead of being parsed as their own path;.pngpaths load the embedded YAML;output_formats="svg"works; dict input holdingPathvalues works;return_types="png"embeds the YAML like file output.- Empty
metadata:,options:,tweak:andadditional_bom_items:sections no longer crash. - YAML aliases (
*name) inconnectionsno longer crash. - Missing output directories are created again (regression in 0.5.0).
- Informational messages no longer go to stdout, where they corrupted
-O -output. - CLI:
cat x.yml | wireviz -f s -O name -writesname.svg;cat x.yml | wireviz -gives a usage error instead of a traceback;-f ""is a usage error; stdin/stdout are UTF-8 on every platform;--prependis ignored (with a warning) when re-rendering a PNG; image search order is deterministic. - Wires with no color are as thick as other single-color wires when multi-color wires are present.
show_equiv: truewithout a gauge no longer crashes (upstream #497, port of upstream #498); gauge1.0finds its AWG equivalent.- Tweak override values containing backslashes (
\N,\l) or characters such as#render correctly. - Image paths containing
&render. - Mates (
-->) accept pin labels, as cable connections do (upstream #510).
Requirements
- Python 3.9 or later (3.7 and 3.8 are end-of-life). CI tests 3.9-3.14.
- Minimum versions: click 8.0, pyyaml 5.4, pillow 10.3, graphviz (Python package) 0.20.