Repository navigation
Fixes for open issues in the original wireviz/WireViz repository. Triage: docs/plans/2026-10-02-upstream-issue-triage.md.
Security
- Untrusted mode:
image.scalewas written without escaping into the generated<img>tag, which let markup hide a second image that Graphviz then read into PNG/PDF output.scalenow accepts onlyfalse,true,width,heightorboth. - Untrusted mode: a bare
>in a value such asgaugeor a color (inSHORTcolor mode) could end a Graphviz HTML label early. All label values are escaped,image.width/heightmust be numbers, and every generated label is checked to be well-formed with balanced angle brackets before Graphviz runs. - Untrusted mode: supplied image files must be
.png,.jpg,.gifor.webp, and their content must match the extension (Pillow no longer probes other decoders such as EPS).
Bug fixes
- A wire number beyond the cable's wire count, or an unknown wire label, gives a clear error (#208). An unknown label used to be drawn as the shield.
- Unquoted
NO,NC,ON,Yesand similar words stay text in labels: YAML is read with YAML 1.2 booleans (#305). Boolean attributes still acceptyes/no/on/off. - A connector or cable with no attributes, an empty input file, and a comment-only file give clear errors (#426, #342).
- Designators that contain
:render (#487). &,<and>in text no longer break the render; Graphviz tags (<b>,<br/>,<font>, ...) and HTML entities still work, while text such as<VBAT>is shown as written (#230, #266).- Using wire
son a cable without a shield is an error. Quoted numeric labels ('10') can be used in connections. ignore_in_bomalso hides the component's additional components; the diagram then lists them in full (#300). Behavior change: to keep a part such as a crimp terminal in the BOM under a hidden connector, setignore_in_bom: falseon that additional component.colors: DINand other list attributes given as a single value give a clear error (#265).image: file.pngworks as a short form ofimage: {src: file.png}(#292).- Loops accept pin labels (#432); loops on non-sequential pin numbers have a regression test (#465).
Behavior changes
- A cable named alone in a connection set (
- B1) now uses wires 1 to n instead of wire 1 n times (#508). Autogenerated cables (- W.) are unchanged. - Errors in the input name the connection set (
connection set 2 (X1 → W1 → X2): ...) and the CLI prints them as one line with exit code 1;--debugshows the traceback (#505, #207). Library callers can catchwireviz.wv_errors.WireVizError(aValueError).
New features
-
Print-ready sheet PDF:
-f D/output_formats="sheet"writes<name>.sheet.pdf, the HTML page (frame, diagram, BOM, title block) on one page at the template's sheet size. Needspip install "wireviz[pdf]"(WeasyPrint 70 or later, Python 3.10 or later); WeasyPrint may load only the inlinedata:images, never a file or URL, and in untrusted mode it runs in a child process with the render timeout. Thedin-6771template no longer lets the diagram overlap the BOM and title block, prints at the right page size, and defaults to A4; the simple template fits the diagram to the page when printed. New<!-- %date% -->placeholder (#32, #304). -
Connector
shorts: [[1, 2, 3], {YE: [N, AUX]}]shows internal shorts and jumpers as a bar in the pin table; shorted pins count as populated (#350). -
Cable
twisted: [[RD, BK], {wires: [3, 4], rate: 20/m}]shows twisted pairs, triads and groups as framed groups in the cable box (#3, #353). -
include:merges shared connector/cable libraries from other files;-I/--include-pathadds search directories (#220). Not allowed in untrusted mode. -
A cable with no
wirecountorcolorstakes its wire count from the wire numbers used in the connections (#508). -
CSV BOM output:
-f c/output_formats="csv"writes<name>.bom.csv(#98). -
Loop colors:
loops: [{RD: [VCC, SENSE]}](#457). -
options.show_title: truedrawsmetadata.titleabove the diagram in PNG, SVG and PDF (#460). -
--disable-key KEY(CLI) andparse(disable_keys=...)drop an attribute such asimagefrom all components, orX1.imagefrom one (#410). -
Cable
show_box: falsehides the cable box and draws each wire straight from connector to connector (#212, #453). -
CSS/HTML color names such as
lightgreenortomato(#135, #271). -
.webpimages are converted to PNG before rendering (#202). -
Embedded images:
image: data:image/png;base64,...(#188, #322). This also works in untrusted mode, which allows no file paths. -
options.terminologyreplaces "pin", "wire" and "shield" in the diagram and BOM (#331). -
Connector
strip: {sleeve: 10, insulation: 2.5}shows stripping lengths in the diagram (#296).