Releases: Kayforkind/NavigatorsLab-PDF-Studio
Releases · Kayforkind/NavigatorsLab-PDF-Studio
Release list
v1.2.0 — the launch release
v1.2.0 — the launch release
Four languages, a full docs site, and an independently audited AI interface.
- Speaks your language — the whole UI is now localized in Spanish, German, and French (plus English), with a one-click switcher that remembers your choice.
- Docs site — every guide, the complete CLI reference, the MCP server reference, the security model, and FAQ, in one searchable site (
docs/site, built with VitePress). - Audited for agents — an independent re-audit of the CLI and MCP server against the project's threat model found and fixed a real sandbox escape (a symlink inside
--rootcould break containment), added a--read-onlyMCP mode, and hardened untrusted-text delimiters. Full report:docs/SECURITY_ASSESSMENT_AGENTS.md. - Cleaner and clearer — stale Netlify/Vercel deploy configs removed, expanded CLI/MCP local-install docs, CI green, new social preview banner.
Try it in your browser — files never leave your device, nothing is tracked: https://navigatorslab.com/pdf-studio
Self-host in one line:
docker run -d -p 8080:80 --name pdf-studio ghcr.io/kayforkind/navigatorslab-pdf-studio:1.2.0
# → http://localhost:8080v1.1.0 — MCP server + CLI
Agentic interfaces
pdfstudioCLI (packages/cli): 9 commands —info,extract-text,search,edit-text,redact,merge,split,rotate,pages. Unix-friendly:-stdin,-o -stdout,--json, exit codes 0/1/2.- MCP server (
packages/mcp): 10 tools over stdio for AI agents (pdf_info,pdf_extract_text,pdf_search_text,pdf_edit_text,pdf_redact_text,pdf_redact_rect,pdf_merge,pdf_split,pdf_rotate,pdf_pages). Path containment, no shell-outs, extracted text marked untrusted against prompt injection. - Same privacy guarantee as the app: document bytes never leave the machine.
Engine fixes (also live on the site)
- Fixed invalid PDF output: TJ-array operands now emitted with the
TJoperator (wasTj— text vanished in strict parsers); deletions emit() Tjinstead of a bare operator. - One-click wipe now clears all stored keys (found in the independent security audit — repo scored A−).
See the README's new Agentic usage section for install, CLI examples, and claude mcp add config.
v1.0.0
PDF Studio v1.0.0
First stable release — the free, open-source PDF editor that runs 100% in your browser. No uploads, no accounts, no watermarks, no page limits.
What it does
- True in-place text editing: rewrites the page content stream itself, exports real vector text
- Fill real AcroForms (text, checkboxes, radios, dropdowns), then flatten them
- Sign and annotate: signature pad, highlight, pen, arrows, shapes, sticky notes, image stamps
- True redaction: covered text is deleted from the file at export, not painted over
- OCR via on-device Tesseract (EN/ES/FR/DE) — nothing uploaded, ever
- On-device AI Q&A over your document (WebLLM, weights cached after first fetch)
- Revision diff, page organize (reorder, rotate, merge, split, duplicate, delete), export stamps
- PWA: installs to phone or desktop, works offline, autosaves locally
In this release
- Mobile experience production-ready (touch drawing fixed, single-column export dialog, reachable Save, 44px touch targets)
- MIT license detection fixed on the repo page
- Docker self-host one-liner:
docker run -d -p 8080:80 ghcr.io/kayforkind/navigatorslab-pdf-studio:latest - Issue and PR templates, third-party notices
Coming in v1.1.0
- MCP server + CLI for agentic workflows