DocFence 0.54.0
DocFence 0.54 applies OPC §10.5.18's XPath prohibition to every XMLDSIG ds:XPath element in a recognized package signature, not only the bounded static coverage chain.
It rejects XPath in an additional same-document, non-coverage SignedInfo reference as well as in the package-object binding and manifest references.
This is a static stored-markup boundary: DocFence does not parse or execute XPath, resolve namespaces, canonicalize XML, evaluate transforms, recompute digests, verify XMLDSIG, or establish trust.
Validation: 69 tests; a fully declared XPath probe accepted with coverage in 0.53 and raises DocumentFormatError in 0.54; 29 public DOCX profiles unchanged; 22 XML signature parts (21 parseable), no XPath elements; checked wheel and sdist.