PDFCAB 1.17.0
Signature boundary controls
- Adds a field-root signature fixture where a valid incremental update leaves a well-formed ByteRange behind the current physical file end.
- Adds a private
/PieceInfo/Type /Sigand/ByteRangelookalike fixture that must not create signature inventory evidence. - Extends the public change contract with
signature_byte_range_coverage_changedand PFP009.
The deterministic corpus now contains 154 paired fixtures. It checks only fixed public static-analysis outputs and never asserts signature validity or publishes offsets, signature contents, certificates, digests, or private fingerprints.
Verification
84 tests and Ruff passed; the PDFFence 1.17 source candidate scored 154/154 through the process-bound public CLI. Two fixed-timestamp builds produced identical wheel and source archives, and clean wheel/source installs passed pip check, fixture verification, and the complete score.