PDFFence 1.15.0
Semantic action roots
Selected action behavior evidence is now derived from concrete PDF document paths, not from a matching dictionary key alone. PDFFence follows catalog document-open and additional actions, catalog JavaScript name-tree values, catalog-reachable page and annotation entries, AcroForm fields and widgets, outlines, and page presentation-step NavNodes; semantic /Next successors begin only at one of those roots.
A /A, /AA, /NA, or /PA key in non-executing application data no longer creates behavior evidence. This includes PieceInfo private data. A Link annotation's archived Web Capture /PA URI is also byte-only; /NA and /PA are execution roots only on a real page /PresSteps NavNode path.
Validation
- 221 tests and Ruff passed.
- PDFCAB 1.15 scored 150/150 through the public CLI; held PDFFence 1.14 scores 145/150 and falsely flags the five passive controls.
- Two fixed-timestamp builds were byte-identical, Twine metadata checks passed, and clean Python 3.12/3.13 wheel installs plus a Python 3.12 source-archive install passed verification and the complete benchmark score.
SHA256SUMS covers the attached wheel and source archive.