PDFFence 1.21.0
Signature ByteRange own-revision coverage
Adds PFP013, require_signature_byte_range_own_revision_coverage.
The new static review gate requires every semantic signature /ByteRange to end at the unambiguous footer of the revision containing its xref-addressable signature dictionary. It is intentionally distinct from current-file coverage: an older signature can remain correctly bounded after later incremental updates.
The release retains aggregate-only public output and fails closed for unavailable, ambiguous, malformed, direct, compressed, or over-limit revision evidence. It does not validate a signature, digest, certificate, trust chain, transform, permission, or incremental update.
Validation: 254 tests, Ruff, exact 158/158 PDFCAB process-bound score, a two-signature pyHanko interoperability exercise, reproducible wheel/sdist builds, and fresh Python 3.12/3.13 installation checks. See docs/validation.md for details.