Skip to content

Releases: kinti/svb

v0.2.1 — encoder crash fix

Choose a tag to compare

@kinti kinti released this 01 Sep 22:15

Implementation-only patch release. No format change — files produced by any encoder remain valid.

Fixed

  • Encoder crash when a gradient reference was inherited from a container: <g fill="url(#g)"> hit a TypeError (the container branch of the style walk did not receive the gradient index map). Gradients on shapes were never affected. Adds a round-trip regression test.

Housekeeping

  • CHANGELOG.md (Keep a Changelog), CONTRIBUTING.md, CODE_OF_CONDUCT.md, SECURITY.md, issue/PR templates, Dependabot for Actions.

Full history: CHANGELOG.md

SVB v0.2.0 — repetition, gradients, command runs

Choose a tag to compare

@kinti kinti released this 30 Aug 22:33

Closes the two big gaps from the v0.1.1 review (F-11, F-12).

New in v0.2

  • DEF chunk — repetition as templates + instances: SVG <use> semantics at the binary layer. Repeated shapes are stored once (~1 template) and referenced by translate-only instances (~4-5 B each, delta-chained MVT-style). The 574 KB repetitive map now encodes to 1,725 B raw.
  • GRAD chunk — gradients: linear/radial, objectBoundingBox (u8) or userSpaceOnUse coordinates, optional gradientTransform, per-gradient alpha. A 2-stop OBB linear gradient costs ~16 B (vs ~250 B in SVG).
  • Command-run packing (MVT CommandInteger port): consecutive same-command path segments pack into one varint — kills the measured 12% command-byte cost.
  • Security: INV-13 (flat templates, no cycles by grammar), INV-14 expansion budget ≤ 1M elements (template-bomb guard), strict gradient vocabulary, version-byte 2 discipline. v1 files remain valid.

Benchmarks (corpus 1,087 production SVGs, svgo-optimized): median ×0.277, svb < svgo+brotli on 100% of files; large repetitive files ×0.064-0.233 of SVG. Organic no-repetition class stays at ×1.055 (conceded to v0.3 geometry modeling).

43 tests · MIT · © 2026 Jesús Quintana

SVB v0.1.1 — security hardening

Choose a tag to compare

@kinti kinti released this 29 Aug 23:09

Security audit of the reference implementation, with every finding kept as a regression test.

  • Critical (fixed): a ~20-byte file declaring 134 million path commands exhausted 4 GB of heap in ~19 s (DoS). Root cause: unbounded declared counts + silent zero-reads past EOF. Now both are normative violations (SPEC §12); rejection is sub-millisecond.
  • High (fixed): decompression bombs — a 199 KB file expanded to 200 MB of RAM. Decompressed output is now capped at 64 MB (Node: maxOutputLength; browser: streaming read with early abort).
  • Medium (fixed): adversarial SVG attribute lists triggered quadratic parsing in the encoder's XML reader (sticky regexes now).
  • Encoder input capped at 10 MB.

Format unchanged: version byte stays 1, all v0.1 files remain valid. 25 tests (19 round-trip + 6 security), MIT · © 2026 Jesús Quintana.

SVB v0.1.0 — first public release

Choose a tag to compare

@kinti kinti released this 29 Aug 22:54

First public release of SVB — Scalable Vector Binary, a binary vector-image format for the web.

What's in v0.1

  • Byte-level specification (chunk container, zigzag delta geometry, first-class A11Y chunk) — SPEC.md, also in Spanish
  • Dependency-free JavaScript reference codec: encoder, decoder, CLI (encode/decode/roundtrip/bench)
  • 19 round-trip tests (varint fuzz, forward compatibility, error handling)
  • Service Worker polyfill — <img src="*.svb"> works in today's browsers: live demo
  • Benchmark over 1,087 production SVGs (svgo-optimized first): median ×0.272, raw SVB beats svgo+brotli in 100% of files — full results
  • Brand assets: logo drawn inside SVB's own subset, 150 B as .svb, WCAG AAA palette

MIT · © 2026 Jesús Quintana