Releases: ttomohisa/wasm-zoo
Release list
WASM Zoo · Brotli 1.2.0 · browser build
Unofficial current-upstream Google Brotli CLI build for browser WebAssembly. Built from exact v1.2.0 / 028fb5a23661f123017c060daa546b55cf4bde29 with Emscripten 6.0.8, the upstream CMake brotli executable target and zero Brotli source patches. The release includes corresponding source/build recipe, in-toto/SLSA provenance, CycloneDX 1.6 SBOM and SHA-256 checksums. Chromium smoke testing verifies the upstream version, quality-11 compression, integrity-test mode and a byte-identical decompression round trip before publication.
WASM Zoo · QPDF 12.4.2 · browser build
Unofficial current-upstream QPDF CLI build for browser WebAssembly. Built from the official QPDF 12.4.2 release source archive with exact digest/tag/commit pins, Emscripten 6.0.8, QPDF native crypto and the exact zlib/libjpeg inputs selected by the pinned Emscripten ports. The release includes corresponding source/build recipe, third-party notices, in-toto/SLSA provenance, CycloneDX 1.6 SBOM and SHA-256 checksums. Chromium smoke testing verifies a real one-page PDF through check, linearize, AES-256 encryption, decryption and final validation before publication.
WASM Zoo · libvips v8.18.7 · browser builds
Unofficial libvips browser library builds for WebAssembly. browser-core targets JPEG/PNG/WebP with a reduced delegate surface; browser-full additionally keeps TIFF/GIF/imagequant. Both profiles use the same pinned upstream API and pass real Chromium PNG decode + resize + JPEG/WebP encode smoke tests. The release includes raw/gzip size comparison, per-profile in-toto/SLSA provenance, CycloneDX 1.6 SBOMs, hashes and corresponding source/build recipes.
WASM Zoo · ImageMagick 7.1.2-32 · browser build
Unofficial upstream ImageMagick magick CLI build for WebAssembly. Includes machine-readable build inventory, exact hashes and corresponding source/build recipe. The browser build passed a real Chromium PNG identify + resize smoke test before publication. Metadata-enabled releases also publish in-toto/SLSA provenance and a CycloneDX 1.6 SBOM.
WASM Zoo v0.18.0 — Manifest-driven Operations
WASM Zoo v0.18.0 — project release review
This project release records the reviewed Manifest-driven Operations work already merged into WASM Zoo. It does not change any package's reviewed upstream pin, Zoo builder version, npm version, immutable package GitHub Release or Registry identity, and it does not authorize automatic publication.
Included in v0.18.0
- Published npm operational membership is manifest-driven. The generic npm workflow accepts a manifest-validated slug, and the Cross-browser Compatibility Lab derives its package membership and threaded classification from reviewed package metadata rather than an eight-package enrollment list.
- Candidate orchestration centralizes automatic-package registration validation, selected-job result routing and promotion repository-checker resolution while retaining explicit package-specific candidate build jobs where source/profile/smoke semantics differ.
- Successful automatic candidates still create review-only promotion PRs. The promotion PR now embeds a generated post-merge human handoff, and a merged
automation/promote-*PR receives a confirmed comment with the reviewed merge SHA and exact manual follow-up commands. - The human handoff never performs merge, package tag, GitHub Release or npm publication. QPDF and Zstandard retain their
keepNpmPinnedbehavior so package promotion cannot silently move their separately reviewed npm source identity. - Release Health schema 2 adds live npm Registry alignment to the existing Release/Playground/freshness/supply-chain checks. It records the reviewed npm version, source Release, Registry exact/latest version, live
dist.shasum, follow-up state and intentional pin state. - Release Health treats a deliberate
keepNpmPinnedmismatch as a visible separate-review warning rather than a broken package Release; unreviewed source drift or a recorded Registry SHA mismatch remains an error. - Local Playground staging now covers all eight available packages, including QPDF.
npm run checkderives every available Playground package from manifests and fails if any one lacks a registered local stager. - The npm workflow contract normalizes workflow line endings before multiline checks, so the same reviewed manifest-driven workflow passes on Windows CRLF and Linux LF checkouts.
- The reviewed-pin boundary remains unchanged: automation may create review-only PRs and explanatory comments, but it never automatically merges, tags, creates a GitHub Release or publishes npm.
Reviewed pre-finalization evidence
The v0.18.0 finalization branch was created from reviewed main commit:
955a825771617b6ec3a3ca541ca788e64013e0e6
At that commit:
- Verify catalog run #168 succeeded.
- The local-preview contract reported 8 available package stagers registered.
- The shared automatic-promotion rehearsal passed for all 8 automatic packages, including libvips fail-closed immutable adapter resolution.
- Cross-browser Compatibility Lab run #99 completed 26/26 workflow jobs successfully: resolver + 24 exact-version browser-operation cells + threaded aggregate.
- QPDF passed Chromium, Firefox and WebKit in that Lab.
- Pages run #152 succeeded after the Lab and published the current main-branch compatibility / Release Health snapshot.
- Release Health schema 2 reported all 8 reviewed npm distributions aligned with no npm follow-up, intentional-pin or Registry identity errors at that time.
These are pre-finalization observations only. After the finalization PR is merged, the release decision must use the newest reviewed-main Verify/Lab/Pages runs rather than reusing these older green results.
Package identity freeze
v0.18.0 is a project-only release. The finalization PR must not mutate any packages/<slug>/package.json, builder versions.env, package release tag, npm package version or npm Registry identity.
The current package set remains independently versioned:
| Package | Upstream | Zoo builder | Package tag | npm |
|---|---|---|---|---|
| FFmpeg | 9.0.2 | 0.2.8 | ffmpeg-v0.2.8 |
@wasm-zoo/ffmpeg@0.2.8 |
| libarchive | 3.8.9 | 0.3.1 | libarchive-v0.3.1 |
@wasm-zoo/libarchive@0.3.1 |
| ImageMagick | 7.1.2-31 | 0.4.3 | imagemagick-v0.4.3 |
@wasm-zoo/imagemagick@0.4.3 |
| libvips | 8.18.6 | 0.5.2 | libvips-v0.5.2 |
@wasm-zoo/libvips@0.5.2 |
| Ghostscript | 10.08.0 | 0.7.2 | ghostscript-v0.7.2 |
@wasm-zoo/ghostscript@0.7.2 |
| jq | 1.8.2 | 0.9.0 | jq-v0.9.0 |
@wasm-zoo/jq@0.9.1 |
| Zstandard | 1.5.7 | 0.3.0 | zstd-v0.3.0 |
@wasm-zoo/zstd@0.3.0 |
| QPDF | 12.4.1 | 0.1.0 | qpdf-v0.1.0 |
@wasm-zoo/qpdf@0.1.0 |
Review checklist (PowerShell 7)
Run this only after manually reviewing and merging the v0.18.0 finalization PR. Do not create the project tag from a PR branch.
cd C:\Users\broth\Desktop\workspace\wasm-zoo
git fetch origin main --tags
git switch main
git pull --ff-only origin main
git status --short
# Confirm the reviewed project version is consistent everywhere.
Get-Content VERSION
node -p "require('./package.json').version"
node -p "require('./site/catalog.json').project.version"
# Re-run deterministic project/release contracts from reviewed main.
npm run catalog
npm run check
npm run metadata:check
npm run promotion:rehearse
git diff --check
git status --short
# Confirm the newest reviewed-main evidence; do not reuse an older passing Lab.
gh run list --workflow verify.yml --branch main --limit 3
gh run list --workflow cross-browser-compat.yml --branch main --limit 3
gh run list --workflow pages.yml --branch main --limit 5
gh run list --workflow npm-qpdf-canary.yml --branch main --limit 3
gh run list --workflow npm-zstd-canary.yml --branch main --limit 3Expected project version output is 0.18.0 in all three locations. npm run catalog must leave the working tree clean. The newest eligible main-branch Lab must contain the full current 24-cell exact-version browser evidence; if a newer run is pending or failed, do not reuse an older green snapshot.
Project tag
The project tag remains a human action after all post-merge gates are reviewed:
git ls-remote --tags origin refs/tags/v0.18.0
# Only if absent, and ONLY from the verified reviewed main commit:
git tag -a v0.18.0 -m "WASM Zoo v0.18.0 — Manifest-driven Operations"
git push origin v0.18.0
git ls-remote --tags origin refs/tags/v0.18.0Do not create or move any package tag as part of this project release.
Suggested GitHub Release
Create the GitHub project Release manually only after the tag above points at the reviewed finalization merge commit.
Title:
WASM Zoo v0.18.0 — Manifest-driven Operations
Suggested release notes:
Manifest-driven operations
- npm workflow enrollment and the browser compatibility matrices now derive published package membership from reviewed manifests.
- Candidate registration/result/checker routing is centralized while package-specific candidate build semantics remain explicit.
- The current production browser target remains 24 real package/browser operations across eight public npm distributions.
Reviewed promotion handoff
- Automatic candidate success may create a review-only promotion PR.
- Promotion PRs now include a generated human handoff.
- After a real promotion merge, a comment-only workflow posts the confirmed merge SHA and the exact manual tag/Release/npm follow-up.
- Automation still never merges, tags, creates reviewed Releases or publishes npm.
npm-aware Release Health
- Release Health schema 2 checks reviewed npm versions against the live Registry.
- It records source Release identity, exact/latest Registry versions and live
dist.shasum. - Intentional QPDF/Zstandard npm pins are surfaced as separate-review state rather than false package-release failures.
- Unexpected source drift or recorded Registry SHA mismatch is treated as an error.
Local preview parity
- All eight available package Playgrounds now have local stagers.
- QPDF local staging rejects stale builds whose upstream version/commit or builder version differs from reviewed pins.
- CI prevents future available Playground packages from being omitted from local staging.
Safety boundary
This project release changes only project-level version/release documentation. Existing package pins, builder versions, immutable package Releases and npm versions remain unchanged. The maintainer still performs every merge, project/package tag, reviewed GitHub Release and npm publication action.
WASM Zoo v0.17.0 — QPDF release, npm and 24-cell Lab
WASM Zoo v0.17.0 — QPDF release, npm and 24-cell Lab
WASM Zoo v0.17.0 completes the reviewed QPDF rollout and expands the Registry-backed Cross-browser Compatibility Lab to all eight public npm distributions.
QPDF
- Added QPDF 12.4.1 as the eighth reviewed WASM Zoo package.
- Built from the official
qpdf-12.4.1.tar.gzrelease source. - Pinned upstream commit:
c37f83ae468abb6cc741f43b2f6fdeb66e550ffb - Zoo builder:
0.1.0 - Emscripten:
6.0.8 - Bundled dependency identities:
- zlib 1.3.2
- libjpeg 9f
- Published immutable package release:
qpdf-v0.1.0 - Added the checksum-verified QPDF Playground.
The browser profile exposes the real upstream qpdf CLI in an isolated Worker with MEMFS and native QPDF crypto. It is single-threaded and does not require SharedArrayBuffer.
Its reviewed browser smoke covers:
- PDF structural validation with
--check - linearization
- AES-256 encryption
- decryption
- final structural validation
npm
Published the eighth public WASM Zoo npm distribution:
@wasm-zoo/qpdf@0.1.0
The initial publication used the exact immutable Release-derived tarball that had already passed Vite production builds and real QPDF operations in Chromium, Firefox and WebKit.
Reviewed npm Registry identity:
dist.shasum: 83b2a89ec339d58ab0dcaf3c118385c3396955f1
Live Registry tests now verify that SHA-1 before installing the package.
QPDF also joins the existing Trusted Publisher staged-review workflow for future npm-only updates. npm publication remains a separate reviewed action from package promotion.
Cross-browser Compatibility Lab
The production compatibility matrix expands from 21 to 24 real browser-operation cells:
- 6 single-threaded packages × Chromium / Firefox / WebKit = 18
- FFmpeg + libvips threaded profiles × Chromium / Firefox / WebKit = 6
- Total = 24
The first v0.17.0 reviewed-main run passed all 24 package/browser cells:
- Cross-browser Compatibility Lab #86
- 25/25 workflow jobs successful
- QPDF Chromium ✅
- QPDF Firefox ✅
- QPDF WebKit ✅
The following Pages deployment published a fresh verified compatibility snapshot with 24 passes and 0 failures.
Automation and reviewed pins
All eight current packages now participate in the review-only automatic candidate model.
Candidate automation may:
upstream detection → Issue → candidate build/test → promotion PR
It does not automatically:
- merge promotion PRs
- change reviewed
main - create package or project tags
- create reviewed package releases
- publish npm packages
libvips remains fail-closed: its wasm-vips adapter, Emscripten source and compatibility inputs must resolve to immutable commits before candidate testing can advance.
Project release
Project version:
0.17.0
Reviewed release commit:
2d7e8599efc9d4dbe8991d38df584b1f05b6853f
This project release does not change any existing package upstream pin, Zoo builder version, npm version or immutable package release merely because the project version advanced.
WASM Zoo · QPDF 12.4.1 · browser build
Unofficial current-upstream QPDF CLI build for browser WebAssembly. Built from the official QPDF 12.4.1 release source archive with exact digest/tag/commit pins, Emscripten 6.0.8, QPDF native crypto and the exact zlib/libjpeg inputs selected by the pinned Emscripten ports. The release includes corresponding source/build recipe, third-party notices, in-toto/SLSA provenance, CycloneDX 1.6 SBOM and SHA-256 checksums. Chromium smoke testing verifies a real one-page PDF through check, linearize, AES-256 encryption, decryption and final validation before publication.
WASM Zoo v0.16.1
WASM Zoo v0.16.1
v0.16.1 completes the reviewed automatic-candidate contract across all seven currently published WASM Zoo packages without changing any published package binary, upstream pin, builder version, npm version, or immutable package release.
Highlights
- Removed the manual libvips adapter-readiness gate.
- Added fail-closed libvips adapter-bundle resolution.
- The watcher now resolves the exact wasm-vips adapter commit before candidate execution.
- Emscripten source and both libvips/Emscripten compatibility branch heads are frozen to immutable commits before build.
- If wasm-vips has not caught up to a new libvips release, no candidate or promotion PR is created; the daily watcher retries later.
- Both
browser-coreandbrowser-fullmust build and pass browser smoke tests before a review-only promotion PR can be prepared. - Shared promotion rehearsal now covers libvips together with the other automatic packages.
Reviewed-pin model
Automation may detect upstream releases, run isolated candidates, and prepare review-only promotion PRs.
It never automatically:
- merges reviewed changes
- creates package or project tags
- creates GitHub Releases
- publishes npm packages
This project release does not republish or replace any existing package Release or npm distribution.
WASM Zoo v0.16.0
WASM Zoo v0.16.0
v0.16.0 hardens WASM Zoo's reviewed upstream automation path without changing any published package binary, upstream pin, builder version, npm version, or immutable package release.
Highlights
- Added shared offline synthetic promotion rehearsal for every package whose manifest declares
candidateMode: auto. - Added Zstandard stable-release candidate automation for both
browser-coreandbrowser-full, including mandatory bidirectional native-zstd interoperability forbrowser-full. - Preserved the separately immutable published npm identity of
@wasm-zoo/zstd@0.3.0across future reviewed package promotions. - Added the public manifest-driven Automation Contract to the Pages dashboard, showing candidate modes, candidate profiles, review-only promotion paths, and rehearsal coverage.
- Kept Ghostscript source archive identity and SHA-256 metadata together through promotion rehearsal.
- Kept jq's exact Oniguruma submodule pin covered by promotion rehearsal.
- Kept libvips explicitly
adapter-gated; it is not treated as an ordinary automatic promotion.
Reviewed-pin model
Automation may detect upstream releases, run isolated candidates, and prepare review-only promotion PRs.
It does not automatically:
- merge reviewed changes
- create package or project tags
- create GitHub Releases
- publish npm packages
This project release does not republish or replace any existing package Release or npm distribution.
WASM Zoo v0.15.0
WASM Zoo v0.15.0
Zstandard joins WASM Zoo
- Add Zstandard 1.5.7 as the seventh available package.
- Publish browser-core and original upstream CLI browser-full profiles.
- Include corresponding source, checksums, SLSA provenance and CycloneDX SBOM.
npm distribution
- Publish @wasm-zoo/zstd@0.3.0 from the reviewed release.
- Retain the existing Consumer API and immutable release model.
Cross-browser compatibility
- Expand the compatibility lab to seven npm packages.
- Verify 21 real browser operations across Chromium, Firefox and WebKit.
- Publish verified results from reviewed main-branch CI only.
Reviewed upstream pins remain unchanged.
PR merges, release tags and publication remain human-controlled.