This is the largest security release Typdf has had. It combines an audit of every outbound call the module makes with six adversarial re-audit cycles, where each cycle re-examined the previous cycle's fixes instead of moving on. That process repeatedly found fixes that had closed the obvious code path and missed a sibling one.
Security release. Completes the fixes started in 1.2.0-alpha4. A follow-up review found that three of the alpha4 fixes closed the obvious code path but missed a second one — those gaps are closed here, along with a health check that had silently stopped running on modern Drupal.
Anyone on 1.2.0-alpha4 or earlier should upgrade. The first issue below is reachable on a default install.
Security release. Sites running 1.2.0-alpha2 or -alpha3 on the default public file scheme should upgrade — two of the issues below are reachable on a default install.
This release contains everything from 1.2.0-alpha2 and -alpha3, which were tagged but never published as releases. Upgrading straight to alpha4 is the correct path.
Typdf 1.2.0-alpha1 is the first release of the 1.2.x branch — a
substantial security & architecture hardening pass that also makes the module
ready for Drupal 12. It is compatible with Drupal 10.3+, 11, and 12.
This is an alpha release. The 1.2.x branch contains significant
changes (see below); please test in a non-production environment before deploying.
The Typst PDF Engine is a high-performance Drupal module that replaces legacy, memory-heavy PDF generators (like Dompdf or TCPDF) with the blazing-fast, Rust-based Typst compiler. Built from the ground up for the modern enterprise, it achieves 100% Dependency Injection purity, PHPStan Level 8 compliance, and strict adherence to Drupal coding standards.
This is the primary development branch for the 1.0.x series of the Typst PDF Engine.
This branch contains the latest, bleeding-edge features and bug fixes. It is generally stable, but if you are running a production site, we highly recommend downloading the latest tagged Alpha/Beta release instead.