NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
pub.dev · #3122 most downloaded on pub.dev
COS object layer for PDF: tokenizer, parser, filters (incl. CCITT, JBIG2, JPEG 2000), xref machinery, encryption, and serializer. Pure Dart, web-ready.
Last release 3 days ago
05 Oct 2026
Ships on a steady schedule
a new release about every 9 days
Nearly every release is documented
notes for 42 of 43 stable releases
Nothing withdrawn
no release was ever pulled
3 months old
43 releases · first in 2026
One column per month.
Add DartPDF 7.0.0 AppStream release notes
Add DartPDF 7.0.0 AppStream release notes
Describe 6.0.0 in Linux release metadata
Release DartPDF 6.0.0
Describe 6.0.0 in Linux release metadata
Co-authored-by: dart-pdf release automation probe actions@github.com
CosDocument.trimDecodedStreamCache() to release decoded payloads
without closing the document or changing subsequent decode results.Bump the app to 5.1.1+41 and the lockstep package suite to 5.1.1 (dart_pdf_cli 0.2.2, dart_pdf_editor_flutter_gpu 0.4.2, dart_pdf_printing 0.2.2), wit
Bump the app to 5.1.1+41 and the lockstep package suite to 5.1.1
(dart_pdf_cli 0.2.2, dart_pdf_editor_flutter_gpu 0.4.2, dart_pdf_printing
0.2.2), with every runtime inter-package constraint at ^.
This is a patch release: no public API breaks since 5.1.0, and one addition
integrators may see:
Write the 5.1.1 changelog sections from the one commit since app-v5.1.0,
the ink afterimage fix (#986): quick back-to-back ink commits each hid the
previous one on screen until the page re-rendered, because the editing
overlay kept only the latest commit as its afterimage. Commits now
accumulate and retire per page once the raster and annotation layer are
current. The other packages carry a version-bump entry. Dev dependency
ranges (<6.0.0) already admit 5.1.1.
Store notes cover the ink fix and note that 5.1.1 includes 5.1.0's
improvements, written platform-neutral per release-notes/README.md, across
20 iOS locales, 21 Play changelogs (41.txt) and both Linux metainfo copies.
The forms guide now says it applies to 5.1.1.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
Bump the app to 5.1.0+40 and the lockstep package suite to 5.1.0 (dart_pdf_cli 0.2.1, dart_pdf_editor_flutter_gpu 0.4.1, dart_pdf_printing 0.2.1), wit
Bump the app to 5.1.0+40 and the lockstep package suite to 5.1.0
(dart_pdf_cli 0.2.1, dart_pdf_editor_flutter_gpu 0.4.1, dart_pdf_printing
0.2.1), with every runtime inter-package constraint at ^.
This is a minor release: no public API breaks since 5.0.0, with two things
integrators should know:
Write the 5.1.0 changelog sections from the commit bodies since
app-v5.0.0: the P-521 order fix, faster ECDSA, tolerant zlib inflate on
the web, the object-cache key and its side map, T-table AES, web SHA-2,
JPEG 2000, in-place updates on recovered documents, rollbackTo and
openAppended(password:) in pdf_cos; the page-loss fix under a short /Count,
linear page loops, reusable signature crypto cores and onFields in
pdf_document; the flagged masked-image output change, codec v10/v11,
cached luminosity masks, the revision-stable colour context, ICC, colorant
buffer and text-extraction speedups in pdf_graphics; trackpad signatures,
annotation previews, touch row menus, the moved-stamp white box, the web
worker fixes and in-place revisions in dart_pdf_editor; the new overprint
and ICC fixtures. Dev dependency ranges (<6.0.0) already admit 5.1.0.
Store notes cover trackpad signatures, annotation previews, touch row
menus, the moved-stamp fix, the page-loss fix, P-521 signatures and the
speedups, written platform-neutral per release-notes/README.md, across 20
iOS locales, 21 Play changelogs (40.txt) and both Linux metainfo copies.
The forms guide now says it applies to 5.1.0.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
u1*G + u2*Q, and curve
constants parsed once per curve. P-256 verify goes from 11.3 to 1.3 ms
(AOT). Signing uses the same arithmetic and stays byte-identical (RFC 6979).
verifyCertificateChain now verifies each certificate against its issuer
once instead of twice.ZLibDecoder read any bytes after the Adler-32 (a trailing EOL before
endstream) as a second zlib header, failed it and returned nothing for
the whole stream: pages rendered blank, fonts went missing, and
CosCompactor (Reduce file size) re-deflated the empty result into the
file. The new inflateZlib stops at the final block, as zlib does, and
FlateFilter uses it. CosCompactor inflates strictly (header, length and
Adler-32 checked) and never replaces a payload of more than 16 bytes with
an empty one. The VM path is unchanged.objectNumber * 65536 + generation) clustered in the VM's int hash, so
whole-graph walks spent most of their time probing: PdfCompressor.optimize
runs 0.39-0.69x and applyRedactions about 0.31x on 14k-37k-object files.
References the packed key cannot hold exactly (an object number of 2^32 or
more, as an edit on a file with a junk /Size allocates, or a generation
over 65535) are cached in a side map, which also stops n 65536 R
resolving to object n+1.applyIncrementalUpdate now folds edits into a document opened through
xref recovery instead of refusing it, so each edit no longer re-runs a
full-file recovery scan. The recovery scan itself is one pass for both
obj and trailer (0.56-0.61x on large files).CosDocument.rollbackTo(length), which takes a document back to an
earlier revision it folded in with applyIncrementalUpdate, in place,
keeping the caches of objects the undone updates did not touch. It returns
null, changing nothing, when that length is not journaled.CosDocument.openAppended accepts an earlier revision's prefix as well as
an append, and takes a password for revisions it cannot donate keys to.
It donates the security handler only while the revision's /Encrypt matches
the dictionary the keys were derived from, entry for entry, so a revision
that re-keys /Encrypt under the same object number authenticates its own
password.ContentOperationCursor.nextOperator and takeOperation, and
CosTokenBuffer.keywordCode, so an interpreter can dispatch short
operators on an int code and read numeric operands without allocating
operation objects. nextOperation and parse keep their contract, and
materialized operands follow the same int-or-real rule on the web as on
the VM.PdfPerf counters for glyph outline builds and the overprint colorant
buffer (glyphOutlinePaths, colorantBufferPages, colorantDraws,
colorantRasterized, colorantBackdropReads, colorantGroups).Roll the Unreleased sections over with Breaking changes subsections and migration notes, and write the ones the batch never got: AF* scripts, comb/Max…
Bump the app to 5.0.0+39 and the lockstep package suite to 5.0.0
(dart_pdf_cli 0.2.0, dart_pdf_editor_flutter_gpu 0.4.0, dart_pdf_printing
0.2.0 - their dependency majors moved under types they expose). This is a
major release because public behaviour and API changed incompatibly since
4.5.0:
Roll the Unreleased sections over with Breaking changes subsections and
migration notes, and write the ones the batch never got: AF* scripts,
comb/MaxLen/password fields, XFA detection, encrypted signing and tab
order in pdf_document; openAppended in pdf_cos; the /ImageMask box filter,
justified-text reflow spaces and multi-select field context in
pdf_graphics; the form-layer, secret-store, Tab navigation and
thumbnail drag-out work in dart_pdf_editor; multi-select values in the
CLI; the print range and copies fixes in dart_pdf_printing; the new
fixtures. Dev dependency ranges on workspace packages now admit <6.0.0 so
the workspace resolves and publishing still accepts the hosted 4.5.0.
Store notes cover form calculations and checks, Tab and multi-select,
password fields kept out of the file, field creation, signing encrypted
PDFs, revocation checks with EU/Adobe trust lists, and Calibri via
Carlito, across 20 iOS locales, 21 Play changelogs, and both Linux
metainfo copies. The forms guide now says it applies to 5.0.0.
Co-Authored-By: Claude Opus 5.5 noreply@anthropic.com
StandardSecurityHandler.decryptObjectGraph (and encryptObjectGraph)
now leave a signature dictionary's /Contents untouched, as ISO 32000 7.6.1
requires (StandardSecurityHandler.isSignatureContents: /Type /Sig or
/DocTimeStamp, or a dictionary with a /ByteRange when /Type is missing).
Code that decrypted /Contents itself after loading must stop doing so - the
loader now hands over the raw CMS bytes.OcspResponse.responderFor), and
OcspResponse.forCertificate matches the whole CertID. Responses that used
to pass on a serial match alone, or from an unauthorized responder, are now
ignored.X509Certificate gained members (listed below). Only classes that
implements X509Certificate need to add them.CosDocument.openAppended, which reopens a document after appended
updates and reuses its already-authenticated security handler (while the
/Encrypt object is unchanged), so follow-on revisions of an encrypted file
do not need the password again.OcspResponse.forCertificate matches
the whole CertID (serial, issuer name hash and issuer key hash) instead of
the serial alone, a delegated responder must be issued and signed by the CA
and carry id-kp-OCSPSigning (responderFor), and the nonce extension and
revocation reason are parsed (nonce, echoesNonce, ocspNonceValue).X509Certificate exposes extendedKeyUsages, isCa, hasOcspNoCheck and
isValidAt, and now reads the RSA key of an id-RSASSA-PSS certificate.issueCertificate can add OCSP (AIA), CRL distribution point, extended key
usage and ocsp-nocheck extensions, and can issue a subordinate CA (isCa).Bump the app to 4.5.0+38 and the lockstep package suite to 4.5.0 (dart_pdf_cli 0.1.8, dart_pdf_editor_flutter_gpu 0.3.4, dart_pdf_printing 0.1.1). Not
Bump the app to 4.5.0+38 and the lockstep package suite to 4.5.0
(dart_pdf_cli 0.1.8, dart_pdf_editor_flutter_gpu 0.3.4, dart_pdf_printing
0.1.1). Nothing public was removed or changed incompatibly since 4.4.0 -
showPdfShellViewOptionsSheet lost its reflow/pageGrid parameters, but it is
not exported - so this is a minor release.
Roll the Unreleased sections over and write the ones the 4.4.0..HEAD batch
never got: WinAnsi widths and the DocMDP P=1 signing refusal in pdf_document,
CJK selection metrics in pdf_graphics, selection continuity, the stroked-text
floor, stem darkening and the page-grid State fix in dart_pdf_editor.
Store notes cover What's new, the Linux antialiasing fix, exported pages
opening in a tab, the view-mode picker, metric-compatible standard-14
substitutes, and selection and stroked-text fixes, across 20 iOS locales,
21 Play changelogs, and both Linux metainfo copies.
Co-Authored-By: Claude Opus 5 noreply@anthropic.com
Storeflight and release-app.yml both created the release for an app-v tag. Storeflight pushes that tag, so its own delivery and the workflow the tag s
Storeflight and release-app.yml both created the release for an app-v tag.
Storeflight pushes that tag, so its own delivery and the workflow the tag
starts were racing to own the same release, and would have attached two sets
of assets for the same platforms under different names.
Storeflight wins, with one exception it cannot cover. A release artifact
there is a single path per platform, and Linux ships two user-facing files -
the portable tarball and the AppImage. Dropping either is not an option:
publish-flatpak.yml downloads dartpdf-linux-x64.tar.gz from the release by
name and verifies its digest, so the Flatpak publisher fails a step later
without it.
So release-app.yml stops creating a release and contributes only the two
Linux assets. It waits for Storeflight's release rather than creating one,
because publishing the tag is what starts it and it can arrive first;
creating one there would be the same race with the roles reversed. It also
asserts the tarball is present under the name the Flatpak publisher looks
for, so a rename fails here rather than ten minutes downstream. The job now
needs only the Linux build, since waiting on the other six delayed that input
for no benefit.
publish-flatpak.yml waits for the asset for the same reason: two workflows
started by one tag have no ordering between them, and an asset still
uploading is not a missing build.
Co-Authored-By: Claude Opus 5 noreply@anthropic.com
Claude-Session: https://claude.ai/code/session_01RNNTEpKG3vAEwMYMvghdvx
Add 4.3.0 Linux release metadata
Add 4.3.0 Linux release metadata
CosCompactor, retaining predictor
data and parameters. Preserve cyclic indirect arrays and PDF 2.0 headers.Lockstep minor release aligned with dart_pdf_editor 4.2.0. No public COS object model, filter, or parsing changes since 4.1.0.
dart_pdf_editor 4.2.0. No public COS
object model, filter, or parsing changes since 4.1.0.Treat holes in sparse progressive byte sources as cache misses tied to the source buffer, avoiding invalid scan recovery and stale reads while remote
archive to 4.2.0.Decode TIFF Predictor 2 streams with 16-bit samples, preserving carries between bytes and restoring high-bit-depth images correctly.
pdf_cos
public API remains source-compatible with 3.8.0.Add the public monotonic CosDocument.revision, incremented after every successful incremental update so higher layers can invalidate derived caches wi
CosDocument.revision, incremented after every
successful incremental update so higher layers can invalidate derived
caches without comparing object identity.Lockstep minor release to align the dart-pdf package suite at 3.7.0. No public pdf_cos API changes since 3.6.0.
pdf_cos API changes since 3.6.0.Lockstep minor release to align the dart-pdf package suite at 3.6.0. No public pdf_cos API changes since 3.5.1.
pdf_cos API changes since 3.5.1.Decode JBIG2 refined text symbols, including refinement deltas, offsets, and shared arithmetic contexts, so scanned MRC text layers render correctly.
Add PdfSourceLoadOptions.completeFirstPaintPageTree. Progressive preview callers can stop the initial page-tree walk after firstPaintPages, avoiding o
PdfSourceLoadOptions.completeFirstPaintPageTree. Progressive preview
callers can stop the initial page-tree walk after firstPaintPages, avoiding
one range request per leaf before page one can paint; the default remains the
correctness-first complete walk for existing callers.Lockstep minor release to align the dart-pdf package suite at 3.4.0. No public pdf_cos API changes since 3.3.1.
pdf_cos API changes since 3.3.1.Lockstep patch release to align the dart-pdf package suite at 3.3.1. No public pdf_cos API changes since 3.3.0.
pdf_cos API changes since 3.3.0.Lockstep minor release to align the dart-pdf package suite at 3.3.0. No public pdf_cos API changes since 3.2.0.
pdf_cos API changes since 3.2.0.Lockstep minor release to align the dart-pdf package suite at 3.2.0. No public pdf_cos API changes since 3.1.1.
pdf_cos API changes since 3.1.1.Lockstep patch release to align the dart-pdf package suite at 3.1.1. No public pdf_cos API changes since 3.1.0.
pdf_cos API changes since 3.1.0.Lossless structural compaction: new CosCompactor/CosCompactionResult rewrite a document's reachable object graph, packing non-stream objects into comp
CosCompactor/CosCompactionResult
rewrite a document's reachable object graph, packing non-stream objects
into compressed object streams behind a PDF 1.5 xref stream and
re-deflating streams stored uncompressed (kept only when smaller).
CosDocumentBuilder gains an objectStreams: mode (W [1 4 2]). The
user-facing entry point is PdfEditor.compress() in pdf_document (#368).cp_reduce
level when an image is displayed far below its native size, instead of
decoding full resolution and downscaling (#525)./JBIG2Globals decode once, not per image (#532).Lockstep major release: a breaking change in dart_pdf_editor moves the whole suite to 3.0.0. pdf_cos's own public API is unchanged.
Lockstep major release: a breaking change in dart_pdf_editor moves the whole
suite to 3.0.0. pdf_cos's own public API is unchanged.
CosDocument so a stream inflated once (xref
reconstruction, content parsing, image extraction) is not re-decoded on the
next access (#392).Append incremental saves to the existing bytes instead of rebuilding the whole file: CosUpdater.saveTail() returns only the new tail (the appended obj
Append incremental saves to the existing bytes instead of rebuilding the
whole file: CosUpdater.saveTail() returns only the new tail (the appended
objects, xref, and trailer), so an incremental revision costs the size of
the change rather than the size of the document. Save cost no longer scales
with the base file - a guard test pins that a 2.78x larger base does not
make a same-sized edit 2.78x more expensive (#413).
Memoise the per-object decryption key so a page's streams and strings derive it once per object rather than once per access, cutting repeated MD5/AES key derivation on encrypted documents (#400).
Speed up CCITT G3/G4 decoding by ~4x on dense scanned pages: a monotonic cursor for the 2-D reference-row scan (was O(transitions^2) per row), peek-once prefix tables for run and mode codes, byte-run span fills, and a byte-at-a-time bit reader. The JBIG2 MMR path, which reuses the same decoder, gains a byte-at-a-time bitmap unpack. Output is byte-identical on well-formed, malformed, and truncated input, locked by golden digests captured from the previous implementation (#398).
Major version bump for the 2.0.0 package suite. A breaking API change in dart_pdf_editor moves every package to 2.0.0 in lockstep; the COS object mode
dart_pdf_editor moves every package to 2.0.0 in lockstep; the COS object
model, syntax, and (de)serialization API is source-compatible with 1.4.7.PdfByteSource) for progressive PDF
loading: the reader pulls ranged slices on demand instead of requiring the
whole file up front, so remote and large local files can paint their first
page before the full download or read completes (#328, #359).EcPrivateKey.generate, deterministic RFC 6979 ecdsaSign, the X.509
v3 builders buildSelfSignedCertificate / buildCaCertificate /
issueCertificate, and ecSubjectPublicKeyInfo / pemEncode for
Sigstore/Fulcio (#322, #337, #355).CosXrefReader from
CosDocument, move the encryption object-graph walk behind the security
handler, share file-tail framing between the builder and updater, and dedupe
ObjStm header parsing between recovery and the stream decoder.Version bump to keep the dart-pdf package suite aligned at 1.4.7. No COS API changes since 1.4.6.
Version bump to keep the dart-pdf package suite aligned at 1.4.6. No COS API changes since 1.4.5.
Version bump to keep the dart-pdf package suite aligned at 1.4.5. No COS API changes since 1.4.4.
Version bump to keep the dart-pdf package suite aligned at 1.4.4. No COS API changes since 1.4.3.
Version bump to keep the dart-pdf package suite aligned at 1.4.3. No COS API changes since 1.4.2.
Version bump to keep the dart-pdf package suite aligned at 1.4.2. No COS API changes since 1.4.1.
Speed up dense content parsing with byte-level real-number parsing, operator interning, and streaming content-token handling.
Version bump to keep the dart-pdf package suite aligned at 1.4.0. Low-level parser, writer, filter, and crypto maintenance supports the higher-level e
Version bump to keep the dart-pdf package suite aligned at 1.3.2. No COS API changes since 1.3.1.
Add ContentStreamSerializer for writing parsed content-stream operations back to PDF syntax, including inline-image (BI/ID/EI) operations.
ContentStreamSerializer for writing parsed content-stream operations
back to PDF syntax, including inline-image (BI/ID/EI) operations.Nothing published for this version
Version bump to keep the dart-pdf package suite aligned at 1.2.3. No COS API changes since 1.2.2.
Version bump to keep the dart-pdf package suite aligned at 1.2.2. No COS API changes since 1.2.1.
Add a package example for pub.dev scoring.
Version bump to keep the dart-pdf package suite aligned at 1.2.0. No low-level COS API changes since 1.1.0.
Performance: a faster content-stream tokenizer. This is the heart of the render-speed work that puts dart-pdf ahead of PDFium on the benchmark corpus.
First stable release. Changes since 0.1.0:
First stable release. Changes since 0.1.0:
COS object model: dictionaries, arrays, names, strings, streams, references.
Initial release.
endobj, junk before the header, broken xref chains with object-scan
recovery).Your coding agent can read these notes before it upgrades. Set up the MCP server →