Security and dependency review — September 9, 2026 UTC
Follow-up action and parser maintenance
A fresh GitHub audit across all seven repositories finds zero open Dependabot security alerts, without dismissals. Routine grouping/scheduling and separate security updates remain enabled.
pptx.dev PR #23 merged as 5c862d23c39f330e4fccdaa5a45bd053ae86a1dc, tree-identical to reviewed 52a51d49f2d01ebc048d2b365d412f3bce9a0cca. It pairs immutable upload-artifact 7.0.1/download-artifact 8.0.1 refs with normal multi-file ZIP behavior and fatal digest mismatch checks. CI 34315591982 builds real Python wheel/source distributions, uploads/downloads them, verifies complete names and SHA-256 hashes and runs Twine checks on Linux/Windows. Both transport jobs, full application CI 34315591938 and Bugbot pass. The absent sdk/mcp publisher scaffold is retired; hosted HTTP MCP remains. Dependabot PRs #16/#17 are closed as superseded. No publishing workflow was dispatched or package released.
PPTX PR #12 merged as 9c0abf1d6f296a62322fac7c4ef5c91d025a3705, tree-identical to reviewed 5016051b45bb35a5d02591cc720a82dda95eae6e. It synchronizes only the lockfile to fast-xml-parser 5.11.1 and its declared helpers, including entities 3.0.0. The existing semver range already permits this graph, which the fresh published 0.5.1 consumer used for registry/native checks also resolves. All four Linux/Windows Node 20/24 CI jobs 34307685202 pass clean install/audit, full converter, packed-consumer and real Chromium tests. Published package versions and immutable release verification refs remain unchanged; do not republish 0.5.1.
pptx.dev browser PR #22's initial review found missing active-draft commits in source export/copy/save and send actions. The follow-up uses the current editor snapshot and commits before canvas unmount; real browser tests activate exports, copy and a local metadata request without relying on pointer blur. The claimed SVG script/data-link injection is not reproduced: the pinned renderer restricts link/image protocols, escapes text/attributes and validates embedded font CSS. A real-browser regression verifies hostile shared Inspector, Author import-preview and mounted-canvas documents stay inert, with safe HTTPS links retained. All four local and exact-preview tests pass on candidate c18b1fdd5d5e5e2e10b259957ba678def598a2ac. Renewed Linux/Windows CI 34316394032 and Bugbot pass; all review threads are resolved. Merge fa94477f8fceb8bb1a0d62fa23d7e0d05423e94a is deployed as dpl_4bQ6pSkG7kiCw8FNAPuEx9RtumTS. All four public tests pass, all 33 deployed font files/licenses verify against the registry package, and the actual production download passes native PowerPoint edit/save/reopen/reimport. See the current handoff and portable docs/evidence/pptx-dev-browser/ reports.
Monaco, Commander, js-yaml and core schema-generator/TypeScript majors remain explicit separate compatibility reviews, as described below. Unrelated site PR #4 and pptx.dev PR #6 are preserved. Vercel redundant-comment settings still require the previously requested browser passkey sign-in; no protection or notification setting has been changed.
Current production and compatibility checkpoint
Core PR #33 merged as 188c32333a903fed9058d781caaaae4cd10b3d28 after package CI 34309217317, coordinated Node 20/24 CI 34309217315 and Bugbot. Published PPTX 0.5.1 is now pinned in the release plan and immutable verification refs. The local preview-packer correction also passed renewed coordinated checks.
All three production deployments now adopt 0.5.1 and have real Edge verification. Website merge 680be53dd69d99701f8b3f21e7e1c0f9b5f9390f / dpl_9aR19f8JG7GHDukBnTLQv4b2hhTm passes four public tests. Gallery PR #21 merge 2ea8ccb75b9a6d9b64a93e6ec36d78100c044f8a / dpl_5cooy8gD6MrZXu5vDDXNNxkBpFjN passes deployed asset hashes and both browser tests after CI 34309168015 and Bugbot. pptx.dev PR #21 merge f1f9e700ae2648467b36baf22b3393a216b78780 / dpl_wkf6fiWCeyW1E562zHFU9RXwM92X passes both public inspector/toolkit browser tests after Linux/Windows CI 34309892749 and Bugbot. Its clean frozen install, audit, 591 tests, typecheck and full build pass. The application retains the narrowly scoped image-size removal override for its separate legacy PptxGenJS generator. OPF 0.5.1 itself no longer needs that override.
Pending pptx.dev upgrades were inspected individually and left unmerged with evidence: Monaco #18 fails worker resolution following changed public exports; Commander #19 requires Node >=22.12 while the CLI supports Node 20; js-yaml #20 fails codec/API tests after the version 5 export change. These require migrations and relevant consumer/browser checks. Current patched dependencies audit clean. Remaining action upgrades and the obsolete MCP publishing workflow need separate maintenance. Vercel comment configuration still awaits browser passkey sign-in; no security alert was dismissed or hidden.
The deployment checks establish package adoption and the documented OPF flows. They do not establish complete browser PPTX transfer controls or broad native PowerPoint raster equivalence. The main pptx.dev renderer/exporter integration remains open. Historical checkpoints below preserve the earlier evidence.
Latest verified production checkpoint: pptx.dev PR #15 merged as 06ebef116608110fa88ac98cbcd6fe8ea6ad76f1, from reviewed aad6b5ce29dc4ed5b03a7982121ff4a7ea4543bc. Linux/Windows CI 34304827786 and Bugbot pass; the standalone/adapter finding is fixed and resolved. Preview E2E passes. Production dpl_638zt5oC7grWNTYEXL3XM4cFMbGE is READY on the merge and aliases www.pptx.dev, pptx.dev, api.pptx.dev and mcp.pptx.dev. The same real Edge inspector author/preview/edit/undo/redo/OPF-download/shared-reimport test passes against https://www.pptx.dev. GitHub open Dependabot alerts now total zero without dismissals. SDK/CLI consolidation is complete for this baseline; main custom renderer/exporter adoption remains open.
Core security PR #30 merged as 6967b037c934c665e312086e232545cb71753bcf after successful package 34304887858, portability 34304887838, coordinated 34304887865 and Bugbot checks. Renderer PR #7 merged as ad59248ad8dbf11e519c1ba75e95d6d3fa4a39ed (CI 34305311878); editor PR #6 merged as aeb2871ba381bf97656e58418b5271ec764ed0d5 (CI 34305316921), both with renewed Bugbot review and clean audit. Their new weekly groups and unfiltered audit gates do not change published versions. Historical PPTX 0.5.0 has two high audit findings via image-size; the compatible 0.5.1 removal is verified below. The suggested downgrade to PptxGenJS 1.1.5 was not applied.
The September 8 audits are historical. Newly indexed advisories require a refreshed audit of each actual lockfile; no advisory has been ignored or dismissed.
PPTX 0.5.1 and refreshed alert state
Website PR #16 merged as 680be53dd69d99701f8b3f21e7e1c0f9b5f9390f; CI 34308522871, Bugbot and all four production Edge tests pass. Deployment dpl_9aR19f8JG7GHDukBnTLQv4b2hhTm serves the new changelog and verified showcase manifest. Gallery PR #21 and pptx.dev PR #21 hold their follow-up 0.5.1 adoption candidates. The latter passes a clean frozen workspace installation, audit, all 591 tests and typecheck while retaining its legacy-generator removal override.
The core coordinated CI found that the local preview staging builder excluded vendor files. Its fix copies all declared literal payloads, checks contained staging paths and invokes npm portably on Windows. Fresh preview tarball consumers pass on Node 20/24; these local previews remain distinct from published registry evidence. The registry package itself includes the required code and license and was unaffected by this staging omission.
PPTX PR #11 merged as f7f30082da3568a4f911d42493ffc75c77dd4e14 after Linux/Windows Node 20/24 CI 34307186304 and Bugbot pass. It removes unused image-size from ordinary npm consumers by shipping the exact licensed and hash-verified PptxGenJS 4.0.1 ESM runtime, with JSZip declared directly. Fresh packed installations audit clean. npm does not audit vendored source as an installed upstream package; provenance and upstream advisory review are explicit maintenance requirements. All 126 corpus PPTX files match the actual 0.5.0 registry release with controlled images/fonts; real Edge checks and three-slide native PowerPoint edit/save/reopen/raster checks pass. Portable evidence.
Trusted publication 34307645895 succeeded for tag opf-pptx-v0.5.1, published at 2026-09-09T03:37:39.613Z. Fresh Node 20/24 coordinated installations and full pinned fidelity suites pass. The fresh consumer has zero npm vulnerabilities; npm audit signatures verifies 64 registry signatures and 15 attestations. Actual registry native PowerPoint edit/save/reopen and raster checks pass. Do not republish. A fresh GitHub audit of core, renderer, PPTX, editor, website, gallery and pptx.dev finds zero open Dependabot alerts without dismissals. Existing registry version 0.5.0 retains its historical dependency graph.
Core PR #31 updates supported Node 20 declarations to 20.19.43 and merged as 47190652f436e80fa5dd0a947bc1ceeb6db709ff after package, coordinated and Windows/macOS CI. Website action PRs #12/#13 passed renewed combined checks and merged. Gallery PR #20 merged as d01cbfc24855d5e41adc6e092841554196a3e9cb after full CI 34307438488, consolidating and closing PRs #16/#17/#18. Its sole review finding incorrectly claimed the pnpm pin did not exist; the live official annotated tag and successful exact-head run establish otherwise, and the thread is resolved.
Core build dependencies and portability
Scoped overrides select js-yaml 4.3.2 for the merge-key CPU advisory and esbuild 0.28.2 for the Windows development-server file-read advisory. Core CI now runs unfiltered pnpm audit. These are build dependencies; published core 0.7.0 and CLI 0.5.0 remain immutable and are not republished.
The CLI portability workflow uses the same reviewed immutable checkout 7.0.1, setup-node 7.0.0 and pnpm/action-setup 6.1.0 refs as package CI. .gitattributes preserves LF for text on Windows: CRLF checkout conversion changed indexed preview byte counts and prevented Markdown fenced-example discovery. Existing source text has no semantic changes. A fresh checkout applies this policy automatically.
Windows Node 20 and 24 both pass core/CLI typechecks and complete tests: 406 core tests, composition/pagination/data/rich-text/list checks, 11 installer tests and 69 CLI command checks. Text/spec integrity and all 126 examples pass. Lint exits successfully with pre-existing warnings. The unfiltered workspace audit reports no known vulnerabilities. Full core tests now also run in the existing Windows/macOS portability matrix, making preview-byte and documentation-example checks repeatable on clean checkouts. A file-symlink case still requires Unix CI because this Windows account lacks that optional privilege; junction and other installer safety cases run locally.
Node type declarations stay on the minimum supported runtime, Node 20. Dependabot PR #15 proposed Node 26 types and was closed with that rationale. Only routine major version updates for @types/node are limited, using version-update:semver-major; no dependency version or security advisory is ignored. Weekly minor/patch groups and separate security groups remain enabled. TypeScript 7 PR #16 is deferred because tsup's declaration bundler depends on removed legacy TypeScript APIs; the reproducible failure is recorded on the PR.
Schema generator major review
PR #13 (beb1e56f3755349cd03b5e78491e6f3eaac0a858) changes json-schema-to-typescript 15 to 16. A direct comparison of all twelve generated type files finds eleven byte-identical files. presentation.ts removes the unrestricted string index signature from ContentPayload and adds a gradient-stop comment. The stricter content type agrees with the schema's existing additionalProperties: false, but may reject consumers that relied on the older declaration. Candidate core/CLI typechecks pass. Keep this major separate from the security patch; integration and consumer declaration compatibility must be reviewed before merging it into the next release. The current YAML override resolves the advisory without requiring that type API change.
Public application security deployments
- Website PR #15: reviewed
592092d51ac9e7d1724c87851176d649add531dc, merged2f1b5428a06079e70f3ad67653768fa55a8c463c. CI34303539609and Bugbot pass. Productiondpl_Bdxr6u3j6rdEjp9fJP9RbLp4f2pSis READY on that merge and aliases both public domains. Four real Edge tests pass againsthttps://www.openpresentation.org: complete skill files and copied installer command, published changelog, mobile layout and exact showcase downloads. - Gallery PR #19: reviewed
afec055b1f8361fd1b1d10fb5a0ec3e1a929f504, merged7d661c074a73dc81487a713a2af040246e62a097. CI34303548885and Bugbot pass. Productiondpl_3GbDE7grPv3zCyCzfzhgAKuCuTsgis READY on that merge. Two real Edge tests pass againsthttps://pptx.gallery: deployed editor bundle hashes and JSON authoring, styled-table preview, inline edit/undo/redo, OPF download and reimport.
Both applications use Next.js 16.3.4 and have clean isolated audits. Gallery also uses patched Vitest 4.1.11 and js-yaml 3.15.2. For either checkout nested inside another pnpm workspace, use pnpm audit --ignore-workspace to audit its own lockfile. Do not use that flag in pptx.dev: its app, TypeScript SDK and CLI share a real root workspace.
pptx.dev PR #15 is merged and its production baseline is verified as recorded above. Its 591 unit tests and anonymous inspector browser flow pass on Linux and Windows, with SDK lockfile consolidation and the Next.js standalone/adapter fix included. The main preview/export still use custom implementations. Existing OPF browser tests, registry rendering tests and three-slide native PowerPoint evidence do not establish full browser PPTX coverage or broad native raster equivalence.
PPTX 0.5.1 integrity: sha512-iXUW3ex9fMunbTuk0L+3BCU32g5oHkuZ7JLXyeteRrW3BaVtK4xagN0/4AAh0htXOgRj1NT+412u5jCwQCHS8w==. Fresh registry reports: Node 20 fidelity, Node 24 fidelity, native source provenance, PowerPoint edit/reopen, measured comparisons and reimports. Release verification now includes the installed vendor directory, and clean npm tests revalidate cached metadata so a just-published version is visible.