{"_id":"pdfnative-cli","_rev":"10-1e0f9aaec9fc37a4b68262b789ce2855","name":"pdfnative-cli","dist-tags":{"latest":"1.5.0"},"versions":{"0.0.1":{"name":"pdfnative-cli","version":"0.0.1","keywords":[],"author":"","license":"ISC","_id":"pdfnative-cli@0.0.1","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"dist":{"shasum":"477053e7c3af843e83db01c8c0ac266eaa0159c4","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-0.0.1.tgz","fileCount":1,"integrity":"sha512-6RmPuX1d9XnkEWnnCKearuR3aatDFpxiVS3A6zfEhddFbuo4UsKqWJubvttgYoCAB3uRrBB34DL2zrPy1iH5zg==","signatures":[{"sig":"MEQCIEvkU6px85tOdcYYjYA5ncXfEVH/CQXv8rTNEBl7nkt4AiBCBY4rOepjub+wrNHNIJS1gtf/DX8zbXMWR15gIiZ/hg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":266},"main":"index.js","gitHead":"762f3f23eb5fe1ff926af479672871a5126cd275","scripts":{"test":"echo \"Error: no test specified\" && exit 1"},"_npmUser":{"name":"nizoka","email":"nizoka@plika.app"},"_npmVersion":"10.9.2","description":"Temporary placeholder for pdfnative-cli","directories":{},"_nodeVersion":"22.17.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_0.0.1_1777276954099_0.7499722511553588","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"pdfnative-cli","version":"0.1.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","command-line"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@0.1.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"c114aa4f46930964a988988ecf145338c68bcf2a","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-0.1.0.tgz","fileCount":9,"integrity":"sha512-5ZcMzf79xj2gWEcfmff155+7dSGk6U08bfhzazFtm3QJ5ytGg0q9ByldZGiwWzFvI0n/yQBr5SxnLZShWWEJgA==","signatures":[{"sig":"MEQCIALNaTkHtKE535bZJSzZva02c1hLDFvzEuFIgqgM+xToAiA19AeVvoscXq/7q1n8s4tkXyTBpE5ulNfFaMUuYTFXRw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":136789},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"d07d8f1e0b3da1cddacfb20906d4bb5c69f8f19d","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.11.0","description":"Official CLI for pdfnative — render JSON to PDF, sign, and inspect. Zero extra runtime dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","dependencies":{"pdfnative":"^1.0.4"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^2.1.9","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.57.2","@vitest/coverage-v8":"^2.1.9"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_0.1.0_1777311716816_0.23924685803928747","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"pdfnative-cli","version":"0.2.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","command-line"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@0.2.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"c5b2cc1aee404a2bec25958917c606c99142a373","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-0.2.0.tgz","fileCount":9,"integrity":"sha512-EXkdPs+0xVyDm9XxCIXDUj/rLXmHFIYg2FQ+Qu1N9Ic+LPf38m+dA1guoiVcG+MB93H0DOlF55c0VNPsDdcs4Q==","signatures":[{"sig":"MEYCIQCbielGAOo11gTtF5nq3/eS2QS8Lu6cs7M8klUNPIzh9gIhAMEtRHIpBLcD4LbxDlO4ZjxXQGorq1IyjL7dxWKIoptp","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":417605},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"8e4f6f05a5f6def484667677ee77973b33ba5def","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.11.0","description":"Official CLI for pdfnative — render JSON to PDF, sign, inspect, and verify. Zero extra runtime dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","dependencies":{"pdfnative":"^1.0.5"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^2.1.9","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.57.2","@vitest/coverage-v8":"^2.1.9"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_0.2.0_1777377513980_0.6929668106407298","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"pdfnative-cli","version":"0.3.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","pdf-watch","command-line"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@0.3.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"8c5774ecc27e9ebe924dab95df8af92b8c57b9b1","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-0.3.0.tgz","fileCount":9,"integrity":"sha512-oG0HdNdpXPowWLaz1fi/D9e/eLXGTKR3Xgc9CpJ9FHaE7J/TEst5tzqwRli91NfSA05fOqmbreqS65k5OiN+8A==","signatures":[{"sig":"MEYCIQDGkOi0Ld7uNQHQzOyl1AkbfkJtYFozSM86AMpAfYsC9QIhAKVVVgUKzjlINokPhKm6Wi6xQsslNbX44knBKRrMzk+C","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@0.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":653314},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"c8cf1f7599895f96503f00cc5bf2c3a741e124f7","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.11.0","description":"Official CLI for pdfnative — render JSON to PDF, sign (RSA + ECDSA), inspect, and verify CMS signatures. Zero extra runtime dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"24.14.1","dependencies":{"pdfnative":"^1.1.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^2.1.9","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.57.2","@vitest/coverage-v8":"^2.1.9"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_0.3.0_1778017459293_0.16979604461131137","host":"s3://npm-registry-packages-npm-production"}},"1.0.0":{"name":"pdfnative-cli","version":"1.0.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@1.0.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"4d81ae6a2e9b3fe59457775197f64d813173fb9c","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-1.0.0.tgz","fileCount":9,"integrity":"sha512-e3UAs6xPlV2DRsLgA+rYMLMH2vY7FaHeI0LQYMVouQ0LSFZ5oL0MhN9siiCG/yndiZfl2MNp+/ExJLoPQrk7JA==","signatures":[{"sig":"MEUCICVGMMqP32iys7rkiCS0iYcWc8RnBxRWKXPSSjsxfjLXAiEA2B1bV0uC71xjwLU22UmXdfEDeW1IrwJNI0DMFt9W1yc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@1.0.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1007603},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"e641bb5ed10efd13aa20448770283f297a65cebb","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.13.0","description":"Official CLI for pdfnative — render JSON to PDF, sign (RSA + ECDSA), inspect, and verify CMS signatures with LTV (RFC 3161 timestamps, OCSP, CRL). Zero extra runtime dependencies.","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"pdfnative":"^1.2.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^4.1.7","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^4.1.7"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_1.0.0_1780151738329_0.763321057346916","host":"s3://npm-registry-packages-npm-production"}},"1.1.0":{"name":"pdfnative-cli","version":"1.1.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line","pdf-ua","accessibility","colr","color-emoji","unicode","text-shaping","opentype","bidi","streaming","telugu","sinhala","khmer","myanmar","tibetan","amharic","ai-agent","agentic","automation","json-output","json-schema","sbom","supply-chain"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@1.1.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"f13090bda8a9368e87ac2546b988b5829080eda3","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-1.1.0.tgz","fileCount":9,"integrity":"sha512-ITyX6gbZQ1WeKnEDMCxkkvx3WzsKsBkwcOqXlCXkIyEcsDGPWUr3uKfPEmq3WXySGcRoei/O5aihrYiQsZmuCA==","signatures":[{"sig":"MEUCIDYDo2jwJ2x0Hbd4y/DTndowhGTvYVLawE5u0TRCLKFlAiEA88Tfg4HTFVYUFYzKWo67Mhol0WWov+7wHcotWJx0nnE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@1.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1173012},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"c329762d38aaf71dc1631c75f06191ad0a18e7b4","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"overrides":{"esbuild":"^0.28.1"},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.13.0","description":"Official CLI for pdfnative — render JSON to PDF (22 Unicode scripts, COLRv1 colour emoji, true constant-memory streaming), sign (RSA + ECDSA), inspect, validate PDF/UA, and verify CMS signatures with LTV (RFC 3161 timestamps, OCSP, CRL). Zero extra runtim","directories":{},"sideEffects":false,"_nodeVersion":"24.16.0","dependencies":{"pdfnative":"^1.3.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^4.1.7","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^4.1.7"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_1.1.0_1781422833826_0.264716028343164","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"pdfnative-cli","version":"1.2.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line","pdf-ua","accessibility","colr","color-emoji","unicode","text-shaping","opentype","bidi","streaming","telugu","sinhala","khmer","myanmar","tibetan","amharic","ai-agent","agentic","ai-governance","hitl","human-in-the-loop","automation","json-output","json-schema","sbom","supply-chain","pdf-merge","pdf-split","pdf-extract","merge","split","annotate","annotations","markup-annotations","bookmarks","outline","page-labels","layout-inspection","math-symbols"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@1.2.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"7f0d4dec7dd29f7d04e36763c49c228cadb0de4d","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-1.2.0.tgz","fileCount":9,"integrity":"sha512-prlmqjjCrQhqscVjHV2e1Up8DmRFWqeRCNvW8/WGDtXt1woX9lGoOFbfDaHF/3lhU6JqZPyOsr50UMnNvBkZ9g==","signatures":[{"sig":"MEUCIE3qDRh1iu7i80hPDcQqZZnPFrAjqsp3d+LAPHU4F/84AiEA5f9hkWxVuTxgrlz3tI+NPyIx2K//0QIhepfWxRSr3fA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@1.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1443844},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"df5eb405418af3ab136835823320250af7d12505","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"overrides":{"vite":"^8.0.16","esbuild":"^0.28.1","js-yaml":"^4.3.0"},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.16.0","description":"Official CLI for pdfnative — render JSON to PDF (22 Unicode scripts, math symbols, COLRv1 colour emoji, bookmarks/outline, true constant-memory streaming), merge/split/extract pages, annotate (markup annotations), sign (RSA + ECDSA, native constant-time c","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"pdfnative":"^1.5.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^4.1.7","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^4.1.7"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_1.2.0_1783364591573_0.6442091648255333","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"pdfnative-cli","version":"1.3.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line","pdf-ua","accessibility","colr","color-emoji","unicode","text-shaping","opentype","bidi","streaming","telugu","sinhala","khmer","myanmar","tibetan","amharic","ai-agent","agentic","ai-governance","hitl","human-in-the-loop","automation","json-output","json-schema","sbom","supply-chain","pdf-merge","pdf-split","pdf-extract","merge","split","annotate","annotations","markup-annotations","bookmarks","outline","page-labels","layout-inspection","math-symbols","extract-text","text-extraction","pdf-to-text","pdf-text","pdf-forms","acroform","form-fill","fill-form","flatten-pdf","encrypt","decrypt","pdf-encryption","pdf-password","aes-256","aes-128","rc4","charts","pdf-charts","data-visualization","rag","llm","llms-txt","mcp","powershell-completion"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@1.3.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"1597a695d558d37bd637b8e83c58c3b892c5bfa0","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-1.3.0.tgz","fileCount":10,"integrity":"sha512-p2g8b3X9HIBj/6VLPCDRjmNaf2Prgr7ct+0rt56E9KJZKXkUaWHFeiLeT4D0KDSUMUpZ8ZQ9YnQdIF+ON4ixOw==","signatures":[{"sig":"MEQCIAp8oSx/RvEWPmt/mF3rnA0kyhOZZvjs9sJg9arV8K2PAiAavvXKZaSOXgvMn8oocrx1H1NLyzWm0/J3FIEyXiA1uA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@1.3.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1743510},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=20"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"1a0c5ae1bb32c383c0f3362254ed4f8c659d5884","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"overrides":{"vite":"^8.0.16","esbuild":"^0.28.1","js-yaml":"^4.3.0"},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.16.0","description":"Official CLI for pdfnative — render JSON to PDF (22 Unicode scripts, math, COLRv1 colour emoji, native vector charts, bookmarks, streaming), extract text (RAG/agents), fill & flatten AcroForms, encrypt/decrypt (AES-128/256), merge/split/extract pages, ann","directories":{},"sideEffects":false,"_nodeVersion":"24.18.0","dependencies":{"pdfnative":"^1.6.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^4.1.7","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^4.1.7"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_1.3.0_1784923491437_0.7697629609652026","host":"s3://npm-registry-packages-npm-production"}},"1.4.0":{"name":"pdfnative-cli","version":"1.4.0","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line","pdf-ua","accessibility","colr","color-emoji","unicode","text-shaping","opentype","bidi","streaming","telugu","sinhala","khmer","myanmar","tibetan","amharic","ai-agent","agentic","ai-governance","hitl","human-in-the-loop","automation","json-output","json-schema","sbom","supply-chain","pdf-merge","pdf-split","pdf-extract","merge","split","annotate","annotations","markup-annotations","bookmarks","outline","page-labels","layout-inspection","math-symbols","extract-text","text-extraction","pdf-to-text","pdf-text","pdf-forms","acroform","form-fill","fill-form","flatten-pdf","encrypt","decrypt","pdf-encryption","pdf-password","aes-256","aes-128","rc4","charts","pdf-charts","data-visualization","rag","llm","llms-txt","mcp","powershell-completion","pdf-compare","pdf-diff","document-timestamp","timestamping","tsa","dss","pades-lt","pades-lta","pdf-metadata","xmp","print-production","bleed","printer-marks","output-intent","pdf-manifest","pipeline"],"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","_id":"pdfnative-cli@1.4.0","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"bin":{"pdfnative":"dist/cli.cjs"},"dist":{"shasum":"8a0a8330acfd0c7e94ee8f2a5df6b4fa2bac16ae","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-1.4.0.tgz","fileCount":10,"integrity":"sha512-V8rASvAIZhhH59C0OsHF8YbtGfF5MbNngobrmFChlh/FDBUg/6lvGO/Q/NfhH+4XW1sXzk13khStfaHWpCjJew==","signatures":[{"sig":"MEUCIQD76PyMUi7erQtNEvSOpo0TY7e/OcfT1Wi3VCnd3E6YDgIgc4xMgRk1xgtOQ4qxXyXlieRA+x03jyiad/pKe/UyXYk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@1.4.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2443854},"main":"./dist/cli.cjs","type":"module","types":"./dist/cli.d.ts","module":"./dist/cli.js","engines":{"node":">=22"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"32d0dd85ccb52c408b73d3d599fe0eec729f98e3","scripts":{"dev":"tsup --watch","lint":"eslint src/","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit","test:watch":"vitest","corpus:pdfa":"node scripts/generate-pdfa-corpus.mjs","test:coverage":"vitest run --coverage","typecheck:all":"npm run typecheck && npm run typecheck:tests","validate:pdfa":"npm run build && npm run corpus:pdfa && node scripts/validate-pdfa.mjs","prepublishOnly":"npm run build","typecheck:tests":"tsc --project tsconfig.test.json --noEmit"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"overrides":{"vite":"^8.0.16","nanoid":"^3.3.18","esbuild":"^0.28.1","js-yaml":"^4.3.1"},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.17.0","description":"Official CLI for pdfnative — render JSON to PDF (22 Unicode scripts, math, COLRv1 colour emoji, 9 native vector chart types, print production with bleed/printer marks, bookmarks, streaming), extract text (RAG/agents), fill & flatten AcroForms, encrypt/dec","directories":{},"sideEffects":false,"_nodeVersion":"24.19.0","dependencies":{"pdfnative":"^1.7.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"devDependencies":{"tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^4.1.7","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^4.1.7"},"_npmOperationalInternal":{"tmp":"tmp/pdfnative-cli_1.4.0_1787706890399_0.06251767752712589","host":"s3://npm-registry-packages-npm-production"}},"1.5.0":{"_id":"pdfnative-cli@1.5.0","bin":{"pdfnative":"dist/cli.cjs"},"bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"dist":{"shasum":"547b88feb6d3fd6fd04768b60bcf074f6afa8fe8","tarball":"https://registry.npmjs.org/pdfnative-cli/-/pdfnative-cli-1.5.0.tgz","fileCount":10,"integrity":"sha512-hHK18k+gqlc1CL55OKMVp7qqZuWPy4hdr8KcBOLf9oi1fFnbX8IzgZYI8QTxuUdxjpdhtsW/uUyUGL5+C/CR3g==","signatures":[{"sig":"MEYCIQCUWSMxBE9toh0dQ9ikvRUVjtpDIh7VYPcFKdJgV3qMcAIhAPl5iDsnTYl/A9XgsIBP5s3StQaWwNmxC3ARVEwcOFsN","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIG3S6XvoX8S3MPCk0u/Jc+qhUoWj1Hx7RYenktwiBVbsAiAwSlZ//r+oiIv2IvOdnrgmZgZUlmy2LIqpG7CIMWV2Dw=="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/pdfnative-cli@1.5.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":2782618},"main":"./dist/cli.cjs","name":"pdfnative-cli","type":"module","types":"./dist/cli.d.ts","author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"module":"./dist/cli.js","engines":{"node":">=22"},"funding":{"url":"https://plika.app","type":"individual"},"gitHead":"441ab757ef78fe22aed2db3f864aba258463e6ef","license":"MIT","scripts":{"dev":"tsup --watch","gate":"npx tsx scripts/gate.ts","lint":"eslint src/","test":"vitest run","build":"tsup","gate:fast":"npx tsx scripts/gate.ts --fast","typecheck":"tsc --noEmit","test:watch":"vitest","corpus:pdfa":"npx tsx scripts/generate-pdfa-corpus.ts","verify:docs":"npx tsx scripts/verify-docs.ts","agents:rules":"npx tsx scripts/build-claude-rules.ts","hooks:install":"node scripts/install-git-hooks.mjs","test:coverage":"vitest run --coverage","test:generate":"npx tsx scripts/generate-samples.ts","typecheck:all":"npm run typecheck && npm run typecheck:tests && npm run typecheck:scripts","validate:pdfa":"npx tsx scripts/validate-pdfa.ts","validate:pdfx":"npx tsx scripts/validate-pdfx.ts","prepublishOnly":"npm run build","verify:samples":"npx tsx scripts/verify-samples.ts","hooks:uninstall":"node scripts/install-git-hooks.mjs --uninstall","release:prepare":"npx tsx scripts/release-prepare.ts","typecheck:tests":"tsc --project tsconfig.test.json --noEmit","typecheck:scripts":"tsc --project tsconfig.scripts.json --noEmit"},"version":"1.5.0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:465c36cb-cbe6-40b7-8ce0-2b0505c579d4"}},"homepage":"https://github.com/Nizoka/pdfnative-cli#readme","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line","pdf-ua","accessibility","colr","color-emoji","unicode","text-shaping","opentype","bidi","streaming","telugu","sinhala","khmer","myanmar","tibetan","amharic","lao","cham","tai-tham","hausa","yoruba","igbo","swahili","pdf-x","pdfx4","cmyk","typography","kerning","reproducible-builds","source-date-epoch","ai-agent","agentic","ai-governance","hitl","human-in-the-loop","automation","json-output","json-schema","sbom","supply-chain","pdf-merge","pdf-split","pdf-extract","merge","split","annotate","annotations","markup-annotations","bookmarks","outline","page-labels","layout-inspection","math-symbols","extract-text","text-extraction","pdf-to-text","pdf-text","pdf-forms","acroform","form-fill","fill-form","flatten-pdf","encrypt","decrypt","pdf-encryption","pdf-password","aes-256","aes-128","rc4","charts","pdf-charts","data-visualization","rag","llm","llms-txt","mcp","powershell-completion","pdf-compare","pdf-diff","document-timestamp","timestamping","tsa","dss","pades-lt","pades-lta","pdf-metadata","xmp","print-production","bleed","printer-marks","output-intent","pdf-manifest","pipeline"],"overrides":{"esbuild":"0.28.1","js-yaml":"4.3.2"},"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"_npmVersion":"11.19.1","description":"Official CLI for pdfnative — render JSON to PDF (typography engine, 27 Unicode scripts + custom fonts, math, COLRv1 colour emoji, 9 native vector chart types, CMYK and PDF/X-4 print production with bleed/printer marks/colour bars, PDF/A, bookmarks, stream","directories":{},"maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"pdfnative":"^1.8.0"},"publishConfig":{"access":"public","provenance":true},"_hasShrinkwrap":false,"packageManager":"npm@10.9.2","devDependencies":{"tsx":"^4.22.4","tsup":"^8.0.0","eslint":"^9.0.0","vitest":"^4.1.11","typescript":"^5.4.0","@types/node":"^22.0.0","typescript-eslint":"^8.59.2","@vitest/coverage-v8":"^4.1.11"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pdfnative-cli_1.5.0_1789944712963_0.39481953675814174"}}},"time":{"created":"2026-04-27T08:02:33.996Z","modified":"2026-09-20T22:51:53.379Z","0.0.1":"2026-04-27T08:02:34.235Z","0.1.0":"2026-04-27T17:41:56.944Z","0.2.0":"2026-04-28T11:58:34.165Z","0.3.0":"2026-05-05T21:44:19.519Z","1.0.0":"2026-05-30T14:35:38.484Z","1.1.0":"2026-06-14T07:40:34.008Z","1.2.0":"2026-07-06T19:03:11.794Z","1.3.0":"2026-07-24T20:04:51.584Z","1.4.0":"2026-08-26T01:14:50.612Z","1.5.0":"2026-09-20T22:51:53.061Z"},"bugs":{"url":"https://github.com/Nizoka/pdfnative-cli/issues"},"author":{"url":"https://pdfnative.dev","name":"Nizoka","email":"hello@pdfnative.dev"},"license":"MIT","homepage":"https://github.com/Nizoka/pdfnative-cli#readme","keywords":["pdf","pdf-generation","cli","pdfnative","pdf-render","pdf-sign","pdf-verify","pdf-inspect","zero-dependency","typescript","pdf-a","digital-signature","cms","pkcs7","ecdsa","rfc3161","ltv","ocsp","crl","pades","pdf-watch","batch","shell-completions","command-line","pdf-ua","accessibility","colr","color-emoji","unicode","text-shaping","opentype","bidi","streaming","telugu","sinhala","khmer","myanmar","tibetan","amharic","lao","cham","tai-tham","hausa","yoruba","igbo","swahili","pdf-x","pdfx4","cmyk","typography","kerning","reproducible-builds","source-date-epoch","ai-agent","agentic","ai-governance","hitl","human-in-the-loop","automation","json-output","json-schema","sbom","supply-chain","pdf-merge","pdf-split","pdf-extract","merge","split","annotate","annotations","markup-annotations","bookmarks","outline","page-labels","layout-inspection","math-symbols","extract-text","text-extraction","pdf-to-text","pdf-text","pdf-forms","acroform","form-fill","fill-form","flatten-pdf","encrypt","decrypt","pdf-encryption","pdf-password","aes-256","aes-128","rc4","charts","pdf-charts","data-visualization","rag","llm","llms-txt","mcp","powershell-completion","pdf-compare","pdf-diff","document-timestamp","timestamping","tsa","dss","pades-lt","pades-lta","pdf-metadata","xmp","print-production","bleed","printer-marks","output-intent","pdf-manifest","pipeline"],"repository":{"url":"git+https://github.com/Nizoka/pdfnative-cli.git","type":"git"},"description":"Official CLI for pdfnative — render JSON to PDF (typography engine, 27 Unicode scripts + custom fonts, math, COLRv1 colour emoji, 9 native vector chart types, CMYK and PDF/X-4 print production with bleed/printer marks/colour bars, PDF/A, bookmarks, stream","maintainers":[{"name":"nizoka","email":"nizoka@plika.app"}],"readme":"# pdfnative-cli\n\n[![CI](https://github.com/Nizoka/pdfnative-cli/actions/workflows/ci.yml/badge.svg)](https://github.com/Nizoka/pdfnative-cli/actions/workflows/ci.yml)\n[![CodeQL](https://github.com/Nizoka/pdfnative-cli/actions/workflows/codeql.yml/badge.svg)](https://github.com/Nizoka/pdfnative-cli/actions/workflows/codeql.yml)\n[![npm version](https://img.shields.io/npm/v/pdfnative-cli)](https://www.npmjs.com/package/pdfnative-cli)\n[![npm downloads](https://img.shields.io/npm/dm/pdfnative-cli)](https://www.npmjs.com/package/pdfnative-cli)\n[![zero extra runtime dependencies](https://img.shields.io/badge/extra%20runtime%20deps-0-brightgreen)](https://www.npmjs.com/package/pdfnative-cli)\n[![TypeScript](https://img.shields.io/badge/TypeScript-strict-blue)](https://www.typescriptlang.org/)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE)\n[![npm provenance](https://img.shields.io/badge/provenance-signed-blueviolet)](https://docs.npmjs.com/generating-provenance-statements)\n[![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/Nizoka/pdfnative-cli/badge)](https://securityscorecards.dev/viewer/?uri=github.com/Nizoka/pdfnative-cli)\n<!-- After registering the project at https://www.bestpractices.dev, add the badge:\n[![OpenSSF Best Practices](https://www.bestpractices.dev/projects/<ID>/badge)](https://www.bestpractices.dev/projects/<ID>) -->\n[![pdfnative](https://img.shields.io/npm/v/pdfnative?label=pdfnative&color=0066FF)](https://www.npmjs.com/package/pdfnative)\n[![website](https://img.shields.io/badge/pdfnative.dev-0066FF?logo=data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCIgZmlsbD0id2hpdGUiPjxyZWN0IHg9IjMiIHk9IjIiIHdpZHRoPSIxNCIgaGVpZ2h0PSIxOCIgcng9IjIiIGZpbGw9Im5vbmUiIHN0cm9rZT0id2hpdGUiIHN0cm9rZS13aWR0aD0iMS41Ii8+PHBhdGggZD0iTTcgN2g2TTcgMTFoOE03IDE1aDQiIHN0cm9rZT0id2hpdGUiIHN0cm9rZS13aWR0aD0iMS41IiBzdHJva2UtbGluZWNhcD0icm91bmQiLz48L3N2Zz4=)](https://pdfnative.dev)\n\nOfficial CLI for the [`pdfnative`](https://github.com/Nizoka/pdfnative) library — render JSON to PDF, apply digital signatures, verify them, and inspect PDF conformance, directly from the terminal. Zero extra runtime dependencies.\n\n> **What's new in v1.5.0** — built on **pdfnative 1.8.0**. `render` gains a **typography\n> engine** (widow/orphan control, keep-with-next, justification, optical margins, soft hyphens,\n> French punctuation spacing, kerning and OpenType features — `layout.typography` plus four\n> flags), **CMYK colours** and printer's **colour bars**, **PDF/X-4 output** (`--pdfx pdfx4\n> --output-intent-icc <cmyk.icc> --trapped`) checked by `inspect --check pdfx`, **27 Unicode\n> scripts** (+ Lao, Tai Tham, New Tai Lue, Tai Le, Cham; `ha`/`yo`/`ig`/`sw` aliases) and\n> **custom fonts** (`--font-file`). Output is now **byte-reproducible**: a global\n> `--creation-date` (or `SOURCE_DATE_EPOCH`) pins every date in UTC. Global flags may now\n> **precede the command**; `annotate` gains `link`; `sign --timestamp-timeout`; `verify` flags\n> SHA-1 timestamp imprints; `inspect --iso-dates`; `doctor` reports fonts, Unicode and\n> conformance targets. The repository ships the same engineering as the engine: one quality\n> gate, a byte-exact sample baseline, a PDF/A + PDF/X conformance corpus, hardened CI with\n> attestations, and a documentation verifier. Zero breaking changes.\n> See [release notes](release-notes/v1.5.0.md) and [docs/AGENT_CONTRACT.md](docs/AGENT_CONTRACT.md).\n>\n> ⭐ Star [`pdfnative`](https://github.com/Nizoka/pdfnative) — the zero-dependency PDF engine that powers this CLI.\n\n## Highlights\n\n- **`render`** — pipe a JSON document into a production-ready PDF. Encryption (AES-128/256),\n  watermarks (text + image), page templates, PDF/A archival, **27 Unicode scripts + COLRv1\n  colour emoji + a bundled math font (`--font math`)**, **native vector charts** (bar, barH,\n  line, pie, donut — pdfnative ≥ 1.6.0), **PDF bookmarks** (`--outline`), **layout introspection**\n  (`--inspect-layout` / `--debug-layout`), streaming (single-pass, page-by-page, or **true\n  constant-memory `--stream-true`**), and a hybrid `flags + --layout file.json` model.\n- **Typography (v1.5.0, pdfnative ≥ 1.8.0)** — `layout.typography` brings paragraph breaking\n  (widows/orphans, `keepWithNext`, splittable paragraphs), `align: \"justify\"`, optical margin\n  alignment, soft hyphens, French punctuation spacing with unit binding (`150 €` never breaks),\n  kerning, OpenType features (`onum`, `smcp`, `tnum`, …) and exact base-14 metrics. Four\n  high-frequency flags — `--split-paragraphs`, `--keep-headings-with-next`, `--kerning`,\n  `--font-features <tag,…>` — cover the common cases; the rest rides in `--layout`.\n- **CMYK & PDF/X-4 (v1.5.0)** — every colour accepts CMYK (`\"c m y k\"` or `[c,m,y,k]`),\n  printer's marks gain **colour bars**, and `render --pdfx pdfx4 --output-intent-icc <cmyk.icc>\n  --trapped false` writes a PDF/X-4 file whose claim `inspect --check pdfx` re-validates with\n  pdfnative's structural validator (`PDFX_*` diagnostics, `--strict` gating). A 22-file\n  conformance corpus (PDF/A via veraPDF, PDF/X via the validator) guards every release.\n- **Reproducible output (v1.5.0)** — the global `--creation-date <iso8601>` (or\n  `SOURCE_DATE_EPOCH`) pins `/CreationDate`, `xmp:CreateDate`, the `{date}` placeholder and\n  the trailer `/ID`, all in UTC, so the same input renders to **byte-identical** bytes on every\n  host and in every timezone. The repository's own 91-sample baseline is held to that promise.\n- **27 scripts & custom fonts (v1.5.0)** — `--font lo|nod|khb|tdd|cjm` add Lao, Tai Tham,\n  New Tai Lue, Tai Le and Cham; `ha`/`yo`/`ig`/`sw` alias `latin` for Hausa, Yoruba, Igbo and\n  Swahili; `--font-file <path.ttf>[:name]` registers your own TrueType/OpenType file (32 MiB\n  cap, magic-byte and parser validation — never from a JSON payload). `--variant table`\n  embeds fonts too, so table renders can claim PDF/A.\n- **`extract-text` / `fill` / `encrypt` / `decrypt`** (v1.3.0, pdfnative ≥ 1.6.0) — extract\n  reading-order text as text/JSON/**NDJSON** for RAG & agents (no OCR); fill, flatten &\n  **export** AcroForms with an incremental save (signatures stay valid; `fill --export` gives\n  a read→edit→fill round-trip); re-secure with **AES-128/256** or remove encryption. `merge` /\n  `split` / `extract` gain `--password`, `--encrypt`, and constant-memory `--stream`.\n- **`doctor`** — an offline environment/capability preflight (CLI/Node/pdfnative versions,\n  Web Crypto CSPRNG required by `encrypt`, command count, and — v1.5.0 — the bundled font\n  inventory probed on disk, the Unicode version and the PDF/A + PDF/X conformance targets).\n  Text or `--json`; exit 0/1 — an ideal agent pre-flight.\n- **`sign`** — CMS/PKCS#7 digital signatures with full metadata (`--reason`, `--name`,\n  `--location`, `--contact`, `--signing-time`) and intermediate CA chains via\n  `--cert-chain` (repeatable). Uses **native `node:crypto`** for constant-time signatures\n  by default (`--pure-crypto` opts out). Keys loaded from env vars or files; never logged.\n  v1.4.0 adds a **functional RFC 3161 `--timestamp <tsa-url>`** (PAdES B-T), **PAdES\n  profile** (`--profile pades` — ETSI.CAdES.detached, ESS signing-certificate-v2),\n  **sha384/512 digests** (RSA), **multi-signatures** (`--allow-multiple` / `--field-name`),\n  and **visible signature placement** (`--signature-rect` / `--signature-page`); v1.5.0 adds\n  `--timestamp-timeout <ms>` for the TSA round-trip.\n- **PAdES long-term signatures (v1.4.0, pdfnative ≥ 1.7.0)** — the full B-T → B-LT → B-LTA\n  ladder: `sign --timestamp <tsa> --profile pades` (B-T) → `ltv add --online` (B-LT: OCSP +\n  CRL validation data archived into `/DSS` + `/VRI`) → `doc-timestamp --url <tsa>` (B-LTA:\n  a `/DocTimeStamp` revision, repeatable for renewal) → `ltv add --online`. The `ltv\n  collect` / `ltv embed` split supports **air-gapped pipelines** — collect on a connected\n  machine, embed fully offline. All network access is explicit opt-in and SSRF-guarded.\n- **`metadata` / `compare`** (v1.4.0) — update `/Info` + XMP metadata with an\n  **incremental save** (existing signatures stay valid); diff two PDFs by **text +\n  structure** with CI-friendly exit codes (identical → 0, different → 1 / `E_CHECK_FAILED`).\n- **`batch --manifest`** (v1.4.0) — a declarative, sequential multi-command pipeline\n  (`render` → `sign` → `verify` → …) in one JSON file, with `@<id>` output references and\n  an `--allow-network` gate so untrusted manifests can never trigger network I/O.\n- **Print production & charts v2** (v1.4.0, pdfnative ≥ 1.7.0) — `render` layout gains\n  bleed/trim/art/crop boxes, printer marks, `userUnit`, ICC output intents, and viewer\n  preferences (duplex, `numCopies`, …); charts grow to **9 types** (stacked bars, area,\n  scatter) with dual axes, log/time/category x-axes, and data labels. `render --strict`\n  turns PDF/A conformance diagnostics into a hard error before the first output byte.\n- **`inspect`** — PDF version, page count, encryption, PDF/A **and PDF/X** conformance,\n  signature count, metadata (`--iso-dates` normalises PDF dates to ISO 8601 — v1.5.0),\n  **page labels**, **markup/link annotations** (`--annotations`), **PDF/UA (ISO 14289-1)\n  structural validation** and a **PDF/X-4 validation report** (`--pdfx`). `--verbose`,\n  `--pages`, and `--check pdfa|signed|encrypted|pdfua|pdfx` for CI assertions.\n- **`verify`** — verify every CMS/PKCS#7 signature: byte-range integrity, RSA/ECDSA\n  signature value (RSA now also sha384/512), certificate chain, trust roots, **RFC 3161\n  timestamp (PAdES-T)**, **`/DocTimeStamp` revisions (PAdES B-LTA)**, and **OCSP + CRL\n  revocation** (embedded `/DSS` offline by default, opt-in SSRF-guarded online).\n  JSON & text output, `--strict`, `--revocation`, `--revocation-policy`; a SHA-1 timestamp\n  imprint is reported as a weak digest and refused under `--strict` (v1.5.0).\n- **`merge` / `split` / `extract`** — page-tree operations (pdfnative ≥ 1.5.0): concatenate\n  several PDFs, split one PDF into many (per-page or per-range), or pull selected pages into\n  a new PDF. `--drop-annotations` and `--max-output-size` guards included.\n- **`annotate`** — attach markup annotations (highlight, text note, square, line, …) and —\n  v1.5.0 — **`link`** annotations (`url`, validated: `http`/`https`/`mailto` only) to an\n  existing PDF via a JSON spec, using an **incremental save** so the original bytes — and any\n  existing signature — stay intact.\n- **`govern`** — expose pdfnative's **AI-governance / HITL** contract: `govern rules`,\n  `govern policy`, and `govern verify-issue <draft.md>` to gate an issue/PR draft (exit 1 /\n  `E_POLICY` on violation) before a **human** reviews and submits it.\n- **`batch`** — render every JSON file in a directory to PDF in parallel, reusing the full\n  `render` pipeline, with a per-file summary and bounded `--concurrency`.\n- **`completion`** — emit `bash`, `zsh`, `fish`, or `powershell` shell-completion scripts.\n- **`schema`** — print a versioned JSON Schema (Draft 2020-12) for any CLI input/output\n  shape, plus **`schema manifest`** (a machine-readable capability manifest) and\n  [`llms.txt`](llms.txt), so agents can self-validate and discover the CLI's tools.\n- **Agent-native** — a global `--json` status/error envelope, 12 stable `E_*` error codes,\n  and a `--dry-run` validation mode let autonomous AI agents and CI drive the CLI\n  deterministically; global flags may precede or follow the command name (v1.5.0).\n  Token-economy levers — **`--summary`** (minimal verdict), **`--fields`** (dot-path\n  projection), and compact JSON under `--json` — shrink agent output ~90 %.\n  See [docs/AGENT_CONTRACT.md](docs/AGENT_CONTRACT.md).\n- **Engineered like the engine (v1.5.0)** — one quality gate (`npm run gate`) with fast / CI /\n  publish profiles, a byte-exact sample baseline (`test-output/samples/` vs\n  `tests/regression/baselines/samples.sha256.json`), a PDF/A + PDF/X conformance corpus,\n  hardened workflows (egress-audited runners, SHA-pinned actions, Trusted Publishing, SBOM +\n  build attestations), a documentation verifier (`npm run verify:docs`) and a committed\n  Claude Code layer with a human-in-the-loop guard hook — 1403 tests.\n- **AI-governance / HITL** — the **`govern`** command surfaces pdfnative's Human-in-the-Loop\n  contract to agents: they act as *draftsmen*, never autonomous submitters. `govern\n  verify-issue` gates a local draft; a human always reviews and submits.\n- **`.pdfnativerc.json`** — optional config file for default flags (global + per-command);\n  precedence is CLI flags > env > config.\n- **Zero extra dependencies** — `pdfnative` is the sole runtime dependency.\n- **Offline by default** — no network access unless you explicitly opt in with\n  `verify --revocation online`, `sign --timestamp`, `ltv --online`, `doc-timestamp --url`,\n  or `batch --allow-network` — and every request passes an SSRF guard (no redirects).\n- **Stdin / stdout by default** — every command is shell-pipeline friendly.\n- **Secret-safe** — signing keys, certs, encryption passwords never appear in error\n  output or stderr. PEM material redacted; layout-file `attachments[].data` injection blocked.\n- **ESM-first, TypeScript strict** — built with tsup, typed declarations included.\n- **NPM provenance** — signed builds via GitHub Actions OIDC.\n\n## Supported Features\n\n| Feature | Status | Notes |\n|---------|--------|-------|\n| **Commands** | | |\n| `render` JSON → PDF | ✅ | Streaming, hybrid layout model, multilingual fonts, bookmarks, layout introspection |\n| `sign` digital signatures | ✅ | RSA/ECDSA (CMS/PKCS#7), metadata fields, cert chains, native `node:crypto` |\n| `inspect` PDF metadata | ✅ | `--verbose`, `--pages`, `--pdfua`, `--pdfx`, `--iso-dates`, `--annotations`, `--form-fields`, `--encryption`, `--password`, page labels, `--check …` |\n| `verify` signature verification | ✅ | Integrity + chain + trust + timestamp + revocation; `--strict` |\n| `extract-text` reading-order text | ✅ | `--format text\\|json\\|ndjson`, `--runs`, `--pages`, `--password`; RAG/agent-native (no OCR) |\n| `fill` fill / flatten / export AcroForms | ✅ | `--data <values.json>`, `--flatten`, `--export` (values → `--data` map); incremental save |\n| `encrypt` / `decrypt` | ✅ | AES-128/256 re-encryption & transparent decryption (`--password`, `--stream`) |\n| `doctor` preflight | ✅ | CLI/Node/pdfnative versions, Web Crypto (CSPRNG), command count, font inventory, Unicode version, conformance targets; text or `--json` |\n| `merge` concatenate PDFs | ✅ | Page-tree API; `--password`, `--encrypt`, `--stream`, `--drop-annotations`, `--max-output-size` |\n| `split` one PDF → many | ✅ | Per-page (default) or per-range (`--pages`); `--password`, `--encrypt`, `--stream` |\n| `extract` selected pages | ✅ | 1-based `--pages` list/range; `--password`, `--encrypt`, `--stream` |\n| `annotate` markup + link annotations | ✅ | Incremental save (signatures preserved); JSON spec via `--annotations`; `link` type with URL validation (v1.5.0) |\n| `govern` AI-governance / HITL | ✅ | `rules` / `policy` / `verify-issue`; gates drafts with `E_POLICY` |\n| `batch` parallel rendering | ✅ | Directory → PDFs, `--concurrency`, `--fail-fast` |\n| `completion` shell scripts | ✅ | `bash` / `zsh` / `fish` / `powershell` |\n| `schema` JSON Schema export | ✅ | Per-command schemas + summaries + `status` + `manifest` (capability manifest) |\n| `.pdfnativerc.json` config file | ✅ | Global + per-command defaults; flags > env > config |\n| **Agent / automation** | | |\n| Global `--json` envelope | ✅ | Status on success, `{ ok, error: { code, message } }` on failure |\n| Stable error codes | ✅ | 12 codes: `E_USAGE`, `E_INPUT`, `E_PARSE`, `E_IO`, `E_SIGN`, `E_VERIFY_FAILED`, `E_CHECK_FAILED`, `E_POLICY`, `E_UNSUPPORTED`, `E_PASSWORD`, `E_NETWORK`, `E_RUNTIME` |\n| Global flags before the command | ✅ | `pdfnative --json --dry-run render …` ≡ `pdfnative render … --json --dry-run` (v1.5.0) |\n| Reproducible output | ✅ | Global `--creation-date <iso8601>` / `SOURCE_DATE_EPOCH` → byte-identical PDFs across hosts and timezones (v1.5.0) |\n| Capability manifest | ✅ | `schema manifest` (JSON) + `llms.txt` — for agent tool discovery |\n| `--dry-run` validation | ✅ | `render` / `sign` / `batch` / `merge` / `split` / `extract` / `annotate` / `fill` / `encrypt` / `decrypt` / `metadata` / `ltv` / `doc-timestamp` |\n| **Document Blocks** | | |\n| Headings, paragraphs, lists | ✅ | Full text styling support |\n| Tables | ✅ | Headers, rows, multi-page |\n| Barcodes | ✅ | QR, Code 128, EAN-13, Data Matrix, PDF417 |\n| Charts | ✅ | `chart` block: bar, barH, line, pie, donut (native PDF paths, pdfnative ≥ 1.6.0) |\n| Hyperlinks | ✅ | URL validation, blue underlined text |\n| Form fields | ✅ | Text, checkbox, radio, dropdown, listbox |\n| Page breaks, spacers | ✅ | Explicit pagination control |\n| Table of contents | ✅ | Auto-generated with `/GoTo` links |\n| **Advanced Layouts (v0.2.0)** | | |\n| PDF/A archival (1b, 2b, 2u, 3b) | ✅ | `--tagged pdfa<level>` (preferred) or `--conformance` (deprecated); validated against the **veraPDF** reference validator in CI (blocking) |\n| Streaming output | ✅ | `--stream` (single-pass) for large documents |\n| Compression | ✅ | `--compress` flag |\n| Encryption (AES-128/256) | ✅ | `--encrypt-*` flags + env-var precedence |\n| Watermarks (text + image) | ✅ | `--watermark-text`, `--watermark-image`, `--watermark-position` |\n| Headers / footers with placeholders | ✅ | `--header-{l,c,r}`, `--footer-{l,c,r}`, `{page}/{pages}/{date}/{title}` |\n| Custom page sizes | ✅ | `--page-size A4\\|Letter\\|…` or `WxH` in points |\n| Custom margins | ✅ | `--margin <N>` or `--margin <t,r,b,l>` |\n| PDF/A-3 attachments | ✅ | `--attachment <path>:<mime>:<rel>:<desc>` (repeatable) |\n| Multilingual fonts | ✅ | 27 Unicode scripts via `--font <code> --lang <code>` (e.g. `th`, `ja`, `ar`, `te`, `si`, `km`, `lo`, `cjm`); Latin built-in |\n| Table-centric variant (`PdfParams`) | ✅ | `--variant table` |\n| Full `PdfLayoutOptions` | ✅ | `--layout <file.json>` |\n| **Signing (v0.2.0)** | | |\n| RSA signatures (rsa-sha256) | ✅ | Default algorithm |\n| ECDSA signatures (ecdsa-sha256) | ✅ | P-256 SEC1 / PKCS#8 keys (v0.3.0) |\n| Auto signature-placeholder injection | ✅ | One-command sign of any rendered PDF (v0.3.0) |\n| Signature metadata | ✅ | `--reason`, `--name`, `--location`, `--contact`, `--signing-time` |\n| Cert chains (intermediate CAs) | ✅ | `--cert-chain <pem>` (repeatable) or `PDFNATIVE_SIGN_CHAIN` env |\n| **Verification (v0.2.0+)** | | |\n| Byte-range integrity (SHA-256) | ✅ | Recomputed and compared with CMS messageDigest attribute |\n| CMS signature-value verification | ✅ | RSA-SHA256 + ECDSA-SHA256 (v0.3.0) |\n| Certificate chain verification | ✅ | Via pdfnative `verifyCertSignature` |\n| Trust roots | ✅ | `--trust <root.pem>` (repeatable) + self-signed acceptance |\n| RFC 3161 timestamp recognition | ✅ | Reported as `timestampPresent` |\n| RFC 3161 timestamp validation (PAdES-T) | ✅ | TSA signature, messageImprint binding, chain, `genTime` |\n| OCSP revocation (RFC 6960) | ✅ | Embedded `/DSS` + opt-in online via AIA (SSRF-guarded) |\n| CRL revocation (RFC 5280) | ✅ | Embedded `/DSS` + opt-in online via CDP (SSRF-guarded) |\n| Revocation policy | ✅ | `--revocation offline\\|online\\|disabled`, `--revocation-policy soft-fail\\|strict` |\n| Sign-side LTV (timestamp embedding / DSS) | ✅ | v1.4.0: `sign --timestamp`, `ltv collect\\|embed\\|add`, `doc-timestamp` (see below) |\n| **Render iteration** | | |\n| Smart tables | ✅ | `--table-wrap`, `--repeat-header`, `--zebra`, `--cell-padding`, `--min-row-height` |\n| Page-by-page streaming | ✅ | `--stream-page-by-page` (TOC- and `{pages}`-compatible) |\n| True constant-memory streaming | ✅ | `--stream-true` (parts freed as emitted; byte-identical output) |\n| Configurable block cap | ✅ | `--max-blocks <n>` (default 100 000) |\n| PDF/UA structural validation | ✅ | `inspect --pdfua` / `--check pdfua` (ISO 14289-1) — developer-time gate, not a substitute for veraPDF |\n| `--watch` re-render on file change | ✅ | 200 ms debounce, requires file `--output` |\n| `--template <file.json>` | ✅ | Deep-merge base under input (caller wins) |\n| `--font` bundled shortcuts | ✅ | Repeatable allow-list: `latin`, `emoji`, `color-emoji`, `math`, 27 script codes + 4 `latin` aliases (`ha`, `yo`, `ig`, `sw`) |\n| **Page-tree & annotations (v1.2.0)** | | |\n| Merge PDFs | ✅ | `merge <a.pdf> <b.pdf> …` (or repeatable `--input`) → `--output` |\n| Split PDF | ✅ | `split --output-dir <dir>` per-page, or `--pages 1-2,3-4` per-range |\n| Extract pages | ✅ | `extract --pages 4,1-2` (1-based; order preserved, repeats allowed) |\n| Drop annotations on copy | ✅ | `--drop-annotations` on `merge` / `split` / `extract` |\n| Output-size guard | ✅ | `--max-output-size <bytes>` on `merge` / `split` / `extract` |\n| Markup annotations | ✅ | `annotate --annotations <spec.json>` — highlight, text, square, circle, line, freetext, … |\n| Incremental save | ✅ | `annotate` preserves original bytes (existing signatures stay valid) |\n| Inspect annotations | ✅ | `inspect --annotations` lists markup + link annotations |\n| Page labels | ✅ | `inspect` reports `/PageLabels` when present |\n| **Bookmarks & layout (v1.2.0)** | | |\n| PDF bookmarks (outline) | ✅ | `render --outline auto` (from headings) or `--outline <tree.json>` |\n| Math / technical symbols | ✅ | `render --font math` (Noto Sans Math; auto-routed code points) |\n| Layout inspection report | ✅ | `render --inspect-layout` → `LayoutInspection` JSON (no PDF) |\n| Layout debug overlay | ✅ | `render --debug-layout [margins,content,cells]` |\n| **Signing crypto (v1.2.0)** | | |\n| Native constant-time crypto | ✅ | `sign` uses `node:crypto` by default (side-channel-resistant) |\n| Pure-JS crypto fallback | ✅ | `sign --pure-crypto` forces pdfnative's portable bignum path |\n| **AI-governance / HITL (v1.2.0)** | | |\n| Governance rules / policy | ✅ | `govern rules` (protocol) / `govern policy` (machine-readable JSON) |\n| Draft verification gate | ✅ | `govern verify-issue <draft.md>` → exit 1 / `E_POLICY` on violation |\n| **Text, forms, encryption & charts (v1.3.0, pdfnative ≥ 1.6.0)** | | |\n| Text extraction | ✅ | `extract-text --format text\\|json\\|ndjson` (reading order, `--runs`, `--password`); no OCR |\n| Fill AcroForms | ✅ | `fill --data <values.json>` (incremental save; encrypted PDFs via `--password`) |\n| Flatten AcroForms | ✅ | `fill --flatten` (stamp appearances, remove interactive fields) |\n| Export form values | ✅ | `fill --export` → `--data`-shaped JSON map (read → edit → fill round-trip) |\n| Encrypt / decrypt | ✅ | `encrypt --owner-password …` (AES-128/256) / `decrypt --password …` (`--stream`) |\n| Encrypted page-tree sources | ✅ | `--password` on `merge` / `split` / `extract` / `inspect` |\n| Re-encrypt page-tree output | ✅ | `--encrypt [aes-128\\|aes-256]` on `merge` / `split` / `extract` |\n| Constant-memory streaming | ✅ | `--stream` (+ `--chunk-size`) on `merge` / `split` / `extract` / `encrypt` / `decrypt` |\n| Native vector charts | ✅ | `chart` document block: bar, barH, line, pie, donut (pure PDF paths, tagged `/Figure`) |\n| List form fields / encryption | ✅ | `inspect --form-fields` / `inspect --encryption` |\n| Unified `render` encryption flags | ✅ | `render --encrypt [aes-128\\|aes-256] --owner-password …` (same vocab as merge/split/extract) |\n| Environment preflight | ✅ | `doctor` (versions, Web Crypto/CSPRNG, command count; text or `--json`) |\n| Capability manifest | ✅ | `schema manifest` + `llms.txt` for agent tool discovery |\n| PowerShell completion | ✅ | `completion powershell` |\n| **Long-term signatures & document ops (v1.4.0, pdfnative ≥ 1.7.0)** | | |\n| RFC 3161 signing timestamp (PAdES B-T) | ✅ | `sign --timestamp <tsa-url>` (+ `--timestamp-digest`, `--timestamp-nonce`); opt-in network, SSRF-guarded |\n| PAdES signature profile | ✅ | `sign --profile pades` (ETSI.CAdES.detached, ESS signing-certificate-v2) |\n| CMS digest selection | ✅ | `sign --digest sha256\\|sha384\\|sha512` (RSA; ECDSA is sha256-only) |\n| Multiple signatures | ✅ | `sign --allow-multiple` + `--field-name` (default stays idempotent single-signature) |\n| Visible signature placement | ✅ | `sign --signature-rect \"x1,y1,x2,y2\"` + `--signature-page` (+ `--placeholder-bytes`) |\n| LTV validation data (PAdES B-LT) | ✅ | `ltv collect\\|embed\\|add` — OCSP + CRL into `/DSS` + `/VRI`; `collect` needs `--online`, `embed` is fully offline (air-gapped) |\n| Document timestamp (PAdES B-LTA) | ✅ | `doc-timestamp --url <tsa>` — `/DocTimeStamp` (ETSI.RFC3161) incremental revision, repeatable for renewal |\n| Verify B-LTA / sha384-512 | ✅ | `verify` validates `/DocTimeStamp` revisions as RFC 3161 tokens; accepts `rsa-sha384` / `rsa-sha512`; reports `fieldName` + `isDocTimestamp` |\n| Signature inventory | ✅ | `inspect --signatures` (fieldName, subFilter, byteRange, isDocTimestamp, isPlaceholder — never signature bytes) + `--check \"signatures>=N\"` |\n| Metadata editing | ✅ | `metadata --title/--author/--subject/--keywords/--mod-date` or `--from-json` — incremental save, signatures stay valid |\n| PDF comparison | ✅ | `compare a.pdf b.pdf --mode text\\|structure\\|both` — exit 0 identical, exit 1 / `E_CHECK_FAILED` on differences; no visual diff |\n| Manifest pipelines | ✅ | `batch --manifest tasks.json` — sequential fail-fast tasks, `@<id>` references, `--allow-network` gate, `--continue-on-error` |\n| PDF/A strict gating | ✅ | `render --strict` — conformance diagnostics become `E_CHECK_FAILED` before any output byte (else stderr warnings + `diagnostics[]` under `--json`) |\n| Charts v2 | ✅ | 9 types (+ stackedBar, stackedBarH, area, scatter), `series.xValues`, `yAxis: right` + `axis2`, log scale, category/linear/time x-axis, data labels, label stride/rotation |\n| Print production | ✅ | `layout.print` (bleed, trimBox, bleedBox, artBox, cropBox, marks, userUnit 1–75000), `layout.outputIntent` (ICC RGB), `layout.viewerPreferences` (duplex, pickTrayByPDFSize, printPageRange, numCopies) |\n| Image blocks by path | ✅ | `{ \"type\": \"image\", \"src\": \"logo.png\" }` (relative to the input JSON) or `dataBase64` |\n| Encrypted annotate | ✅ | `annotate --password` — appended objects re-encrypted under the existing scheme |\n| Page-box preservation | ✅ | `merge` / `split` / `extract` now preserve BleedBox/TrimBox/ArtBox/UserUnit (pdfnative ≥ 1.7.0; previously dropped) |\n| Anti zip-bomb cap | ✅ | Global `--max-inflate-size <bytes>` — cap on any decompressed stream while parsing (default 100 MiB) |\n| Network error code | ✅ | Stable `E_NETWORK` — opt-in network operation failed (TSA / OCSP / CRL fetch) |\n| **Typography, PDF/X-4, CMYK & reproducible output (v1.5.0, pdfnative ≥ 1.8.0)** | | |\n| Typography engine | ✅ | `layout.typography` — widows/orphans, `keepWithNext`, splittable paragraphs, paragraph `align: \"justify\"`, optical margins, soft hyphens (U+00AD, always honoured), punctuation spacing (`\"fr\"` / `\"fr-CA\"` preset or a rules array + unit binding), kerning, OpenType `fontFeatures`, exact base-14 `metrics` |\n| Typography flags | ✅ | `render --split-paragraphs`, `--keep-headings-with-next`, `--kerning`, `--font-features <tag,…>` (merged into `layout.typography`; flags win over `--layout`) |\n| CMYK colours | ✅ | Every colour field and flag accepts `\"c m y k\"` (0–1) or `[c,m,y,k]` (percent) beside hex / RGB; `DeviceCMYK` operators emitted |\n| Printer's colour bars | ✅ | `layout.print.marks.colourBars: true \\| { tints, size }` |\n| PDF/X-4 output | ✅ | `render --pdfx pdfx4 --output-intent-icc <cmyk.icc> [--output-intent-id <s>] [--trapped true\\|false\\|unknown]`; coherence errors → `E_INPUT`, `PDFX_*` diagnostics → `--strict` / `E_CHECK_FAILED`; envelope carries `pdfx` |\n| PDF/X check | ✅ | `inspect --pdfx` (full report) and `--check pdfx` (exit 0/1); `pdfxConformance` always reported; `--summary` adds `pdfx` |\n| 27 Unicode scripts | ✅ | + `lo` (Lao), `nod` (Tai Tham), `khb` (New Tai Lue), `tdd` (Tai Le), `cjm` (Cham); `ha` / `yo` / `ig` / `sw` alias `latin` |\n| Custom fonts | ✅ | `render --font-file <path.ttf>[:name]` (repeatable; 32 MiB cap, magic bytes, `parseFontData` + `validateFontData`; never from JSON) |\n| Table variant fonts | ✅ | `--variant table --font latin --lang latin` embeds fonts, so table renders can claim PDF/A |\n| Reproducible dates | ✅ | Global `--creation-date <iso8601>` (or `SOURCE_DATE_EPOCH`) pins `/CreationDate`, `xmp:CreateDate`, `{date}`, trailer `/ID`, in UTC; envelope carries `creationDate` |\n| Layout revival | ✅ | `--layout` files and inline `layout` accept `creationDate` (ISO string), `outputIntent.iccProfile` (`number[]`), nested `typography` / `outputIntent` merges one level |\n| ISO dates in `inspect` | ✅ | `inspect --iso-dates` normalises `metadata.creationDate` / `modDate` from `D:YYYY…` to ISO 8601 |\n| Link annotations | ✅ | `annotate` type `link` (`rect` + `url`; `http` / `https` / `mailto`, validated) |\n| TSA timeout | ✅ | `sign --timestamp-timeout <ms>` (with `--timestamp`); envelope `timestamp.timeoutMs` |\n| Weak timestamp digest | ✅ | `verify` reports `timestampDigest` and notes a SHA-1 messageImprint; refused under `--strict` |\n| Global flags first | ✅ | `pdfnative --json --dry-run <command> …` — every global flag is accepted before the command name |\n| `doctor` capabilities | ✅ | `fonts` (31 modules / 27 scripts probed on disk), `unicode` (`USE_UNICODE_VERSION`), `conformance` (`pdfa1b,pdfa2b,pdfa2u,pdfa3b,pdfx4`) |\n| SSRF ranges | ✅ | Benchmarking `198.18.0.0/15`, TEST-NET-1 `192.0.2.0/24` and NAT64 `64:ff9b::/96` join the blocked ranges |\n| Layout file cap | ✅ | `--layout` files share the 50 MB JSON cap; ICC profiles 16 MiB (`acsp` signature checked) |\n\n**Note:** everything listed works today. Planned work is tracked in [ROADMAP.md](ROADMAP.md).\n\n### PDF/A & PDF/X status (v1.5.0)\n\nThe CLI's PDF/A outputs are **validated against the [veraPDF](https://verapdf.org)\nreference validator in CI (blocking)**, and its PDF/X-4 outputs against pdfnative's\nstructural PDF/X validator: a corpus of 22 files produced by the CLI itself — 18 claiming\nPDF/A (renders across all four levels plus attachments, headers/footers, outline, watermark,\na table-variant render with embedded fonts, an AcroForm, Gray and CMYK output intents, an\nincremental PAdES signature and a `metadata` update) and 4 claiming PDF/X-4 (a CMYK and a\nGray print render, a signed print render and a negative canary\nbroken by an annotation outside the page boxes) — is checked against the profile each file\nclaims in XMP. It includes **negative canaries** that the validators must reject — so a\nvalidator that accepts everything fails the run instead of turning it green. The PDF/A\nrecipe is `--tagged pdfa<level> --font latin --lang latin` (fonts must be embedded per\nISO 19005; the sRGB OutputIntent is emitted automatically by the engine); the PDF/X-4\nrecipe is `--pdfx pdfx4 --output-intent-icc <cmyk.icc> --font latin --lang latin\n--trapped false --strict`. Run the same gates locally with `npm run corpus:pdfa &&\nnpm run validate:pdfx && npm run validate:pdfa` — without veraPDF installed the PDF/A\nstep prints install hints and exits 0 as a **skip, not a pass** (`npx tsx scripts/gate.ts\n--publish --require-all` turns the skip into a failure). See\n[CONTRIBUTING.md](CONTRIBUTING.md#pdfa-validation-verapdf) for details. Not a\ncertification — validation evidence against a specific veraPDF version (1.30.2) and the\nengine's own PDF/X-4 validator (not a certified preflight tool).\n\n## Installation\n\n```bash\nnpm install --global pdfnative-cli\n```\n\nOr run without installing:\n\n```bash\nnpx pdfnative-cli render --input doc.json --output report.pdf\n```\n\n**Requirements:** Node.js ≥ 22 (Node 20 reached end-of-life 2026-04-30; CI runs 22/24) | Bun | Deno (`node dist/cli.cjs`)\n\n## Documentation\n\n- 📘 **[Quick Start](#quick-start)** (below) — Get rendering in 5 minutes\n- 🏛️ **[KNOWLEDGE_BASE.md](docs/KNOWLEDGE_BASE.md)** — Full CLI reference, architecture, integration patterns\n- 🤖 **[AGENT_CONTRACT.md](docs/AGENT_CONTRACT.md)** — The process contract for autonomous agents (envelopes, error codes, token economy)\n- 📚 **[samples/README.md](samples/README.md)** — runnable samples organized by feature\n- 🔧 **[pdfnative library](https://github.com/Nizoka/pdfnative)** — Underlying PDF engine docs\n- ❓ **[FAQ](docs/KNOWLEDGE_BASE.md#12-frequently-asked-questions)** — Common questions & troubleshooting\n\n## Quick Start\n\n### Render a PDF from JSON\n\n```bash\n# From a file\npdfnative render --input document.json --output report.pdf\n\n# From stdin\ncat document.json | pdfnative render --output report.pdf\n\n# Streaming (large documents)\npdfnative render --input big-doc.json --output report.pdf --stream\n\n# True constant-memory streaming (lowest peak memory; byte-identical)\npdfnative render --input big-doc.json --output report.pdf --stream-true\n\n# PDF/A conformance (embed the bundled Latin font — ISO 19005 requires embedded\n# fonts; this recipe is what the blocking veraPDF CI gate validates)\npdfnative render --input document.json --output archived.pdf \\\n  --tagged pdfa2b --font latin --lang latin\n```\n\n`document.json` is a [`DocumentParams`](https://github.com/Nizoka/pdfnative) object\n(`pdfnative schema render` prints the full shape, typography and PDF/X included):\n\n```json\n{\n  \"title\": \"Monthly Report\",\n  \"blocks\": [\n    { \"type\": \"heading\", \"text\": \"Monthly Report\", \"level\": 1 },\n    { \"type\": \"paragraph\", \"text\": \"Summary for April 2026.\" },\n    { \"type\": \"list\", \"style\": \"bullet\", \"items\": [\"Revenue: +18%\", \"NPS: 72\"] }\n  ],\n  \"footerText\": \"Confidential\",\n  \"metadata\": { \"author\": \"Finance Team\", \"subject\": \"April 2026 Report\" }\n}\n```\n\n### Typography, PDF/X-4 & reproducible output (v1.5.0)\n\n```bash\n# Typography: split long paragraphs across pages, keep headings with their body,\n# kern the bundled Latin font and turn on old-style numerals\npdfnative render --input report.json --output report.pdf --font latin --lang latin \\\n  --split-paragraphs --keep-headings-with-next --kerning --font-features onum,smcp\n\n# The full typography surface lives in layout.typography (JSON or --layout file):\n# widows/orphans, justify, optical margins, soft hyphens, French spacing + unit binding\npdfnative render --input report.json --output report.pdf --layout typography.json\n\n# PDF/X-4 for print: CMYK output intent, trapped flag, strict diagnostics — then re-check\npdfnative render --input brochure.json --output brochure.pdf \\\n  --pdfx pdfx4 --output-intent-icc press.icc --font latin --lang latin --trapped false --strict\npdfnative inspect --input brochure.pdf --check pdfx          # exit 0 when the claim holds\n\n# Reproducible bytes: pin the creation instant (or export SOURCE_DATE_EPOCH=1767225600)\npdfnative render --input doc.json --output a.pdf --creation-date 2026-01-01T00:00:00Z\nTZ=Asia/Tokyo pdfnative render --input doc.json --output b.pdf --creation-date 2026-01-01T00:00:00Z\nsha256sum a.pdf b.pdf                                        # identical\n```\n\n### Sign a PDF\n\n```bash\n# Keys from environment variables (recommended for CI/CD)\nexport PDFNATIVE_SIGN_KEY=\"$(cat private.pem)\"\nexport PDFNATIVE_SIGN_CERT=\"$(cat cert.pem)\"\npdfnative sign --input document.pdf --output signed.pdf\n\n# Keys from files\npdfnative sign --input document.pdf --output signed.pdf \\\n  --key private.pem --cert cert.pem\n```\n\n### Inspect a PDF\n\n```bash\n# JSON output (default)\npdfnative inspect --input report.pdf\n\n# Human-readable\npdfnative inspect --input report.pdf --format text\n\n# PDF/UA (ISO 14289-1) structural validation report\npdfnative inspect --input report.pdf --pdfua\n\n# CI accessibility gate (exit 1 if not PDF/UA-structurally-valid)\npdfnative inspect --input report.pdf --check pdfua\n\n# PDF/X-4 validation report, ISO 8601 dates (v1.5.0)\npdfnative inspect --input brochure.pdf --pdfx --iso-dates --fields pdfx.valid,metadata.creationDate\n\n# From stdin\ncat report.pdf | pdfnative inspect\n```\n\nExample output:\n\n```json\n{\n  \"version\": \"1.7\",\n  \"pageCount\": 3,\n  \"encrypted\": false,\n  \"pdfaConformance\": \"2b\",\n  \"signatures\": 1,\n  \"metadata\": {\n    \"title\": \"Monthly Report\",\n    \"author\": \"Nizoka\",\n    \"creationDate\": \"D:20260427120000+00'00'\"\n  }\n}\n```\n\n### Merge, split & extract pages (v1.2.0)\n\n```bash\n# Concatenate several PDFs (sources as positional args or repeated --input)\npdfnative merge a.pdf b.pdf c.pdf --output combined.pdf\n\n# Split one PDF into one file per page\npdfnative split --input report.pdf --output-dir pages/ --prefix page\n\n# Split into ranges — one output per comma-separated segment\npdfnative split --input report.pdf --output-dir out/ --pages \"1-2,3-4\"\n\n# Extract selected pages (1-based; order preserved, repeats allowed)\npdfnative extract --input report.pdf --output cover.pdf --pages \"4,1-2\"\n```\n\n### Extract text, fill forms & encrypt (v1.3.0)\n\n```bash\n# Extract reading-order text as NDJSON (one object per page — ideal for RAG/agents)\npdfnative extract-text --input report.pdf --format ndjson > pages.ndjson\n\n# Export a form's current values, edit, then fill (read → edit → fill)\npdfnative fill --input form.pdf --export > values.json\npdfnative fill --input form.pdf --data values.json --output filled.pdf\npdfnative fill --input filled.pdf --flatten --output flat.pdf\n\n# Preflight the environment (agents: gate `encrypt` on this)\npdfnative doctor --format json\n\n# Encrypt with AES-256, confirm the scheme, then decrypt\npdfnative encrypt --input report.pdf --output secure.pdf \\\n  --owner-password \"$OWNER\" --user-password \"$USER\" --algorithm aes-256\npdfnative inspect --input secure.pdf --encryption --password \"$USER\"\npdfnative decrypt --input secure.pdf --output plain.pdf --password \"$USER\"\n\n# Render native vector charts from a document with a `chart` block\npdfnative render --input dashboard.json --output dashboard.pdf\n```\n\n### Long-term signatures, compare & metadata (v1.4.0)\n\nThe canonical **PAdES ladder** — each rung is one command, network access is always\nan explicit opt-in (`--timestamp` / `--online` / `--url`), SSRF-guarded, no redirects:\n\n```bash\n# B-T  — sign with a PAdES profile and an RFC 3161 trusted timestamp\npdfnative sign --input doc.pdf --output signed.pdf \\\n  --profile pades --timestamp https://tsa.example.com/tsr\n\n# B-LT — archive the OCSP/CRL validation data into /DSS + /VRI\npdfnative ltv add --input signed.pdf --output lt.pdf --online\n\n# B-LTA — append a document timestamp covering every byte (repeat to renew)\npdfnative doc-timestamp --input lt.pdf --output lta.pdf --url https://tsa.example.com/tsr\npdfnative ltv add --input lta.pdf --output archived.pdf --online\n\n# Air-gapped variant: collect on a connected machine, embed fully offline\npdfnative ltv collect --input signed.pdf --output ltv.json --online\npdfnative ltv embed   --input signed.pdf --data ltv.json --output lt.pdf\n```\n\n```bash\n# Diff two PDFs by text + structure (exit 0 identical, exit 1 on differences)\npdfnative compare original.pdf revised.pdf --mode both --format json\n\n# Update /Info + XMP metadata without breaking existing signatures (incremental save)\npdfnative metadata --input signed.pdf --output retitled.pdf \\\n  --title \"Q3 Report (final)\" --author \"Finance Team\"\n\n# Verify the whole ladder — /DocTimeStamp revisions are validated as RFC 3161 tokens\npdfnative verify --input archived.pdf --strict\npdfnative inspect --input archived.pdf --signatures --check \"signatures>=1\"\n```\n\n### Annotate a PDF (v1.2.0)\n\n```bash\n# Attach markup annotations from a JSON spec (incremental save — signatures stay intact)\npdfnative annotate --input report.pdf --output annotated.pdf \\\n  --annotations notes.json\n\n# List them back out\npdfnative inspect --input annotated.pdf --annotations --format text\n```\n\n`notes.json` is a JSON array (or `{ \"annotations\": [...] }`), each entry a markup or link\nannotation plus a 1-based `page`:\n\n```json\n{\n  \"annotations\": [\n    { \"page\": 1, \"type\": \"highlight\", \"rect\": [72, 700, 320, 715], \"color\": \"#FFD400\", \"contents\": \"Check this figure.\" },\n    { \"page\": 1, \"type\": \"text\", \"rect\": [330, 700, 350, 720], \"icon\": \"Comment\", \"contents\": \"Needs a citation.\" },\n    { \"page\": 1, \"type\": \"link\", \"rect\": [72, 640, 300, 655], \"url\": \"https://pdfnative.dev\" }\n  ]\n}\n```\n\n### Render bookmarks & introspect layout (v1.2.0)\n\n```bash\n# Add a bookmark tree derived from the document's headings\npdfnative render --input doc.json --output book.pdf --outline auto\n\n# …or supply an explicit OutlineItem[] tree\npdfnative render --input doc.json --output book.pdf --outline outline.json\n\n# Register the bundled math font so ∑ ∫ √ π render as real glyphs\npdfnative render --input math.json --output math.pdf --font latin --font math\n\n# Emit a LayoutInspection JSON report instead of a PDF\npdfnative render --input doc.json --output layout.json --inspect-layout\n\n# Render a PDF with debug guides overlaid\npdfnative render --input doc.json --output debug.pdf --debug-layout margins,content,cells\n```\n\n### AI-governance / Human-in-the-Loop (v1.2.0)\n\nAgents act as **draftsmen**: they may draft an issue/PR locally, but a **human** must review\nand submit it. Nothing here touches the network.\n\n```bash\n# Print the human/agent protocol and the machine-readable policy\npdfnative govern rules\npdfnative govern policy --pretty\n\n# Gate a locally-authored draft (exit 1 / E_POLICY on a violation)\npdfnative govern verify-issue ./draft.md\n```\n\n## Examples\n\nReady-to-run examples are in [`samples/`](samples/), organized by feature category:\n\n| Category | Examples | Description |\n|----------|----------|-------------|\n| [`render/document/`](samples/render/document/) | 6 files | Minimal, report, all-blocks reference, invoice, technical spec, `--max-blocks` guard |\n| [`render/table/`](samples/render/table/) | 2 files | Project status, financial summary |\n| [`render/table-smart/`](samples/render/table-smart/), [`table-variant/`](samples/render/table-variant/) | 1 + 1 files | Smart-table flags; `--variant table` (`PdfParams`, fonts embedded since v1.5.0) |\n| [`render/barcode/`](samples/render/barcode/) | 3 files | QR code, Code 128 shipping label, EAN-13 product |\n| [`render/form/`](samples/render/form/) | 2 files | Contact form, survey |\n| [`render/toc/`](samples/render/toc/) | 1 file | Document with auto-generated table of contents |\n| [`render/link/`](samples/render/link/) | 1 file | Resource directory with hyperlinks |\n| [`render/watermark/`](samples/render/watermark/) | 3 files | Draft watermark, confidential watermark, CLI-flag styling |\n| [`render/layout/`](samples/render/layout/) | 3 files | US Letter, A5 portrait, A4 landscape |\n| [`render/headers-footers/`](samples/render/headers-footers/), [`template/`](samples/render/template/) | 1 + 2 files | Page-number placeholders; `--template` deep-merge |\n| [`render/pdfa/`](samples/render/pdfa/), [`attachments/`](samples/render/attachments/) | 5 + 1 files | PDF/A-1b, PDF/A-2b, PDF/A-2u, PDF/A-3b archival conformance; (v1.5.0) an AcroForm under PDF/A-2b; PDF/A-3b XML attachment |\n| [`render/encryption/`](samples/render/encryption/) | 2 files | AES-128 / AES-256 protected renders |\n| [`render/outline/`](samples/render/outline/) | 2 files | PDF bookmarks — `--outline auto` + explicit tree |\n| [`render/math/`](samples/render/math/) | 1 file | Math/technical symbols via `--font math` |\n| [`render/inspect-layout/`](samples/render/inspect-layout/) | scripts | `--inspect-layout` report + `--debug-layout` guides |\n| [`render/font/`](samples/render/font/) | 5 files | Bundled font presets: Latin, the 1.3.0 scripts, emoji, (v1.5.0) the five 1.8.0 scripts, `--font-file`, colour-emoji skin tones / ZWJ sequences / flags |\n| [`render/multilang/`](samples/render/multilang/) | 11 files | Thai, Japanese, multilingual drivers, (v1.5.0) Lao, Tai Tham / New Tai Lue / Tai Le / Cham, Hausa / Yoruba / Igbo / Swahili, and four families (European & Caucasian, right-to-left, Indic, Chinese & Korean) — every one of the 27 script codes is rendered by the corpus |\n| [`render/chart/`](samples/render/chart/) | 5 files | Native vector charts — bar/line/pie/donut plus (v1.4.0) stacked bars, area/scatter, dual axes, log & time axes |\n| [`render/print/`](samples/render/print/) | 7 files | Print production — bleed/trim boxes + printer's marks, viewer preferences, (v1.5.0) CMYK colours, colour bars, PDF/X-4 with a synthetic CMYK profile |\n| [`render/typography/`](samples/render/typography/) | 7 files | (v1.5.0) Paragraph breaking, justify + optical margins + soft hyphens, French (`fr`, `fr-CA`) and custom punctuation spacing, unit binding, kerning + OpenType features, per-block `keepWithNext` / `splittable` |\n| [`render/base14/`](samples/render/base14/) | 1 file | (v1.5.0) `layout.typography.metrics: \"exact\"` on the base-14 path — rendered with no `--font` flag, the only place the option acts |\n| [`render/reproducible/`](samples/render/reproducible/) | 2 files | (v1.5.0) `--creation-date` / `SOURCE_DATE_EPOCH` — the double-render script proves byte identity across timezones |\n| [`render/watch/`](samples/render/watch/) | scripts | `--watch` re-render on change |\n| [`merge/`](samples/merge/) | scripts | Concatenate PDFs (page-tree) |\n| [`split/`](samples/split/) | scripts | Split one PDF per-page or per-range |\n| [`extract/`](samples/extract/) | scripts | Pull selected pages into a new PDF |\n| [`extract-text/`](samples/extract-text/) | scripts | Reading-order text (text / json / ndjson) |\n| [`fill/`](samples/fill/) | scripts | Fill, flatten & export AcroForms |\n| [`encrypt/`](samples/encrypt/) | scripts | Encrypt / decrypt round-trip (AES-256, `--stream`) |\n| [`doctor/`](samples/doctor/) | 2 pairs | Environment / capability preflight; (v1.5.0) fonts, Unicode and conformance targets |\n| [`metadata/`](samples/metadata/) | scripts | Update /Info + XMP metadata (incremental save) |\n| [`compare/`](samples/compare/) | scripts | Diff two PDFs by text + structure |\n| [`annotate/`](samples/annotate/) | 2 pairs | Attach markup annotations (incremental save); (v1.5.0) `link` annotations |\n| [`govern/`](samples/govern/) | scripts | AI-governance / HITL: rules, policy, verify-issue |\n| [`sign/`](samples/sign/) | 10 pairs | Digital signature incl. timestamp (B-T), LTV ladder, multi-signatures, native vs pure-JS crypto, (v1.5.0) `--timestamp-timeout` (Bash + PowerShell) |\n| [`verify/`](samples/verify/) | 7 pairs | Signature verification: trust roots, revocation, strict mode, (v1.5.0) weak-digest note |\n| [`inspect/`](samples/inspect/) | 10 pairs | JSON & text inspection incl. `--annotations`, `--signatures`, (v1.5.0) `--check pdfx` and `--iso-dates` (Bash + PowerShell) |\n| [`batch/`](samples/batch/) | 3 pairs | Directory render and `--manifest` pipelines |\n| [`agent/`](samples/agent/) | 5 pairs | `--json` + `--dry-run`, `schema`, the error envelope, token economy, (v1.5.0) global flags before the command |\n| [`completion/`](samples/completion/), [`config/`](samples/config/) | 1 + 1 pairs | Shell completions; `.pdfnativerc.json` defaults |\n| [`streaming/`](samples/streaming/) | 2 pairs | Streaming render (single-pass, page-by-page, true constant-memory) |\n\n**Render every sample at once** (the same run the CI baseline uses):\n\n```bash\nnpm run build && npm run test:generate     # → test-output/samples/ (91 sample PDFs, byte-stable)\nnpx tsx scripts/verify-samples.ts          # compare with tests/regression/baselines/samples.sha256.json\n```\n\n`PDFNATIVE_CLI=$(which pdfnative) npm run test:generate` drives a globally installed binary instead.\n\nSee [`samples/README.md`](samples/README.md) for full descriptions, block type reference, and integration patterns (GitHub Actions, Docker, TypeScript).\n\n---\n\n## Command Reference\n\nThe 21 commands are grouped by purpose (the global `pdfnative --help` shows the same grouping):\n\n| Group | Commands |\n|-------|----------|\n| **Create & edit** | [`render`](#pdfnative-render), [`fill`](#pdfnative-fill), [`annotate`](#pdfnative-annotate), [`metadata`](#pdfnative-metadata) |\n| **Page tree** | [`merge`](#pdfnative-merge), [`split`](#pdfnative-split), [`extract`](#pdfnative-extract) |\n| **Security** | [`sign`](#pdfnative-sign), [`verify`](#pdfnative-verify), [`ltv`](#pdfnative-ltv), [`doc-timestamp`](#pdfnative-doc-timestamp), [`encrypt`](#pdfnative-encrypt), [`decrypt`](#pdfnative-decrypt) |\n| **Read & extract** | [`inspect`](#pdfnative-inspect), [`extract-text`](#pdfnative-extract-text), [`compare`](#pdfnative-compare) |\n| **Automation & meta** | [`batch`](#pdfnative-batch), [`doctor`](#pdfnative-doctor), [`schema`](#pdfnative-schema), [`completion`](#pdfnative-completion), [`govern`](#pdfnative-govern) |\n\n### `pdfnative render`\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--input <file>` | stdin | Path to a JSON file (`DocumentParams` or `PdfParams` if `--variant table`) |\n| `--output <file>` | stdout | Output PDF path |\n| `--stream` | false | Single-pass streaming output (`AsyncGenerator`); no TOC, no `{pages}` |\n| `--stream-page-by-page` | false | Stream at PDF object boundaries (TOC- and `{pages}`-compatible) |\n| `--stream-true` | false | True constant-memory streaming; parts freed as emitted; byte-identical; no TOC, no `{pages}` |\n| `--chunk-size <bytes>` | `65536` | Chunk size for `--stream` / `--stream-true` (not `--stream-page-by-page`) |\n| `--variant <kind>` | `document` | `document` (default) or `table` (selects `buildPDFBytes`) |\n| `--layout <file.json>` | — | Load a `Partial<PdfLayoutOptions>` (CLI flags override) |\n| `--page-size <size>` | from layout file or pdfnative default | Named (`a4`, `letter`, `legal`, `a3`, `tabloid`, `a5`) or `WxH` in points |\n| `--margin <N>` or `--margin <t,r,b,l>` | from layout / default | Page margins in points |\n| `--compress` | false | Enable FlateDecode compression |\n| `--max-blocks <n>` | `100000` | Maximum document blocks before pdfnative aborts (large-report guard) |\n| `--tagged <level>` | none | PDF/A: `none`, `pdfa1b`, `pdfa2b`, `pdfa2u`, `pdfa3b` (mutually exclusive with `--pdfx`) |\n| `--pdfx <target>` | none | (v1.5.0) PDF/X: `pdfx4` (ISO 15930-7). Requires a CMYK ICC output intent (`--output-intent-icc` or `layout.outputIntent`), refuses encryption and PDF/A in the same file (`E_INPUT` / exit 2); the `--json` envelope carries `pdfx` |\n| `--output-intent-icc <file.icc>` | — | (v1.5.0) ICC profile for `layout.outputIntent.iccProfile` (16 MiB cap, `acsp` signature checked; `prtr` CMYK required for PDF/X) |\n| `--output-intent-id <s>` | ICC file basename | (v1.5.0) `outputIntent.outputConditionIdentifier` |\n| `--trapped true\\|false\\|unknown` | — | (v1.5.0) `/Trapped` + `pdf:Trapped` (PDF/X-4 requires `true` or `false`) |\n| `--strict` | false | Escalate the 9 diagnostic codes — PDF/A (`PDFA_NO_FONT_ENTRIES`, `PDFA_UNEMBEDDED_FORM_FONT`, `PDFA_DEVICE_CMYK_IMAGE`, `PDFA_*`), PDF/X (`PDFX_NO_FONT_ENTRIES`, `PDFX_DEVICE_CMYK`, `PDFX_ANNOTATIONS`) and `TYPOGRAPHY_FEATURE_INEFFECTIVE` — into an error (exit 1, `E_CHECK_FAILED`) **before** any output byte; without it they are stderr warnings + a `diagnostics[]` array in the `--json` envelope |\n| `--split-paragraphs` | false | (v1.5.0) `layout.typography.splitParagraphs` — long paragraphs may break across pages (widow/orphan rules apply) |\n| `--keep-headings-with-next` | false | (v1.5.0) `layout.typography.keepHeadingsWithNext` — a heading never ends a page alone |\n| `--kerning` | false | (v1.5.0) `layout.typography.kerning` — GPOS pair kerning for embedded fonts |\n| `--font-features <tag,…>` | — | (v1.5.0) `layout.typography.fontFeatures` — OpenType feature tags (`onum`, `smcp`, `tnum`, …; ligature features are not applied by the engine; four alphanumerics each) |\n| `--conformance <1b\\|2b\\|3b>` | — | **Deprecated** — use `--tagged pdfa<level>` |\n| `--watermark-text <s>` / `--watermark-image <path>` | — | Text or image watermark |\n| `--watermark-opacity <0-1>` / `--watermark-angle <deg>` / `--watermark-color <#hex>` / `--watermark-font-size <pt>` / `--watermark-position background\\|foreground` | — | Watermark styling |\n| `--watermark-position background\\|foreground` | `background` | Render order |\n| `--header-{left,center,right} <tpl>` | — | Header template; placeholders `{page}`, `{pages}`, `{date}`, `{title}` |\n| `--footer-{left,center,right} <tpl>` | — | Footer template; same placeholders |\n| `--encrypt [aes-128\\|aes-256]` | — | Enable encryption (bare = aes-128). Same vocabulary as merge/split/extract |\n| `--owner-password <s>` | `$PDFNATIVE_ENCRYPT_OWNER_PASS` | Owner password (required to encrypt) |\n| `--user-password <s>` | `$PDFNATIVE_ENCRYPT_USER_PASS` | Optional user (open) password |\n| `--permissions <list>` | _all denied_ | Comma list: `print,copy,modify,extract` |\n| _(legacy aliases)_ | — | `--encrypt-algorithm`, `--encrypt-owner-pass`, `--encrypt-user-pass`, `--encrypt-permissions` still work |\n| `--attachment <path>[:mime[:rel[:desc]]]` _(repeatable)_ | — | PDF/A-3 file attachment |\n| `--lang <code,code>` | — | Activate registered font loaders for non-Latin scripts (`th`, `ja`, `ar`, `te`, `si`, `km`, `lo`, …); Latin is built-in. Aliases `ha`, `yo`, `ig`, `sw` resolve to `latin` |\n| `--font <name>` _(repeatable)_ | — | Register a bundled font shortcut. Allow-list: `latin`, `emoji`, `color-emoji`, `math`, and the 27 script codes `ar hy bn ru hi am ka el he ja km ko my pl zh si ta te th bo tr vi` + (v1.5.0) `lo nod khb tdd cjm`; `ha yo ig sw` alias `latin`. The name doubles as the `--lang` code. `--variant table` embeds them too |\n| `--font-file <path.ttf>[:name]` _(repeatable)_ | — | (v1.5.0) Register a custom TrueType/OpenType font from disk (name defaults to the file stem, `[a-z0-9-]`; added to `--lang`). 32 MiB cap, magic bytes (`00 01 00 00` / `true` / `OTTO` — collections and WOFF refused), parsed and validated by pdfnative before use; a name colliding with the allow-list is a usage error. Never loadable from a JSON payload |\n| `--outline auto\\|<file.json>` | — | Add a PDF bookmark tree: `auto` derives it from headings; a path loads an explicit `OutlineItem[]` tree |\n| `--inspect-layout` | false | Emit a `LayoutInspection` JSON report instead of a PDF (document variant only) |\n| `--debug-layout [margins,content,cells]` | — | Overlay layout debug guides on the rendered PDF (bare flag = all) |\n\n**Document & layout JSON (v1.5.0, pdfnative ≥ 1.8.0)** — `layout.typography`\n(`widows`, `orphans`, `splitParagraphs`, `keepHeadingsWithNext: true | { minLines }`,\n`opticalMargins`, `punctuationSpacing: \"fr\" | \"fr-CA\" | [{ char, side, space }]`,\n`unitBinding`, `bindShortWords`, `hyphenationLanguage`, `kerning`, `fontFeatures: [tag, …]`,\n`metrics: \"exact\"` — base-14 path only, inert once `--font` registers a font; soft hyphens U+00AD are honoured unconditionally), paragraph\n`align: \"justify\"`, block-level `keepWithNext` / `splittable`; every colour accepts CMYK (`\"c m y k\"` 0–1 or\n`[c,m,y,k]` percent) beside hex / RGB; `layout.print.marks.colourBars: true | { tints, size }`;\n`layout.pdfx: \"pdfx4\"` with a `prtr` CMYK `layout.outputIntent` (`iccProfile` as a number\narray in JSON); `layout.creationDate` (ISO string) — flags win over the file, nested\n`typography` / `outputIntent` objects merge one level deep. `--strict` also covers the\n`TYPOGRAPHY_FEATURE_INEFFECTIVE` diagnostic (a requested feature the font cannot honour).\n\n**Document & layout JSON (v1.4.0, pdfnative ≥ 1.7.0)** — no new flags, richer JSON:\nimage blocks accept `src` (a path resolved relative to the `--input` JSON's directory)\nas an alternative to `dataBase64`; `chart` blocks grow to **9 types** (`bar`, `barH`,\n`stackedBar`, `stackedBarH`, `line`, `area`, `scatter`, `pie`, `donut`) with\n`series[].xValues`, `series[].yAxis: \"right\"` + `axis2`, `axis.scale: \"log\"`,\n`xAxis: category|linear|time`, `dataLabels`, `labelStride`, and `labelRotation`; the\n`--layout` file gains `print` (bleed, `trimBox`, `bleedBox`, `artBox`, `cropBox`,\nprinter `marks`, `userUnit` 1–75000), `outputIntent` (ICC RGB) and `viewerPreferences`\n(`duplex`, `pickTrayByPDFSize`, `printPageRange`, `numCopies`); `params.metadata`\naccepts `author`/`subject`/`keywords`/`trapped`. Validate with `pdfnative schema render`.\n\nSee `samples/render/` for a working example of every category.\n\n### `pdfnative sign`\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--input <file>` | stdin | Path to the input PDF |\n| `--output <file>` | stdout | Output signed PDF path |\n| `--key <file>` | `$PDFNATIVE_SIGN_KEY` | Path to PEM private key (env var takes precedence) |\n| `--cert <file>` | `$PDFNATIVE_SIGN_CERT` | Path to PEM certificate (env var takes precedence) |\n| `--cert-chain <file>` _(repeatable)_ | `$PDFNATIVE_SIGN_CHAIN` | Intermediate CA PEMs |\n| `--algorithm rsa-sha256\\|ecdsa-sha256` | `rsa-sha256` | Signature algorithm (RSA or P-256 ECDSA) |\n| `--digest sha256\\|sha384\\|sha512` | `sha256` | CMS digest algorithm (RSA only; `ecdsa-sha256` is sha256-only) |\n| `--profile pkcs7\\|pades` | `pkcs7` | `pades` = ETSI.CAdES.detached (PAdES B-B: ESS signing-certificate-v2, omits signing-time) |\n| `--reason <s>` | — | Reason for signing (PDF metadata) |\n| `--name <s>` | — | Signer name (PDF metadata) |\n| `--location <s>` | — | Signing location (PDF metadata) |\n| `--contact <s>` | — | Signer contact (PDF metadata) |\n| `--signing-time <ISO 8601>` | now | Explicit signing timestamp |\n| `--timestamp <tsa-url>` | — | Embed a verified **RFC 3161** timestamp token at signing time (PAdES B-T with `--profile pades`). **Opt-in network**, SSRF-guarded. TSA failure → `E_NETWORK`; malformed response → `E_PARSE`; never a silent fallback |\n| `--timestamp-digest sha256\\|sha384\\|sha512` | `sha256` | Digest for the TSA message imprint |\n| `--timestamp-nonce <hex>` | random 8 bytes | Explicit TSA request nonce |\n| `--timestamp-timeout <ms>` | `10000` | (v1.5.0) Timeout for the TSA round-trip (positive integer; usage error without `--timestamp`); reported as `timestamp.timeoutMs` |\n| `--allow-multiple` | false | Allow signing an already-signed PDF (appends a signature field); default stays idempotent single-signature (1.x behaviour) |\n| `--field-name <name>` | auto | Signature form-field name |\n| `--signature-rect \"x1,y1,x2,y2\"` | invisible | Visible signature widget rectangle (PDF points) |\n| `--signature-page <n>` | `1` | 1-based page for the signature widget |\n| `--placeholder-bytes <n>` | auto | Explicit `/Contents` placeholder size (overrides the estimate) |\n| `--pure-crypto` | false | Force pdfnative's pure-JS RSA/ECDSA math instead of the default native `node:crypto` (constant-time) provider |\n\nWithout `--timestamp` the command performs **no network I/O**, and `--dry-run` never\ntouches the network even when `--timestamp` is present. Under `--json`, a timestamped\nsignature adds `timestamp: { url, digest, timeoutMs? }` to the success envelope.\n`--signing-time` is a deliberate legal instant and is **not** pinned by the global\n`--creation-date`.\n\n### `pdfnative inspect`\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--input <file>` | stdin | Path to the PDF to inspect |\n| `--output <file>` | stdout | Output report path |\n| `--format json\\|text` | `json` | Output format |\n| `--verbose` | false | Add trailer keys, catalog keys, object count, XMP |\n| `--pages` | false | Add per-page metadata array (width/height/rotation + `cropBox`/`trimBox`/`bleedBox`/`artBox`/`userUnit` when present) |\n| `--annotations` | false | List markup + link annotations per page (page labels are reported automatically when present) |\n| `--form-fields` | false | List AcroForm fields (name, type, value, required/read-only, options) |\n| `--encryption` | false | Report the encryption scheme (`algorithm`, `revision`, `authenticatedAs`), or `null` |\n| `--signatures` | false | Signature-field inventory: `fieldName`, `subFilter`, `byteRange`, `isDocTimestamp`, `isPlaceholder`, `sigObjNum`, `contentsLength` — never the signature bytes |\n| `--password <s>` | — | Password for an encrypted PDF (env: `PDFNATIVE_PASSWORD`) |\n| `--pdfua` | false | Add a PDF/UA (ISO 14289-1) structural validation report (`valid` + `errors` + `warnings`) |\n| `--pdfx` | false | (v1.5.0) Add a PDF/X-4 validation report (`pdfx: { valid, target, errors, warnings }`, pdfnative's `validatePdfX`); `pdfxConformance` (XMP `GTS_PDFXVersion`) is always reported |\n| `--iso-dates` | false | (v1.5.0) Normalise `metadata.creationDate` / `modDate` from `D:YYYYMMDD…` to ISO 8601 (unparsable strings are left as is) |\n| `--check pdfa\\|signed\\|encrypted\\|pdfua\\|pdfx\\|\"signatures>=N\"` _(repeatable)_ | — | CI-friendly assertion; AND semantics; sets exit code (0 = pass, 1 = fail). `signatures>=N` counts real signatures (placeholders and `/DocTimeStamp` fields excluded); `pdfx` requires a PDF/X-4 claim that validates |\n\nv1.4.0 also fixes the top-level `signatures` and `formFields` counters, which previously\nalways reported `0`, and reports `metadata.trapped` when present. `--summary` returns\n`{ pages, encrypted, signatures, pdfa, pdfx }`.\n\n### `pdfnative verify`\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--input <file>` | stdin | Path to the (possibly signed) PDF |\n| `--format json\\|text` | `json` | Output format |\n| `--strict` | false | Exit 1 on any failure or zero signatures (CI-friendly) |\n| `--trust <root.pem>` _(repeatable)_ | _self-signed only_ | Trusted root certificates (PEM) |\n| `--revocation offline\\|online\\|disabled` | `offline` | Revocation source: embedded `/DSS` only, also fetch online (SSRF-guarded), or skip |\n| `--revocation-policy soft-fail\\|strict` | `soft-fail` | `strict` fails the signature on any non-`good` status; `soft-fail` only fails on explicit `revoked` |\n\n**Scope:** byte-range integrity (SHA-256), full CMS signature value\n(RSA-PKCS#1 v1.5 — SHA-256/384/512, reported as `rsa-sha256`/`rsa-sha384`/`rsa-sha512` —\nplus ECDSA-SHA256 over P-256), certificate chain + trust, **RFC 3161 timestamp validation\n(PAdES-T)**, and **OCSP (RFC 6960) + CRL (RFC 5280) revocation** — embedded from the PDF\n`/DSS` offline by default, with opt-in online fetching through an SSRF-guarded HTTP client.\nv1.4.0 additions: each signature also reports its `fieldName` and `isDocTimestamp`, and\n**`/DocTimeStamp` revisions (PAdES B-LTA)** are validated as RFC 3161 timestamp tokens.\nv1.5.0: each timestamp reports its `messageImprint` algorithm as `timestampDigest`; a\nSHA-1 imprint adds the note `weak digest: RFC 3161 messageImprint uses SHA-1 (refused\nunder --strict)` and, under `--strict`, fails the timestamp (`E_VERIFY_FAILED`).\nSign-side LTV lives in [`sign --timestamp`](#pdfnative-sign), [`ltv`](#pdfnative-ltv) and\n[`doc-timestamp`](#pdfnative-doc-timestamp).\n\n### `pdfnative ltv`\n\nPAdES **B-LT**: archive the certificates, OCSP responses and CRLs needed to validate the\ndocument's signatures long after certificates expire, into the PDF's `/DSS` + `/VRI`\ndictionaries (incremental save — existing signatures stay valid).\n\n```bash\npdfnative ltv collect --input signed.pdf --online [--output ltv.json]  # fetch → replayable JSON\npdfnative ltv embed   --input signed.pdf --data ltv.json [--output out.pdf]  # 100 % offline\npdfnative ltv add     --input signed.pdf --online [--output out.pdf]   # collect + embed\n```\n\n`collect` **requires `--online`** (explicit network opt-in, SSRF-guarded, no redirects)\nand emits a replayable JSON file (schema subject: `ltv-data`). `embed` **never** performs\nnetwork I/O — the collect/embed split supports air-gapped pipelines: collect on a\nconnected machine, embed offline. `add` does both in one pass.\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--input <file>` | stdin | Signed source PDF |\n| `--output <file>` | stdout | Output: JSON (`collect`) or PDF (`embed` / `add`) |\n| `--online` | — **(required for `collect` / `add`)** | Explicit opt-in for network fetches (SSRF-guarded, no redirects) |\n| `--prefer ocsp\\|crl` | `ocsp` | Preferred revocation source |\n| `--extra-cert <pem>` _(repeatable)_ | — | Extra chain certificates (PEM) |\n| `--data <file>` | — **(required for `embed`)** | Previously collected `ltv-data` JSON |\n| `--timeout <ms>` | `10000` | Network timeout |\n| `--dry-run` | false | Validate inputs; no output, no network |\n\n**The canonical PAdES ladder:**\n\n```text\nsign --timestamp <tsa> --profile pades   →  B-T\nltv add --online                         →  B-LT\ndoc-timestamp --url <tsa>                →  B-LTA\nltv add --online                         →  LTV for the doc-timestamp itself\n```\n\n### `pdfnative doc-timestamp`\n\nPAdES **B-LTA**: append a `/DocTimeStamp` signature field (SubFilter `/ETSI.RFC3161`,\nISO 32000-2 §12.8.5) covering every byte of the document, as an incremental revision —\nearlier revisions stay **byte-identical**. Repeat periodically to renew LTA protection.\n\n| Flag | Default | Description |\n|------|---------|-------------|\n| `--input <file>` | stdin | Signed source PDF |\n| `--output <file>` | stdout | Output PDF |\n| `--url <tsa-url>` | — **(required)** | RFC 3161 TSA URL (explicit network opt-in; SSRF-guarded, no redirects) |\n| `--digest sha256\\|sha384\\|sha512` | `sha256` | Timestamp message-imprint digest |\n| `--field-name <name>` | `DocTimeStamp1` | Timestamp field name (auto-suffixed on collision) |\n| `--placeholder-bytes <n>` | `12288` | `/Contents` placeholder size |\n| `--nonce <hex>` | random | Explicit TSA request nonce |\n| `--timeout <ms>` | `10000` | Network timeout |\n| `--dry-run` | false | Validate inputs; no output, no network |\n\nTSA failures map to `E_NETWORK`; a malformed TSA response maps to `E_PARSE`.\n`verify` validates `/DocTimeStamp` revisions as RFC 3161 tokens (`isDocTimestamp: true`).\n\n### `pdfnative batch`\n\nTwo modes: **directory mode** (render every `*.json` in a direct","readmeFilename":"README.md"}