foliojs/pdfkit
59.1
Adequate · 2 October 2026
13.4k
lines of production code
JavaScript
primary language
2
measurements over time
What this system is
This system is a JavaScript library for generating PDF documents, designed to function in both Node.js and browser environments. It provides core capabilities for creating structured documents, including text rendering, image embedding with format support, and form field creation. The library also features advanced layout tools such as table generation with accessibility support and integrates with modern bundlers like Webpack and Browserify for client-side usage.
How it got here
2011 — ES6 migration and dependency modernization
8 changes.
The project underwent a comprehensive migration from CoffeeScript to ES6, rewriting core libraries for font parsing, image handling, and mixins to improve browser compatibility and feature support. This effort was accompanied by modernizing the build infrastructure, switching to Yarn 4 and Vitest, and updating dependencies to require Node 20+ and support modern module systems.
2018–2021 — test coverage and browser examples
7 changes.
This period focused on expanding test coverage for image processing, PDF generation features, and visual regression testing to ensure robustness. It also introduced new examples and demos for accessibility, forms, and browser-based bundling with Browserify and Webpack 5.
2025–2026 — PDF rendering and infrastructure modernization
7 changes.
This period focused on enhancing PDF capabilities by introducing a new accessible table component and developing tools for efficient AFM font conversion. Concurrently, the project modernized its underlying infrastructure by migrating cryptography libraries to modern alternatives and updating the Yarn package manager.
Features
Add PDF table rendering with accessibility support
Introduces a new table component in \lib/table\ that renders structured PDF tables with support for row/column spanning, dynamic column widths (including star-based distribution), and cell styling (borders, padding, background colors). The implementation includes built-in accessibility features, generating PDF structure elements (Table, TR, TD/TH) with proper headers, scopes, and IDs to improve screen-reader compatibility.
lib/table · high confidence
Add webpack 5 example for browser-based PDF generation
Introduces a new webpack 5 example demonstrating how to bundle PdfKit for browser environments. The setup configures webpack to handle Node.js-specific modules (buffer, stream, zlib, util, assert) via fallbacks, disables the crypto module to reduce bundle size, and provides rules to inline static assets as base64 while loading lazy assets as URLs. The example includes a live editor that allows users to modify and preview PDF generation code in the browser.
examples/webpack · high confidence
Introduce AFM font conversion tools and build documentation
Adds a new set of tooling scripts and documentation for converting Adobe Font Metrics (AFM) files into JavaScript modules. The \tools/afm-converter.js\ script and its entry points (\convert-afm-runtime.js\, \convert-afm-parsed.js\) generate pre-parsed font data to avoid runtime parsing overhead, supporting both compact runtime formats and raw parsed schemas. The \tools/README.md\ documents these commands and the resulting data structures, while \asset-plugin.mjs\ and \binary-plugin.mjs\ provide Rollup utilities to embed source files and binary assets as base64 strings during the build process.
tools · high confidence
New Browserify demo with live code editing and local storage
Added a new browser-based demo in the examples/browserify directory that bundles PDFKit with Browserify. The demo features an interactive code editor (Ace) where users can modify PDF generation scripts and see the results update in real-time within an embedded iframe. It also persists the editor's content to the browser's local storage, allowing users to resume their work in subsequent sessions.
examples/browserify · high confidence
New and updated examples for accessibility, forms, and PDF features
The examples directory has been refreshed with new and updated scripts demonstrating key PDFKit capabilities. A new accessible-links example shows how to create PDF/UA compliant documents with properly nested link structure elements. The kitchen-sink-accessible example provides a comprehensive guide to building fully accessible PDFs with logical structure, alt text, and headings. Existing examples have been updated to showcase form field creation (including text, buttons, and lists), file attachments, PNG transparency and opacity options, horizontal text scaling, and spot color usage.
examples · high confidence
Architecture
Core library rewritten in ES6 with platform-specific entry points
The library has been rewritten in ES6, introducing separate entry points for browser and Node.js environments (\document.browser.js\ and \document.node.js\) to handle platform-specific dependencies like file system access and standard font loading. The core \PDFDocument\ class now extends Node's \Readable\ stream, and the codebase replaces Node \Buffer\ operations with \Uint8Array\-based helpers in \binary.js\ and \data.js\ to improve browser compatibility and reduce bundle size.
lib · high confidence
Behavioural changes
Added TypeScript definitions for Vitest custom matchers
Added a new type declaration file (types/jest.custom-matchers.d.ts) that provides ambient typings for custom Vitest matchers, specifically to enable TypeScript language server support for the new toContainChunk and toContainText matchers used in tests.
types · high confidence
Demo migrated from CoffeeScript to JavaScript
The demo application has been converted from CoffeeScript to JavaScript (ES6+). This change removes the \demo/test.coffee\ source file and the \demo/tiger.js\ data file, replacing them with their JavaScript equivalents to align with the project's broader language migration.
demo · high confidence
Major rewrite of mixins to ES6 and addition of new PDF features
The mixins in lib/mixins have been rewritten from CoffeeScript to ES6, introducing support for PDF tables, AcroForm options mapping, and enhanced text handling. The changes also include fixes for text wrapping, font cache collisions, and accessibility features, along with the addition of new methods for rounded rectangles and arc drawing.
lib/mixins · high confidence
Removal of legacy CoffeeScript font table parsers
The \lib/font/tables\ directory has been cleared of its previous CoffeeScript implementation files, specifically deleting the parsers for the \cmap\, \head\, \hhea\, \hmtx\, \maxp\, \name\, \os2\, and \post\ font tables. This change removes the old font parsing library from this location, aligning with the commit intent to switch to a new prototype-based approach for handling font data.
lib/font/tables · high confidence
Replace crypto-js with @noble/hashes and native APIs
The internal cryptography implementation in lib/crypto has been migrated from the crypto-js library to the @noble/hashes and @noble/ciphers packages, alongside the use of native browser APIs for random number generation. This change updates the underlying providers for AES (CBC/ECB), MD5, and SHA-256 hashing, as well as RC4 encryption, ensuring consistent build outputs and potentially improved performance or bundle size by using modern, tree-shakeable libraries.
lib/crypto · high confidence
Rewrite JPEG and PNG image parsers in JavaScript with improved EXIF and transparency support
The JPEG and PNG image parsers in lib/image have been rewritten from CoffeeScript to modern JavaScript (ES6+). The new JPEG parser now reads EXIF orientation data to correctly handle rotated images, and the PNG parser has been updated to properly support interlaced images, indexed transparency, and 16-bit alpha channels. These changes improve compatibility with various image formats and ensure images are embedded into PDFs with correct orientation and transparency.
lib/image · high confidence
Rewrite font parsing engine from CoffeeScript to ES6
The font parsing logic in lib/font has been completely rewritten from CoffeeScript to ES6. The new implementation introduces a dedicated AFMFont class for handling Adobe Font Metrics, which now includes support for kerning pairs and explicit WinAnsi encoding mappings. Standard fonts are now embedded using this new AFM-based engine, replacing the previous parsing approach. The old CoffeeScript font files (afm.coffee, dfont.coffee, directory.coffee, table.coffee, ttf.coffee) have been removed.
lib/font · high confidence
Test coverage
Added package resolution tests for Node and browser builds; Added tests for AFM font converter tool; Added unit tests for image processing; Added unit tests for the toContainChunk Jest matcher; Added visual regression tests for PDF rendering; Expanded unit test coverage for PDF generation features.
Dependencies
PDFKit v0.20.2: Modernized build, Node 20+ requirement, and new ESM/Node exports
This release updates the pdfkit library to version 0.20.2, shifting the minimum Node.js requirement to v20.0.0 and replacing the CoffeeScript source with native JavaScript. The package now supports modern module systems via new \exports\ and \imports\ fields, providing distinct entry points for Node.js (ESM and CommonJS) and browsers, including specific subpath exports for standard fonts. Dependency management has been modernized with \yarn\ v4, and runtime dependencies have been updated to use \fflate\ for compression, \@noble/hashes\ for hashing, and \fontkit\ for font handling. A new webpack example is included to demonstrate bundling with these updated dependencies.
(dependencies) · high confidence
Yarn updated to version 4.16.0
The bundled Yarn binary in .yarn/releases has been upgraded to version 4.16.0. This update brings the latest improvements and bug fixes from the Yarn team to the project's package management workflow.
.yarn · high confidence
Housekeeping
Initial repository setup and configuration scaffolding
This change establishes the foundational project configuration by introducing Yarn 4 as the package manager, replacing Jest with Vitest for testing, and configuring ESLint and Prettier for code quality. It also adds standard development scaffolding including .gitignore, .npmignore, CONTRIBUTING.md, and a Rollup build configuration, while updating the README to reflect the current JavaScript API and features.
(repo-wide) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings — which rule fired, in which file, on which line, and how to fix it — are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.
Score
- CAI 59 → 59 (+0.3)
- Rubric changed (rubric-2026.09.12 → rubric-2026.09.18) — scores are not directly comparable.
Lenses
- Code Health 57 → 57 (+0.0)
- Architecture 83 → 78 (-4.9)
- Maturity 68 → 69 (+0.3)
- Readiness 61 → 63 (+1.7)
- Security 69 → 73 (+4.0)
- Accessibility 55 → 55 (+0.0)
- Performance 70 (new)
Resolved (6)
- Dependency hygiene PARTLY measured — npm pinning read, dependency currency not (no pnpm-resolved versions to grade)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- Hotspot: docs/generate.js (docs/generate.js)
- Off-boarding risk: anonymized user #1
New (18)
- Documentation: no project overview (docs/table.md)
- Documentation: no project overview (docs/text.md)
- Documentation: no project overview (docs/vector.md)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- Low: security finding (details withheld)
- Low: security finding (details withheld)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium vulnerability: [GHSA redacted] (yarn.lock)
- Medium: security finding (details withheld)
- Medium: security finding (details withheld)
- Off-boarding risk: anonymized user #1
- Outdated (npm): @noble/ciphers
- Outdated (npm): @noble/hashes
- Projects may be oversized for their cohesion
- Repeated repair: lib/mixins/text.js (lib/mixins/text.js)
Changes since last survey
- 3 commits — 1 feature/other, 2 fixes
By area
- (root) — 3 commits
Notable commits
- fix: Fix doc.list() throwing on a numbered or lettered list with align center or right (#1800)
- fix: Fix wrapped text decorations counting character and word spacing twice (#1806)
- change: Let the Node build be bundled: export registerStdFonts, resolve standard fonts and the ICC profile on first use (#1802)
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
foliojs/pdfkit was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 2 October 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 380631182e1d4f23889dc54cbafa1e0560802eca — the exact code this score is about.
- Scored under rubric-2026.09.18 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-e569280dd5e2.