New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@korala/pdf-rfc3161

Package Overview
Dependencies
Maintainers
1
Versions
3
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@korala/pdf-rfc3161

[Korala fork of pdf-rfc3161 @ 3ff05c8] A pure JS library to add RFC 3161 trusted timestamps to PDFs. Edge-ready, works in Node.js, Cloudflare Workers, and Browsers without native dependencies.

latest
Source
npmnpm
Version
0.2.0-korala.1
Version published
Weekly downloads
312
122.86%
Maintainers
1
Weekly downloads
 
Created
Source

@korala/pdf-rfc3161

This is an unmodified fork-build of pdf-rfc3161 by Denis Mingulov, republished under the @korala scope. MIT licensed — see LICENSE.

Why this package exists

Upstream pdf-rfc3161 0.2.0 is not yet released to npm: the latest published release is v0.1.4, while 0.2.0 lives on the upstream main branch behind a monorepo refactor. Korala's document-signing pipeline wants 0.2.0's timestamping hardening — TSA nonce verification, eContentType enforcement, SSRF validation of AIA/OCSP/CRL/TSA URLs, response-size caps, and the requireTimestampingEKU / requireCertValidAtGenTime verification defaults that 0.1.4 does not expose.

A plain git dependency cannot work: the published artifact is files: ["dist"] and the build runs from prepublishOnly, which package managers do not execute for git installs.

What this is

Built from upstream commit 3ff05c895240b71da78c8f01fceaa0829a439fe8 (packages/core). The TypeScript sources are byte-identical to that commit; only the package name, version and this README differ.

The version is 0.2.0-korala.1, deliberately not 0.2.0: upstream's commit is untagged, so their eventual 0.2.0 release may differ from this snapshot. The -korala.N suffix keeps the two from ever colliding.

Consuming it

Alias it so no import statements change:

{
  "dependencies": {
    "pdf-rfc3161": "npm:@korala/pdf-rfc3161@0.2.0-korala.1"
  }
}
import { KNOWN_TSA_URLS, timestampPdf } from 'pdf-rfc3161';

Deprecation plan

This package is temporary. When upstream tags and publishes 0.2.0, switch back to pdf-rfc3161 from the public registry and deprecate this fork. Issues with the library itself belong upstream; issues with this republish belong to Korala.

For full upstream documentation see the upstream README.

Keywords

pdf

FAQs

Package last updated on 21 Aug 2026

Related posts