@korala/pdf-rfc3161
This is an unmodified fork-build of pdf-rfc3161
by Denis Mingulov, republished under the @korala scope. MIT licensed — see LICENSE.
Why this package exists
Upstream pdf-rfc3161 0.2.0 is not yet released to npm: the latest published
release is v0.1.4, while 0.2.0 lives on the upstream main branch behind a
monorepo refactor. Korala's document-signing pipeline wants 0.2.0's timestamping
hardening — TSA nonce verification, eContentType enforcement, SSRF validation
of AIA/OCSP/CRL/TSA URLs, response-size caps, and the requireTimestampingEKU /
requireCertValidAtGenTime verification defaults that 0.1.4 does not expose.
A plain git dependency cannot work: the published artifact is files: ["dist"]
and the build runs from prepublishOnly, which package managers do not execute
for git installs.
What this is
Built from upstream commit
3ff05c895240b71da78c8f01fceaa0829a439fe8
(packages/core). The TypeScript sources are byte-identical to that commit; only
the package name, version and this README differ.
The version is 0.2.0-korala.1, deliberately not 0.2.0: upstream's commit
is untagged, so their eventual 0.2.0 release may differ from this snapshot. The
-korala.N suffix keeps the two from ever colliding.
Consuming it
Alias it so no import statements change:
{
"dependencies": {
"pdf-rfc3161": "npm:@korala/pdf-rfc3161@0.2.0-korala.1"
}
}
import { KNOWN_TSA_URLS, timestampPdf } from 'pdf-rfc3161';
Deprecation plan
This package is temporary. When upstream tags and publishes 0.2.0, switch back to
pdf-rfc3161 from the public registry and deprecate this fork. Issues with the
library itself belong upstream; issues with this republish belong to Korala.
For full upstream documentation see the
upstream README.