From 3c606bbc62899e39511a147870e6c18cc232129e Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?R=C3=A9mi=20Marche?= <35939574+ecstrema@users.noreply.github.com> Date: Thu, 4 Dec 2025 08:34:19 -0500 Subject: [PATCH 01/12] Add `block: true` in docs example for `read` function (#7523) --- crates/typst-library/src/loading/read.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crates/typst-library/src/loading/read.rs b/crates/typst-library/src/loading/read.rs index d003f1d38c..71a6fe7b4a 100644 --- a/crates/typst-library/src/loading/read.rs +++ b/crates/typst-library/src/loading/read.rs @@ -16,7 +16,7 @@ use crate::loading::{DataSource, Load, Readable}; /// ```example /// An example for a HTML file: \ /// #let text = read("example.html") -/// #raw(text, lang: "html") +/// #raw(text, block: true, lang: "html") /// /// Raw bytes: /// #read("tiger.jpg", encoding: none) From 7f98e0506908c0f6b65fe4ca518bbc0389066626 Mon Sep 17 00:00:00 2001 From: ultimatile Date: Sat, 6 Dec 2025 00:47:05 +0900 Subject: [PATCH 02/12] Fix wording in `grid.footer` docs (#7530) --- crates/typst-library/src/layout/grid/mod.rs | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/crates/typst-library/src/layout/grid/mod.rs b/crates/typst-library/src/layout/grid/mod.rs index 41bade5006..47b56c1b1e 100644 --- a/crates/typst-library/src/layout/grid/mod.rs +++ b/crates/typst-library/src/layout/grid/mod.rs @@ -598,7 +598,7 @@ pub struct GridHeader { /// A repeatable grid footer. /// /// Just like the [`grid.header`] element, the footer can repeat itself on every -/// page of the table. +/// page of the grid. /// /// No other grid cells may be placed after the footer. #[elem(name = "footer", title = "Grid Footer")] From eae095cd1b4f37e2f82053e49161f2f0a82fc3fa Mon Sep 17 00:00:00 2001 From: Cady Date: Fri, 5 Dec 2025 17:06:40 +0100 Subject: [PATCH 03/12] Friendly hint and docs clarification for `array.sorted` (#7528) Co-Authored-By: Laurenz --- crates/typst-library/src/foundations/array.rs | 22 +++++++++++++++---- tests/suite/foundations/array.typ | 8 +++++++ 2 files changed, 26 insertions(+), 4 deletions(-) diff --git a/crates/typst-library/src/foundations/array.rs b/crates/typst-library/src/foundations/array.rs index 0c2e2f5326..7dbe8e64bd 100644 --- a/crates/typst-library/src/foundations/array.rs +++ b/crates/typst-library/src/foundations/array.rs @@ -9,7 +9,9 @@ use serde::{Deserialize, Serialize}; use smallvec::SmallVec; use typst_syntax::{Span, Spanned}; -use crate::diag::{At, HintedStrResult, SourceDiagnostic, SourceResult, StrResult, bail}; +use crate::diag::{ + At, HintedStrResult, HintedString, SourceDiagnostic, SourceResult, StrResult, bail, +}; use crate::engine::Engine; use crate::foundations::{ Args, Bytes, CastInfo, Context, Dict, FromValue, Func, IntoValue, Reflect, Repr, Str, @@ -836,8 +838,9 @@ impl Array { /// Return a sorted version of this array, optionally by a given key /// function. The sorting algorithm used is stable. /// - /// Returns an error if two values could not be compared or if the key - /// or comparison function (if given) yields an error. + /// Returns an error if a pair of values selected for comparison could not + /// be compared, or if the key or comparison function (if given) yield an + /// error. /// /// To sort according to multiple criteria at once, e.g. in case of equality /// between some criteria, the key function can return an array. The results @@ -975,7 +978,18 @@ impl Array { match (key_of(a.clone()), key_of(b.clone())) { (Ok(a), Ok(b)) => ops::compare(&a, &b).unwrap_or_else(|err| { if result.is_ok() { - result = Err(err).at(span); + result = + Err(HintedString::from(err).with_hint(match key { + None => { + "consider choosing a `key` \ + or defining the comparison with `by`" + } + Some(_) => { + "consider defining the comparison with `by` \ + or choosing a different `key`" + } + })) + .at(span); } Ordering::Equal }), diff --git a/tests/suite/foundations/array.typ b/tests/suite/foundations/array.typ index 6558d687f4..7ab75dc11f 100644 --- a/tests/suite/foundations/array.typ +++ b/tests/suite/foundations/array.typ @@ -461,12 +461,19 @@ // Error: 32-37 cannot divide by zero #(1, 2, 0, 3).sorted(key: x => 5 / x) +--- array-sorted-underdetermined-with-key --- +// Error: 2-40 cannot compare content and content +// Hint: 2-40 consider defining the comparison with `by` or choosing a different `key` +#((1, []), (1, [])).sorted(key: a => a) + --- array-sorted-uncomparable --- // Error: 2-26 cannot compare content and content +// Hint: 2-26 consider choosing a `key` or defining the comparison with `by` #([Hi], [There]).sorted() --- array-sorted-uncomparable-lengths --- // Error: 2-26 cannot compare 3em with 2pt +// Hint: 2-26 consider choosing a `key` or defining the comparison with `by` #(1pt, 2pt, 3em).sorted() --- array-sorted-key-function-positional-2 --- @@ -555,4 +562,5 @@ --- issue-6285-crashed-with-sorting-non-total-order --- // Error: 2-66 cannot compare none and string +// Hint: 2-66 consider choosing a `key` or defining the comparison with `by` #(("a", "b", "c", "d", "e", "z") * 3 + ("c", none, "a")).sorted() From fbfed309e7072182a2e09e7a9409db8c179fd2d0 Mon Sep 17 00:00:00 2001 From: Laurenz Date: Tue, 9 Dec 2025 14:31:28 +0100 Subject: [PATCH 04/12] Bump `wasmi` (#7551) --- Cargo.lock | 16 ++++++++-------- Cargo.toml | 2 +- 2 files changed, 9 insertions(+), 9 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index e90832b0c0..b783e37979 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -3694,9 +3694,9 @@ dependencies = [ [[package]] name = "wasmi" -version = "0.51.2" +version = "0.51.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "118030b2d125bc893e0cc5b1ce156eb41461f4373308cb5f2e3c698533b5e547" +checksum = "bb321403ce594274827657a908e13d1d9918aa02257b8bf8391949d9764023ff" dependencies = [ "spin", "wasmi_collections", @@ -3707,24 +3707,24 @@ dependencies = [ [[package]] name = "wasmi_collections" -version = "0.51.2" +version = "0.51.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "653fa20efc966818934524dceb54b1b81e6f845bbcc2e155d6e9fc32becf667e" +checksum = "e9b8e98e45a2a534489f8225e765cbf1cb9a3078072605e58158910cf4749172" [[package]] name = "wasmi_core" -version = "0.51.2" +version = "0.51.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "65701f60308c7e46cca85f273ad17e80c60998cc63d3fa168ac393f62b123038" +checksum = "c25f375c0cdf14810eab07f532f61f14d4966f09c747a55067fdf3196e8512e6" dependencies = [ "libm", ] [[package]] name = "wasmi_ir" -version = "0.51.2" +version = "0.51.5" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "a6539f63bf2a6838f27876e2877f0b00a088e84f91e92445620cc6b977fde032" +checksum = "624e2a68a4293ecb8f564260b68394b29cf3b3edba6bce35532889a2cb33c3d9" dependencies = [ "wasmi_core", ] diff --git a/Cargo.toml b/Cargo.toml index 91712f246b..415c092ab4 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -141,7 +141,7 @@ ureq = { version = "2", default-features = false, features = ["native-tls", "gzi usvg = { version = "0.45", default-features = false, features = ["text"] } utf8_iter = "1.0.4" walkdir = "2" -wasmi = { version = "0.51.2", default-features = false, features = ["simd"] } +wasmi = { version = "0.51.5", default-features = false, features = ["simd"] } web-sys = "0.3" xmlparser = "0.13.5" xmlwriter = "0.1.0" From e632510cf6889bc66f7c29313fde0ebbf2ff5028 Mon Sep 17 00:00:00 2001 From: Tobias Schmitz Date: Thu, 11 Dec 2025 15:23:59 +0100 Subject: [PATCH 05/12] Fix running tests in release mode (#7562) --- tests/src/run.rs | 6 ++++++ tests/suite/pdftags/break.typ | 1 - 2 files changed, 6 insertions(+), 1 deletion(-) diff --git a/tests/src/run.rs b/tests/src/run.rs index 70ee5bab9e..55bf2779ab 100644 --- a/tests/src/run.rs +++ b/tests/src/run.rs @@ -245,6 +245,12 @@ impl<'a> Runner<'a> { // Check hints. for hint in &diag.hints { + // HACK: This hint only gets emitted in debug builds, so filter it + // out to make the test suite also pass for release builds. + if hint == "set `RUST_BACKTRACE` to `1` or `full` to capture a backtrace" { + continue; + } + self.validate_note(NoteKind::Hint, diag.span.id(), range.clone(), hint); } } diff --git a/tests/suite/pdftags/break.typ b/tests/suite/pdftags/break.typ index 57eeb063bb..fe355db278 100644 --- a/tests/suite/pdftags/break.typ +++ b/tests/suite/pdftags/break.typ @@ -30,5 +30,4 @@ Foo #quote($$ + parbreak()) #show heading: v(0pt) + [A] // Error: 3-6 internal error: tags weren't properly closed (occurred at crates/typst-pdf/src/tags/tree/build.rs:187:9) // Hint: 3-6 please report this as a bug -// Hint: 3-6 set `RUST_BACKTRACE` to `1` or `full` to capture a backtrace #[= A]B From 6a797283e81a84c8004c756d118848ca1497eb38 Mon Sep 17 00:00:00 2001 From: Andrew Voynov <37143421+Andrew15-5@users.noreply.github.com> Date: Thu, 11 Dec 2025 17:37:14 +0300 Subject: [PATCH 06/12] Fix and improve regex documentation (#7211) Co-Authored-By: Y.D.X. <73375426+YDX-2147483647@users.noreply.github.com> Co-Authored-By: Laurenz --- crates/typst-library/src/foundations/str.rs | 20 ++++++++++++-------- 1 file changed, 12 insertions(+), 8 deletions(-) diff --git a/crates/typst-library/src/foundations/str.rs b/crates/typst-library/src/foundations/str.rs index 49d2bab90c..2bfccb3ec8 100644 --- a/crates/typst-library/src/foundations/str.rs +++ b/crates/typst-library/src/foundations/str.rs @@ -58,8 +58,8 @@ pub use crate::__format_str as format_str; /// #"\"hello\n world\"!" \ /// #"1 2 3".split() \ /// #"1,2;3".split(regex("[,;]")) \ -/// #(regex("\d+") in "ten euros") \ -/// #(regex("\d+") in "10 euros") +/// #(regex("\\d+") in "ten euros") \ +/// #(regex("\\d+") in "10 euros") /// ``` /// /// # Escape sequences { #escapes } @@ -933,7 +933,7 @@ fn string_is_empty() -> EcoString { /// #"a,b;c".split(regex("[,;]")) /// /// // Works with show rules. -/// #show regex("\d+"): set text(red) +/// #show regex("\\d+"): set text(red) /// /// The numbers 1 to 10. /// ``` @@ -955,14 +955,18 @@ impl Regex { pub fn construct( /// The regular expression as a string. /// - /// Most regex escape sequences just work because they are not valid Typst - /// escape sequences. To produce regex escape sequences that are also valid in - /// Typst (e.g. `[\\]`), you need to escape twice. Thus, to match a verbatim - /// backslash, you would need to write `{regex("\\\\")}`. + /// Both Typst strings and regular expressions use backslashes for + /// escaping. To produce a regex escape sequence that is also valid in + /// Typst, you need to escape the backslash itself (e.g., writing + /// `{regex("\\\\")}` for the regex `\\`). Regex escape sequences that + /// are not valid Typst escape sequences (e.g., `\d` and `\b`) can be + /// entered into strings directly, but it's good practice to still + /// escape them to avoid ambiguity (i.e., `{regex("\\b\\d")}`). See the + /// [list of valid string escape sequences]($str/#escapes). /// /// If you need many escape sequences, you can also create a raw element /// and extract its text to use it for your regular expressions: - /// ```{regex(`\d+\.\d+\.\d+`.text)}```. + /// ``{regex(`\d+\.\d+\.\d+`.text)}``. regex: Spanned, ) -> SourceResult { Self::new(®ex.v).at(regex.span) From 6c0b9b94f31296d913f54b5e4ba5ba3f2b31f5ed Mon Sep 17 00:00:00 2001 From: Laurenz Date: Fri, 12 Dec 2025 11:23:44 +0100 Subject: [PATCH 07/12] Typst 0.14.2 changelog (#7566) --- docs/changelog/0.14.2.md | 16 ++++++++++++++++ docs/changelog/welcome.md | 1 + docs/src/lib.rs | 1 + 3 files changed, 18 insertions(+) create mode 100644 docs/changelog/0.14.2.md diff --git a/docs/changelog/0.14.2.md b/docs/changelog/0.14.2.md new file mode 100644 index 0000000000..69b7049061 --- /dev/null +++ b/docs/changelog/0.14.2.md @@ -0,0 +1,16 @@ +--- +title: 0.14.2 +description: Changes in Typst 0.14.2 +--- + +# Version 0.14.2 { #v0.14.2 } + +## Security +- Updated the WebAssembly runtime used for executing [plugins]($plugin). The version used in Typst 0.14.0 and 0.14.1 suffers from a memory handling vulnerability. Based on our investigation, the vulnerability would be very hard to exploit in practice, but an exploit could theoretically be feasible. In any case, **we recommend upgrading to Typst 0.14.2.** This holds in particular for local users. In the web app, the bug is not critical as the browser offers an extra layer of protection. + + Typst 0.13.1 and below are not affected by this vulnerability. + + _Technical details:_ The [`wasmi`](https://github.com/wasmi-labs/wasmi/) WebAssembly runtime versions used in 0.14.0 and 0.14.1 have a _use-after-free_ memory handling bug in certain memory growth situations. Specifically, the bug occurs when the plugin tries to grow its memory, but allocating the requested amount of memory fails. Based on our investigation, the bug is hard to trigger in practice as the WebAssembly linear memory is always limited to 4GB on a technical level and modern operating systems rarely fail to serve a 4GB memory allocation request (typically not even under RAM pressure). Once the bug is triggered, it would also still be very challenging to turn it into an actual exploit. Regardless, we recommend upgrading to Typst 0.14.2 for protection against a potential exploit. + +## Diagnostics +- Added a hint when [`array.sorted`] fails because a pair of elements could not be compared. This hint aids with fixing bugs in user code that were surfaced by a change in internal sorting behavior in Typst 0.14.1. diff --git a/docs/changelog/welcome.md b/docs/changelog/welcome.md index 6b97b16e36..e2b47d85cf 100644 --- a/docs/changelog/welcome.md +++ b/docs/changelog/welcome.md @@ -10,6 +10,7 @@ forward. This section documents all changes to Typst since its initial public release. ## Versions +- [Typst 0.14.2]($changelog/0.14.2) - [Typst 0.14.1]($changelog/0.14.1) - [Typst 0.14.0]($changelog/0.14.0) - [Typst 0.13.1]($changelog/0.13.1) diff --git a/docs/src/lib.rs b/docs/src/lib.rs index 352594315b..ab996c3b7d 100644 --- a/docs/src/lib.rs +++ b/docs/src/lib.rs @@ -219,6 +219,7 @@ fn changelog_pages(resolver: &dyn Resolver) -> PageModel { let mut page = md_page(resolver, resolver.base(), load!("changelog/welcome.md")); let base = format!("{}changelog/", resolver.base()); page.children = vec![ + md_page(resolver, &base, load!("changelog/0.14.2.md")), md_page(resolver, &base, load!("changelog/0.14.1.md")), md_page(resolver, &base, load!("changelog/0.14.0.md")), md_page(resolver, &base, load!("changelog/0.13.1.md")), From b33de9de113c91c184214b299bd7a8eb3070c3ab Mon Sep 17 00:00:00 2001 From: Laurenz Date: Fri, 12 Dec 2025 11:30:32 +0100 Subject: [PATCH 08/12] Version bump --- Cargo.lock | 46 ++++++++++++++++++++-------------------- Cargo.toml | 38 ++++++++++++++++----------------- docs/changelog/0.14.2.md | 5 ++++- 3 files changed, 46 insertions(+), 43 deletions(-) diff --git a/Cargo.lock b/Cargo.lock index b783e37979..1440749dd4 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -2948,7 +2948,7 @@ checksum = "6af6ae20167a9ece4bcb41af5b80f8a1f1df981f6391189ce00fd257af04126a" [[package]] name = "typst" -version = "0.14.1" +version = "0.14.2" dependencies = [ "comemo", "ecow", @@ -2966,13 +2966,13 @@ dependencies = [ [[package]] name = "typst-assets" -version = "0.14.1" +version = "0.14.2" source = "registry+https://github.com/rust-lang/crates.io-index" -checksum = "98b250f6c1ddd0f435db2283c7eb36a9b72bee34d6397625bf7f817c64ad7c62" +checksum = "5613cb719a6222fe9b74027c3625d107767ec187bff26b8fc931cf58942c834f" [[package]] name = "typst-cli" -version = "0.14.1" +version = "0.14.2" dependencies = [ "chrono", "clap", @@ -3018,12 +3018,12 @@ dependencies = [ [[package]] name = "typst-dev-assets" -version = "0.14.1" -source = "git+https://github.com/typst/typst-dev-assets?tag=v0.14.1#03addcfb64f3f95209464a521e6aa49645bd271a" +version = "0.14.2" +source = "git+https://github.com/typst/typst-dev-assets?tag=v0.14.2#fe6cad916d8b20c20742512b2a3f3b247a2bc4f8" [[package]] name = "typst-docs" -version = "0.14.1" +version = "0.14.2" dependencies = [ "clap", "codex", @@ -3049,7 +3049,7 @@ dependencies = [ [[package]] name = "typst-eval" -version = "0.14.1" +version = "0.14.2" dependencies = [ "comemo", "ecow", @@ -3067,7 +3067,7 @@ dependencies = [ [[package]] name = "typst-fuzz" -version = "0.14.1" +version = "0.14.2" dependencies = [ "comemo", "libfuzzer-sys", @@ -3079,7 +3079,7 @@ dependencies = [ [[package]] name = "typst-html" -version = "0.14.1" +version = "0.14.2" dependencies = [ "bumpalo", "comemo", @@ -3098,7 +3098,7 @@ dependencies = [ [[package]] name = "typst-ide" -version = "0.14.1" +version = "0.14.2" dependencies = [ "comemo", "ecow", @@ -3115,7 +3115,7 @@ dependencies = [ [[package]] name = "typst-kit" -version = "0.14.1" +version = "0.14.2" dependencies = [ "dirs", "ecow", @@ -3139,7 +3139,7 @@ dependencies = [ [[package]] name = "typst-layout" -version = "0.14.1" +version = "0.14.2" dependencies = [ "az", "bumpalo", @@ -3173,7 +3173,7 @@ dependencies = [ [[package]] name = "typst-library" -version = "0.14.1" +version = "0.14.2" dependencies = [ "az", "bitflags 2.9.1", @@ -3238,7 +3238,7 @@ dependencies = [ [[package]] name = "typst-macros" -version = "0.14.1" +version = "0.14.2" dependencies = [ "heck", "proc-macro2", @@ -3248,7 +3248,7 @@ dependencies = [ [[package]] name = "typst-pdf" -version = "0.14.1" +version = "0.14.2" dependencies = [ "az", "bytemuck", @@ -3272,7 +3272,7 @@ dependencies = [ [[package]] name = "typst-realize" -version = "0.14.1" +version = "0.14.2" dependencies = [ "arrayvec", "bumpalo", @@ -3288,7 +3288,7 @@ dependencies = [ [[package]] name = "typst-render" -version = "0.14.1" +version = "0.14.2" dependencies = [ "bytemuck", "comemo", @@ -3306,7 +3306,7 @@ dependencies = [ [[package]] name = "typst-svg" -version = "0.14.1" +version = "0.14.2" dependencies = [ "base64", "comemo", @@ -3328,7 +3328,7 @@ dependencies = [ [[package]] name = "typst-syntax" -version = "0.14.1" +version = "0.14.2" dependencies = [ "ecow", "rustc-hash", @@ -3345,7 +3345,7 @@ dependencies = [ [[package]] name = "typst-tests" -version = "0.14.1" +version = "0.14.2" dependencies = [ "bitflags 2.9.1", "clap", @@ -3372,7 +3372,7 @@ dependencies = [ [[package]] name = "typst-timing" -version = "0.14.1" +version = "0.14.2" dependencies = [ "parking_lot", "serde", @@ -3382,7 +3382,7 @@ dependencies = [ [[package]] name = "typst-utils" -version = "0.14.1" +version = "0.14.2" dependencies = [ "once_cell", "portable-atomic", diff --git a/Cargo.toml b/Cargo.toml index 415c092ab4..d662cda181 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -4,7 +4,7 @@ default-members = ["crates/typst-cli"] resolver = "2" [workspace.package] -version = "0.14.1" +version = "0.14.2" rust-version = "1.89" # also change in ci.yml authors = ["The Typst Project Developers"] edition = "2024" @@ -16,24 +16,24 @@ keywords = ["typst"] readme = "README.md" [workspace.dependencies] -typst = { path = "crates/typst", version = "0.14.1" } -typst-cli = { path = "crates/typst-cli", version = "0.14.1" } -typst-eval = { path = "crates/typst-eval", version = "0.14.1" } -typst-html = { path = "crates/typst-html", version = "0.14.1" } -typst-ide = { path = "crates/typst-ide", version = "0.14.1" } -typst-kit = { path = "crates/typst-kit", version = "0.14.1" } -typst-layout = { path = "crates/typst-layout", version = "0.14.1" } -typst-library = { path = "crates/typst-library", version = "0.14.1" } -typst-macros = { path = "crates/typst-macros", version = "0.14.1" } -typst-pdf = { path = "crates/typst-pdf", version = "0.14.1" } -typst-realize = { path = "crates/typst-realize", version = "0.14.1" } -typst-render = { path = "crates/typst-render", version = "0.14.1" } -typst-svg = { path = "crates/typst-svg", version = "0.14.1" } -typst-syntax = { path = "crates/typst-syntax", version = "0.14.1" } -typst-timing = { path = "crates/typst-timing", version = "0.14.1" } -typst-utils = { path = "crates/typst-utils", version = "0.14.1" } -typst-assets = "0.14.1" -typst-dev-assets = { git = "https://github.com/typst/typst-dev-assets", tag = "v0.14.1" } +typst = { path = "crates/typst", version = "0.14.2" } +typst-cli = { path = "crates/typst-cli", version = "0.14.2" } +typst-eval = { path = "crates/typst-eval", version = "0.14.2" } +typst-html = { path = "crates/typst-html", version = "0.14.2" } +typst-ide = { path = "crates/typst-ide", version = "0.14.2" } +typst-kit = { path = "crates/typst-kit", version = "0.14.2" } +typst-layout = { path = "crates/typst-layout", version = "0.14.2" } +typst-library = { path = "crates/typst-library", version = "0.14.2" } +typst-macros = { path = "crates/typst-macros", version = "0.14.2" } +typst-pdf = { path = "crates/typst-pdf", version = "0.14.2" } +typst-realize = { path = "crates/typst-realize", version = "0.14.2" } +typst-render = { path = "crates/typst-render", version = "0.14.2" } +typst-svg = { path = "crates/typst-svg", version = "0.14.2" } +typst-syntax = { path = "crates/typst-syntax", version = "0.14.2" } +typst-timing = { path = "crates/typst-timing", version = "0.14.2" } +typst-utils = { path = "crates/typst-utils", version = "0.14.2" } +typst-assets = "0.14.2" +typst-dev-assets = { git = "https://github.com/typst/typst-dev-assets", tag = "v0.14.2" } arrayvec = "0.7.4" az = "1.2" base64 = "0.22" diff --git a/docs/changelog/0.14.2.md b/docs/changelog/0.14.2.md index 69b7049061..8688ced7bf 100644 --- a/docs/changelog/0.14.2.md +++ b/docs/changelog/0.14.2.md @@ -3,7 +3,7 @@ title: 0.14.2 description: Changes in Typst 0.14.2 --- -# Version 0.14.2 { #v0.14.2 } +# Version 0.14.2 (December 12, 2025) { #v0.14.2 } ## Security - Updated the WebAssembly runtime used for executing [plugins]($plugin). The version used in Typst 0.14.0 and 0.14.1 suffers from a memory handling vulnerability. Based on our investigation, the vulnerability would be very hard to exploit in practice, but an exploit could theoretically be feasible. In any case, **we recommend upgrading to Typst 0.14.2.** This holds in particular for local users. In the web app, the bug is not critical as the browser offers an extra layer of protection. @@ -14,3 +14,6 @@ description: Changes in Typst 0.14.2 ## Diagnostics - Added a hint when [`array.sorted`] fails because a pair of elements could not be compared. This hint aids with fixing bugs in user code that were surfaced by a change in internal sorting behavior in Typst 0.14.1. + +## Contributors + From e60da51b2b5ed87b0dd40777834ad4f33a232ee3 Mon Sep 17 00:00:00 2001 From: 3w36zj6 <52315048+3w36zj6@users.noreply.github.com> Date: Tue, 29 Sep 2026 02:56:08 +0900 Subject: [PATCH 09/12] =?UTF-8?q?chore:=20=E3=82=B3=E3=83=B3=E3=83=95?= =?UTF-8?q?=E3=83=AA=E3=82=AF=E3=83=88=E3=82=92=E8=A7=A3=E6=B6=88?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- crates/typst-library/src/layout/grid/mod.rs | 5 ----- 1 file changed, 5 deletions(-) diff --git a/crates/typst-library/src/layout/grid/mod.rs b/crates/typst-library/src/layout/grid/mod.rs index bdb6004a2c..1d1dc4d1d0 100644 --- a/crates/typst-library/src/layout/grid/mod.rs +++ b/crates/typst-library/src/layout/grid/mod.rs @@ -552,12 +552,7 @@ pub struct GridHeader { /// 繰り返し可能なグリッドのフッター。 /// -<<<<<<< HEAD /// [`grid.header`]要素と同様に各ページで繰り返し可能です。 -======= -/// Just like the [`grid.header`] element, the footer can repeat itself on every -/// page of the grid. ->>>>>>> b33de9de113c91c184214b299bd7a8eb3070c3ab /// /// フッターの後に他のグリッドセルを配置できません。 #[elem(name = "footer", title = "Grid Footer")] From 9fe8d20e247b875df06622f851fb053fbeb71299 Mon Sep 17 00:00:00 2001 From: 3w36zj6 <52315048+3w36zj6@users.noreply.github.com> Date: Tue, 29 Sep 2026 02:59:55 +0900 Subject: [PATCH 10/12] =?UTF-8?q?chore:=20=E3=83=90=E3=83=BC=E3=82=B8?= =?UTF-8?q?=E3=83=A7=E3=83=B3=E3=82=92v0.14.2=E3=81=AB=E6=9B=B4=E6=96=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- website/metadata.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/website/metadata.json b/website/metadata.json index f0b784e316..b5c86fee26 100644 --- a/website/metadata.json +++ b/website/metadata.json @@ -1,7 +1,7 @@ { "$schema": "./typst-docs-web/metadata.schema.json", "language": "ja-JP", - "version": "0.14.1", + "version": "0.14.2", "typstOfficialUrl": "https://typst.app", "typstOfficialDocsUrl": "https://typst.app/docs/", "githubOrganizationUrl": "https://github.com/typst-jp", From fa52599df95b21ba8b187c8c27a07175ed8c3096 Mon Sep 17 00:00:00 2001 From: 3w36zj6 <52315048+3w36zj6@users.noreply.github.com> Date: Tue, 29 Sep 2026 03:03:01 +0900 Subject: [PATCH 11/12] =?UTF-8?q?chore:=20=E7=BF=BB=E8=A8=B3=E3=82=B9?= =?UTF-8?q?=E3=83=86=E3=83=BC=E3=82=BF=E3=82=B9=E3=82=92=E6=9B=B4=E6=96=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- website/translation-status.json | 1 + 1 file changed, 1 insertion(+) diff --git a/website/translation-status.json b/website/translation-status.json index 19fd912f71..2e2b94b9e5 100644 --- a/website/translation-status.json +++ b/website/translation-status.json @@ -179,6 +179,7 @@ "/docs/guides/tables/": "untranslated", "/docs/guides/accessibility/": "translated", "/docs/changelog/": "translated", + "/docs/changelog/0.14.2/": "untranslated", "/docs/changelog/0.14.1/": "untranslated", "/docs/changelog/0.14.0/": "translated", "/docs/changelog/0.13.1/": "translated", From ca5b0b3cdc933ccd313cc4180767521f19a02dda Mon Sep 17 00:00:00 2001 From: 3w36zj6 <52315048+3w36zj6@users.noreply.github.com> Date: Tue, 29 Sep 2026 03:05:49 +0900 Subject: [PATCH 12/12] =?UTF-8?q?chore:=20=E3=83=AA=E3=83=B3=E3=82=AF?= =?UTF-8?q?=E3=82=92=E8=A7=A3=E6=B1=BA?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- docs/changelog/0.14.2.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/changelog/0.14.2.md b/docs/changelog/0.14.2.md index 8688ced7bf..2f26258eb7 100644 --- a/docs/changelog/0.14.2.md +++ b/docs/changelog/0.14.2.md @@ -13,7 +13,7 @@ description: Changes in Typst 0.14.2 _Technical details:_ The [`wasmi`](https://github.com/wasmi-labs/wasmi/) WebAssembly runtime versions used in 0.14.0 and 0.14.1 have a _use-after-free_ memory handling bug in certain memory growth situations. Specifically, the bug occurs when the plugin tries to grow its memory, but allocating the requested amount of memory fails. Based on our investigation, the bug is hard to trigger in practice as the WebAssembly linear memory is always limited to 4GB on a technical level and modern operating systems rarely fail to serve a 4GB memory allocation request (typically not even under RAM pressure). Once the bug is triggered, it would also still be very challenging to turn it into an actual exploit. Regardless, we recommend upgrading to Typst 0.14.2 for protection against a potential exploit. ## Diagnostics -- Added a hint when [`array.sorted`] fails because a pair of elements could not be compared. This hint aids with fixing bugs in user code that were surfaced by a change in internal sorting behavior in Typst 0.14.1. +- Added a hint when [`array.sorted`]($array.sorted) fails because a pair of elements could not be compared. This hint aids with fixing bugs in user code that were surfaced by a change in internal sorting behavior in Typst 0.14.1. ## Contributors