Skip to content

Bundle WASM-only image codec runtimes - #44

Merged
343dev merged 6 commits into
mainfrom
improvement/wasm-hardening
Sep 25, 2026
Merged

343dev merged 6 commits into
mainfrom
improvement/wasm-hardening

Conversation

@343dev

@343dev 343dev commented Sep 25, 2026

Copy link
Copy Markdown
Owner

Replace the platform-specific Sharp, Guetzli, and Gifsicle binaries with WebAssembly runtimes bundled with Optimizt.

This PR also converts the repository to npm workspaces. Each codec runtime can now be built, verified, and vendored independently. Only @343dev/optimizt is published.

User-facing changes

  • Sharp, Guetzli, and Gifsicle now use WebAssembly runtimes bundled with Optimizt.
  • Wasm64 lets Guetzli process JPEG files beyond the 4 GiB wasm32 address-space limit.
  • GIF optimization now rejects encoded inputs larger than 128 MiB.
  • GIF optimization now rejects images with more than 100,000 frames.
  • GIF optimization now rejects images whose canvas area exceeds 134,217,728 pixels.
  • GIF optimization now rejects images whose total frame area exceeds 134,217,728 pixels.
  • Optimizt can now terminate Gifsicle operations when a run is interrupted.
  • This PR updates the CLI option descriptions and migration documentation.

Breaking changes

  • Optimizt now requires Node.js 24.0.0 or newer.
  • The bundled Guetzli and Gifsicle runtimes require WebAssembly memory64.
  • Optimizt no longer installs platform-specific Sharp binaries.
  • Optimizt rejects GIF files that exceed the new safety limits.

Implementation

  • Move the CLI to the packages/optimizt workspace.
  • Add private workspaces for the Sharp, Guetzli, and Gifsicle runtimes.
  • Vendor the generated codec distributions in the published Optimizt package.
  • Pin and verify the upstream sources and build toolchains.
  • Add native-parity fixtures and verification tests for Guetzli and Gifsicle.
  • Add package-content tests that verify all required vendored files are published.
  • Update the Docker and CI workflows to use the workspace-based build.

Compatibility

The existing Optimizt CLI and configuration format remain unchanged. Parity tests compare each codec's output with the corresponding native implementation.

@343dev 343dev self-assigned this Sep 25, 2026
Replace native Sharp installations with a reproducibly generated WebAssembly-only distribution that is vendored into the published CLI package.\n\nBREAKING CHANGE: the package no longer installs platform-specific Sharp binaries.
@343dev
343dev force-pushed the improvement/wasm-hardening branch from 4ee6d0a to 8d4f405 Compare September 25, 2026 05:49
Vendor a reproducible wasm64 Guetzli build, its provenance sources, parity fixtures, and the CLI adapter. Raise the runtime requirement to Node.js 24 for WebAssembly memory64 support.\n\nBREAKING CHANGE: Optimizt now requires Node.js 24.0.0 or newer.
@343dev
343dev force-pushed the improvement/wasm-hardening branch 2 times, most recently from 9ce6eeb to 4ae5e78 Compare September 25, 2026 06:07
Vendor a reproducible wasm64 Gifsicle build with Worker-based cancellation, provenance sources, parity evidence, and codec-specific license notices.
@343dev
343dev force-pushed the improvement/wasm-hardening branch from 4ae5e78 to 5ea6e32 Compare September 25, 2026 08:16
@343dev
343dev merged commit fed61f8 into main Sep 25, 2026
10 checks passed
@343dev
343dev deleted the improvement/wasm-hardening branch September 25, 2026 09:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant