- Added the Sprint 16B Image → Text OCR interface for the v2.1.0 development cycle with single-image PNG/JPEG/WebP input, English/Korean/combined recognition, editable results, copy, UTF-8 TXT download, cancellation, retry, orientation-correct previews, request-identity safeguards, and complete six-locale UI coverage.
- Added the internal Sprint 16A local OCR foundation with pinned, same-origin Tesseract.js 7.0.0 worker/core assets, English and Korean language data, orientation-aware image preparation, normalized progress, worker reuse, cancellation, cleanup, and real OCR smoke coverage. No public OCR tool was added.
- Started the v2 cycle with a production Image category and local Image Converter.
- Added Image Resize with pixel and percentage modes, aspect-ratio preservation, optional enlargement, Original/JPEG/PNG/WebP output, and local batch ZIP saving.
- Added Image Compressor with Original/JPEG/PNG/WebP output, truthful format-specific quality behavior, unchanged dimensions, and local batch ZIP saving.
- Added the single-file Image Metadata Inspector & Cleaner for JPEG, PNG, and WebP with honest partial/opaque reporting, authoritative Privacy Clean, ICC preservation, and fail-closed verification before save.
- Pinned the immutable
secure-metadata v0.1.1browser Release artifact as a same-origin dependency with exact provenance and SHA-256 release-gate coverage. - Added per-file and aggregate compression metrics that distinguish byte savings from larger generated results.
- Added production crawler discovery files, canonical URLs, page-specific Open Graph metadata, SEO regression coverage, and search-engine submission guidance for securetools.app.
- Added production favicon, Apple touch, and same-origin social preview assets with Open Graph and Twitter/X card metadata.
- Added per-image output dimension/pixel checks and a 200-megapixel aggregate resize-output workload limit.
- Added JPEG, PNG, and WebP input/output, lossy quality controls for JPEG/WebP, deterministic white JPEG transparency, metadata-stripping canvas re-encoding, collision-safe Unicode names, and ZIP batch output.
- Added per-file, queue, dimension, decoded-pixel, and 200-megapixel aggregate-work protections with recoverable errors.
-
Hardened the v2.1.0 release candidate with real English, Korean, and combined local OCR smoke coverage plus reproducible browser, privacy, CSP, asset, locale, responsive, accessibility, and regression evidence.
-
Hardened v2 promotion gates for all ten production tools, vendored-resource integrity, local-only network invariants, save failure paths, and resource boundaries.
-
Upgraded secure-metadata to v0.1.1 so JPEG Privacy Clean preserves one valid rendering Orientation while removing other targeted EXIF/GPS data without decoding or re-encoding pixels.
-
Aligned Image and PDF Metadata action panels and bounded their primary decoded summaries while retaining complete details.
-
Corrected canonical repository links and extended integration CI to
v2pushes. -
Narrowed homepage and category privacy copy to production file-content processing and localized shared navigation and summary accessible names across all six interface languages.
-
Added a live v2 promotion QA matrix that keeps blocked browser evidence separate from passing automated checks.
-
Recorded completed manual Chrome release QA and verified EXIF Orientation preservation, advancing the documented v2 status to READY FOR PROMOTION without creating a release.
-
Reorganized project documentation around a concise README and focused architecture, privacy, dependency, tool-status, and audit references.
-
Removed the standalone planned Rotate PDF card; page rotation remains available as part of PDF Organizer.
-
Moved shared browser image validation and decoding into
tools/shared/image.jsfor PDF and Image tools. -
Promoted Privacy from generic planned placeholders to a production navigation hub for the existing Image and PDF metadata tools, with distinct supported-scope copy in all six locales.
-
Repaired the Image category’s semantic tool list so all four available cards remain within the same list.
Secure Tools v1.0.0 was published on 2026-08-24 after the Sprint 11 release-candidate hardening and manual release process.
- Convert ordered JPEG, PNG, and WebP images into a PDF.
- Merge, split, organize, and export PDFs locally without rasterizing source pages.
- Convert PDF pages into PNG, JPEG, or WebP files and predictable ZIP archives.
- Inspect supported document-info metadata and save a verified cleaned copy.
- Process file contents locally in the browser with no upload service, accounts, analytics, advertising, or tracking pixels.
- Keep theme and language preferences as the only application values stored in
localStorage. - Serve processing libraries, locale catalogs, fonts, modules, and workers from the same origin.
- Provide semantic controls, keyboard-operable queues and page ordering, visible focus treatment, live status messaging, and reduced-motion foundations.
- Preserve native file-input paths alongside drag-and-drop interactions.
- Provide complete English, Korean, Japanese, Spanish, German, and French interface catalogs.
- Detect supported browser languages, persist manual selection, and update document language and metadata without resetting tool state.
- Enforce a restrictive Content Security Policy with no inline code, runtime CDN, remote API, or evaluation exception.
- Validate supported file signatures and apply queue, file-size, image-dimension, decoded-pixel, render, and metadata-display limits.
- Pin four audited browser dependencies with package metadata, licenses, upstream provenance, and runtime hashes in the repository.
- Cover corrupt, encrypted, empty, spoofed, boundary-size, repeated-operation, deterministic-naming, cancellation, and save-error paths.
- Use a shared File System Access save path when supported and a revoking Blob-download fallback elsewhere.
- Run syntax, functional, route/resource, privacy/network, security, localization, responsive-contract, accessibility, CI, dependency-integrity, and save-path checks through one test command.