DEV Community

Cover image for JS Barcode Universal 1.6.4: security hardening, real formats and a better Bun day
Sythos
Sythos

Posted on AI-assisted

JS Barcode Universal 1.6.4: security hardening, real formats and a better Bun day

There is a new release of Sythos JS Barcode Universal: v1.6.4.

It is not a dramatic “we changed every public API at 3 a.m.” release. It is the nicer kind: a focused security and delivery tune-up that makes the package safer to ship, keeps the runtime surface boring (in the best possible way), and gives Bun a little more room to prove it belongs at the party.

The short version

@sythos/js_barcode_universal@1.6.4 is an open-source MIT-licensed JavaScript/TypeScript SDK for generating and reading 1D and 2D barcodes. It runs in browsers, Web Workers, Node.js and Bun, with zero runtime dependencies.

The release keeps the public barcode API stable. The important changes are in the security and release plumbing:

  • the development-only brace-expansion resolution is now 5.0.12, covering the three reported GHSA advisories;
  • a CI lockfile guard checks vulnerable resolutions before dependencies are installed;
  • the green Dependabot updates for fast-check 4.10.2 and the CodeQL upload action 4.38.2 are included;
  • the npm package and GitHub release are aligned at 1.6.4, with build provenance attached;
  • the published SDK still has no runtime dependencies.

In other words: the barcode engine did not suddenly grow a secret subscription plan. The release makes the boring parts more defensible, which is exactly what boring infrastructure should do.

“Are all those formats actually usable?”

Short answer: yes, and the repository is deliberately specific about what “usable” means.

This is not a README that lists fifty impressive names and then quietly hands you a stub. The runtime exposes listFormats(), where writing and reading are reported as separate capabilities. The format table in the README shows the same distinction, so an application can ask the SDK what a format really supports instead of guessing from its name.

The library includes the familiar stuff — QR, Data Matrix, Aztec, PDF417, EAN, UPC, Code 128 and GS1 families — alongside postal formats, Micro QR, rMQR, MaxiCode, Han Xin, DotCode, colour experiments and structured payload helpers such as vCard, VIN, SEPA QR, Swiss QR-bill and AAMVA data.

The useful detail is the project’s honesty about the edges:

  • a format can be write-capable, read-capable, or both;
  • experimental and bounded profiles are labelled as such;
  • Pharmacode, for example, is intentionally write-only in the generic image reader;
  • payload conventions are documented as payload conventions, not magically renamed into new symbologies;
  • a format is not treated as finished merely because the project can round-trip its own output.

The verification story goes beyond “encode, decode, high-five.” The repository uses structural invariants, first-principles reference values, property-based tests, independent black-box implementations and, most importantly, real scanner/device evidence. A symbol that only its author’s decoder can read is not a victory lap; it is a very elaborate typo.

Security without pretending to be a magic shield

Barcode data is untrusted input. Pixels, camera frames, rendering options and decoded text all cross a trust boundary. Version 1.6.4 hardens the development dependency path and the CI guard, while the SDK itself keeps its runtime boundary explicit:

  • image dimensions and channel values are validated before decoder work;
  • render sizes, scales, margins and bar heights are bounded before allocations;
  • browser examples put decoded values in text nodes rather than interpreting them as HTML;
  • the published package carries no runtime dependency tree that can quietly grow behind it.

That does not turn a decoded URL into a trustworthy URL. If an application scans a code, it still has to validate destinations, identifiers and business rules for its own domain. The project says this plainly in SECURITY.md and the security guide, which is much healthier than promising that a barcode library is also a complete application security policy.

npm is current, not an afterthought

The package is published as @sythos/js_barcode_universal@1.6.4, and latest points at 1.6.4.

Install it with:

npm install @sythos/js_barcode_universal
Enter fullscreen mode Exit fullscreen mode

The package is plain ESM, ships declarations, keeps its source and generated bundles visible, and has zero runtime dependencies. You can import the whole surface or use focused subpaths when you only need, say, the QR writer and SVG renderer.

The release also carries build provenance and the release page provides the generated bundles, the npm tarball and SHA256SUMS:

Bun gets a real compatibility check

Bun is not a decorative badge in this release. The repository has a dedicated bun-compat.yml workflow that runs the build and test toolchain under Bun on every push.

That workflow covers linting, TypeScript compilation, generated-output checks, browser bundle generation, focused format tests, core tests, property-based checks, documentation assertions, public type checks and the package-surface/zero-runtime-dependency validation.

The practical usage is pleasantly uneventful:

import {
  decode,
  encode,
  toImageData,
  toSVG,
} from '@sythos/js_barcode_universal';

const payload = 'Hello from a barcode that read the instructions';
const matrix = encode(payload, { format: 'qr', ecc: 'M' });
const image = toImageData(matrix, { scale: 8, margin: 4 });
const result = decode(image, { formats: ['qr'] });

console.log(result[0]?.text);
Enter fullscreen mode Exit fullscreen mode

Run the same ESM file with either:

node barcode.mjs
bun barcode.mjs
Enter fullscreen mode Exit fullscreen mode

No adapter circus, no native add-on, no hidden image codec. The application still owns camera capture and image decoding; the SDK stays focused on barcode encoding, decoding and rendering.

The paperwork lives where it should

The legal and provenance material is not sprinkled through random comments like confetti. It has its own, inspectable home:

  • licenses/ contains the per-format licensing and provenance notes;
  • NOTICE.md records origin, attribution and verification boundaries;
  • docs/guides/legal-exclusions.md lists formats excluded for licensing, patent, trademark or issuing-authority reasons;
  • LICENSE carries the MIT licence plus the informational specification/trademark appendix.

There is an important footnote here: engineering notes are not legal advice, and a provenance record is not a patent clearance certificate. The point is that the questions are visible, scoped and reviewable instead of being hidden behind a cheerful “MIT” badge.

So, what changed for a consumer?

If you already use the SDK, this is a low-drama upgrade:

npm update @sythos/js_barcode_universal
Enter fullscreen mode Exit fullscreen mode

The public barcode API stays the same. You get the security dependency fix, the lockfile guard, refreshed development tooling, a current npm package and stronger Bun verification without having to rewrite your encoder or decoder calls.

If you are evaluating the project, start with the repository, inspect the release, read the security and legal notes, then generate a symbol and point an independent scanner at it. That last step is still delightfully old-fashioned — and still the most convincing demo.

Happy encoding, decoding and legally-aware pixel sorcery. 🧃

Disclosure: AI assistance was used for the editorial draft and for test/documentation workflow review. The release facts and links above are taken from the public repository and release metadata; the SDK itself does not add an AI runtime dependency.

Top comments (0)