Writer and Calc Guides updated to new LibreOffice 7.5 release

The Documentation Team is proud to announce the immediate availability of the Writer Guide and Calc Guide release 7.5, narrowing the time gap between the software release date and the Guides’ release date.

Writer Guide 7.5
Writer Guide 7.5
Calc Guide 7.5
Calc Guide 7.5

The Writer Guide 7.5 update was coordinated by Jean Weber with the support of Kees Kriek, Tsvetelina Georgieva, Antonio Fernández and Olivier Hallot. The Guide contains topics on Additional hyphenation settings (Chapter 2), Language Tool, a remote grammar checker (Chapters 2 and 20), Additional change tracking features (Chapter 3) Outline folding (Chapter 3), Page line-spacing for printed documents (Chapter 6), Gutter margins in page styles (Chapters 8 and 9), Revised and additional information about using styles (Chapter 8), Additional information about using master documents (Chapter 16), New features for bookmarks (Chapter 17) and Content controls (Chapter 18)

The Calc Guide 7.5 update was coordinated by Olivier Hallot, based on the Calc Guide 7.4. The guide contains topics on document properties (Chapter 1), AutoFilter with color filtering and more (Chapter 2), Chart data table (Chapter 3) and notes on AutoFormat of ranges and themes (Chapter 4 and 5).

The Guides are available for immediate download in PDF format as well as in source format (OpenDocument Format). Soon they will be available as printed books by LuLu inc. and in HTML format for online reading

Download the Writer and Calc guides 7.5 from the documentation websites at: documentation.libreoffice.org and the bookshelf at books.libreoffice.org.

Olivier Hallot
Olivier Hallot
Jean Weber
Jean Weber

The Document Foundation announces LibreOffice 7.5 Community

LibreOffice 7.5 banner

Berlin, February 2, 2023 – LibreOffice 7.5 Community, the new major release of the volunteer-supported free office suite for desktop productivity, is immediately available for download for Windows (Intel/AMD and ARM processors), macOS (Apple Silicon and Intel processors), and Linux.

Most Significant New Features

GENERAL

  • Major improvements to dark mode support
  • New application and MIME-type icons, more colorful and vibrant
  • The Start Centre can filter documents by type
  • An improved version of the Single Toolbar UI has been implemented
  • PDF Export improved with several fixes, and new options and features
  • Support for font embedding on macOS
  • Improvements to the Font Features dialog with several new options
  • Addition of a zoom slider at the bottom right of the macro editor

WRITER

  • Bookmarks have been significantly improved, and are also much more visible
  • Objects can be marked as decorative, for better accessibility
  • New types added to content controls, which also improve the quality of PDF forms
  • A new automatic accessibility checker option has been added to the Tools menu
  • Initial machine translation is available, based on DeepL translate APIs
  • Several spell checking improvements

CALC

  • Data tables are now supported in charts
  • The Function Wizard now lets you search by descriptions
  • “Spell out” number formats have been added
  • Conditional formatting conditions are now case insensitive
  • Correct behavior when entering numbers with a single prefix quote (‘)

IMPRESS & DRAW

  • New set of default table styles, and creation of table styles
  • Table styles can be customized, saved as master elements and exported
  • Objects can be drag-and-dropped in the navigator
  • It is now possible to crop inserted videos in the slide and still play them
  • The presenter console can also run as a normal window instead of fullscreen

A video summarizing the top new features in LibreOffice 7.5 Community is available on YouTube and PeerTube. A description of all new features is available in the Release Notes.

Interoperability with Microsoft Office

Based on the distinctive features of the LibreOffice Technology platform for personal productivity on desktop, mobile and cloud, LibreOffice 7.5 provides a large number of improvements and new features targeted at users sharing documents with MS Office or migrating from MS Office. These users should check new releases of LibreOffice on a regular basis, as the progress is so fast, that each new version improves dramatically over the previous one.

LibreOffice offers the highest level of compatibility in the office suite market segment, with native support for the OpenDocument Format (ODF) – beating proprietary formats for security and robustness – to superior support for MS Office files, along with filters for a large number of legacy document formats, to return ownership and control to users.

Microsoft files are still based on the proprietary format deprecated by ISO in 2008, and not on the ISO approved standard, so they hide a large amount of artificial complexity. This causes handling issues with LibreOffice, which defaults to a true open standard format (the OpenDocument Format).

Contributors to LibreOffice 7.5 Community

LibreOffice 7.5 Community’s new features have been developed by 144 contributors: 63% of code commits are from the 47 developers employed by three companies sitting in TDF’s Advisory Board – Collabora, Red Hat and allotropia – or other organizations, 12% are from 6 developers at The Document Foundation, and the remaining 25% are from 91 individual volunteers.

Other 112 volunteers – representing hundreds of other people providing translations – have committed localizations in 158 languages. LibreOffice 7.5 Community is released in 120 different language versions, more than any other free or proprietary software, and as such can be used in the native language (L1) by over 5.4 billion people worldwide. In addition, over 2.3 billion people speak one of those 120 languages as their second language (L2).

LibreOffice for Enterprises

For enterprise-class deployments, TDF strongly recommends the LibreOffice Enterprise family of applications from ecosystem partners – for desktop, mobile and cloud – with a large number of dedicated value-added features and other benefits such as SLA (Service Level Agreements): www.libreoffice.org/download/libreoffice-in-business/.

Every line of code developed by ecosystem companies for their enterprise customers is shared with the community on the master code repository, and improves the LibreOffice Technology platform.

Products based on LibreOffice Technology are available for major desktop operating systems (Windows, macOS, Linux and Chrome OS), for mobile platforms (Android and iOS), and for the cloud.

Migrations to LibreOffice

The Document Foundation has developed a Migration Protocol to support enterprises moving from proprietary office suites to LibreOffice, which is based on the deployment of an LTS version from the LibreOffice Enterprise family, plus migration consultancy and training sourced from certified professionals who offer value-added solutions and services in line with proprietary offerings. Reference: www.libreoffice.org/get-help/professional-support/.

In fact, LibreOffice – thanks to its mature codebase, rich feature set, strong support for open standards, excellent compatibility and LTS options from certified partners – is the ideal solution for businesses that want to regain control of their data and free themselves from vendor lock-in.

Availability of LibreOffice 7.5 Community

Donate bannerLibreOffice 7.5 Community is available from: www.libreoffice.org/download/. Minimum requirements for proprietary operating systems are Microsoft Windows 7 SP1 and Apple macOS 10.14. LibreOffice Technology-based products for Android and iOS are listed here: www.libreoffice.org/download/android-and-ios/.

For users who don’t need the latest features, and prefer a release that has undergone more testing and bug fixing, The Document Foundation maintains the LibreOffice 7.4 family, which includes some months of back-ported fixes. The current version is LibreOffice 7.4.5.

The Document Foundation does not provide technical support for users, although they can get it from volunteers on user mailing lists and the Ask LibreOffice website: ask.libreoffice.org

LibreOffice users, free software advocates and community members can support The Document Foundation with a donation at www.libreoffice.org/donate.

Press Kit

Download link

The Document Foundation releases LibreOffice 7.4.5 Community

LibreOffice banner

Berlin, January 26, 2023 – The Document Foundation announces the release of LibreOffice 7.4.5 Community, a maintenance release which solves a crash affecting a large number of users. The new release is immediately available from https://www.libreoffice.org/download/ for Windows (Intel and ARM processors), macOS (Apple and Intel processors), and Linux.

All LibreOffice users are invited to update their installation to LibreOffice 7.4.5, as the older versions have reached the end of life and are not maintained.

LibreOffice offers the highest level of compatibility in the office suite market segment, with native support for the OpenDocument Format (ODF) – beating proprietary formats for security and robustness – to superior support for MS Office files, to filters for a large number of legacy document formats, to return ownership and control to users.

LibreOffice Technology Platform

Products based on the LibreOffice Technology platform – the transactional engine shared by all LibreOffice based products, which provides a rock solid solution with a high level of coherence and interoperability – are available for major desktop operating systems (Windows, macOS, Linux and Chrome OS), for mobile platforms (Android and iOS), and for the cloud.

For enterprise-class deployments, TDF strongly recommends the LibreOffice Enterprise family of applications from ecosystem partners – for desktop, mobile and cloud – with a large number of dedicated value-added features and other benefits such as SLA (Service Level Agreements): https://www.libreoffice.org/download/libreoffice-in-business/. All code developed by ecosystem companies for enterprise customers is shared with the community and improves the LibreOffice Technology platform.

Availability of LibreOffice 7.4.5 Community

LibreOffice 7.4.5 Community is available from: https://www.libreoffice.org/download/. Minimum requirements for proprietary operating systems are Microsoft Windows 7 SP1 and Apple macOS 10.12. LibreOffice Technology-based products for Android and iOS are listed here: https://www.libreoffice.org/download/android-and-ios/

The Document Foundation does not provide technical support for users, although they can get it from volunteers on user mailing lists and the Ask LibreOffice website: https://ask.libreoffice.org

LibreOffice users, free software advocates and community members can support The Document Foundation with a donation at https://www.libreoffice.org/donate

Change log page: https://wiki.documentfoundation.org/Releases/7.4.5/RC1

TDF position on EU’s proposed Cyber Resilience Act

THE DOCUMENT FOUNDATION
Summary of Issues of the Cyber Resilience Act (in the current status)

Introduction

The Cyber Resilience Act (CRA) sets out a number of cybersecurity and vulnerability management requirements for manufacturers (Annex I) and will require products to be accompanied by information and instructions for users (Annex II). Software vendors will also be required to conduct a risk assessment and produce technical documentation (Annex V) to demonstrate compliance.
Currently, the text implies that if a developer or supplier derives commercial benefit from OSS, it would be subject to the Cyber Resilience Act. It even implies, in relation to the distribution of software, that open source producers or developers could be held liable if their open source projects are used commercially.

If the Cyber Resilience Act becomes EU law without clarification, the impact on several European-based open source projects, such as products based on LibreOffice technology, could have devastating (unintended) consequences.

The Commission recognises that not all products in our society are equally dependent. The Cyber Resilience Act therefore distinguishes between products and critical products, reflecting the level of cybersecurity risk associated with these products. On the other hand, the CRA ignores the security risks associated with files created by the software covered by the act itself, which can have even more devastating consequences (according to security expert Kaspersky Labs, in 2018, 70% of all malware worldwide was carried by documents created by the most widely used office suite).

Software developers must declare compliance with the requirements of the Cyber Resilience Act and therefore take responsibility for compliance in one of three ways. They can either:

  1. perform a self-assessment, or
  2. apply for a product examination by an auditor and then set up checks and balances for their development processes, or
  3. apply for an assessment of their quality system by an auditor.

These options come with a growing administrative/compliance burden.

The Cyber Resilience Act attempts to exempt open source software from its provisions. But there’s some problematic language about how the CRA draws the line between commercial and non-commercial use of OSS, which could affect all products based on LibreOffice technology and many other products based on open source software.

This is the text of the Open Source Software exception:

In order not to hamper innovation or research, free and open-source software developed or supplied outside the course of a commercial activity should not be covered by this Regulation. This is in particular the case for software, including its source code and modified versions, that is openly shared and freely accessible, usable, modifiable and redistributable.

While the Cyber Resilience Act does not define commercial activity, the EU Blue Guide to the implementation of EU product legislation does:

Commercial activity is understood as providing goods in a business related context. Non-profit organisations may be considered as carrying out commercial activities if they operate in such a context. This can only be appreciated on a case by case basis taking into account the regularity of the supplies, the characteristics of the product, the intentions of the supplier, etc. In principle, occasional supplies by charities or hobbyists should not be considered as taking place in a business related context.

For the purposes of the Cyber Resilience Act, there is a real risk that software based on LibreOffice technology will be considered to be made in the course of a commercial activity, and thus subject to the legislation, based on the following:

  1. Products based on LibreOffice technology are developed by the majority of full-time employees of ecosystem companies or by individuals who make a living from consulting services related to their project work.
  2. Products based on LibreOffice Technology are goods in a business-related context because they are intended to provide software that can be used immediately by businesses or employees in their daily work.
  3. The Document Foundation has never missed a LibreOffice release in 12 years.
  4. Products based on LibreOffice technology are high quality software that matches the quality of commercial products.

So the features of a product based on LibreOffice technology are equivalent to those of commercial products.

Charging for support also makes open source a commercial activity. The Document Foundation does not charge for support, but it certifies professionals who are supposed to charge companies for consulting and support, and encourages companies to adopt professionally supported software.

Having said all this, it is important to remind the reader that The Document Foundation provides software free of charge, on a non-profit basis, and under OSI-approved open source licences that permit further use, study, modification and redistribution, whereas ecosystem companies provide commercial software with service level agreements.

Impact Assessment

CE Markings for Software Products

Basically, the core of the proposed legislation is to extend the CE marking regime to all software products distributed in Europe. Our understanding is that this process will be applied to open source software that is made available under open source licences and distributed free of charge.

We are deeply concerned that the Cyber Resilience Act could fundamentally alter the social contract that underpins the entire open source ecosystem: open source software that is provided free of charge, that can be modified and redistributed free of charge, but without warranty or liability to the authors, contributors, or open source distributors.

Legally changing this arrangement through legislation is likely to have unintended consequences for Europe’s innovation economy.

Without a clearer exemption for open source, in order to comply with the legislation, The Document Foundation will need to develop, document and implement policies and procedures for each project to ensure that they comply with the requirements of the Cyber Resilience Act, including:

  • All development and post-release security requirements specified in Annex I, including the provision of notification and update mechanisms.
  • All the requirements for user documentation set out in Annex II.
  • All of the product technical documentation set forth in Annex V, including … complete information on the design and development of the product… including, where applicable, drawings and schemes and/or a description of the system architecture explaining how software components build on or feed into each other and integrate into the overall processing
  • For each release, prepare the documentation required by Annex V, including … an assessment of the cybersecurity risks against which the product with digital elements is designed, developed, produced, delivered and maintained…
  • Determine for each product whether it meets the definition of product with digital elements, critical product with digital elements or highly critical product with digital elements
  • For each product which is a product with digital elements, establish, complete and document a CE mark self assessment process
  • For each critical product with digital elements or highly critical product with digital elements engage with an external CE auditing body and complete the additional processes required to get the CE mark approval
  • For each individual release, document that the CE marking process has been followed (as described above), that an EU Declaration of Conformity has been written and signed by an officer of the Foundation, that the CE mark has been affixed, and that the technical documentation and EU Declaration of Conformity will be made available for at least 10 years after the release.

Note that we estimate that The Document Foundation’s projects release at least a dozen versions in any given year. It is not clear to us what the cost in time, resources and money would be to implement these external review processes. We assume that they would be substantial.

Article 4 (3)

Member States shall not prevent the making available of unfinished software which does not comply with this Regulation provided that the software is only made available for a limited period required for testing purposes and that a visible sign clearly indicates that it does not comply with this Regulation and will not be available on the market for purposes other than testing.

Projects based on LibreOffice technology make integration, nightly, weekly and milestone builds available under their open source licences indefinitely. The intent is to provide community testing and traceability. These binaries are marked as such, but the terms under which they are provided do not require that they be used for testing purposes only.

It is not clear how this requirement could be implemented by any open source project using modern CI/CD infrastructure and operating under the principle of transparency.

Even if the binaries are marked as for testing only, the open source licences under which they are provided permit uses other than testing. In addition, it is common practice to provide interim builds for extended periods of time to allow testers access to previous builds for problem identification and resolution.

Discontinuing this practice would be very disruptive. And any solution based on making intermediate builds available under non-open source licences would be impossible for projects based on the LibreOffice technology, as TDF does not own the copyright and obtaining the consent of all contributors would be impractical.

In summary, compliance with the proposed requirements of the Cyber Resilience Act would be a significant blow to open source development best practices.

Article 5 (1) and Section 1 of Annex I

(1) Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks

This would probably ask for the development and enforcement of written policies that require each project to assess its level of cybersecurity risk and to implement processes to ensure that the level of risk and justification for the development processes adopted are determined.

(k) ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic updates and the notification of available updates to users

With few exceptions, products based on LibreOffice technology do not require registration and do not provide a mechanism for notifying all users that an update is either available or required. Implementing these requirements would require a whole new infrastructure to be mandated across all projects.

Article 5 (2)

In general, The Document Foundation can deal with many of the requirements, as it has a security team and TDF is also a CVE numbering authority. However, there are two notable elements in the requirements.

(1) identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the product

This would impose a legal requirement to produce SBOMs for all projects based on the LibreOffice technology, which would be a very significant effort, and would also require active monitoring of all dependencies for known vulnerabilities.

(3) apply effective and regular tests and reviews of the security of the product with digital elements

These would require a significant change to our community’s development processes to mandate a whole class of testing that is not currently mandated for our projects. This is a very significant effort, both to implement and to maintain.

Section 2 of Annex I “Vulnerability Handling Requirements”

(1) Products with digital elements shall be designed, developed and produced in such a way that they ensure an appropriate level of cybersecurity based on the risks
(2) Products with digital elements shall be delivered without any known exploitable vulnerabilities
(3) On the basis of the risk assessment referred to in Article 10 (2) and where applicable, products with digital elements shall:
(a) be delivered with a secure by default configuration, including the possibility to reset the product to its original state
(b) ensure protection from unauthorised access by appropriate control mechanisms, including but not limited to authentication, identity or access management systems
(c) protect the confidentiality of stored, transmitted or otherwise processed data, personal or other, such as by encrypting relevant data at rest or in transit by state of the art mechanisms
(d) protect the integrity of stored, transmitted or otherwise processed data, personal or other, commands, programs and configuration against manipulation or modification not authorised by the user, as well as report on corruptions
(e) process only data, personal or other, that are adequate, relevant and limited to what is necessary in relation to the intended use of the product (minimisation of data)
(f) protect the availability of essential functions, including the resilience against and mitigation of denial of service attacks
(g) minimise their own negative impact on the availability of services provided by other devices or networks
(h) be designed, developed and produced to limit attack surfaces, including external interfaces
(i) be designed, developed and produced to reduce the impact of an incident using appropriate exploitation mitigation mechanisms and techniques
(j) provide security related information by recording and/or monitoring relevant internal activity, including the access to or modification of data, services or functions
These would require a significant change to our community’s release processes to require certifications that there are no known vulnerabilities and to meet the many requirements listed.
(k) ensure that vulnerabilities can be addressed through security updates, including, where applicable, through automatic updates and the notification of available updates to users

Several products based on LibreOffice technology do not require any kind of user registration and do not provide a mechanism for notifying all users that an update is either available or required. Implementing these requirements would require a whole new infrastructure to be mandated.

Recommendation and Conclusion

We propose that all open source development and distribution activities should be excluded from the scope of the Cyber Resilience Act, without exception. This is the simplest solution to the problems previously described in the document.

In order to encourage open source developers and distributors to continue their activities, we believe it is important that the Regulation provides comfort and certainty to these organisations that their activities are exempt from the obligations of the Regulation. Although it is the aim of Recital 10 to clearly establish this exemption, we believe that including the FOSS exemption in the body of the Regulation itself would establish the exemption with greater clarity and certainty.

As an alternative, we suggest clarifying the interpretation of “commercial activity” in a way that is more appropriate to the context of open source software. This would recognise that not all efforts to generate recurring revenue (such as paid “technical support services”) should be characterised as “commercial activity”.

Even without the commercial activity qualifier, the wording of Recital 10 would still require companies that primarily monetise open source software, for example by charging for products incorporating such software, to comply with the Regulation, but would no longer cover organisations that make FOSS available to the developer community.

LibreOffice 7.4.4 Community available for download

Donate logoBerlin, January 12, 2023 – LibreOffice 7.4.4 Community, the fourth maintenance release of LibreOffice 7.4, the volunteer-supported office suite for personal productivity on the desktop, is immediately available from https://www.libreoffice.org/download for Windows (Intel and Arm processors), macOS (Apple M1 and Intel processors), and Linux.

LibreOffice offers the highest level of compatibility in the office suite market segment, with native support for the OpenDocument Format (ODF) – beating proprietary formats for security and robustness – to superior support for MS Office files, to filters for a large number of legacy document formats, to return ownership and control to users.

LibreOffice Technology Platform

Products based on the LibreOffice Technology platform – the transactional engine shared by all LibreOffice based products, which provides a rock solid solution with a high level of coherence and interoperability – are available for major desktop operating systems (Windows, macOS, Linux and Chrome OS), for mobile platforms (Android and iOS), and for the cloud.

For enterprise-class deployments, TDF strongly recommends the LibreOffice Enterprise family of applications from ecosystem partners – for desktop, mobile and cloud – with a large number of dedicated value-added features and other benefits such as SLA (Service Level Agreements): https://www.libreoffice.org/download/libreoffice-in-business/. All code developed by ecosystem companies for enterprise customers is shared with the community and improves the LibreOffice Technology platform.

LibreOffice – thanks to its mature codebase, rich feature set, strong support for open standards, excellent compatibility and LTS options from certified partners – is the ideal solution for businesses that want to regain control of their data and free themselves from vendor lock-in.

Availability of LibreOffice 7.4.4 Community

LibreOffice 7.4.4 Community is available from: https://www.libreoffice.org/download/. Minimum requirements for proprietary operating systems are Microsoft Windows 7 SP1 and Apple macOS 10.12. LibreOffice Technology-based products for Android and iOS are listed here: https://www.libreoffice.org/download/android-and-ios/

Users still deploying the LibreOffice 7.3 family because of the additional testing and bug fixing, should switch immediately to LibreOffice 7.4.4, which has been extensively tested by millions of users worldwide, as the older version have reached the end of life and are not be maintained after November 30, 2022.

The Document Foundation does not provide technical support for users, although they can get it from volunteers on user mailing lists and the Ask LibreOffice website: https://ask.libreoffice.org

Donate logoLibreOffice users, free software advocates and community members can support The Document Foundation with a donation at https://www.libreoffice.org/donate

Change log pages:
https://wiki.documentfoundation.org/Releases/7.4.4/RC1 (changed in RC1)
https://wiki.documentfoundation.org/Releases/7.4.4/RC2 (changed in RC2)