Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove x-data-spreadsheet, as it has unaddressed vulnerabilities #36

Commits on Apr 16, 2023

  1. Remove x-data-spreadsheet, as it has unaddressed vulnerabilities

    Dependabot reports that
    > All versions of package x-data-spreadsheet are vulnerable to
    > Cross-site Scripting (XSS) due to missing sanitization of values
    > inserted into the cells.
    (up to current version 1.1.9.)
    
    Note that this issue reports an XSS issue:
    myliang/x-spreadsheet#580
    With this fixing PR which has not been merged:
    myliang/x-spreadsheet#581
    
    Also, some issues may have been fixed, but not released,
    as this issue complains that there hasn't been a release in years
    despite unreleased fixes:
    myliang/x-spreadsheet#632
    
    The package also depends on the discontinued opencollective
    package, which brings additional problematic dependencies.
    barnardb committed Apr 16, 2023
    Configuration menu
    Copy the full SHA
    dd41cb9 View commit details
    Browse the repository at this point in the history