SuperMap / vue-iclient

SuperMap iClient UI Components for Vue.js
https://iclient.supermap.io/web/apis/vue/
Apache License 2.0
193 stars 56 forks source link

[Snyk] Upgrade xlsx from 0.17.2 to 0.18.5 #51

Closed snyk-bot closed 1 year ago

snyk-bot commented 1 year ago

Snyk has created this PR to upgrade xlsx from 0.17.2 to 0.18.5.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Regular Expression Denial of Service (ReDoS)
SNYK-JS-WORDWRAP-3149973
372/1000
Why? Proof of Concept exploit, CVSS 5.3
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: xlsx from xlsx GitHub release notes
Commit messages
Package name: xlsx
  • 0400a87 version bump 0.18.5: basic NUMBERS write
  • e69ecd4 remove broken CDNs [ci skip]
  • 0f0b3de popping IIFEs to appease rollup tree shaking
  • 2f274dd book_append_sheet rolling names
  • a5b3877 Fix rawNumber support inside sheet_to_json
  • 69bb1e7 "side-effect free"
  • 90a7b4e remove SSF._general_int
  • 61487bc use TextEncoder for zip strings (fixes #2616)
  • 61b17a8 version bump 0.18.4
  • 2cbc28d vue-modify demo [ci skip]
  • 9a3294c phasing out patterns with side effects
  • f443aa8 react-modify demo [ci skip]
  • b9e7d0d XLSB/XLS Record Name refactor
  • 0270784 `skipHidden` for `sheet_to_json` [ci skip]
  • 0044f3b clean cptable global pollution
  • 0b6ebc6 DBF preserve field properties
  • b3793e2 HTML Parsing fix misaligned cells (fixes #1621)
  • b738e5d pulling ssf into main project [ci skip]
  • d97fce4 ssf repo reorg
  • c6a86cf make stream utils available to Node ESM
  • a32b304 CSV omit trailing record separator [ci skip]
  • 467020f stream.to_json end (fixes #1779)
  • ba3280e Demos [ci skip]
  • 6ede9dc xlsx-cli v1.1.2 [ci skip]
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

stale[bot] commented 1 year ago

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.