nissl-lab / npoi

a .NET library that can read/write Office formats without Microsoft Office installed. No COM+, no interop.
Apache License 2.0
5.65k stars 1.42k forks source link

Using unsafe package #1361

Closed spoomyfly closed 2 months ago

spoomyfly commented 2 months ago

NPOI Version

2.7.0

Issue Description

NPOI 2.7.0 uses nuget package with moderate vulnerability: https://www.nuget.org/packages/SixLabors.ImageSharp/2.1.7

Bykiev commented 2 months ago

Fixed in https://github.com/nissl-lab/npoi/pull/1317