nissl-lab / npoi

a .NET library that can read/write Office formats without Microsoft Office installed. No COM+, no interop.
Apache License 2.0
5.74k stars 1.44k forks source link

Using unsafe package #1361

Closed spoomyfly closed 5 months ago

spoomyfly commented 5 months ago

NPOI Version

2.7.0

Issue Description

NPOI 2.7.0 uses nuget package with moderate vulnerability: https://www.nuget.org/packages/SixLabors.ImageSharp/2.1.7

Bykiev commented 5 months ago

Fixed in https://github.com/nissl-lab/npoi/pull/1317