Skip to content

Security issue on XLSX dependency #571

@digital-codes

Description

@digital-codes

XLSX library that is bundled with danfojs has secirity issue. Suggest upgrade dependency to 0.19.3 of xlsx:

$ npm audit

npm audit report

xlsx *
Severity: high
Prototype Pollution in sheetJS - GHSA-4r6h-8v6p-xvw6
fix available via npm audit fix --force
Will install danfojs@0.1.1, which is a breaking change
node_modules/danfojs/node_modules/xlsx
danfojs >=0.1.2
Depends on vulnerable versions of xlsx
node_modules/danfojs

2 high severity vulnerabilities

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions