Skip to content

[Snyk] Upgrade xlsx from 0.14.1 to 0.17.0

Created by: snyk-bot

Snyk has created this PR to upgrade xlsx from 0.14.1 to 0.17.0.

merge advice Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 22 versions ahead of your current version.
  • The recommended version was released 2 months ago, on 2021-05-13.

The recommended version fixes:

Severity Issue PriorityScore (*) Exploit Maturity
Denial of Service (DoS)
SNYK-JS-XLSX-1311141
768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Proof of Concept
Denial of Service (DoS)
SNYK-JS-XLSX-1311139
768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Proof of Concept
Denial of Service (DoS)
SNYK-JS-XLSX-1311137
768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Proof of Concept
Regular Expression Denial of Service (ReDoS)
SNYK-JS-XLSX-585898
768/1000
Why? Proof of Concept exploit, Recently disclosed, Has a fix available, CVSS 7.5
Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Release notes
Package name: xlsx
  • 0.17.0 - 2021-05-13
    • Explicit errors on inconsistent XLS records
    • DBF cap worksheet to 1<<20 rows
  • 0.16.9 - 2020-11-20
  • 0.16.8 - 2020-10-06

    version bump 0.16.8: CRLF in formulae

  • 0.16.7 - 2020-09-11
  • 0.16.6 - 2020-08-12

    version bump 0.16.6: xlfn option

  • 0.16.5 - 2020-07-31

    version bump 0.16.5: sheet_add_dom (fixes #2073)

  • 0.16.4 - 2020-07-16
  • 0.16.3 - 2020-06-29
    • updated SSF to 0.11.2
    • XLS write support for bookSST
  • 0.16.2 - 2020-06-05

    version bump 0.16.2

  • 0.16.1 - 2020-05-17
    • Custom Properties use correct encoding
    • AMD wrapper change (see #1937)
  • 0.16.0 - 2020-04-30

    closes #1904 h/t

    • @ atcazzual : Adam Cazzolla of the Sonatype Security Research team
    • @ davisjam : James (Jamie) Davis of Virginia Tech
  • 0.15.6 - 2020-03-15
    • CFB prevent infinite loop (h/t @ rossj)
    • pass updated eslint checks (fixes #1726 h/t @ BjoernRave)
    • defined name proper encoding (fixes #1785 h/t @ laohe98)
    • correct theme color order (fixes #389 h/t @ foreverpw)
    • ODS / XLML more aggressive flagging of stub cells
    • cellStyles implies sheetStubs
    • updated SSF to 0.10.3
  • 0.15.5 - 2020-01-28
  • 0.15.4 - 2019-12-23
  • 0.15.3 - 2019-11-27
  • 0.15.2 - 2019-11-15
  • 0.15.1 - 2019-08-14
  • 0.15.0 - 2019-08-04
  • 0.14.5 - 2019-08-03
  • 0.14.4 - 2019-07-21
  • 0.14.3 - 2019-04-30
  • 0.14.2 - 2019-04-01
  • 0.14.1 - 2018-11-13
from xlsx GitHub release notes
Commit messages
Package name: xlsx
  • 3542d62 version bump 0.17.0
  • 6c5db36 AWS Lambda Binary Media Types
  • 59b3dae Tested the MongoDB scripts and fixed them
  • e958dbf Refresh server demos
  • 1d7aff4 suppress modified test files
  • f8c0a86 [Tests] migrate tests to Github Actions
  • 58e59dc updates to react demo
  • 333deae write and parse ods in mini build (#2197)
  • 20212e1 version bump 0.16.9: utf-8 codenames
  • f7835d6 Add support for outline configuration
  • eec93b0 Fixed parsing for first cell in .fods documents
  • 6ecfeb6 Added google sheet example
  • b0e68a9 Add escape slash to cell matcher
  • 9f1ba60 version bump 0.16.8: CRLF in formulae
  • b9323c5 Update 78_writebiff.js
  • d4cfadb Fix #2071
  • 5985739 Mark generated files as binary
  • 542636b Update 80_parseods.js
  • 82b7ada version bump 0.16.7
  • 0cc6cc9 XLSX verify formula is string (fixes #1703)
  • 2c5a863 Removed null ws return from 90_utils
  • 2e32611 version bump 0.16.6: xlfn option
  • 3b589f0 XLSX SST treat <si></si> as empty (fixes #2083)
  • abed474 whitespace check (fixes #2075)

Compare


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs

合并请求报告