You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
SheetJS have chosen to publish all xlsx versions > 0.18.5 only as self-hosted tarballs on cdn.sheetjs.com - see here for more info.
0.18.5 is becoming a stale dependency version and accumulating security vulnerabilities such as CVE-2023-30533 (although note that this vuln is not exploitable in fides's use of the package).
Steps to Reproduce
n/a
Expected behavior
admin-ui's use of xlsx is deprecated in favor of a different npm package that is maintained.
Screenshots
n/a
Environment
Version: fides >= 2.10
OS: All supported
Python Version: All supported
Docker Version: All supported
Additional context
Technically it is possible to include SheetJS's self-hosted tarballs as dependencies, but I suspect this will lead to issues with Dependabot, which we rely on heavily for dependency security alerts and updates.
The text was updated successfully, but these errors were encountered:
Bug Description
0.18.5
is the final version of xlsx published to the npm registry by the SheetJS maintainers.> 0.18.5
only as self-hosted tarballs on cdn.sheetjs.com - see here for more info.0.18.5
is becoming a stale dependency version and accumulating security vulnerabilities such as CVE-2023-30533 (although note that this vuln is not exploitable in fides's use of the package).Steps to Reproduce
n/a
Expected behavior
admin-ui's use of xlsx is deprecated in favor of a different npm package that is maintained.
Screenshots
n/a
Environment
>= 2.10
Additional context
Technically it is possible to include SheetJS's self-hosted tarballs as dependencies, but I suspect this will lead to issues with Dependabot, which we rely on heavily for dependency security alerts and updates.
The text was updated successfully, but these errors were encountered: