Skip to content

Conversation

NicolasToussaint
Copy link
Member

Proposing

GitHub Dependabot shows a vulnerability warning about the phpoffice/phpspreadsheet/ used in src/composer.lock

https://github.com/Orange-OpenSource/fossology/security/dependabot/src/composer.lock/phpoffice%2Fphpspreadsheet/open
image

I don't think that Fossology is impacted by the vulnerability, but it would still make sense to upgrade the dependency.
We could also upgrade directly to newest version 1.20.

I tested licences export and import feature, but I'm not sure where else the library is used

@shaheemazmalmmd
Copy link
Member

Hello @NicolasToussaint i have observed that this changes are already solved here https://github.com/fossology/fossology/pull/2107/files#diff-708d3319cde742c23125d07bdbacc4742dea301cb5cecc89164864b73daf3443R31
Can we close this PR if you are ok with that ?

@shaheemazmalmmd shaheemazmalmmd added duplicate When a PR/Issue is duplicate of others. needs clarification labels Jan 3, 2022
@NicolasToussaint
Copy link
Member Author

Oh, perfect then @shaheemazmalmmd, thanks !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

duplicate When a PR/Issue is duplicate of others. needs clarification

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants