Repository navigation
fix: harden spreadsheet parsing and update SheetJS - #196
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
|
Merged after refreshed-main validation (56 files / 248 tests) and green CI. Production deployment dpl_AcZveJyoHdnCFb77RfKCb9YBUrtA is READY, aliased to https://piccnewyork.org at 5feada8. Production browser sign-in returns 200 with Google sign-in visible. Parser functionality was verified locally with representative workbook/CSV fixtures; no customer data was uploaded or changed. Remaining tooling advisories are addressed separately in #198. |
Problem and outcome
The registry version of SheetJS has known security advisories. Switch to the maintainer's pinned 0.20.3 distribution with lockfile integrity, keeping existing workbook and proposal-report behavior. Official installation source: https://docs.sheetjs.com/docs/getting-started/installation/nodejs/
Closes #107.
Changes
Validation
RED: unsupported type, oversized workbook and disguised text regression cases failed before implementation. GREEN: nine focused cases including valid workbook coverage, quoted commas, Unicode, leading-zero identifiers, prices, JSON and excessive columns.
Clean
npm ciandnpm run verifypassed on Node 22: 55 test files / 244 tests, lint, types, Prisma validation, production build.git diff --checkpassed.Fresh npm audit no longer reports xlsx. Remaining findings: four high entries in the Prisma tooling chain and one low esbuild development advisory, tracked separately in #197. No claim of an advisory-free dependency tree.
Scope / risk
Eight files including SESSION. Existing adapter behavior retained; no UI, schema, external writes, or provider changes. Size/range checks are safeguards, not a sandbox for arbitrary hostile archives. Direct official tarball requires CDN availability on a cold install; lockfile integrity pins its content. Reviewed #135 file list and other active cleanup PRs for overlap. Later dependency changes must build on this lockfile.