Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Need new supported release of 3.0.0 #592

Closed
leopoldodonnell opened this issue Jun 6, 2018 · 10 comments
Closed

Need new supported release of 3.0.0 #592

leopoldodonnell opened this issue Jun 6, 2018 · 10 comments
Labels
Done in caxlsx This has already been solved in the caxlsx fork.

Comments

@leopoldodonnell
Copy link

3.0.0.pre is a much needed update that addresses some security concerns. If there is no reason not to release, this candidate should become the latest gem released version.

thanks - for dragging this out of mothballs!

@compwron
Copy link

compwron commented Jun 6, 2018

Ditto. :)

In the meantime, this is what we're doing to work around it- gem 'axlsx', '3.0.0.pre' # TODO: Unpin when a non-pre version without the ruby-zip vuln is released

@fmluizao
Copy link

@randym, do you want some kind of help with the maintenance? I absolutely love this gem and use it extensively, I will be happy to contribute.

@fabn
Copy link

fabn commented Aug 29, 2018

See also #599

@noniq
Copy link
Collaborator

noniq commented Aug 29, 2018

Also see #536

@fmluizao
Copy link

Since we get no response, I'm taking over the maintenance in my personal fork:

https://github.com/fernandoluizao/axlsx-alt
https://rubygems.org/gems/axlsx-alt

I merged some PRs and released a new version with a new name. I haven't changed the gem's namespace, so it should be easy to migrate.

Please, note that this isn't a hard fork... If someone wants to help, ping me.

@mdavidn
Copy link

mdavidn commented Oct 29, 2018

@fernandoluizao You may want to release a fix to the 2.x major version as well. I prepared such a backport in #536.

@fmluizao
Copy link

I'm not intending to support older versions... sorry 😞

@noniq
Copy link
Collaborator

noniq commented Dec 15, 2019

There's now https://github.com/caxlsx/caxlsx which has released 3.0.0 (and 3.0.1 and also 2.0.2 with a backport for the rubyzip dependency).

@noniq noniq added the Done in caxlsx This has already been solved in the caxlsx fork. label Dec 15, 2019
@leopoldodonnell
Copy link
Author

There's now https://github.com/caxlsx/caxlsx which has released 3.0.0 (and 3.0.1 and also 2.0.2 with a backport for the rubyzip dependency).

So, should this be considered the preferred solution?

@leopoldodonnell
Copy link
Author

Going with caxlsx as a solution where there is some community support - thanks @noniq !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Done in caxlsx This has already been solved in the caxlsx fork.
Projects
None yet
Development

No branches or pull requests

6 participants