From 08b454423b5e2db1e8adba842551abd9d3f9fc77 Mon Sep 17 00:00:00 2001 From: shaw Date: Tue, 7 Apr 2026 17:22:17 +0800 Subject: [PATCH] chore: renew expired xlsx audit exceptions to 2026-07-06 --- .github/audit-exceptions.yml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/.github/audit-exceptions.yml b/.github/audit-exceptions.yml index 82cdefe4..b71422a7 100644 --- a/.github/audit-exceptions.yml +++ b/.github/audit-exceptions.yml @@ -5,14 +5,14 @@ exceptions: severity: high reason: "Admin export only; switched to dynamic import to reduce exposure (CVE-2023-30533)" mitigation: "Load only on export; restrict export permissions and data scope" - expires_on: "2026-04-05" + expires_on: "2026-07-06" owner: "security@your-domain" - package: xlsx advisory: "GHSA-5pgg-2g8v-p4x9" severity: high reason: "Admin export only; switched to dynamic import to reduce exposure (CVE-2024-22363)" mitigation: "Load only on export; restrict export permissions and data scope" - expires_on: "2026-04-05" + expires_on: "2026-07-06" owner: "security@your-domain" - package: lodash advisory: "GHSA-r5fr-rjxr-66jc"