4811 Commits

Author SHA1 Message Date
oleibman 3a3cad8610 Prepare Changelog for New Release 2.4.0 2025-08-09 23:45:13 -07:00
oleibman 334a67797a Breaking Change When Loading External Images
Images will be loaded from an external source (e.g. http://example.com/img.png) only if the reader is explicitly set to allow it via `$reader->setAllowExternalImages(true)`.
2025-08-02 18:38:33 -07:00
oleibman 6109682431 Changelog Update Semantic Versioning Statement 2025-07-25 22:34:10 -07:00
oleibman 22058ce75b All Readers - Allow or Forbid Fetching of External Images Release222 (#4547)
* All Readers - Allow or Forbid Fetching of External Images Release222

Add to all readers the option to allow or forbid fetching external images. This is unconditionally allowed now. The default will be set to "allow", so no code changes are necessary. However, we are giving consideration to changing the default.

* Update Changelog
2.3.10
2025-07-22 21:43:28 -07:00
oleibman 12e0d9f5ef Allow Xlsx Reader to Specify ParseHuge Release222 (#4517)
* Allow Xlsx Reader to Specify ParseHuge Release222

Fix #4260. A number of Security Advisories related to libxml_options were opened. In the end, we disabled the ability to specify any libxml_options. However, some users were adversely affected because they needed LIBXML_PARSEHUGE for some of their files. Having finally obtained access to a file demonstrating this problem, we can restore this ability.
- The operation is potentially dangerous, a vector for memory leaks and out-of-memory errors. It is not recommended unless absolutely needed.
- It will not be permitted as a global (static) property with the ability to adversely affect other users on the same server.
- It will instead be implemented as an instance property of Xlsx Reader (default to false), with a setter. I do not see a use case for a getter.
- People will need to set this property individually for each file which they think needs it.
- This change will be backported to all supported releases.
- The sheer size and processing time for the file involved makes it impractical to add a formal test case. It has, nevertheless, been tested satisfactorily.

* Unneeded Blank Line

* Update CHANGELOG.md
2.3.9
2025-06-22 18:20:15 -07:00
oleibman 448a3436af Removing Columns/Rows Containing Merged Cells (#4471)
Backport PR #4465.
2025-05-15 21:56:30 -07:00
oleibman 76978140f0 Allow Spreadsheet Serialization Branch release222 (#4407) 2025-03-14 07:37:59 -07:00
oleibman a02e4c2ebe Allow php-cs-fixer to Handle Implicit Backslashes 2025-02-10 23:52:57 -08:00
oleibman 4eefcceee8 Fix TEXT and TIMEVALUE Functions 2.3 Branch (#4354)
Fix #4249. Technically speaking, only the 1.29 branch needs fixing, and only for TEXT. It was fixed for the other branches by PR #3898. However, in adding test cases for the fix, it became apparent that PhpSpreadsheet's parsing in TIMEVALUE (which is called from TEXT in the original issue) did not really match Excel's. There are probably still edge cases where it doesn't, but, in the absence of a spec for how it operates, this will do for now.

We do not usually backport fixes from the master branch. Because this is more of a forward port from the earlier branch, there is an equivalent PR for each active branch.
2025-02-10 20:47:25 -08:00
oleibman e6cc4129b7 Update content-hash (composer update --lock) 2025-02-07 21:54:35 -08:00
oleibman 7a70068374 Update Changelog for New Release 2.3.8 2025-02-07 19:01:45 -08:00
oleibman 6ef0269e97 Writer Xls Parser Backport 2 Changes
PR #4233 and PR #4244.
2025-02-06 21:26:08 -08:00
oleibman cf357183b1 Update Changelog 2.3.7 2025-01-25 20:53:06 -08:00
oleibman e237309829 Security Patch Control Characters in Protocol 2025-01-23 23:52:50 -08:00
oleibman 7af20c39d8 Upgrade mitoteam/jpgraph 2025-01-15 22:53:52 -08:00
oleibman 51f774ce27 Tweak One Test
Fluke failure in CI push.
2025-01-15 01:51:54 -08:00
oleibman 098b848ee6 Backported Security Patch 2.3.6 2025-01-11 19:22:26 -08:00
oleibman 345e7f09a2 Change hash code for worksheet branch release222 (#4308)
* Change hash code for worksheet branch release210

Backport of PR #4207.

* Retitling Clone Worksheets

Backport of PR #4302.
2025-01-08 14:39:01 -08:00
oleibman cc41c3bdc7 Remove Scrutinizer and Coverage from release222 (#4305)
Don't need them for backported branches.
2025-01-06 19:03:23 -08:00
oleibman 452187795e Update License 2025-01-04 21:37:46 -08:00
oleibman eba8d700de Upgrade tcpdf to 6.8.0 2024-12-27 16:21:32 -08:00
oleibman d836f2d730 Backport Html Writer Security Patches 2.3.5 2024-12-26 21:17:46 -08:00
oleibman b8fac55aa5 Backport Security Patches for Samples 2024-12-25 19:40:39 -08:00
oleibman 22c65debbb Install Language Packs to Avoid Skipping Some Tests 2024-12-23 09:19:40 -08:00
oleibman 7019886ac9 Restore Accidentally Disabled Test 2024-12-15 15:02:13 -08:00
oleibman 54885f20cb Additional Context Options for http(s) Image
Backport of PR #4276.
2024-12-13 15:18:45 -08:00
oleibman 01c4122a12 Missed One Test 2.3.4 2024-12-08 07:43:45 -08:00
oleibman 81f781a494 Update CHANGELOG.md 2024-12-07 22:20:06 -08:00
oleibman afa5428588 Upgrade Dompdf 2024-12-07 22:11:49 -08:00
oleibman 0adf030a4f Fix Minor Break Handling Drawings
Backport of #4241. Some security batches caused a minor break in Drawings, forcing `setWorksheet` to come after `setPath`. Although the problem is easily fixed in user code, this was not an intended change. Some slight recoding restores the earlier functionality where the order of calls was not important, without sacrificing the security gains.
2024-11-25 20:26:18 -08:00
oleibman 526cdf3bf2 Try Again To Suppress github-pages For This Branch 2024-11-22 22:57:06 -08:00
oleibman 91a4b42e41 Ignore Settings::libXmlLoaderOptions
Backport of PR #4233.
2.3.3
2024-11-21 22:11:37 -08:00
oleibman 570bb6edf2 Upgrade PhpUnit
To a version which knows Php8.4 deprecates E_STRICT.
2024-11-14 14:31:10 -08:00
oleibman 4f70a4701a Upgrade Symfony/Process
Used only in dev, current version has a security advisory. May as well fix it.
2024-11-12 19:27:13 -08:00
oleibman b59e9bdbed Update GitHub Pages Only For Branch master 2024-11-12 07:09:20 -08:00
oleibman 6e85375fcc Update One Github Action
It was using deprecated version.
2024-11-10 10:23:49 -08:00
oleibman 08d4e08cf0 Backport Security Fix 2.3.2 2024-11-10 01:35:47 -08:00
oleibman 8628d6385c Backport PR #4189 Csv Method 2024-10-14 21:44:31 -07:00
oleibman c972c146dd Update Changelog 2.3.0 2024-09-29 00:06:02 -07:00
oleibman c251ef5efc Restore 2 Disabled Tests 2024-09-24 17:45:23 -07:00
oleibman a9693d1182 Backport Security Patch 2024-09-24 05:53:42 -07:00
oleibman f0b70ed108 Html Writer Validate Hyperlink Protocols 2024-09-14 05:28:06 -07:00
oleibman 3bcd51826b Security Patch 2024-09-13 10:16:19 -07:00
oleibman c2428f622b AMORDEGRC and Csv Reader
Backports of PR #4162 and PR #4164 intended for Php 3.0.0.


Signed-off-by: oleibman <10341515+oleibman@users.noreply.github.com>
2024-09-07 21:32:15 -07:00
oleibman c370bfceb4 Php 8.4 Will Deprecate fgetcsv Parameter
As described in issue #4161, Php seems to be prepared to break the fgetcsv function in release 9, marking the existing usage deprecated in 8.4. This gives us a long-term problem. This PR provides a short-term solution.
2024-09-06 01:46:25 -07:00
oleibman 3990173db1 Validate POST Input in Sample 45
Errors will result if inputs are not numeric.
2024-09-05 10:27:28 -07:00
oleibman bce30f945e Improve Xlsx Reader Speed
Backport of PR #4153.
2024-09-04 20:27:42 -07:00
oleibman ffbcee6806 Merge pull request #4132 from oleibman/issue4128
Worksheet applyStylesFromArray Retain Active Cell
2.2.2
2024-08-08 02:31:26 +00:00
oleibman 905d93f60d Update CHANGELOG.md 2024-08-07 19:23:00 -07:00
oleibman 9450bc1acb Merge branch 'master' into issue4128 2024-08-07 11:31:01 -07:00