Only the latest published version receives security fixes.
Please use GitHub private vulnerability reporting for vectojs/numera-xlsx.
Do not include malicious workbook payloads in public issues. Include the package
version, runtime, reproduction conditions, and expected impact in the private
report.
XLSX input is untrusted archive content. The package rejects malformed, unsupported, and resource-excessive archives before or immediately after parsing; consumers must preserve the default limits unless they control input.