{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://data.datagrok.ai/vex/npm.json",
  "author": "Datagrok",
  "timestamp": "2026-09-07T01:06:28Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "GHSA-w5hq-g745-h8pq"
      },
      "products": [
        {
          "@id": "pkg:npm/%40datagrok/admetica@1.3.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer dependency version; upgrade the affected npm dependency."
    },
    {
      "vulnerability": {
        "name": "GHSA-fgmj-fm8m-jvvx"
      },
      "products": [
        {
          "@id": "pkg:npm/%40datagrok/charts@1.8.1"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer dependency version; upgrade the affected npm dependency."
    },
    {
      "vulnerability": {
        "name": "GHSA-w5hq-g745-h8pq"
      },
      "products": [
        {
          "@id": "pkg:npm/%40datagrok-libraries/compute-api@0.7.6"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "uuid enters only via exceljs (through @datagrok-libraries/compute-utils), and exceljs calls uuid.v4() exclusively (lib/xlsx/xform/sheet/cf-ext/cf-rule-ext-xform.js); the advisory requires a caller-supplied buf to v3/v5/v6. compute-api is <1.0 (unpublishable beta), so the consumer-side overrides.uuid fix cannot ship until 1.0."
    },
    {
      "vulnerability": {
        "name": "GHSA-w5hq-g745-h8pq"
      },
      "products": [
        {
          "@id": "pkg:npm/%40datagrok/pyodide@1.4.0"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer dependency version; upgrade the affected npm dependency."
    },
    {
      "vulnerability": {
        "name": "GHSA-jmr9-qjv8-65gv"
      },
      "products": [
        {
          "@id": "pkg:npm/datagrok-tools@6.5.7"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer dependency version; upgrade the affected npm dependency."
    },
    {
      "vulnerability": {
        "name": "GHSA-w5hq-g745-h8pq"
      },
      "products": [
        {
          "@id": "pkg:npm/%40datagrok/tutorials@1.11.3"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer dependency version; upgrade the affected npm dependency."
    }
  ]
}
