{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://data.datagrok.ai/vex/npm/datagrok-libraries-compute-api/0.8.0.json",
  "author": "Datagrok",
  "timestamp": "2026-09-28T01:06:12Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "GHSA-w5hq-g745-h8pq"
      },
      "products": [
        {
          "@id": "pkg:npm/%40datagrok-libraries/compute-api@0.8.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "uuid enters only via exceljs (through @datagrok-libraries/compute-utils), and exceljs calls uuid.v4() exclusively (lib/xlsx/xform/sheet/cf-ext/cf-rule-ext-xform.js); the advisory requires a caller-supplied buf to v3/v5/v6. compute-api is <1.0 (unpublishable beta), so the consumer-side overrides.uuid fix cannot ship until 1.0."
    }
  ]
}
