1. d43c238 Reject path traversal filenames during HMEF attachment extraction (#1066) by jmestwa-coder · 8 days ago trunk
  2. bc6aa26 Guard HDGF PointerFactory offset/length uint32 narrowing (#1076) by metsw24-max · 8 days ago
  3. e81982e Validate HDGF v6+ chunk Length before narrowing to int (#1075) by metsw24-max · 9 days ago
  4. 9727f3e replace casts long to int with Math.toIntExact (#1072) by PJ Fanning · 10 days ago
  5. 370963f Update XSLFSheet.java (#1074) by PJ Fanning · 10 days ago
  6. 9804b78 Update IOUtils.java (#1073) by PJ Fanning · 10 days ago
  7. 4046f94 Reject oversized OOXML ptCount values in XDDFDataSourcesFactory (#1070) by metsw24-max · 10 days ago
  8. 96447f0 Increase coverage for function CountIf by Dominik Stadler · 2 weeks ago
  9. c65c4a2 Bug 70005: Fix countifs with multi-element arrays by Dominik Stadler · 3 weeks ago
  10. 6ff105f Update .asf.yaml by Dominik Stadler · 11 days ago
  11. 3b9cfaa Add sample document and test for issue #1013 by Dominik Stadler · 3 months ago
  12. 4ea6fc6 Reject oversized XSSF table counts during integer conversion (#1067) by metsw24-max · 11 days ago
  13. 145ca46 Harden HPSF allocation-size arithmetic against silent overflow (#1064) by metsw24-max · 11 days ago
  14. c0a49d5 rework temp file permissions (#1065) by PJ Fanning · 11 days ago
  15. 7e761ad Harden temporary file permissions (#1063) by metsw24-max · 12 days ago
  16. 7607d1b Apply zip bomb checks to encrypted temp ZIP processing (#1057) by jmestwa-coder · 12 days ago
  17. d80ff2d Validate EMF description bounds before allocation (#1060) by jmestwa-coder · 12 days ago
  18. c3b0a61 log4j 2.26.0 by PJ Fanning · 2 weeks ago
  19. 39c891f Update class description for PoiLogManager by PJ Fanning · 2 weeks ago
  20. e0d7f54 Revert "Enforce max entry size consistently for streaming ZIP entries (#1055)" by PJ Fanning · 3 weeks ago
  21. 142050f Enforce max entry size consistently for streaming ZIP entries (#1055) by jmestwa-coder · 3 weeks ago
  22. 80f0e30 police overflow in blip calculations (#1054) by PJ Fanning · 3 weeks ago
  23. e6a04b4 add setOutputPassword for HSLFSlideShow and HWPFDocument (#1050) by PJ Fanning · 4 weeks ago
  24. 8afdb88 decouple xlsb from xmlbeans (#1043) by Tim Allison · 5 weeks ago
  25. eacd5f9 Event based extractor: refactor password support (#1026) by PJ Fanning · 5 weeks ago
  26. 1a91f5c Reject invalid WMF unitsPerInch=0 to prevent infinite scaling (#1045) by jmestwa-coder · 5 weeks ago
  27. d809edb bc 1.84 by PJ Fanning · 5 weeks ago
  28. 4fc020b log4j 2.25.4 by PJ Fanning · 5 weeks ago
  29. da17d72 Bump bouncy castle from 1.83 to 1.84 (#1047) by David Frizelle · 5 weeks ago
  30. be8875b Bug 60848 and 65907 - Fix SUMPRODUCT with unary minus (--) on array arguments and other cases by Dominik Stadler · 6 weeks ago
  31. d117241 Open up xssfb to simplify client usage/modifications. (#1042) by Tim Allison · 5 weeks ago
  32. b5d2426 Fix Row.setRowStyle() not propagating styles to cells in XSSFCell and SXSSFCell (#1031) by Md Fakhrul Islam · 7 weeks ago
  33. e657fc9 Remove redundant stripe style settings in CreateTable (#1040) by PJ Fanning · 9 weeks ago
  34. 3cc9731 Bump org.sonarqube from 7.2.2.6593 to 7.2.3.7755 (#1037) by dependabot[bot] · 9 weeks ago
  35. 702be5b Bump org.mockito:mockito-core from 5.22.0 to 5.23.0 (#1034) by dependabot[bot] · 9 weeks ago
  36. 113059e Fix ArrayIndexOutOfBoundsException in XSSFTextParagraph when auto number scheme index is out of range (#1033) by amos-wnjsoft · 9 weeks ago
  37. ddb4900 Bump org.mockito:mockito-core from 5.21.0 to 5.22.0 (#1019) by dependabot[bot] · 9 weeks ago
  38. dbeb744 Bump actions/upload-artifact from 4 to 7 (#1029) by dependabot[bot] · 2 months ago
  39. 173ef2b Bump github/codeql-action from 2 to 4 (#1030) by dependabot[bot] · 2 months ago
  40. 70a44cb [fuzz] Integrate CIFuzz GitHub Action for continuous security testing (#1028) by Vishal S · 2 months ago
  41. 32a2220 Update StressMap.java by PJ Fanning · 3 months ago
  42. 9cd4103 work around poi-scratchpad issue by PJ Fanning · 3 months ago
  43. 90560c3 Move fuzz-targets from oss-fuzz to Apache POI by Dominik Stadler · 3 months ago
  44. 1d9425a Log instead of assertion when handling a slightly corrupted wmf-file by Dominik Stadler · 3 months ago
  45. b19e73b Add fuzz targets for OSS-Fuzz integration (RLE + FormulaParser) (#1020) by Vishal S · 3 months ago
  46. 54874ae Update commons-compress version in index.xml by PJ Fanning · 3 months ago
  47. 715ddce support upcoming COMPRESS-598 change by PJ Fanning · 3 months ago
  48. 3b02cd8 typo by PJ Fanning · 3 months ago
  49. a023a29 reformat by PJ Fanning · 3 months ago
  50. 87c4c38 HSLF: support passing password as a param (#1023) by PJ Fanning · 3 months ago
  51. f669cec add password support by PJ Fanning · 3 months ago
  52. 9051507 support opening hwpf docs by passing passwords (#1017) by PJ Fanning · 3 months ago
  53. 4bbeddf Remove stress xls (#1022) by PJ Fanning · 3 months ago
  54. 90f1ae7 Revert "Update HWPFDocumentCore.java" by PJ Fanning · 3 months ago
  55. 7cf5b04 Update HWPFDocumentCore.java by PJ Fanning · 3 months ago
  56. 41ff567 move stress.xls to stress.xlsx (#1021) by PJ Fanning · 3 months ago
  57. cfb713d use javadocs.dev by PJ Fanning · 3 months ago
  58. 44598bd Avoid OOM with incorrect property sizes by Dominik Stadler · 3 months ago
  59. 2336958 Avoid assertion when handling slightly corrupted emf-file by Dominik Stadler · 3 months ago
  60. 9d9865c Avoid NPE when handling diagrams in pptx by Dominik Stadler · 3 months ago
  61. e9e9612 Avoid ClassCastException when reading headers of EMF files by Dominik Stadler · 3 months ago
  62. 1594baf Avoid NPE when updating cell-anchors by Dominik Stadler · 3 months ago
  63. 839ce4a Avoid NPE in HSSFShapeGroup.setShapeId() by Dominik Stadler · 3 months ago
  64. 260b22f Handle slightly broken file with empty BlipFill properly by Dominik Stadler · 3 months ago
  65. ac4e3c1 more HSSFEventFactory changes by PJ Fanning · 3 months ago
  66. a1f6f27 Update RecordFactoryInputStream.java by PJ Fanning · 3 months ago
  67. b923655 update tests by PJ Fanning · 3 months ago
  68. 6b72a2d Update DocumentInputStream.java by PJ Fanning · 3 months ago
  69. c797644 Update TestRecordFactoryInputStream.java by PJ Fanning · 3 months ago
  70. 811eb4a support reading HSSFWorkbook with password passed as param (#1016) by PJ Fanning · 3 months ago
  71. 6ba4a1b Update TestDocumentEncryption.java by PJ Fanning · 3 months ago
  72. 4efa2b7 Update OldExcelExtractor.java by PJ Fanning · 3 months ago
  73. 139321c Update HSSFWorkbook.java by PJ Fanning · 3 months ago
  74. 6a92243 deprecate unnecessary constructor by PJ Fanning · 3 months ago
  75. df5604a check input stream read params (#1012) by PJ Fanning · 3 months ago
  76. eafd6c0 Update security.xml by PJ Fanning · 3 months ago
  77. e340f31 Bump net.bytebuddy:byte-buddy-agent from 1.18.4 to 1.18.5 (#1009) by dependabot[bot] · 3 months ago
  78. bc02ef0 Avoid NPE with malformed wmf headers by Dominik Stadler · 3 months ago
  79. 692caf0 Avoid NPE with malformed master-style by Dominik Stadler · 3 months ago
  80. e96c9e1 Avoid NPE with malformed EscherAggregate by Dominik Stadler · 3 months ago
  81. 55c1608 Avoid NPE with malformed anchors in slideshow files by Dominik Stadler · 3 months ago
  82. 5338b17 Avoid NPE with malformed Visio diagram by Dominik Stadler · 3 months ago
  83. c92c533 Prevent large allocations when writing PPDrawing items by Dominik Stadler · 3 months ago
  84. 8d53613 Bug 69935: Add short-based column setters to ClientAnchor (#1006) by Yongho Hwang · 3 months ago
  85. 62ae400 Do not call getColumn() twice by Dominik Stadler · 4 months ago
  86. ae3ed57 Prevent a file-handle leak by Dominik Stadler · 6 months ago
  87. 8f149f5 Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 (#1004) by dependabot[bot] · 4 months ago
  88. ab196a7 Use log instead of assert when parsing emf-files by Dominik Stadler · 4 months ago
  89. da3d64d Add an NPE check when retrieving fonts for bullet-items by Dominik Stadler · 4 months ago
  90. 04f4c1f Avoid NPE when retrieving sheets by name with invalid name by Dominik Stadler · 4 months ago
  91. 513a805 Describe where to get the latest spotbugs by Dominik Stadler · 4 months ago
  92. 0ae15ed Perform an allocation-check for .emf files by Dominik Stadler · 4 months ago
  93. 5eba199 Fix tests for no-scratchpad by Dominik Stadler · 4 months ago
  94. 0de8ecd Recent tests add one more file to ooxml-lite by Dominik Stadler · 4 months ago
  95. d1f3f94 Add check for too large allocation in SharedFormulaGroup by Dominik Stadler · 4 months ago
  96. d1f0a88 Avoid NPE in XSLFDiagram by Dominik Stadler · 4 months ago
  97. beab88f Remove obsolete if-condition by Dominik Stadler · 4 months ago
  98. 6610918 Only allocate the required size for EscherComplexProperty by Dominik Stadler · 4 months ago
  99. c9b3767 Introduce getComplexSize() by Dominik Stadler · 4 months ago
  100. e54ba88 Log instead of an assertion by Dominik Stadler · 4 months ago