
Research
Security News
Malicious npm Packages Use Telegram to Exfiltrate BullX Credentials
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
node-xlsx-xc
Advanced tools
Excel file parser/builder that relies on js-xlsx.
npm install node-xlsx --save
import xlsx from 'node-xlsx';
// Or var xlsx = require('node-xlsx').default;
// Parse a buffer
const workSheetsFromBuffer = xlsx.parse(fs.readFileSync(`${__dirname}/myFile.xlsx`));
// Parse a file
const workSheetsFromFile = xlsx.parse(`${__dirname}/myFile.xlsx`);
import xlsx from 'node-xlsx';
// Or var xlsx = require('node-xlsx').default;
const data = [[1, 2, 3], [true, false, null, 'sheetjs'], ['foo', 'bar', new Date('2014-02-19T14:30Z'), '0.3'], ['baz', null, 'qux']];
var buffer = xlsx.build([{name: "mySheetName", data: data}]); // Returns a buffer
import xlsx from 'node-xlsx';
// Or var xlsx = require('node-xlsx').default;
const data = [[1, 2, 3], [true, false, null, 'sheetjs'], ['foo', 'bar', new Date('2014-02-19T14:30Z'), '0.3'], ['baz', null, 'qux']]
const options = {'!cols': [{ wch: 6 }, { wch: 7 }, { wch: 10 }, { wch: 20 } ]};
var buffer = xlsx.build([{name: "mySheetName", data: data}], options); // Returns a buffer
A1:A4
in every sheetsimport xlsx from 'node-xlsx';
// Or var xlsx = require('node-xlsx').default;
const data = [[1, 2, 3], [true, false, null, 'sheetjs'], ['foo', 'bar', new Date('2014-02-19T14:30Z'), '0.3'], ['baz', null, 'qux']];
const range = {s: {c: 0, r:0 }, e: {c:0, r:3}}; // A1:A4
const options = {'!merges': [ range ]};
var buffer = xlsx.build([{name: "mySheetName", data: data}], options); // Returns a buffer
A1:A4
in second sheet onlyimport xlsx from 'node-xlsx';
// Or var xlsx = require('node-xlsx').default;
const dataSheet1 = [[1, 2, 3], [true, false, null, 'sheetjs'], ['foo', 'bar', new Date('2014-02-19T14:30Z'), '0.3'], ['baz', null, 'qux']];
const dataSheet2 = [[4, 5, 6], [7, 8, 9, 10], [11, 12, 13, 14], ['baz', null, 'qux']];
const range = {s: {c: 0, r:0 }, e: {c:0, r:3}}; // A1:A4
const sheetOptions = {'!merges': [ range ]};
var buffer = xlsx.build([{name: "myFirstSheet", data: dataSheet1}, {name: "mySecondSheet", data: dataSheet2, options: sheetOptions}]); // Returns a buffer
//居中样式
const center = {
alignment: {
vertical: 'center',
horizontal: 'center'
}
};
let data = [
[{
v: '今日第001单',
s: center
}]
];
data.push([`客户名称:测试111`]);
data.push([`订单编号:202020`])
data.push([`下单时间:2020-06-08`]);
//空行
data.push([""])
//标题
data.push([{ v: `#`, s: center }, "商品名称", "商品数量", "商品规格", "商品价格"]);
//行列合并
let merges = [
{ s: { c: 0, r: 0 }, e: { c: 4, r: 0 } },
{ s: { c: 0, r: 1 }, e: { c: 4, r: 1 } },
{ s: { c: 0, r: 2 }, e: { c: 4, r: 2 } },
{ s: { c: 0, r: 3 }, e: { c: 4, r: 3 } },
{ s: { c: 0, r: 4 }, e: { c: 4, r: 4 } }
];
//列宽
let cols = [
{ wpx: 40 },
{ wpx: 120 },
{ wpx: 80 },
{ wpx: 100 },
{ wpx: 100 },
];
//填充数据
for (let i = 0; i < goods.length; i++) {
const g = goods[i];
data.push([
{ v: (i + 1), s: center },
g.name,
g.number,
g.sku,
parseFloat(g.price)
]);
}
//egg导出
this.ctx.attachment("今日第001单.xlsx");
this.ctx.set('Content-Type', 'application/octet-stream');
this.ctx.body = nodeXlsx.build([{ name: "订单详细", data: data }], { '!merges': merges, '!cols': cols });
Beware that if you try to merge several times the same cell, your xlsx file will be seen as corrupted.
Examples:
const rowAverage = [[{t:'n', z:10, f:'=AVERAGE(2:2)'}], [1,2,3];
var buffer = xlsx.build([{name: "Average Formula", data: rowAverage}]);
Refer to xlsx documentation for valid structure and values:
This library requires at lease nodeJS v4. For legacy versions, you can use this workaround before using the lib.
npm i --save object-assign
Object.prototype.assign = require('object-assign');
Please submit all pull requests the against master branch. If your unit test contains javascript patches or features, you should include relevant unit tests. Thanks!
Script | Description |
---|---|
start | Alias of test:watch |
test | Run mocha unit tests |
test:watch | Run and watch mocha unit tests |
lint | Run eslint static tests |
compile | Compile the library |
compile:watch | Compile and watch the library |
Olivier Louvignes
Copyright (C) 2012-2014 Olivier Louvignes
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
Except where noted, this license applies to any and all software programs and associated documentation files created by the Original Author and distributed with the Software:
Inspired by SheetJS gist examples, Copyright (c) SheetJS.
FAQs
NodeJS Excel files parser & builder for xiaocan
The npm package node-xlsx-xc receives a total of 4 weekly downloads. As such, node-xlsx-xc popularity was classified as not popular.
We found that node-xlsx-xc demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?
Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.
Research
Security News
Socket uncovers an npm Trojan stealing crypto wallets and BullX credentials via obfuscated code and Telegram exfiltration.
Research
Security News
Malicious npm packages posing as developer tools target macOS Cursor IDE users, stealing credentials and modifying files to gain persistent backdoor access.
Security News
AI-generated slop reports are making bug bounty triage harder, wasting maintainer time, and straining trust in vulnerability disclosure programs.