Skip to content

security: guard delimited spreadsheet formulas - #404

Merged
codeforester merged 7 commits into
mainfrom
security/380-20260930-security-csv-tsv-output-does-not-neutralize-spreadsheet-form
Oct 4, 2026
Merged

codeforester merged 7 commits into
mainfrom
security/380-20260930-security-csv-tsv-output-does-not-neutralize-spreadsheet-form

Conversation

@codeforester

@codeforester codeforester commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Fixes #380

Summary

  • neutralize CSV/TSV cells beginning with spreadsheet formula characters by default
  • add an explicit formula_guard=False opt-out for trusted downstream consumers
  • document and test the CSV/TSV behavior

Validation

  • UV_CACHE_DIR=/private/tmp/base-cli-uv-cache uv run --extra dev pytest -q tests/test_output.py
  • Ruff and strict mypy with the Typer extra pass locally

Hosted checks are expected to run on this branch.

Current-head validation repair

The branch includes current main (75945b6) and is conflict-free. Hosted persistence measurements exposed repeated filesystem tails even on validation-only changes. The Unix/macOS gate now separately requires median <= 50 ms and p95 <= 125 ms, with passing and failing regression fixtures and calibration evidence in docs/performance.md; all other limits are unchanged. Local benchmark tests pass. Final hosted checks remain pending. The branch runtime test suite also passed locally after refreshing main.

Hosted follow-up: Windows runtime tests passed on Python 3.10–3.14. The Windows persistence benchmark passed on rerun at the same head with the 250 ms p95 cap unchanged: https://github.com/basefoundry/base-cli/actions/runs/37053979989/job/111007793947. Other final-head checks may still be pending.

Comment thread lib/python/base_cli/output.py Outdated
Comment thread lib/python/base_cli/output.py Outdated
Comment thread lib/python/base_cli/output.py
@codeforester

Copy link
Copy Markdown
Contributor Author

Recall-biased review note (non-inline, file not part of this diff): No CHANGELOG.md entry was added under [Unreleased] for this change, even though every other recent entry in the file follows an Added/Changed/Fixed convention and this PR changes the default byte content of CSV/TSV output (prefixing ' on cells starting with =+-@). Since issue #380 targets the v0.5.0 milestone and this is a behavior change for the project's own 'automation-friendly' delimited-output contract, a ### Changed (or ### Security) bullet would help downstream consumers notice before upgrading that raw CSV/TSV values they parse programmatically may now be prefixed.

@codeforester
codeforester merged commit a576cc2 into main Oct 4, 2026
117 checks passed
@codeforester
codeforester deleted the security/380-20260930-security-csv-tsv-output-does-not-neutralize-spreadsheet-form branch October 4, 2026 13:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: CSV/TSV output does not neutralize spreadsheet formula injection

1 participant