fix: add excel macro filter for csv output #1634
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I've added some basic excel macro prevention to the csv output. That means trimming leading special characters (+, -, =, @) used by excel for formulae.
Honestly, it's a bit unlikely that anyone would manage to put an excel macro into the NVD data, but it is possible that folk might share triage with intentional or unintentional comments that parse as macros. Either way, there's no reason for us to allow these characters in output so we might as well add the filter for additional safety.