Skip to content

Conversation

@feefladder
Copy link
Contributor

@feefladder feefladder commented Jun 24, 2021

The engine_kwargs argument was not passed properly and this was not tested. Also added some documentation.

@pep8speaks
Copy link

pep8speaks commented Jun 24, 2021

Hello @joeperdefloep! Thanks for updating this PR. We checked the lines you've touched for PEP 8 issues, and found:

There are currently no PEP 8 issues detected in this Pull Request. Cheers! 🍻

Comment last updated at 2021-07-12 21:54:21 UTC

@mattelacchiato
Copy link

We would really love to have this fix in the next version of pandas, since we have to mitigate XLSX injections. Is there something I could help here to achieve this?

@jreback jreback added the IO Excel read_excel, to_excel label Jul 6, 2021
@jreback jreback added this to the 1.4 milestone Jul 6, 2021
@jreback jreback added the Docs label Jul 6, 2021
@jreback
Copy link
Contributor

jreback commented Jul 6, 2021

@joeperdefloep can you merge master

Copy link
Member

@rhshadrach rhshadrach left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for the PR!

)

self.book = Workbook(self.handles.handle, **engine_kwargs)
self.book = Workbook(self.handles.handle, engine_kwargs)
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can you add a test for this.

Comment on lines +762 to +765
... with ExcelWriter(
... "path_to_file.xlsx",
... engine_kwargs={"strings_to_formulas":False}
... ) as writer:
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this will only be valid with xlsxwriter, is that right? Can you specify the engine here to make it clear that's what is being used.

ExcelWriter(f, engine="xlsxwriter", mode="a")



Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove this blank line, it will not pass code checks (two blank lines between functions)

@github-actions
Copy link
Contributor

This pull request is stale because it has been open for thirty days with no activity. Please update or respond to this comment if you're still interested in working on this.

@github-actions github-actions bot added the Stale label Aug 15, 2021
@alimcmaster1
Copy link
Member

@joeperdefloep do you still want to work on this?

@alimcmaster1 alimcmaster1 self-assigned this Aug 25, 2021
@mroeschke
Copy link
Member

Thanks for the PR, but it appears to have gone stale. Let us know if you're still interested in working on this and we can reopen. Closing.

@mroeschke mroeschke closed this Sep 2, 2021
@rhshadrach
Copy link
Member

@mattelacchiato - any interest in picking this up?

@feefladder
Copy link
Contributor Author

feefladder commented Sep 5, 2021

Heyy, sorry I was on holidays a bit so that's why it stopped and went stale...

Also there was a weird thing that there was a merge conflict, where my test was changed to another one. That's why this PR doesn't mention it.

I will be at my computer tomorrow and hopefully will come back to this this week :)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Docs IO Excel read_excel, to_excel Stale

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Excel formula injection in pandas .to_excel()

7 participants