-
-
Notifications
You must be signed in to change notification settings - Fork 32.3k
child_process: validate exec's options.shell
as string
#59185
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
child_process: validate exec's options.shell
as string
#59185
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #59185 +/- ##
==========================================
- Coverage 90.04% 90.03% -0.01%
==========================================
Files 648 648
Lines 190978 191031 +53
Branches 37434 37451 +17
==========================================
+ Hits 171964 171994 +30
- Misses 11641 11650 +9
- Partials 7373 7387 +14
🚀 New features to boost your workflow:
|
@@ -33,7 +33,7 @@ const testCopy = (shellName, shellPath) => { | |||
const system32 = `${process.env.SystemRoot}\\System32`; | |||
|
|||
// Test CMD | |||
test(true); |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
shell: true
is a widely used input. many downstream devs (and me) are actually using it.
https://github.com/search?q=child_process+shell%3A+true+language%3AJavaScript&type=code&l=JavaScript
So this is a breaking change. I personally unvote this
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
On exec()
or its sister functions?
This is only adding validation of documented behaviour, which by precedent is not a breaking change – not that it's for me to say.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
yeah, it is string on document. But I think it's too loose before on runtime, now it's hard to make it back
exec()
is documented to only take a string for the shell option, but this is not validated; passing something like{ shell: false }
(or any other invalid value) is currently silently ignored. This adds explicit validation.Replaces #58525.