Skip to content

Specific code for "The flag X must be used with extreme caution" #59818

Description

@davidje13

What is the problem this feature will solve?

When using (for example) --allow-child-process, NodeJS (correctly) warns that this can allow bypassing the --permission protection:

(node:16778) SecurityWarning: The flag --allow-child-process must be used with extreme caution. It could invalidate the permission model.
(Use node --trace-warnings ... to show where the warning was created)

This warning is good, but if the developer is still confident in their setup, it would be useful to be able to suppress it without suppressing other warnings. Currently the only way to suppress this warning is with --disable-warning=SecurityWarning, which is far too broad.

What is the feature you are proposing to solve the problem?

--disable-warning already accepts codes as well as types, but this particular warning has no code set:

process.emitWarning(
`The flag ${flag} must be used with extreme caution. ` +
'It could invalidate the permission model.', 'SecurityWarning');

I'm suggesting picking a suitable code for this warning and adding it as the third argument to that call, perhaps something like PERM0001 (though I don't know the naming convention for these codes).

What alternatives have you considered?

No response

Activity

  1. davidje13 commented on Sep 9, 2025

    @davidje13
    ContributorAuthor

    For context on my specific situation and why I'd like to be able to suppress this warning:

    I am enabling --permission on my production build with --allow-fs-read=./*, and I would like to be able to also enable it for local testing so that any issues the policy might introduce are picked up quickly. But when running in watch mode, my build tool Rollup uses a child process, so I need to enable --allow-child-process for local development only.

    In this situation, I'm not trying to protect against malicious code, but to catch accidental actions that are blocked by the permission policy, so I'm confident that this specific warning can be silenced. But of course I still want to see any other SecurityWarnings that might appear.

  2. github-actions commented on Mar 9, 2026

    @github-actions
    Contributor

    There has been no activity on this feature request for 5 months. To help maintain relevant open issues, please add the never-stale Issues and PRs exempt from automated stale handling. label or close this issue if it should be closed. If not, the issue will be automatically closed 6 months after the last non-automated comment.
    For more information on how the project manages feature requests, please consult the feature request management document.

  3. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Mar 9, 2026
  4. davidje13 commented on Mar 9, 2026

    @davidje13
    ContributorAuthor

    This is still relevant. I think the only question here is what the code should be to conform to existing naming conventions. My suggestion of PERM0001 may or may not be appropriate.

  5. removed
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Mar 10, 2026
  6. khalidsaidi commented on Mar 25, 2026

    @khalidsaidi
  7. github-actions commented on Jul 20, 2026

    @github-actions
    Contributor

    This issue has been marked as stale due to 90 days of inactivity.
    It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.

  8. added
    staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.
    on Jul 20, 2026
  9. added a commit that references this issue on Jul 21, 2026
  10. added a commit that references this issue on Aug 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature requestIssues requesting new Node.js features.staleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions