Repository navigation
Specific code for "The flag X must be used with extreme caution" #59818
Description
Activity
- addedfeature requestIssues requesting new Node.js features.Issues requesting new Node.js features.
on Sep 9, 2025 For context on my specific situation and why I'd like to be able to suppress this warning:
I am enabling
--permissionon my production build with--allow-fs-read=./*, and I would like to be able to also enable it for local testing so that any issues the policy might introduce are picked up quickly. But when running in watch mode, my build tool Rollup uses a child process, so I need to enable--allow-child-processfor local development only.In this situation, I'm not trying to protect against malicious code, but to catch accidental actions that are blocked by the permission policy, so I'm confident that this specific warning can be silenced. But of course I still want to see any other
SecurityWarnings that might appear.Reacted by ExE Boss, Zoran Ravic, Puls3 and Przemysław ZalewskiThere has been no activity on this feature request for 5 months. To help maintain relevant open issues, please add the never-stale
Issues and PRs exempt from automated stale handling. label or close this issue if it should be closed. If not, the issue will be automatically closed 6 months after the last non-automated comment.
For more information on how the project manages feature requests, please consult the feature request management document.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Mar 9, 2026 This is still relevant. I think the only question here is what the code should be to conform to existing naming conventions. My suggestion of
PERM0001may or may not be appropriate.- removedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Mar 10, 2026 github-actions commented
on Jul 20, 2026 on Jul 20, 2026 – with GitHub ActionsContributorMore actionsThis issue has been marked as stale due to 90 days of inactivity.
It will be automatically closed in 30 days if no further activity occurs. If this is still relevant, please leave a comment or update it to keep it open.- addedstaleIssues and PRs marked stale due to inactivity and scheduled for automatic closure.Issues and PRs marked stale due to inactivity and scheduled for automatic closure.
on Jul 20, 2026 - added a commit that references this issue
on Jul 21, 2026 - added a commit that references this issue
on Aug 2, 2026 - added 2 commits that reference this issue
on Aug 17, 2026 - added a commit that references this issue
on Aug 20, 2026
Metadata
Metadata
Assignees
Labels
Type
Projects
- StatusShow more project fieldsAwaiting Triage
What is the problem this feature will solve?
When using (for example)
--allow-child-process, NodeJS (correctly) warns that this can allow bypassing the--permissionprotection:This warning is good, but if the developer is still confident in their setup, it would be useful to be able to suppress it without suppressing other warnings. Currently the only way to suppress this warning is with
--disable-warning=SecurityWarning, which is far too broad.What is the feature you are proposing to solve the problem?
--disable-warningalready acceptscodes as well as types, but this particular warning has nocodeset:node/lib/internal/process/pre_execution.js
Lines 588 to 590 in 96a749b
I'm suggesting picking a suitable code for this warning and adding it as the third argument to that call, perhaps something like
PERM0001(though I don't know the naming convention for these codes).What alternatives have you considered?
No response