graphql-js
4ebcb8d9 - avoid spawn with shell: true and arguments (#4456)

Commit
90 days ago
avoid spawn with shell: true and arguments (#4456) spawn with shell: true and arguments leads to the below deprecation warning [DEP0190] DeprecationWarning: Passing args to a child process with shell option true can lead to security vulnerabilities, as the arguments are not escaped, only concatenated. This does not appear to presently cause us any security concerns as this is used only with safe input from our own integration scripts, but we can avoid the use of the shell entirely and protect from removal of this functionality in a later version, while still preserving win32 compatibility.
Author
Parents
Loading