Skip to content

runTest.js triggers Node DEP0190 by passing args with shell: true #362

Description

Environment

  • Windows 11
  • Node.js v26.5.0
  • @vscode/test-electron 2.5.2 (via @vscode/test-cli 0.0.10)

Problem

Every vscode-test run prints a Node deprecation warning before anything else:

(node:5828) [DEP0190] DeprecationWarning: Passing args to a child process with shell option true can lead to security vulnerabilities, as the arguments are not escaped, only concatenated.
(Use `node --trace-deprecation ...` to show where the warning was created)

Cause

out/runTest.js:

async function innerRunTests(executable, args, testRunnerEnv) {
    const fullEnv = Object.assign({}, process.env, testRunnerEnv);
    const shell = process.platform === 'win32';
    const cmd = cp.spawn(shell ? `"${executable}"` : executable, args, { env: fullEnv, shell });

Passing a non-empty args array together with shell: true is exactly the pattern Node deprecates as DEP0190.

Suggestion

Spawn without a shell (resolve the actual .exe / .cmd and pass args directly), or otherwise escape/concatenate the arguments explicitly. On Windows the arguments here include paths that may contain spaces (--extensionDevelopmentPath=..., --user-data-dir=...), so dropping shell: true and quoting is the safer route.

This may also be related to #361: in both cases the spawned CLI process does not behave as expected on Windows when it lives on a different drive than the profile directories.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions