Browse Source

doc: add note that vm module is not a security mechanism

the text added in this commit should warn users about
wrong idea that vm module can be secure to run unsafe scripts
in sandboxes

PR-URL: https://github.com/nodejs/node/pull/11557
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Evan Lucas <evanlucas@me.com>
Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
Reviewed-By: Ben Noordhuis <info@bnoordhuis.nl>
v6
Ruslan Bekenev 8 years ago
committed by James M Snell
parent
commit
2e74b0da8f
  1. 3
      doc/api/vm.md

3
doc/api/vm.md

@ -14,6 +14,9 @@ const vm = require('vm');
JavaScript code can be compiled and run immediately or compiled, saved, and run JavaScript code can be compiled and run immediately or compiled, saved, and run
later. later.
*Note*: The vm module is not a security mechanism.
**Do not use it to run untrusted code**.
## Class: vm.Script ## Class: vm.Script
<!-- YAML <!-- YAML
added: v0.3.1 added: v0.3.1

Loading…
Cancel
Save