mirror of
https://github.com/denoland/deno.git
synced 2025-01-03 21:08:56 -05:00
5504acea67
This replaces `--allow-net` for import permissions and makes the security sandbox stricter by also checking permissions for statically analyzable imports. By default, this has a value of `--allow-import=deno.land:443,jsr.io:443,esm.sh:443,raw.githubusercontent.com:443,gist.githubusercontent.com:443`, but that can be overridden by providing a different set of hosts. Additionally, when no value is provided, import permissions are inferred from the CLI arguments so the following works because `fresh.deno.dev:443` will be added to the list of allowed imports: ```ts deno run -A -r https://fresh.deno.dev ``` --------- Co-authored-by: David Sherret <dsherret@gmail.com>
52 lines
1.1 KiB
Text
52 lines
1.1 KiB
Text
{
|
|
"tests": {
|
|
"info": {
|
|
"args": "info main.ts",
|
|
"output": "info.out"
|
|
},
|
|
"cache": {
|
|
"args": "cache main.ts",
|
|
"output": "cache.out",
|
|
"exitCode": 1
|
|
},
|
|
"check": {
|
|
"args": "check main.ts",
|
|
"output": "check.out",
|
|
"exitCode": 1
|
|
},
|
|
"compile": {
|
|
"args": "compile main.ts",
|
|
"output": "compile.out",
|
|
"exitCode": 1
|
|
},
|
|
"doc": {
|
|
"args": "doc doc.ts",
|
|
"output": "doc.out",
|
|
"exitCode": 0
|
|
},
|
|
"doc_allowed": {
|
|
"args": "doc --allow-import doc.ts",
|
|
"output": "doc_allowed.out",
|
|
"exitCode": 0
|
|
},
|
|
"run": {
|
|
"args": "run main.ts",
|
|
"output": "run.out",
|
|
"exitCode": 1
|
|
},
|
|
"serve": {
|
|
"args": "serve main.ts",
|
|
"output": "serve.out",
|
|
"exitCode": 1
|
|
},
|
|
"builtin_host": {
|
|
"args": "run --quiet builtin_host.ts",
|
|
"output": "3\n"
|
|
},
|
|
"builtin_host_replaced": {
|
|
"args": "run --quiet --allow-import=other.host builtin_host.ts",
|
|
"output": "[WILDCARD]Requires import access[WILDCARD]",
|
|
"exitCode": 1
|
|
}
|
|
}
|
|
}
|