Summary
On Windows with Node 24, the CLI prints (node:NNNN) [DEP0190] DeprecationWarning: Passing args to a child process with shell option true can lead to security vulnerabilities… when it spawns npm (reported in discussion #15315 after omniroute update --apply, and visible earlier in the logs of #14240). It is cosmetic, but it looks alarming on a command whose job is diagnosing the install.
Cause
bin/cli/npm-exec.mjs::npmExecOptions() returns { shell: true, windowsHide: true } on win32 so npm.cmd can be spawned at all (Node ≥ 24 refuses to spawn .cmd without a shell, CVE-2024-27980). bin/cli/commands/update.mjs then calls execFile(npmBin(), ["view", "omniroute", "version", "--prefer-online"], npmExecOptions(...)), i.e. an argv array together with shell: true, which is exactly the combination DEP0190 deprecates. The args are literals, as the file's own comment says (Hard Rule #13), so there's no injection risk, only the warning.
Fix
When shell is true, spawn with a single command string built only from literals (no args array), which doesn't trigger DEP0190. Keep Hard Rule #13: no runtime value may reach that string. If a caller ever needs one, it has to be validated first (bin/cli/utils/winShellArgs.mjs already has the escaping helper for that case).
Acceptance
Refs discussion #15315, #14240
Summary
On Windows with Node 24, the CLI prints
(node:NNNN) [DEP0190] DeprecationWarning: Passing args to a child process with shell option true can lead to security vulnerabilities…when it spawns npm (reported in discussion #15315 afteromniroute update --apply, and visible earlier in the logs of #14240). It is cosmetic, but it looks alarming on a command whose job is diagnosing the install.Cause
bin/cli/npm-exec.mjs::npmExecOptions()returns{ shell: true, windowsHide: true }onwin32sonpm.cmdcan be spawned at all (Node ≥ 24 refuses to spawn.cmdwithout a shell, CVE-2024-27980).bin/cli/commands/update.mjsthen callsexecFile(npmBin(), ["view", "omniroute", "version", "--prefer-online"], npmExecOptions(...)), i.e. an argv array together withshell: true, which is exactly the combination DEP0190 deprecates. The args are literals, as the file's own comment says (Hard Rule #13), so there's no injection risk, only the warning.Fix
When
shellis true, spawn with a single command string built only from literals (no args array), which doesn't trigger DEP0190. Keep Hard Rule #13: no runtime value may reach that string. If a caller ever needs one, it has to be validated first (bin/cli/utils/winShellArgs.mjsalready has the escaping helper for that case).Acceptance
win32asserts that no argv array is passed together withshell: true.omniroute updateand the doctor's version check print no DEP0190.Refs discussion #15315, #14240