Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 6 additions & 1 deletion SECURITY.md
Original file line number Diff line number Diff line change
Expand Up @@ -264,7 +264,12 @@ then untrusted input must not lead to arbitrary JavaScript code execution.

* The developers and infrastructure that run it.
* The operating system that Node.js is running under and its configuration,
along with anything under the control of the operating system.
along with anything under the control of the operating system. An attacker
who can already run commands on the host and uses an official, signed
Node.js binary to execute malicious JavaScript does not exploit a
vulnerability in Node.js. A code signature identifies the publisher of the
Node.js binary; it is not a statement about the trustworthiness of the
scripts that binary executes.
* The deployment network environment for the privacy of traffic and routing
decisions, including internal networks through which Node.js traffic passes
and configured HTTP(S) proxy servers. Built-in proxy support is intended to
Expand Down
Loading