Skip to content

Conversation

@mcollina
Copy link
Member

Add a new section to the security model clarifying that experimental features behind compile-time flags are not covered by the vulnerability reporting policy. These features are intended for development only and are not enabled in official releases.

@nodejs-github-bot
Copy link
Collaborator

Review requested:

  • @nodejs/tsc

@mcollina
Copy link
Member Author

@nodejs/tsc

@nodejs-github-bot nodejs-github-bot added the doc Issues and PRs related to the documentations. label Dec 18, 2025
Copy link
Contributor

@aduh95 aduh95 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Would it be worth it to explicitely state whether e.g. --without-sqlite qualifies?

Add a new section to the security model clarifying that experimental
features behind compile-time flags are not covered by the vulnerability
reporting policy. These features are intended for development only and
are not enabled in official releases.
@mcollina mcollina force-pushed the doc/security-compile-time-flags branch from 6c0fc80 to 7267b0c Compare December 18, 2025 11:40
@lpinca lpinca added the commit-queue Add this label to land a pull request using GitHub Actions. label Dec 19, 2025
@mcollina
Copy link
Member Author

mcollina commented Dec 19, 2025

Would it be worth it to explicitely state whether e.g. --without-sqlite qualifies?

Can you send a patch?

@nodejs-github-bot nodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label Dec 20, 2025
@nodejs-github-bot nodejs-github-bot merged commit 0a54180 into nodejs:main Dec 20, 2025
19 checks passed
@nodejs-github-bot
Copy link
Collaborator

Landed in 0a54180

@mcollina mcollina deleted the doc/security-compile-time-flags branch December 22, 2025 09:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

doc Issues and PRs related to the documentations.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants