Skip to content

Commit dc06784

Browse files
committed
Updated tsc Security Properties (markdown)
1 parent 713d542 commit dc06784

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎tsc-Security-Properties.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,7 +16,7 @@ The TypeScript compiler (`tsc`) is a **build tool**, not a sandbox. It transform
1616

1717
**Arbitrary file writes.** `tsc` writes compiler output to paths derived from its configuration (`outDir`, `outFile`, `declarationDir`, etc.) and the structure of the input project. A malicious `tsconfig.json` can direct output to any path writable by the calling user. This is by design: writing files to disk *is the point* of a compiler. Callers who need to constrain output locations must do so externally (e.g., filesystem permissions, containers, sandboxing). Similarly, running `tsc --build --clean` may delete files from disk; crafted `.tsbuildinfo` or `tsconfig.json`s may cause any file to be deleted.
1818

19-
**File read sandboxing.** `tsc` will read files from paths specified in input files, and transitive references from there, including import paths and reference directives. An attacker in control of these files may therefore cause a *read* of any file path the `tsc` process has privilege to run, and `tsc` may reprint file contents in its output messages. In other words, for example, it is not safe to run `tsc` on untrusted code and print back the error message contents to an untrusted party, as this could expose local filesystem contents to the attacker. Use of standard sandboxing strategies is recommended to secure scenarios similar to this.
19+
**File read sandboxing.** `tsc` will read files from paths specified in input files, and transitive references from there, including import paths and reference directives. An attacker in control of these files may therefore cause a *read* of any file path the `tsc` process has privileges to read, and `tsc` may reprint certain file contents in its output messages. In other words, for example, it is not generally safe to run `tsc` on untrusted code and print back the error message contents to an untrusted party, as this could expose local filesystem contents to the attacker. Use of standard sandboxing strategies is recommended to secure scenarios similar to this.
2020

2121
**Resource consumption.** TypeScript's type system is Turing-complete. A crafted input file can cause `tsc` to consume unbounded CPU time or memory during type-checking. The compiler provides no built-in timeouts or memory limits. Callers operating on untrusted input should enforce resource limits externally (e.g., `ulimit`, cgroups, process timeouts). You should not assume that an adverserially-constructed program will successfully typecheck in any bounded amount of time.
2222

0 commit comments

Comments
 (0)