Deno Development
Version Requirements
- Always use Deno 2
Testing
- Use
deno test -Pfor running tests with permissions granted - The
-Pflag allows permissions described indeno.jsonduring testing. - Define test permissions in the
testsection ofdeno.json.
Package Management
- Use JSR (JavaScript Registry) for package dependencies https://jsr.io/
- JSR is the modern package registry for JavaScript and TypeScript
Common Commands
Adding Dependencies
# Add from JSR
deno add jsr:@std/log
deno add jsr:@std/path
# Add from npm (when necessary)
deno add npm:express
Running Tests
# Run all tests with permissions
deno test -P
# Run specific test file
deno test -P test/example.test.ts
Running Applications
# Run with limited permissions - AVOID -A unless absolutely necessary
deno run --allow-read=. main.ts
deno run --allow-net --allow-read=./public server.ts
deno run --allow-env --allow-read=. config.ts
# for `export default { fetch }`
deno serve serve.ts
# Use permission sets from deno.json
deno run -P main.ts
Configuration with deno.json
Permission Sets
Define permission sets in deno.json for consistent security:
{
"permissions": {
"default": {
"read": ["."],
"env": {
"allow": ["NODE_ENV", "PORT"],
"deny": ["SECRET_KEY"],
"ignore": ["TEMP_*"]
}
},
"server": {
"read": ["./public"],
"net": ["localhost:8000", "deno.land"],
"env": {
"allow": ["DATABASE_URL", "API_KEY"]
}
}
}
}
Test Permissions
Configure test permissions in deno.json:
{
"test": {
"permissions": {
"read": ["."],
"net": true
}
}
}
Best Practices
- NEVER use
-A(all permissions) unless absolutely necessary - Always use the most restrictive permissions possible
- Use
--allow-read=.instead of--allow-readto limit to current directory - Use permission sets in deno.json for consistent security
- Define test permissions in deno.json under the
testsection - Use
env.allow,env.deny, andenv.ignorefor fine-grained environment variable control (read.ignorealso available) - Do not use
importstatements with full URLs for external dependencies. Instead, usedeno addfirst. - Leverage Deno's built-in security features
- Use JSR for package discovery and management