Summary
On Windows with modern Node.js (18.20.2+/20.12.2+/22/24), the postdeploy azd hook fails immediately with spawnSync az.cmd EINVAL. The run() helper in scripts/azd/postdeploy.mjs calls spawnSync("az.cmd", …) without shell: true, which Node now refuses for .cmd/.bat files as part of the CVE-2024-27980 fix. The web deploy succeeds; only the post-deploy migration/seed step fails.
Error
ERROR: failed running post hooks: 'postdeploy' hook failed with exit code: '1',
Path: '...\scripts\azd\postdeploy.mjs'.
stdout: Starting migrations job dpp-<env>-migrations; synthetic demo seeding is true.
stderr:
Error: Unable to run az.cmd: spawnSync az.cmd EINVAL
at run (.../scripts/azd/postdeploy.mjs:17:11)
Node.js v24.13.0
Root cause
scripts/azd/postdeploy.mjs run():
const result = spawnSync(executable, args, {
cwd: projectRoot,
encoding: "utf8",
stdio: ["ignore", "pipe", "pipe"],
});
azExecutable is az.cmd on Windows. Since Node's security fix (CVE-2024-27980), spawning a .cmd requires shell: true, otherwise it throws EINVAL. azd.exe is unaffected because it's a real .exe.
Proposed fix
Enable a shell when spawning on Windows:
const result = spawnSync(executable, args, {
cwd: projectRoot,
encoding: "utf8",
stdio: ["ignore", "pipe", "pipe"],
shell: process.platform === "win32",
});
The same guard should be applied to any other hook that shells out to az.cmd (e.g. preprovision.mjs).
Workaround
Run the migration/seed job manually after the failed hook (deploy itself succeeded):
az containerapp job start --name dpp-<env>-migrations --resource-group rg-dpp-<env>
Or use a Node LTS < 18.20.2 / 20.12.2.
Steps to reproduce
- On Windows with Node ≥ v22/v24, run
azd deploy web (or azd up).
- Web deploys successfully; the
postdeploy hook throws spawnSync az.cmd EINVAL.
Environment
- Windows, Node.js v24.13.0, azd, Azure CLI (
az.cmd on PATH)
Impact
azd up / azd deploy cannot complete cleanly on Windows with current Node LTS — the migration/seed step always fails, blocking a one-shot deployment for most Windows users.
Related
Same governed/Windows deployment path as #33 (unquoted buildArgs) and #34 (ACR network default-action).
Summary
On Windows with modern Node.js (18.20.2+/20.12.2+/22/24), the
postdeployazd hook fails immediately withspawnSync az.cmd EINVAL. Therun()helper inscripts/azd/postdeploy.mjscallsspawnSync("az.cmd", …)withoutshell: true, which Node now refuses for.cmd/.batfiles as part of the CVE-2024-27980 fix. Thewebdeploy succeeds; only the post-deploy migration/seed step fails.Error
Root cause
scripts/azd/postdeploy.mjsrun():azExecutableisaz.cmdon Windows. Since Node's security fix (CVE-2024-27980), spawning a.cmdrequiresshell: true, otherwise it throwsEINVAL.azd.exeis unaffected because it's a real.exe.Proposed fix
Enable a shell when spawning on Windows:
The same guard should be applied to any other hook that shells out to
az.cmd(e.g.preprovision.mjs).Workaround
Run the migration/seed job manually after the failed hook (deploy itself succeeded):
Or use a Node LTS < 18.20.2 / 20.12.2.
Steps to reproduce
azd deploy web(orazd up).postdeployhook throwsspawnSync az.cmd EINVAL.Environment
az.cmdon PATH)Impact
azd up/azd deploycannot complete cleanly on Windows with current Node LTS — the migration/seed step always fails, blocking a one-shot deployment for most Windows users.Related
Same governed/Windows deployment path as #33 (unquoted
buildArgs) and #34 (ACR network default-action).