FrostebiteandClaude Sonnet 5 ae0171202c fix: resolve "latest" CLI version using the action's own token, not an env var (#852)
* fix: resolve "latest" CLI version using the action's own token, not an env var

`resolveLatestTag()` only checked `process.env.GITHUB_TOKEN`/`GH_TOKEN` for
authenticating the GitHub API call that resolves `cliVersion: latest`. GitHub
Actions does not inject GITHUB_TOKEN into a JS action's process environment
automatically - a calling workflow has to set it explicitly via `env:` - and
essentially no consumer workflow had reason to do that before this action
started making its own API calls. So this was unauthenticated for effectively
every consumer, not just ones under unusual load, and the unauthenticated
limit (60 req/hour, shared across every job on the runner's IP) is easy to
exhaust.

Hit live via game-ci/unity-test-runner#328's consumer, whose six-version test
matrix failed simultaneously with "GitHub API returned 403" - this action
shares the identical resolveLatestTag/downloadCli pattern (copy-pasted, per
the original comments referencing each other) and is exposed to the exact same
gap.

This action had no `githubToken` input at all, unlike unity-test-runner, so
there was no way for a consumer to hand it a token even deliberately. Added
one, defaulting to `${{ github.token }}` - populated by GitHub Actions on
every run with no consumer action needed - and threaded it through
downloadCli -> resolveLatestTag, ahead of the env var fallback (kept for the
CLI/install.sh path, which has no Action input to read from).

2 new tests, confirmed to catch the regression: removing the parameter
threading fails exactly "sends an Authorization header from the githubToken
parameter" and "forwards its githubToken parameter to resolveLatestTag", and
nothing else in the existing 12.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* fix: satisfy yarn format:check on download-cli.ts

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* test: cover the GH_TOKEN fallback branch in resolveLatestTag

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* test: verify explicit githubToken takes precedence over env fallbacks

Addresses a CodeRabbit nitpick on PR #852: the existing tests covered
the GITHUB_TOKEN and GH_TOKEN fallback paths individually but not the
precedence rule itself (githubToken > GITHUB_TOKEN > GH_TOKEN) when
more than one is present at once.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

---------

Co-authored-by: Claude Sonnet 5 <[email protected]>
2026-09-16 16:25:16 +01:00
2022-03-30 23:27:10 +02:00
2023-02-13 23:07:10 -06:00
2020-01-19 01:54:56 +01:00
2020-05-01 17:55:27 +02:00
2023-11-25 19:33:36 +01:00
2019-11-30 19:02:47 +01:00
2023-03-04 15:39:31 -06:00

Unity - Builder

(Not affiliated with Unity Technologies)

GitHub Action to build Unity projects for different platforms.

Part of the GameCI open source project.

Builds - Ubuntu Builds - Windows Builds - MacOS codecov - test coverage

How to use

Find the docs on the GameCI documentation website.

Visit the GameCI Unity Actions status repository for related Actions.

Community

Feel free to join us on Discord and engage with the community.

Contributing

To help improve the documentation, please find the docs repository.

To contribute to Unity Builder, kindly read the contribution guide.

Support us

GameCI is free for everyone forever.

You can support us at OpenCollective.

Licence

This repository is MIT licensed.

This includes all contributions from the community.

S
Description
No description provided
Readme MIT
1.6 GiB
Languages
TypeScript 95.5%
JavaScript 3.6%
Shell 0.9%