mirror of
https://github.com/game-ci/unity-builder.git
synced 2026-09-29 12:07:05 -07:00
1ab7c56964988f2e479c08fc90398a67718fd9be
CodeQL flagged the install.sh invocation (js/actions/uncontrolled- command-line) - correctly this time, unlike the pre-existing false positive on src/index.ts:45. resolvedVersion/destDir were passed safely as quoted positional params ($0/$1/$2) rather than concatenated into the command text, so it wasn't exploitable, but building a `bash -c '... "$0" ...'` string at all is exactly the shape that query looks for, and there was a strictly better option available: fetch install.sh's content directly, write it to a file, and run that file with a plain args array - the same shape this file's own callers already use for the CLI binary itself, with no shell-text construction step for the query to flag in the first place. Also fixes a real, environment-dependent test bug found while touching this: the "restores from cache" test's real fs.chmod call throws ENOENT on Linux for a path that doesn't exist on disk, gets swallowed by restoreFromCache's own try/catch, and silently falls through to the real install path - passing locally only because the chmod call is skipped entirely on `win32` (a Windows dev machine), never because the cache-restore logic under test actually worked. fs/promises is now mocked like @actions/cache and @actions/exec already were.
Unity - Builder
(Not affiliated with Unity Technologies)
GitHub Action to build Unity projects for different platforms.
Part of the GameCI open source project.
How to use
Find the docs on the GameCI documentation website.
Related actions
Visit the GameCI Unity Actions status repository for related Actions.
Community
Feel free to join us on
and engage with the community.
Contributing
To help improve the documentation, please find the docs repository.
To contribute to Unity Builder, kindly read the contribution guide.
Support us
GameCI is free for everyone forever.
You can support us at OpenCollective.
Licence
This repository is MIT licensed.
This includes all contributions from the community.
Languages
TypeScript
95.5%
JavaScript
3.6%
Shell
0.9%