Files
unity-builder/action.yml
T
FrostebiteandClaude Sonnet 5 ae0171202c fix: resolve "latest" CLI version using the action's own token, not an env var (#852)
* fix: resolve "latest" CLI version using the action's own token, not an env var

`resolveLatestTag()` only checked `process.env.GITHUB_TOKEN`/`GH_TOKEN` for
authenticating the GitHub API call that resolves `cliVersion: latest`. GitHub
Actions does not inject GITHUB_TOKEN into a JS action's process environment
automatically - a calling workflow has to set it explicitly via `env:` - and
essentially no consumer workflow had reason to do that before this action
started making its own API calls. So this was unauthenticated for effectively
every consumer, not just ones under unusual load, and the unauthenticated
limit (60 req/hour, shared across every job on the runner's IP) is easy to
exhaust.

Hit live via game-ci/unity-test-runner#328's consumer, whose six-version test
matrix failed simultaneously with "GitHub API returned 403" - this action
shares the identical resolveLatestTag/downloadCli pattern (copy-pasted, per
the original comments referencing each other) and is exposed to the exact same
gap.

This action had no `githubToken` input at all, unlike unity-test-runner, so
there was no way for a consumer to hand it a token even deliberately. Added
one, defaulting to `${{ github.token }}` - populated by GitHub Actions on
every run with no consumer action needed - and threaded it through
downloadCli -> resolveLatestTag, ahead of the env var fallback (kept for the
CLI/install.sh path, which has no Action input to read from).

2 new tests, confirmed to catch the regression: removing the parameter
threading fails exactly "sends an Authorization header from the githubToken
parameter" and "forwards its githubToken parameter to resolveLatestTag", and
nothing else in the existing 12.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* fix: satisfy yarn format:check on download-cli.ts

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* test: cover the GH_TOKEN fallback branch in resolveLatestTag

Co-Authored-By: Claude Sonnet 5 <[email protected]>

* test: verify explicit githubToken takes precedence over env fallbacks

Addresses a CodeRabbit nitpick on PR #852: the existing tests covered
the GITHUB_TOKEN and GH_TOKEN fallback paths individually but not the
precedence rule itself (githubToken > GITHUB_TOKEN > GH_TOKEN) when
more than one is present at once.

Co-Authored-By: Claude Sonnet 5 <[email protected]>

---------

Co-authored-by: Claude Sonnet 5 <[email protected]>
2026-09-16 16:25:16 +01:00

263 lines
10 KiB
YAML

name: 'Unity - Builder'
author: Webber Takken <[email protected]>
description: 'Build Unity projects for different platforms.'
inputs:
targetPlatform:
required: true
default: ''
description: 'Platform that the build should target.'
unityVersion:
required: false
default: 'auto'
description:
'Version of unity to use for building the project. Use "auto" to get from your ProjectSettings/ProjectVersion.txt.
A value other than "auto" is currently ignored - the underlying game-ci CLI always detects the version from the
checked-out project and has no override flag yet.'
cliVersion:
required: false
default: 'latest'
description:
'Release tag of the game-ci/cli binary to install and run (e.g. "v0.1.0"). Defaults to the latest release; pin
this for reproducible builds.'
githubToken:
required: false
default: '${{ github.token }}'
description:
'Token used to authenticate the GitHub API call that resolves cliVersion: latest to a concrete release tag.
Defaults to the token GitHub Actions provides for every run automatically - no need to set this unless you
have a reason to override it.'
customImage:
required: false
default: ''
description: 'Specific docker image that should be used for building the project'
projectPath:
required: false
default: ''
description: 'Path to the project to be built, relative to the repository root.'
buildProfile:
required: false
default: ''
description: 'Path to the build profile to activate, relative to the project root.'
buildName:
required: false
default: ''
description: 'Name of the build. Should not include a file extension.'
buildsPath:
required: false
default: ''
description: 'Path where the builds should be stored.'
buildMethod:
required: false
default: ''
description: 'Path to a Namespace.Class.StaticMethod to run to perform the build.'
manualExit:
required: false
default: ''
description: 'Suppresses `-quit`. Exit your build method using `EditorApplication.Exit(0)` instead.'
enableGpu:
required: false
default: ''
description: 'Launches unity without specifying `-nographics`.'
customParameters:
required: false
default: ''
description: 'Custom parameters to configure the build.'
useHostNetwork:
required: false
default: false
description: 'Initialises Docker using the host network. (Linux only)'
versioning:
required: false
default: 'Semantic'
description: 'The versioning scheme to use when building the project'
version:
required: false
default: ''
description: 'The version, when used with the "Custom" versioning scheme'
androidVersionCode:
required: false
default: ''
description: 'The android versionCode'
androidExportType:
required: false
default: 'androidPackage'
description:
'The android export type. Should be androidPackage for apk, androidAppBundle for aab, or androidStudioProject for
an android studio project.'
androidKeystoreName:
required: false
default: ''
description: 'The android keystoreName'
androidKeystoreBase64:
required: false
default: ''
description: 'The base64 contents of the android keystore file'
androidKeystorePass:
required: false
default: ''
description: 'The android keystorePass'
androidKeyaliasName:
required: false
default: ''
description: 'The android keyaliasName'
androidKeyaliasPass:
required: false
default: ''
description: 'The android keyaliasPass'
androidTargetSdkVersion:
required: false
default: ''
description: 'The android target API level.'
androidSymbolType:
required: false
default: 'none'
description: 'The android symbol type to export. Should be "none", "public" or "debugging".'
sshAgent:
required: false
default: ''
description: 'SSH Agent path to forward to the container'
sshPublicKeysDirectoryPath:
required: false
default: ''
description: 'Path to a directory containing SSH public keys to forward to the container.'
gitPrivateToken:
required: false
default: ''
description: 'Github private token to pull from github'
providerStrategy:
default: 'local'
required: false
description:
'Build execution strategy. Use "local" (the default) for Docker/Mac builds driven by this action itself, or
"local-system" to build natively on the host with no Docker at all (game-ci/orchestrator''s own local-system
provider, invoked via `game-ci orchestrate`) - useful for self-hosted runners that already have Unity installed.
For remote builds (aws, k8s, etc.), install @game-ci/orchestrator and use the game-ci/orchestrator action which
declares its own inputs.'
runAsHostUser:
required: false
default: 'false'
description:
'Whether to run as a user that matches the host system or the default root container user. Only applicable to
Linux hosts and containers. This is useful for fixing permission errors on Self-Hosted runners.'
chownFilesTo:
required: false
default: ''
description: 'User and optionally group (user or user:group or uid:gid) to give ownership of the resulting build artifacts'
dockerCpuLimit:
required: false
default: ''
description: 'Number of CPU cores to assign the docker container. Defaults to all available cores on all platforms.'
dockerMemoryLimit:
required: false
default: ''
description:
'Amount of memory to assign the docker container. Defaults to 95% of total system memory rounded down to the
nearest megabyte on Linux and 80% on Windows. On unrecognized platforms, defaults to 75% of total system memory.
To manually specify a value, use the format <number><unit>, where unit is either m or g. ie: 512m = 512 megabytes'
dockerIsolationMode:
required: false
default: 'default'
description:
'Isolation mode to use for the docker container. Can be one of process, hyperv, or default. Default will pick the
default mode as described by Microsoft where server versions use process and desktop versions use hyperv. Only
applicable on Windows'
containerRegistryRepository:
required: false
default: 'unityci/editor'
description: 'Container registry and repository to pull image from. Only applicable if customImage is not set.'
containerRegistryImageVersion:
required: false
default: '3'
description: 'Container registry image version. Only applicable if customImage is not set.'
allowDirtyBuild:
required: false
default: ''
description: 'Allows the branch of the build to be dirty, and still generate the build.'
cacheUnityInstallationOnMac:
default: 'false'
required: false
description: 'Whether to cache the Unity hub and editor installation on MacOS'
unityHubVersionOnMac:
default: ''
required: false
description:
'The version of Unity Hub to install on MacOS (e.g. 3.4.0). Defaults to latest available on brew if empty string
or nothing is specified.'
unityLicensingServer:
default: ''
required: false
description: 'The Unity licensing server address to use for activating Unity.'
dockerWorkspacePath:
default: '/github/workspace'
required: false
description:
'The path to mount the workspace inside the docker container. For windows, leave out the drive letter. For example
c:/github/workspace should be defined as /github/workspace'
skipActivation:
default: 'false'
required: false
description:
'Skip the activation/deactivation of Unity. This assumes Unity is already activated. Also honoured by
providerStrategy=local-system, for self-hosted runners with an already-licensed, long-lived Unity Hub session.'
linux64RemoveExecutableExtension:
default: 'false'
required: false
description: 'When building for StandaloneLinux64, remove the default file extension of `.x86_64`. Set to true to restore the extensionless behavior from v4.'
engineLaunchWrapper:
default: ''
required: false
description:
"Only applicable to providerStrategy=local-system. Command to prefix the Unity engine process invocation with
(e.g. a self-hosted runner's own launch-serialization lock). Applied precisely around the engine launch itself,
not the surrounding build step. Empty by default."
enableBuildRetry:
default: 'false'
required: false
description:
'Only applicable to providerStrategy=local-system. Enable automatic classify/decide/retry recovery for failed
Unity builds (budget-gated). Default off: a single failed attempt still throws exactly as before - retry can
back up or wipe the Library folder as a recovery action, which is a meaningful behavior change to opt into.'
localCacheEnabled:
default: 'false'
required: false
description:
'Only applicable to providerStrategy=local-system. Enable local filesystem caching of the Unity Library folder
and/or .git/lfs between builds on the same self-hosted runner. Off by default.'
localCacheLibrary:
default: 'true'
required: false
description:
'Only applicable to providerStrategy=local-system, and only takes effect when localCacheEnabled=true. Cache the
engine Library folder locally.'
localCacheLfs:
default: 'false'
required: false
description:
'Only applicable to providerStrategy=local-system, and only takes effect when localCacheEnabled=true. Cache
.git/lfs locally.'
localCacheMode:
default: 'tar'
required: false
description:
'Only applicable to providerStrategy=local-system, and only takes effect when localCacheEnabled=true. Local
cache save/restore mode: "tar", "move-directory", or "copy-directory".'
outputs:
volume:
description: 'The Persistent Volume (PV) where the build artifacts have been stored by Kubernetes'
buildVersion:
description: 'The generated version used for the Unity build'
androidVersionCode:
description: 'The generated versionCode used for the Android Unity build'
engineExitCode:
description:
'Returns the exit code from the build scripts. This code is 0 if the build was successful. If there was an error
during activation, the code is from the activation step. If activation is successful, the code is from the project
build step.'
branding:
icon: 'box'
color: 'gray-dark'
runs:
using: 'node24'
main: 'dist/index.js'