mirror of
https://github.com/game-ci/unity-builder.git
synced 2026-09-29 12:07:05 -07:00
b3b4352c8079d236d62587a882a12d35ca8dcd50
CodeQL flagged this line (js/command-line-injection, critical) since args ultimately derives from Action inputs, and its static analysis can't see through @actions/exec's internals to confirm safety. Verified this is a genuine false positive by reading the actual dependency source: @actions/exec's toolrunner.js passes args straight to child_process.spawn(fileName, args, options) - node_modules/@actions/exec/lib/toolrunner.js line 413 - never a shell string, never shell-parsed. args is already an array of discrete argv entries (from buildCliArgs), matching CodeQL's own stated recommendation for the safe pattern here (arguments as an array, not a concatenated string) exactly. Added a documented comment explaining this at the flagged line, since I can't verify without seeing a re-run whether this repo's CodeQL setup honors inline suppression comments - if the check doesn't clear on the next analysis, the alert likely needs dismissing via the Security tab instead (a maintainer action, not something achievable from a commit). No functional change - comment only.
Unity - Builder
(Not affiliated with Unity Technologies)
GitHub Action to build Unity projects for different platforms.
Part of the GameCI open source project.
How to use
Find the docs on the GameCI documentation website.
Related actions
Visit the GameCI Unity Actions status repository for related Actions.
Community
Feel free to join us on
and engage with the community.
Contributing
To help improve the documentation, please find the docs repository.
To contribute to Unity Builder, kindly read the contribution guide.
Support us
GameCI is free for everyone forever.
You can support us at OpenCollective.
Licence
This repository is MIT licensed.
This includes all contributions from the community.
Languages
TypeScript
95.5%
JavaScript
3.6%
Shell
0.9%