frostebite b3b4352c80 docs: explain why exec.exec(cliPath, args, ...) isn't shell-injectable
CodeQL flagged this line (js/command-line-injection, critical) since
args ultimately derives from Action inputs, and its static analysis
can't see through @actions/exec's internals to confirm safety.

Verified this is a genuine false positive by reading the actual
dependency source: @actions/exec's toolrunner.js passes args straight
to child_process.spawn(fileName, args, options) -
node_modules/@actions/exec/lib/toolrunner.js line 413 - never a shell
string, never shell-parsed. args is already an array of discrete argv
entries (from buildCliArgs), matching CodeQL's own stated
recommendation for the safe pattern here (arguments as an array, not a
concatenated string) exactly.

Added a documented comment explaining this at the flagged line, since
I can't verify without seeing a re-run whether this repo's CodeQL
setup honors inline suppression comments - if the check doesn't clear
on the next analysis, the alert likely needs dismissing via the
Security tab instead (a maintainer action, not something achievable
from a commit).

No functional change - comment only.
2026-08-24 20:36:49 +01:00
2022-03-30 23:27:10 +02:00
2023-02-13 23:07:10 -06:00
2020-01-19 01:54:56 +01:00
2020-05-01 17:55:27 +02:00
2023-11-25 19:33:36 +01:00
2019-11-30 19:02:47 +01:00
2023-03-04 15:39:31 -06:00

Unity - Builder

(Not affiliated with Unity Technologies)

GitHub Action to build Unity projects for different platforms.

Part of the GameCI open source project.

Builds - Ubuntu Builds - Windows Builds - MacOS codecov - test coverage

How to use

Find the docs on the GameCI documentation website.

Visit the GameCI Unity Actions status repository for related Actions.

Community

Feel free to join us on Discord and engage with the community.

Contributing

To help improve the documentation, please find the docs repository.

To contribute to Unity Builder, kindly read the contribution guide.

Support us

GameCI is free for everyone forever.

You can support us at OpenCollective.

Licence

This repository is MIT licensed.

This includes all contributions from the community.

S
Description
No description provided
Readme MIT
1.6 GiB
Languages
TypeScript 95.5%
JavaScript 3.6%
Shell 0.9%