mirror of
https://github.com/game-ci/unity-builder.git
synced 2026-09-29 12:07:05 -07:00
CodeQL flagged this line (js/command-line-injection, critical) since args ultimately derives from Action inputs, and its static analysis can't see through @actions/exec's internals to confirm safety. Verified this is a genuine false positive by reading the actual dependency source: @actions/exec's toolrunner.js passes args straight to child_process.spawn(fileName, args, options) - node_modules/@actions/exec/lib/toolrunner.js line 413 - never a shell string, never shell-parsed. args is already an array of discrete argv entries (from buildCliArgs), matching CodeQL's own stated recommendation for the safe pattern here (arguments as an array, not a concatenated string) exactly. Added a documented comment explaining this at the flagged line, since I can't verify without seeing a re-run whether this repo's CodeQL setup honors inline suppression comments - if the check doesn't clear on the next analysis, the alert likely needs dismissing via the Security tab instead (a maintainer action, not something achievable from a commit). No functional change - comment only.