fix: write buildVersion/androidVersionCode to $GITHUB_OUTPUT - #301
Conversation
… them core.setOutput logged `(mock) Output "<key>" is set to "<value>"` and returned; it never wrote the file a runner hands the step. The shim has behaved that way since the first CLI commit, which was harmless while the CLI *was* the action. It stopped being harmless when unity-builder became a subprocess wrapper (#844, first shipped in v6.0.0): the action runs the CLI as a child and relies on it to publish buildVersion/androidVersionCode, since $GITHUB_OUTPUT is inherited. Nothing published them, so both outputs arrived empty on every Unity build. Mirror the real @actions/core split - append to $GITHUB_OUTPUT when it is set, and keep the printed line only as the standalone fallback. The delimiter form is load-bearing: the value is a user-supplied version string, and `key=value` cannot carry a newline. Refs game-ci/unity-builder#854 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthrough
ChangesAction output writing
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix Merge Risk: ⚪ Minimal · up to This change makes buildVersion and androidVersionCode outputs reach the runner output file. No actionable merge risk was found. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Fixed output names and randomly delimited records limit the risks from user-supplied version strings. No introduced exploit was demonstrated, but downstream consumption, interrupted writes, and release compatibility remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches📝 Generate docstrings
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Changes
core.setOutputwrites a real record to$GITHUB_OUTPUTinstead of only printing(mock) Output "<key>" is set to "<value>". It has printed-and-returned since the first CLI commit, which was harmless while the CLI was the action.buildVersion/androidVersionCode, on the reasoning that$GITHUB_OUTPUTis inherited by the child. Nothing ever published them, so both outputs came out empty on every Unity build going through the CLI.cliVersiondefaults tolatest.The implementation mirrors the real
@actions/core: append to$GITHUB_OUTPUTwhen it is set, and keep the printed line only as the standalone fallback when there is no runner. The delimiter form is load-bearing rather than cosmetic -key=valuecannot carry a newline, and the value is a user-supplied version string.Checklist
Notes for reviewers
src/module/actions/core.test.ts(new) covers the record shape, a value containing newlines, append-not-overwrite across several outputs, and the printed fallback with no$GITHUB_OUTPUT.src/model/output.test.tsgains an end-to-end case assertingOutput.setBuildVersion/setAndroidVersionCodeland in the file.dist/index.jsis deliberately untouched. It is already stale onmain- last regenerated 2026-08-14 (Monorepo step 1: orchestrator + unity-engine-core in-repo, path-scoped review and CI #78), roughly 15src/commits ago - and nothing reads it:package.jsonpoints bothmainandbinatsrc/index.ts.bun run buildcannot regenerate it on a fresh checkout for an unrelated reason:plugins/steam-workshopmaps non-Bun conditions to./dist/index.js, and plugindist/is not checked in. Happy to fold a regenerated bundle in here if you'd rather.🤖 Generated with Claude Code
Summary by CodeRabbit