aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorSami Shalayel <sami.shalayel@qt.io>2026-06-17 10:55:12 +0200
committerQt Cherry-pick Bot <cherrypick_bot@qt-project.org>2026-07-02 13:46:47 +0000
commit80b77796cdc2f9fbe6cbb7e13236d81eef0c6d3c (patch)
treec8bcc0c38c5f7e468c82427172e153daf18ad3da
parentc85642125d449348077b9fe09178ad95a5eb6a01 (diff)
doc: add security note for usages of qmllint + qmlformat in CIv6.12.0-beta2
Add notes on how to run qmllint and qmlformat on untrusted code. Pick-to: 6.11 Fixes: QTBUG-147553 Change-Id: I59fec7d8c2753eb95d68837fa7065b757b47b26b Reviewed-by: Ulf Hermann <ulf.hermann@qt.io> (cherry picked from commit b6157d04401970e86f583dbdca32422601734fe3) Reviewed-by: Qt Cherry-pick Bot <cherrypick_bot@qt-project.org>
-rw-r--r--src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc3
-rw-r--r--src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc3
2 files changed, 6 insertions, 0 deletions
diff --git a/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc b/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc
index 0b0d75e36e..e5847ab441 100644
--- a/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc
+++ b/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc
@@ -156,6 +156,9 @@ For boolean options, pass the flag on the command line or set the variable to
\endtable
\section1 Usage
+\e qmlformat is flexible and can be configured according to your needs. \e qmlformat should be
+deployed in a sandbox, container, or other safe environment when running on untrusted code, for
+example when formatting QML files during testing in a public CI.
\section2 Output
qmlformat writes the formatted version of the file to stdout.
diff --git a/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc b/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc
index fb6b281e85..548dae409c 100644
--- a/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc
+++ b/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc
@@ -220,6 +220,9 @@ level. Use the special filename '-' to write to stdout instead of a file.
This can be used to more easily integrate qmllint in your pre-commit hooks or
CI testing.
+\note qmllint should be deployed in a sandbox, container, or other safe environment
+when running on untrusted code.
+
\sa {Type Description Files}
\sa {Qt Quick Tools and Utilities}
*/