diff options
| author | Sami Shalayel <sami.shalayel@qt.io> | 2026-06-17 10:55:12 +0200 |
|---|---|---|
| committer | Qt Cherry-pick Bot <cherrypick_bot@qt-project.org> | 2026-07-02 13:46:47 +0000 |
| commit | 80b77796cdc2f9fbe6cbb7e13236d81eef0c6d3c (patch) | |
| tree | c8bcc0c38c5f7e468c82427172e153daf18ad3da | |
| parent | c85642125d449348077b9fe09178ad95a5eb6a01 (diff) | |
doc: add security note for usages of qmllint + qmlformat in CIv6.12.0-beta2
Add notes on how to run qmllint and qmlformat on untrusted code.
Pick-to: 6.11
Fixes: QTBUG-147553
Change-Id: I59fec7d8c2753eb95d68837fa7065b757b47b26b
Reviewed-by: Ulf Hermann <ulf.hermann@qt.io>
(cherry picked from commit b6157d04401970e86f583dbdca32422601734fe3)
Reviewed-by: Qt Cherry-pick Bot <cherrypick_bot@qt-project.org>
| -rw-r--r-- | src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc | 3 | ||||
| -rw-r--r-- | src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc | 3 |
2 files changed, 6 insertions, 0 deletions
diff --git a/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc b/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc index 0b0d75e36e..e5847ab441 100644 --- a/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc +++ b/src/qml/doc/src/tools/qtqml-tooling-qmlformat.qdoc @@ -156,6 +156,9 @@ For boolean options, pass the flag on the command line or set the variable to \endtable \section1 Usage +\e qmlformat is flexible and can be configured according to your needs. \e qmlformat should be +deployed in a sandbox, container, or other safe environment when running on untrusted code, for +example when formatting QML files during testing in a public CI. \section2 Output qmlformat writes the formatted version of the file to stdout. diff --git a/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc b/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc index fb6b281e85..548dae409c 100644 --- a/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc +++ b/src/qml/doc/src/tools/qtqml-tooling-qmllint.qdoc @@ -220,6 +220,9 @@ level. Use the special filename '-' to write to stdout instead of a file. This can be used to more easily integrate qmllint in your pre-commit hooks or CI testing. +\note qmllint should be deployed in a sandbox, container, or other safe environment +when running on untrusted code. + \sa {Type Description Files} \sa {Qt Quick Tools and Utilities} */ |
