71 documented changes.

Version
1.0.0-beta.13
Released
Oct 7, 2026
Product
Unity CLI
Unity CLI release notes

Unity CLI 1.0.0-beta.13

Official notes

Security

  1. Security

    `unity install` with `--changeset` , and `unity editors add` and `unity editor module refresh` when they read an Editor's build from the download server, now refuse a changeset that is not letters and digits, and a manifest file name from the server that is not a plain file name. Both went into the download address unchecked, so a value with `/` , `?` or `..` could point the request somewhere else.

  2. Security

    Setting `UNITY_PEER_AUTH_MODE=identify-only` no longer weakens your real sign-in: a broker started that way runs as a separate dev broker with its own address and its own sign-in, never reads yours, and on macOS and Windows refuses Unity-signed applications. Use it only for apps you build yourself, and sign in from the app that uses it, since `unity auth login` signs in your normal sign-in.

    • Windows
    • macOS
  3. Security

    The CLI now checks that the sign-in service it talks to is genuine Unity software and that it checks the apps that connect to it. If the check fails, commands that need your sign-in stop with an error, and `unity build` , `unity run` , `unity test` and `unity open` start the Editor signed out with a warning; run with `UNITY_NO_AUTH_BROKER=1` to read your saved sign-in directly.

  4. Security

    When `unity projects create` , `unity projects link vcs` or `unity vcs setup` looks up your GitLab groups for `--git-namespace` , it now follows further pages of results only on GitLab itself, so your token isn't sent to another host. The lookup also stops after 100 pages of groups.

  5. Security

    When `unity auth login` sends your service account credentials or finishes a browser sign-in and the server redirects the request to another host, the CLI no longer follows the redirect. It stops and reports the request as failed, so your credentials and the sign-in request body are not sent on to that host.

  6. Security

    `unity build` , `unity run` and `unity test` no longer print your Unity access token. The Editor writes its full command line into its log, including the `-accessToken` value the CLI passes it, and the CLI streamed that log to your terminal or CI output.

  7. Security

    On Linux, verifying a connecting peer's identity (for the auth broker's enforced peer-allowlist mode, and for the hardened tier's consent cache) now confirms the peer process is still alive before trusting what was read about it. On a shared Linux host, a narrow race let another local process grab a just-exited peer's process id before the identity check finished reading it, which could make that unrelated process pass the check instead of the one that actually connected.

    • Linux
  8. Security

    When `unity projects clone` , `unity projects create` , `unity projects link vcs` or `unity vcs setup` calls GitLab with your token and GitLab redirects the request to another host, the CLI no longer sends the token on to that host.

  9. Security

    A repository URL whose password contains `@` no longer shows part of that password. When `unity projects clone` , `unity projects link vcs` , `unity vcs setup` or a git error printed such a URL, it removed only the text up to the first `@` , so the rest of the password stayed visible.

  10. Security

    Before an install, `unity install` and `unity install-modules` check whether they can write to the destination folder by creating and removing a test file there. That file now has an unpredictable name and is never created through a link someone else placed in the folder, and a file that was already there is left alone.

  11. Security

    A quoted credential value in the Editor's log is now masked in full. A line such as `-password "two words"` used to show as `-password "*** words"` , printing everything after the first space.

  12. Security

    On Linux, the auth broker's check for a debugger or tracer attached to a connecting process can no longer be misled by that process's name.

    • Linux

Added

  1. Feature

    `unity mcp` now reads `UNITY_PROJECT_PATH` when you don't pass `--project-path` , the way `unity command` , `list` , `job` and `status` already do. Set it once per worktree or agent session and the MCP server talks to that project's Editor, not whichever Editor the client's working directory happens to sit in.

  2. Feature

    `unity setup codex` and `unity setup grok` install Unity's agent plugin, with its Unity skills, into Codex and Grok Build in one step, the way `unity setup claude` does for Claude Code. Each runs the agent's own plugin commands for you and reports the plugin's version and where its skills are.

Changed

  1. Change

    On a Mac with Apple silicon running macOS 28 or later, `unity releases` no longer lists Intel (x86_64) Editor builds, which can't run without Rosetta 2. Earlier macOS versions still list both, as `unity install` and `unity editors upgrade` already did.

    • macOS
  2. Change

    `unity projects upgrade` into Unity 6.7 or later now needs a Unity Cloud choice when the project isn't linked: `--cloud` links it to a new Unity Cloud project, `--cloud-project ` links an existing one, and `--no-cloud` upgrades without linking. Without one, the upgrade stops before it installs or opens anything.

  3. Change

    `unity open` and `unity projects open` no longer move a project onto Unity 6.7 or later. If the Editor you pick, with `--editor-version` , with `--editor-path` or at the missing-Editor prompt, is 6.7 or later and the project was saved with an older version, the command stops with `PROJECT_UPGRADE_REQUIRED` before installing or launching anything.

Fixed

  1. Fix

    `unity config set proxyRequestLogging true` now works. The setting was already read by `--log-proxy` 's persisted tier, but `unity config` had no way to actually set it, so `config set proxyRequestLogging true` failed with an unknown-key error.

  2. Fix

    `unity serve` 's session no longer exits with an error when the host writes a line that parses as JSON but isn't a request object (an array, a bare number, `null` , or a `method` that isn't a string). That line is now dropped silently instead of crashing the whole session.

  3. Fix

    `unity serve` now answers a request line that contains an escaped unpaired surrogate, such as `\uD800` , with a parse error. Before, such a line could go unanswered, or end the whole session with an error.

  4. Fix

    On Windows, a console Ctrl-C during a `unity license` command that had just started the Unity Licensing Client no longer also stops the client. The client is a user-level service that is supposed to outlive the CLI; it now leads its own process group, so it is excluded from the console's Ctrl-C delivery, matching the behavior already in place on macOS and Linux.

    • Windows
    • macOS
    • Linux
  5. Fix

    `unity projects create` and `unity pipeline install` now show two messages in your language instead of English: the one saying the Unity registry lists no published version of the Pipeline package, and the one saying Unity Cloud returned no project when a cloud project was created.

  6. Fix

    `unity status` now tells you when a dialog open in the Unity Editor is blocking it, such as a save prompt. The Editor still reads `starting` , with a line naming the dialog, and the error is `STATUS_BLOCKED_BY_DIALOG` instead of `STATUS_NOT_READY` ; `--format json` adds a `blockedBy` field with the dialog's level and title.

  7. Fix

    A project whose build settings file in `Library/` is malformed in a deeply nested way no longer crashes the `unity projects` commands that read it. The file is treated like any other unreadable build settings file: the project keeps the build target it last had, or shows none if it never had one.

  8. Fix

    On macOS, `unity templates create` no longer adds hidden `._*` entries to the template archive for files that carry extended attributes, such as downloaded or Finder-tagged files. Archives created on macOS now match the ones created on Windows and Linux.

    • Windows
    • macOS
    • Linux
  9. Fix

    `unity templates` commands and `unity projects create --template` no longer hang when a named pipe or a device sits where a template file is expected, such as a template archive, a `package.json` in your templates folder or `--output` for `unity templates pack` . Such a file is now treated as unreadable, and `unity templates pack --output --overwrite` fails with "Operation not permitted".

  10. Fix

    When the CLI can't save your sign-in because it can't write to its credential folder, the warning it records in `cli-log.json` is now filed under `SealedCredentialStore` rather than `AuthBroker` , and a folder the CLI isn't allowed to write to is named `UnauthorizedAccessException` rather than `IOException` . Only the log line changes; signing in behaves as before.

  11. Fix

    `unity mcp` screenshots ( `capture_game_view` and `capture_scene_view` ) no longer try to close a display library that failed to load. On a machine where the display library can't be loaded, such as Linux without `libX11` , the capture now just reports that it couldn't load it.

    • Linux
  12. Fix

    `unity command run_tests --async_tests true` no longer shows a misleading "0/0 passed" in TSV and other table output the instant an async PlayMode or EditMode run starts. It now shows the server's own message telling you to poll `test_status` for the real result.

  13. Fix

    When `unity projects link vcs` refuses a URL combined with repository or cloud options, the error now names `--coppa` too. In languages other than English it also names `--git-description` , which the translated message left out.

  14. Fix

    On Windows, the CLI now installs the licensing client from Git Bash too. With Git for Windows on `PATH` , `unity license` and the other commands that download the licensing client failed with `tar: Cannot connect to C: resolve failed` and left it uninstalled.

    • Windows
  15. Fix

    `unity cloud org create` works again: it failed with a 404 for every request. It now asks for the same company profile as the Unity Dashboard, which replaced the industry field: pass `--first-name` and `--last-name` for an individual or `--company-name` for a company, plus `--country` , and `--region` for organizations in the US, Canada, and Mexico.

  16. Fix

    `unity auth logout` now accepts `-y` and `--yes` , which its help has always listed. Signing out never asks for confirmation, so the flag changes nothing; it no longer fails as an unknown option.

  17. Fix

    When `unity install` or `unity install-modules` fails with `--format json` , the output now lists which modules failed and why in `data.failedUids` and `data.failures` , as `--format ndjson` already did. Before, `data` was `null` and the only error said how many items failed.

  18. Fix

    The warning you get when only one of `UNITY_SERVICE_ACCOUNT_ID` and `UNITY_SERVICE_ACCOUNT_SECRET` is set now appears in your CLI language. It used to print in English in every language, saying that service-account sign-in won't activate and which variable to set or unset.

  19. Fix

    `unity editors module remove` now shows its refusals in your display language. They used to print in English whatever language you had chosen.

  20. Fix

    A corrupt template archive whose header claims gigabytes of data no longer crashes `unity templates list` and the other commands that read your templates, or makes them set that much memory aside first. The archive is skipped like any other unreadable one.

  21. Fix

    `unity editors module` (also `unity editor module` ) now says what to pass when several installed Editors match your version: the full version when they are different patches, or `--architecture` when one version is installed for several architectures. It used to say "No editor found", including when `--architecture` still left several patches.

  22. Fix

    `unity editors module` now honors `-a` and `--architecture` , as `unity editor module` does. It used to ignore the value, so a version installed for several architectures could not be chosen there.

  23. Fix

    `unity editors install-path --set` now says another program is using the setting, and that the install path was not changed, when a leftover lock from an earlier run could not be cleared. It used to say the lock file could not be created and send you to check folder permissions.

  24. Fix

    `unity install-modules --non-interactive` now tells you what to pass when several installed Editors match your `--editor-version` : the full version when they are different patches, or `--architecture` when one version is installed for several architectures. A version that exactly matches an installed Editor now wins over a longer one that contains it, such as `6000.3.0a1` beside `6000.3.0a12` .

  25. Fix

    `unity uninstall` , `unity editors verify` and `unity editors path` now pick the installed Editor whose version exactly matches the version you pass, so `6000.3.0a1` selects that Editor instead of being ambiguous with `6000.3.0a12` . A partial version still matches every installed Editor that contains it, and `--architecture` now picks only among the exact version's installs, so it no longer swaps in `6000.3.0a12` .

  26. Fix

    `unity open` and `unity projects open` now say what to pass, in your display language, when they install an Editor for you and then find several installed Editors that match. That is the full version when they are different patches, or `--architecture` when one version is installed for several architectures.

  27. Fix

    In every language except English, `unity self-update` on Windows no longer tells you to close other running `unity` processes after it stages an update or a rollback. A failed binary replacement in `unity self-install` now suggests checking for software that holds the file open, such as antivirus.

    • Windows
  28. Fix

    On Windows, the cross-process install lock of an install that has exited no longer holds up `unity install` , `unity install-modules` or `unity projects require` while another program still has that process open. Once the lock goes stale, the CLI takes it over instead of waiting, or instead of exiting `9` with `INSTALL_LOCK_BUSY` under `--no-wait` .

    • Windows
  29. Fix

    `unity open` and `unity projects open` now say what to pass when several installed Editors match and nothing can ask you, such as under `--non-interactive` : the full version for different patches, or `--architecture` for one version installed for several architectures. They used to name `--architecture` every time, which can't separate two patches of one architecture.

  30. Fix

    `unity open` and `unity projects open` now use `-a` and `--architecture` to choose between the installs that a partial `--editor-version` matches. With `6000.0.32f1` installed for both arm64 and x86_64, `unity open --editor-version 6000.0 -a arm64` opens the arm64 Editor.

  31. Fix

    `unity projects create` and `unity projects new` now use `-a` and `--architecture` to choose between the installs that a partial `--editor-version` matches. With `6000.0.32f1` installed for both arm64 and x86_64, `unity projects new MyGame --editor-version 6000.0 -a arm64` creates the project with the arm64 Editor.

  32. Fix

    When two installs of one Editor version have architectures the CLI can't read, the error from the commands that pick an Editor, such as `unity run` , `unity build` and `unity install-modules` , now points to `unity editors list --installed --verbose` to find the incomplete install. It used to suggest `unity editors verify` , which refused both installs.

  33. Removal

    On macOS and Linux, `unity uninstall` now asks for your administrator password when the Editor sits in a folder you can't write to, such as `/opt` or `/Applications` , instead of failing with "The Editor … could not be uninstalled." If the removal still fails, the error code is now `UNINSTALL_FAILED` .

    • macOS
    • Linux
  34. Removal

    `unity uninstall` , `unity editors prune --remove` and `unity editors upgrade --replace` now say in your CLI language that an Editor could not be uninstalled, when the removal fails for a reason the CLI can't name. The message printed in English whatever language you had chosen.

  35. Fix

    `unity projects import` now shows its warning for an entry with no usable path, and its error for more than 50 MB on stdin, in your display language. Both printed in English whatever language you had chosen.

  36. Fix

    `unity projects import` now stops reading piped input as soon as it passes the 50 MB limit and fails with the same error. It used to read the whole stream into memory before checking the size, so a very large or endless pipe could use up memory or never finish.

  37. Fix

    Commands that change your project list, such as `unity projects add` , `pin` and `import` , no longer fail, or save the change where Unity Hub doesn't look, when Unity Hub or another `unity` command is creating that list at the same moment. This could happen on a new installation when both start together on a busy machine.

  38. Fix

    When git refuses a `unity vcs sync` pull, the error no longer lists git's download progress ( `Counting objects` , `Receiving objects` ), so git's explanation (the diverged branch, the conflicted files, or the untracked file in the way) is easier to find.

  39. Fix

    When the CLI ends a git command that made no progress, the error now names the command, such as `git clone` , `git pull` or `git push` . It used to name the first setting the CLI passes to git, such as the proxy address or the credential helper config, so a stalled `unity projects clone` or `unity vcs sync` pointed at the wrong thing.

  40. Fix

    `unity config proxy ` and `unity config proxy --unset` now protect the shared proxy settings file the way the other shared files already were. When the file can't be read or lists the same name twice, the change is refused with the same error the other settings files give, and the file stays as it was.

  41. Fix

    `unity templates delete` and `unity templates edit` now print their "Path doesn't exist" error in your display language, and its grammar is fixed (it read "doesn't exists"). It appears only if the templates folder disappears while the command runs.

  42. Fix

    `unity cache clean` now explains in your CLI language why it refuses to clean a cache folder that is a symbolic link. The message printed in English whatever language you had chosen.

  43. Fix

    `unity command` , `unity list` and the other commands that connect to a running Editor now tell you in your CLI language when no Editor is available to them, and when a `--project-path` isn't a Unity project. These errors printed in English whatever language you had set.

  44. Fix

    `unity status --project-path` no longer matches a sibling project whose path starts with the one you named, so `unity status --until-ready --project-path /x/MyGame` no longer ends on an Editor open on `/x/MyGame-lighting` . A value that is an existing directory now matches that project only, so a parent folder no longer matches the projects inside it (run `unity status` without the flag to list them all).

  45. Fix

    On Windows, sign-in now refuses to talk to the shared authentication process's communication channel if it's owned by a different local account than yours. On a shared or multi-user Windows machine, this closes a narrow window where another account could stand up a channel under the same name before yours starts and have the CLI unknowingly connect to it; your own sign-in session is never affected.

    • Windows
  46. Fix

    `unity pipeline install` and `unity pipeline upgrade` now show their two target errors in your CLI language: a `--project-path` that isn't a Unity project, and a run from a folder that isn't one when no Editor is open. Both printed in English whatever language you had chosen.

  47. Fix

    `unity build --format json` now writes exactly one JSON document to stdout, so you can parse it whole. The progress lines and the streamed Editor log used to come first; they now go to stderr.

  48. Fix

    `unity install-modules --force` no longer hangs on Windows for the full install timeout when reinstalling over an already-installed module. A stuck antivirus file scan could make the reinstall wait retry itself forever; it's now bounded and retried automatically instead.

    • Windows
  49. Fix

    `unity build` now shows its `--args` errors in your CLI language: a forwarded flag that the command already sets itself, such as `-projectPath` , and a quote that is never closed. Both printed in English whatever language you had chosen.

  50. Fix

    On macOS, `unity` no longer crashes partway through a command when a program that handles signals itself started it, such as `gh` or another tool written in Go. Commands that read a lot of data were affected, such as `unity vcs diff` on a large scene, and so was the auth broker the CLI starts in the background.

    • macOS
  51. Fix

    On macOS, the Unity Licensing Client that `unity` starts no longer crashes when another program sends it a `SIGUSR1` signal. The CLI no longer passes a leftover signal setting to the programs it starts.

    • macOS
  52. Fix

    Help for some options no longer shows their default twice. `unity releases --help` , for example, listed `--limit` with `(default: 20) (default: 20)` , and `unity build` , `unity command` , `unity doctor` and `unity logs` repeated a default the same way.

  53. Fix

    `unity mcp configure` now writes a project-local config when you run it from a drive or filesystem root, such as `C:\` or `/` . It used to refuse the write.

  54. Fix

    On Windows, the warning that an update didn't finish installing now appears in your CLI language, the one you set with `unity language` , instead of always in English. It stays in English when no language is saved.

    • Windows

Pick your Unity version

Unity Releases compares releases against the version your project is on. Picking it now keeps Compare versions focused on what changes between where you are and where you might be going.