Skip to content

Codecov uploads authenticate by OIDC #302

Description

@alunduil

The Upload to Codecov step in ci.yml passes token: ${{ secrets.CODECOV_TOKEN }}. alunduil-chezmoi uploads with use_oidc: true instead, which leaves no upload token to store, rotate, or leak, and alunduil/zfs-replicate#687 adopts the same. Converging the rest gives the repositories one Codecov pattern.

  • Add id-token: write to the coverage job's permissions block, alongside the contents: read it already needs for checkout.
  • Replace the action's token: input with use_oidc: true.
  • Delete the CODECOV_TOKEN secret once no workflow reads it.

Additional context

  • Reference: the shell-tests job in alunduil-chezmoi's ci.yml.
  • A fork's pull request gets a read-only GITHUB_TOKEN, so id-token: write is unavailable there and the upload fails. Secrets are withheld from fork pull requests too, so the token this replaces fails the same way; worth confirming rather than assuming when the change lands.
  • The secret itself lives wherever alunduil-infrastructure manages this repository, so the last item is a change there, not here.

Metadata

Metadata

Assignees

No one assigned

    Labels

    infrastructureCI, build, tooling, repo plumbing

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions