Skip to content

ci: upload coverage over OIDC instead of a token #patch - #54

Merged
nmichlo merged 1 commit into
mainfrom
ci/codecov-oidc
Sep 13, 2026
Merged

nmichlo merged 1 commit into
mainfrom
ci/codecov-oidc

Conversation

@nmichlo

@nmichlo nmichlo commented Sep 13, 2026

Copy link
Copy Markdown
Owner

Coverage now uploads with OIDC, so this repo needs no CODECOV_TOKEN.

-   secrets:
-     CODECOV_TOKEN: \${{ secrets.CODECOV_TOKEN }}
+   permissions:
+     contents: read
+     id-token: write

A reusable workflow cannot hold more permission than its caller, so the id-token grant has to live here.

Pairs with nmichlo/.github#4 -- merge this one first, since that PR deletes the CODECOV_TOKEN declaration and passing an undeclared secret is a hard error.

Codecov failures never fail the build (fail_ci_if_error: false).

🤖 Generated with Claude Code

@nmichlo
nmichlo merged commit 9a63aee into main Sep 13, 2026
5 checks passed
@nmichlo
nmichlo deleted the ci/codecov-oidc branch September 13, 2026 18:16

This branch was successfully deployed

1 active deployment
pypi — 0c7640f8 Deployed Sep 13, 2026 by nmichlo via Publish to PyPI #4
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant