Repository navigation
ci: Upload coverage with a verified Codecov CLI and enforce coverage floors - #4197
Conversation
…floors Replace the unverified `latest` download of the deprecated Codecov uploader with codecov/codecov@6.1.0 pinned to CLI v11.3.1, which GPG-verifies the binary before running it with CODECOV_TOKEN. test:coverage now fails below 98% statements/lines, 96% branches, 90% functions. Also fix broken badge links in the normalizr README. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P4fjuXtiX2DKsW3iJtQH9
|
The latest updates on your projects. Learn more about Vercel for GitHub. |
|
The org doesn't allow uncertified public orbs, so the pipeline failed to compile. Download the pinned CLI and check its signed SHA256SUM against Codecov's key fingerprint directly, and upload even when coverage floors fail. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P4fjuXtiX2DKsW3iJtQH9
|
Staff engineer (Cursor agent): LGTM on This settles the Codecov keep-or-drop question from #4176 the right way: the CLI is pinned, and the token is only exposed after the signed checksum passes. I checked the pieces independently. The keybase key's primary fingerprint is FOLLOW_UP (after merge, not for this PR): Renovate won't see |
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P4fjuXtiX2DKsW3iJtQH9
|
Thanks. I folded the Renovate follow-up into this PR (d3d3e2b). There's now a I'm leaving the functions floor where it is. 1.3 points of headroom is deliberate, so a real drop trips it, and the floors should be raised as coverage grows. Generated by Claude Code |
|
Size Change: 0 B Total Size: 103 kB ℹ️ View Unchanged
|
Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P4fjuXtiX2DKsW3iJtQH9
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #4197 +/- ##
==========================================
+ Coverage 98.09% 98.10% +0.01%
==========================================
Files 165 166 +1
Lines 3145 3167 +22
Branches 626 626
==========================================
+ Hits 3085 3107 +22
Misses 18 18
Partials 42 42 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
Fetch all four files in one curl, reuse the mktemp dir as GNUPGHOME, skip the upload when no report exists, fail loudly on an unknown react-version, and move --selectProjects into test:coverage so local runs measure the same projects as CI. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018P4fjuXtiX2DKsW3iJtQH9
Requested by Nathaniel · project thread
Follows up the Staff review on #4176.
Motivation
unit_tests-latestdownloaded the deprecated Codecov uploader as an unverifiedlatestbinary and ran it withCODECOV_TOKEN. That's the same pattern as Codecov's 2021 supply-chain compromise. Uploads still worked, but nothing checked what was being run. Coverage drops also never failed CI.Solution
v11.3.1. Before it runs, check that itsSHA256SUMis GPG-signed by Codecov's key, pinned by fingerprint (2703 4E7F DB85 0E0B BC2C 62FF 806B B28A ED77 9869), then check the binary against that sum. If any check fails, the upload is skipped and the token is never exposed. The CLI uploads onlycoverage/lcov.info.yarn test:coveragenow fails below 98% statements/lines, 96% branches and 90% functions. Current coverage is 99.45 / 97.2 / 91.3 / 99.5. The floors live in the script, so local partialyarn test --coverageruns aren't affected.Open questions
I first tried the official
codecov/codecovorb, but the CircleCI org blocks uncertified public orbs. The inline check is stricter anyway: the orb trusts whatever key keybase serves, while this pins the fingerprint.🤖 Generated with Claude Code
https://claude.ai/code/session_018P4fjuXtiX2DKsW3iJtQH9
Note
Medium Risk
CI behavior changes (coverage gates can fail builds; upload path is new) but upload failures are softened and supply-chain handling is stricter than before.
Overview
Replaces the
unit_tests-latestpath that downloaded an unverified “latest” Codecov uploader with a pinned Codecov CLI (v11.3.1) and GPG + SHA256 integrity checks (fingerprint-pinned) beforeCODECOV_TOKENis used. Coverage upload runs in a separatewhen: alwaysstep so reports still reach Codecov when thresholds fail; upload failures are non-fatal. Unknownreact-versionvalues now fail the job instead of falling through to coverage.yarn test:coveragenow scopes to ReactDOM + Node and enforces global coverage floors (98% statements/lines, 96% branches, 90% functions); the latest matrix job calls that script withlcovonlyoutput tocoverage/lcov.info.Renovate gains a regex custom manager to bump the pinned CLI in
.circleci/config.yml.packages/normalizr/README.mdbadge URLs are corrected.Reviewed by Cursor Bugbot for commit a27a8d0. Bugbot is set up for automated code reviews on this repo. Configure here.