alunduil / alunduil/collection-json.hs

Codecov uploads authenticate by OIDC

Aberta
#302 0 comentários 0 reações 0 responsáveis Ver no GitHub
infrastructure
Linguagem predominante
Haskell
Estrelas
3
Forks
1
Merge médio
5h 53min
PRs com merge (30d)
63

Descrição

The `Upload to Codecov` step in `ci.yml` passes `token: ${{ secrets.CODECOV_TOKEN }}`. `alunduil-chezmoi` uploads with `use_oidc: true` instead, which leaves no upload token to store, rotate, or leak, and `alunduil/zfs-replicate#687` adopts the same. Converging the rest gives the repositories one Codecov pattern.

- [ ] Add `id-token: write` to the coverage job's `permissions` block, alongside the `contents: read` it already needs for checkout.
- [ ] Replace the action's `token:` input with `use_oidc: true`.
- [ ] Delete the `CODECOV_TOKEN` secret once no workflow reads it.

## Additional context

- Reference: the `shell-tests` job in `alunduil-chezmoi`'s `ci.yml`.
- A fork's pull request gets a read-only `GITHUB_TOKEN`, so `id-token: write` is unavailable there and the upload fails. Secrets are withheld from fork pull requests too, so the token this replaces fails the same way; worth confirming rather than assuming when the change lands.
- The secret itself lives wherever `alunduil-infrastructure` manages this repository, so the last item is a change there, not here.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Start with ci.yml and the coverage job's permissions block, then compare its Upload to Codecov step with the shell-tests job in alunduil-chezmoi. Check how fork pull requests receive tokens and review the repository's infrastructure configuration for CODECOV_TOKEN ownership. Done means the workflow uses the requested OIDC settings, fork behavior is confirmed, and no workflow still reads the secret.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
github-actions
Domínio
ci-cd, security
Tipo de issue
Funcionalidade
Dificuldade
3/5
Tempo estimado
1-2 dias
Status de atividade
Ativa
Clareza
Claramente especificada
Facilidade para iniciantes
68/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.