alunduil / alunduil/siren-json.hs

Codecov uploads authenticate by OIDC

Aperta
#156 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
infrastructure
Lingua principale
Haskell
Stelle
3
Fork
1
Merge medio
5h 46m
PR unite (30g)
63

Descrizione

The `Upload to Codecov` step in `ci.yml` passes `token: ${{ secrets.CODECOV_TOKEN }}`. `alunduil-chezmoi` uploads with `use_oidc: true` instead, which leaves no upload token to store, rotate, or leak, and `alunduil/zfs-replicate#687` adopts the same. Converging the rest gives the repositories one Codecov pattern.

- [ ] Add `id-token: write` to the coverage job's `permissions` block, alongside the `contents: read` it already needs for checkout.
- [ ] Replace the action's `token:` input with `use_oidc: true`.
- [ ] Delete the `CODECOV_TOKEN` secret once no workflow reads it.

## Additional context

- Reference: the `shell-tests` job in `alunduil-chezmoi`'s `ci.yml`.
- A fork's pull request gets a read-only `GITHUB_TOKEN`, so `id-token: write` is unavailable there and the upload fails. Secrets are withheld from fork pull requests too, so the token this replaces fails the same way; worth confirming rather than assuming when the change lands.
- The secret itself lives wherever `alunduil-infrastructure` manages this repository, so the last item is a change there, not here.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Start with the coverage job in ci.yml and compare its Upload to Codecov step with the shell-tests job in alunduil-chezmoi. Check the workflow permissions and Codecov action inputs, then confirm fork pull requests behave as described. Done means this repository uses OIDC without CODECOV_TOKEN, and the secret is removed where alunduil-infrastructure manages it.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
github-actions
Ambito
ci-cd, security
Tipo di issue
Refactoring
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Attiva
Chiarezza
Specificata chiaramente
Idoneità per principianti
65/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.