move codecov from token to oidc#191
Merged
bckohan merged 2 commits intodjango-commons:mainfrom May 1, 2026
Merged
Conversation
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Moves Codecov uploads in CI from using a repository secret token to GitHub OIDC, and updates the release workflow to support the new auth mechanism.
Changes:
- Remove
CODECOV_TOKENsecret wiring from the reusabletest.ymlworkflow and its callers - Enable OIDC for the Codecov upload step and grant
id-token: writepermission to the coverage job - Adjust release workflow behavior by removing the
--prereleaseflag from GitHub Release creation
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.
| File | Description |
|---|---|
| .github/workflows/test.yml | Switch Codecov upload from token auth to OIDC and update permissions accordingly |
| .github/workflows/release.yml | Stop passing Codecov token into reusable workflow; add OIDC permission; change release creation flags |
Comments suppressed due to low confidence (1)
.github/workflows/test.yml:1
- With the move to
use_oidc: true, the workflow now depends on Codecov’s OIDC configuration (and the expected OIDC claims) rather than a token. Consider adding a short inline comment near this step linking to the repo’s Codecov OIDC setup requirements (or internal docs) so future maintainers know what must be configured in Codecov for uploads to succeed.
name: Test
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
Codecov Report✅ All modified and coverable lines are covered by tests. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.