mirror of
https://github.com/codecov/codecov-action
synced 2026-09-07 20:03:43 +00:00
Compare commits
14
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
efcc1c7b52 | ||
|
|
fb8b3582c8 | ||
|
|
ca0a928a4c | ||
|
|
e79a6962e0 | ||
|
|
51e64229ac | ||
|
|
57e3a136b7 | ||
|
|
f67d33dda8 | ||
|
|
75cd11691c | ||
|
|
87d39f4a2c | ||
|
|
1af58845a9 | ||
|
|
c143300dea | ||
|
|
671740ac38 | ||
|
|
96b38e9e60 | ||
|
|
9b6d1f84bd |
@@ -1,14 +0,0 @@
|
||||
name: Enforce License Compliance
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
branches: [main]
|
||||
|
||||
jobs:
|
||||
enforce-license-compliance:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: 'Enforce License Compliance'
|
||||
uses: getsentry/action-enforce-license-compliance@57ba820387a1a9315a46115ee276b2968da51f3d # main
|
||||
with:
|
||||
fossa_api_key: ${{ secrets.FOSSA_API_KEY }}
|
||||
@@ -1,3 +1,11 @@
|
||||
## v5.5.2
|
||||
|
||||
### What's Changed
|
||||
|
||||
|
||||
**Full Changelog**: https://github.com/codecov/codecov-action/compare/v5.5.1..v5.5.2
|
||||
|
||||
|
||||
## v5.5.1
|
||||
|
||||
### What's Changed
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
deploy:
|
||||
$(eval VERSION := $(shell cat src/version))
|
||||
git tag -d v5
|
||||
git push origin :v5
|
||||
git tag v5
|
||||
git tag -d v7
|
||||
git push origin :v7
|
||||
git tag v7
|
||||
git tag v$(VERSION) -s -m ""
|
||||
git push origin --tags
|
||||
|
||||
@@ -6,6 +6,16 @@
|
||||
|
||||
### Easily upload coverage reports to Codecov from GitHub Actions
|
||||
|
||||
## v7 Release
|
||||
|
||||
`v7` of the Codecov GitHub Action bumps the [Codecov Wrapper](https://github.com/codecov/wrapper) submodule, which now fetches the Codecov Uploader PGP verification key from the `codecovsecops` Keybase account.
|
||||
|
||||
`v7.1.0` updates the wrapper to `0.3.0`, which adds an optional `cleanup` input to download the CLI into a temporary directory, and accepts CircleCI-style `1`/`0` values for `skip_validation` and `use_pypi`.
|
||||
|
||||
## v6 Release
|
||||
|
||||
`v6` of the Codecov GitHub Action support node24
|
||||
|
||||
## v5 Release
|
||||
|
||||
`v5` of the Codecov GitHub Action will use the [Codecov Wrapper](https://github.com/codecov/wrapper) to encapsulate the [CLI](https://github.com/codecov/codecov-cli). This will help ensure that the Action gets updates quicker.
|
||||
@@ -129,6 +139,7 @@ Codecov's Action supports inputs from the user. These inputs, along with their d
|
||||
| :--- | :--- | :---: |
|
||||
| `base_sha` | 'The base SHA to select. This is only used in the "pr-base-picking" run command' | Optional
|
||||
| `binary` | The file location of a pre-downloaded version of the CLI. If specified, integrity checking will be bypassed. | Optional
|
||||
| `cleanup` | If true, download the CLI into a temporary directory and clean it up after the run. Off by default. | Optional
|
||||
| `codecov_yml_path` | The location of the codecov.yml file. This is currently ONLY used for automated test selection (https://docs.codecov.com/docs/getting-started-with-ats). Note that for all other cases, the Codecov yaml will need to be located as described here: https://docs.codecov.com/docs/codecov-yaml#can-i-name-the-file-codecovyml | Optional
|
||||
| `commit_parent` | SHA (with 40 chars) of what should be the parent of this commit. | Optional
|
||||
| `directory` | Folder to search for coverage files. Default to the current working directory | Optional
|
||||
@@ -140,7 +151,7 @@ Codecov's Action supports inputs from the user. These inputs, along with their d
|
||||
| `env_vars` | Environment variables to tag the upload with (e.g. PYTHON \| OS,PYTHON) | Optional
|
||||
| `exclude` | Comma-separated list of folders to exclude from search. | Optional
|
||||
| `fail_ci_if_error` | On error, exit with non-zero code | Optional
|
||||
| `files` | Comma-separated explicit list of files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using "disable-search" to disable uploading other files. | Optional
|
||||
| `files` | Comma-separated explicit list of files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using "disable_search" to disable uploading other files. | Optional
|
||||
| `flags` | Comma-separated list of flags to upload to group coverage metrics. | Optional
|
||||
| `force` | Only used for empty-upload run command | Optional
|
||||
| `git_service` | Override the git_service (e.g. github_enterprise) | Optional
|
||||
|
||||
+26
-9
@@ -10,6 +10,10 @@ inputs:
|
||||
binary:
|
||||
description: 'The file location of a pre-downloaded version of the CLI. If specified, integrity checking will be bypassed.'
|
||||
required: false
|
||||
cleanup:
|
||||
description: 'If true, download the CLI into a temporary directory and clean it up after the run. Off by default to preserve legacy behavior of downloading into the current working directory.'
|
||||
required: false
|
||||
default: 'false'
|
||||
codecov_yml_path:
|
||||
description: 'The location of the codecov.yml file. This is crrently ONLY used for automated test selection (https://docs.codecov.com/docs/getting-started-with-ats). Note that for all other cases, the Codecov yaml will need to be located as described here: https://docs.codecov.com/docs/codecov-yaml#can-i-name-the-file-codecovyml'
|
||||
required: false
|
||||
@@ -50,7 +54,7 @@ inputs:
|
||||
required: false
|
||||
default: 'false'
|
||||
files:
|
||||
description: 'Comma-separated list of explicit files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using disable-search to disable uploading other files.'
|
||||
description: 'Comma-separated list of explicit files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using disable_search to disable uploading other files.'
|
||||
required: false
|
||||
flags:
|
||||
description: 'Comma-separated list of flags to upload to group coverage metrics.'
|
||||
@@ -177,16 +181,25 @@ runs:
|
||||
steps:
|
||||
- name: Check system dependencies
|
||||
shell: sh
|
||||
env:
|
||||
INPUT_SKIP_VALIDATION: ${{ inputs.skip_validation }}
|
||||
run: |
|
||||
missing_deps=""
|
||||
|
||||
# Check for required commands
|
||||
for cmd in bash git curl gpg; do
|
||||
# Check for always-required commands
|
||||
for cmd in bash git curl; do
|
||||
if ! command -v "$cmd" >/dev/null 2>&1; then
|
||||
missing_deps="$missing_deps $cmd"
|
||||
fi
|
||||
done
|
||||
|
||||
# Check for gpg only if validation is not being skipped
|
||||
if [ "$INPUT_SKIP_VALIDATION" != "true" ]; then
|
||||
if ! command -v gpg >/dev/null 2>&1; then
|
||||
missing_deps="$missing_deps gpg"
|
||||
fi
|
||||
fi
|
||||
|
||||
# Report missing required dependencies
|
||||
if [ -n "$missing_deps" ]; then
|
||||
echo "Error: The following required dependencies are missing:$missing_deps"
|
||||
@@ -223,7 +236,7 @@ runs:
|
||||
GITHUB_REPOSITORY: ${{ github.repository }}
|
||||
|
||||
- name: Get OIDC token
|
||||
uses: actions/github-script@60a0d83039c74a4aee543508d2ffcb1c3799cdea # v7.0.1
|
||||
uses: actions/github-script@ed597411d8f924073f98dfc5c65a23a2325f34cd # v8.0.0
|
||||
id: oidc
|
||||
with:
|
||||
script: |
|
||||
@@ -238,24 +251,27 @@ runs:
|
||||
- name: Get and set token
|
||||
shell: bash
|
||||
run: |
|
||||
if [ "${{ inputs.use_oidc }}" == 'true' ] && [ "$CC_FORK" != 'true' ];
|
||||
if [ "$INPUT_USE_OIDC" == 'true' ] && [ "$CC_FORK" != 'true' ];
|
||||
then
|
||||
echo "CC_TOKEN=$CC_OIDC_TOKEN" >> "$GITHUB_ENV"
|
||||
elif [ -n "${{ env.CODECOV_TOKEN }}" ];
|
||||
elif [ -n "$INPUT_CODECOV_TOKEN" ];
|
||||
then
|
||||
echo -e "\033[0;32m==>\033[0m Token set from env"
|
||||
echo "CC_TOKEN=${{ env.CODECOV_TOKEN }}" >> "$GITHUB_ENV"
|
||||
echo "CC_TOKEN=$INPUT_CODECOV_TOKEN" >> "$GITHUB_ENV"
|
||||
else
|
||||
if [ -n "${{ inputs.token }}" ];
|
||||
if [ -n "$INPUT_TOKEN" ];
|
||||
then
|
||||
echo -e "\033[0;32m==>\033[0m Token set from input"
|
||||
CC_TOKEN=$(echo "${{ inputs.token }}" | tr -d '\n')
|
||||
CC_TOKEN=$(echo "$INPUT_TOKEN" | tr -d '\n')
|
||||
echo "CC_TOKEN=$CC_TOKEN" >> "$GITHUB_ENV"
|
||||
fi
|
||||
fi
|
||||
env:
|
||||
CC_OIDC_TOKEN: ${{ steps.oidc.outputs.result }}
|
||||
CC_OIDC_AUDIENCE: ${{ inputs.url || 'https://codecov.io' }}
|
||||
INPUT_USE_OIDC: ${{ inputs.use_oidc }}
|
||||
INPUT_TOKEN: ${{ inputs.token }}
|
||||
INPUT_CODECOV_TOKEN: ${{ env.CODECOV_TOKEN }}
|
||||
|
||||
- name: Override branch for forks
|
||||
shell: bash
|
||||
@@ -305,6 +321,7 @@ runs:
|
||||
CC_BINARY: ${{ inputs.binary }}
|
||||
CC_BUILD: ${{ inputs.override_build }}
|
||||
CC_BUILD_URL: ${{ inputs.override_build_url }}
|
||||
CC_CLEANUP: ${{ inputs.cleanup }}
|
||||
CC_CODE: ${{ inputs.report_code }}
|
||||
CC_DIR: ${{ inputs.directory }}
|
||||
CC_DISABLE_FILE_FIXES: ${{ inputs.disable_file_fixes }}
|
||||
|
||||
Vendored
+48
-16
@@ -37,11 +37,12 @@ g="\033[0;32m" # info/debug
|
||||
r="\033[0;31m" # errors
|
||||
x="\033[0m"
|
||||
retry="--retry 5 --retry-delay 2"
|
||||
CC_WRAPPER_VERSION="0.2.7"
|
||||
CC_WRAPPER_VERSION="0.3.0"
|
||||
CC_VERSION="${CC_VERSION:-latest}"
|
||||
CC_FAIL_ON_ERROR="${CC_FAIL_ON_ERROR:-false}"
|
||||
CC_RUN_CMD="${CC_RUN_CMD:-upload-coverage}"
|
||||
CC_CLI_TYPE=${CC_CLI_TYPE:-"codecov-cli"}
|
||||
CC_CLEANUP="${CC_CLEANUP:-false}"
|
||||
say " _____ _
|
||||
/ ____| | |
|
||||
| | ___ __| | ___ ___ _____ __
|
||||
@@ -63,14 +64,28 @@ then
|
||||
else
|
||||
exit_if_error "Could not find binary file $CC_BINARY"
|
||||
fi
|
||||
elif [ "$CC_USE_PYPI" == "true" ];
|
||||
elif [ "$CC_USE_PYPI" == "true" ] || [ "$CC_USE_PYPI" == "1" ];
|
||||
then
|
||||
if ! pip install "${CC_CLI_TYPE}$([ "$CC_VERSION" == "latest" ] && echo "" || echo "==$CC_VERSION")"; then
|
||||
exit_if_error "Could not install via pypi."
|
||||
exit
|
||||
fi
|
||||
CC_COMMAND="${CC_CLI_TYPE}"
|
||||
if [[ "$CC_CLI_TYPE" == "codecov-cli" ]]; then
|
||||
CC_COMMAND="codecovcli"
|
||||
elif [[ "$CC_CLI_TYPE" == "sentry-prevent-cli" ]]; then
|
||||
CC_COMMAND="sentry-prevent-cli"
|
||||
else
|
||||
CC_COMMAND="${CC_CLI_TYPE}"
|
||||
fi
|
||||
else
|
||||
CC_DOWNLOAD_DIR="."
|
||||
if [ "$CC_CLEANUP" == "true" ]; then
|
||||
CC_DOWNLOAD_DIR=$(mktemp -d)
|
||||
cleanup_downloads() {
|
||||
rm -rf "$CC_DOWNLOAD_DIR"
|
||||
}
|
||||
trap cleanup_downloads EXIT
|
||||
fi
|
||||
if [ -n "$CC_OS" ];
|
||||
then
|
||||
say "$g==>$x Overridden OS: $b${CC_OS}$x"
|
||||
@@ -87,7 +102,7 @@ else
|
||||
fi
|
||||
CC_FILENAME="${CC_CLI_TYPE%-cli}"
|
||||
[[ $CC_OS == "windows" ]] && CC_FILENAME+=".exe"
|
||||
CC_COMMAND="./$CC_FILENAME"
|
||||
CC_COMMAND="$CC_DOWNLOAD_DIR/$CC_FILENAME"
|
||||
[[ $CC_OS == "macos" ]] && \
|
||||
! command -v gpg 2>&1 >/dev/null && \
|
||||
HOMEBREW_NO_AUTO_UPDATE=1 brew install gpg
|
||||
@@ -95,24 +110,36 @@ else
|
||||
CC_URL="$CC_URL/${CC_VERSION}"
|
||||
CC_URL="$CC_URL/${CC_OS}/${CC_FILENAME}"
|
||||
say "$g ->$x Downloading $b${CC_URL}$x"
|
||||
curl -O $retry "$CC_URL"
|
||||
curl -o "$CC_COMMAND" $retry "$CC_URL"
|
||||
say "$g==>$x Finishing downloading $b${CC_OS}:${CC_VERSION}$x"
|
||||
v_url="https://cli.codecov.io/api/${CC_OS}/${CC_VERSION}"
|
||||
v=$(curl $retry --retry-all-errors -s "$v_url" -H "Accept:application/json" | tr \{ '\n' | tr , '\n' | tr \} '\n' | grep "\"version\"" | awk -F'"' '{print $4}' | tail -1)
|
||||
say " Version: $b$v$x"
|
||||
say " "
|
||||
fi
|
||||
if [ "$CC_SKIP_VALIDATION" == "true" ] || [ -n "$CC_BINARY" ] || [ "$CC_USE_PYPI" == "true" ];
|
||||
if [ "$CC_SKIP_VALIDATION" == "true" ] || [ "$CC_SKIP_VALIDATION" == "1" ] || [ -n "$CC_BINARY" ] || [ "$CC_USE_PYPI" == "true" ] || [ "$CC_USE_PYPI" == "1" ];
|
||||
then
|
||||
say "$r==>$x Bypassing validation..."
|
||||
if [ "$CC_SKIP_VALIDATION" == "true" ];
|
||||
if [ "$CC_SKIP_VALIDATION" == "true" ] || [ "$CC_SKIP_VALIDATION" == "1" ];
|
||||
then
|
||||
chmod +x "$CC_COMMAND"
|
||||
fi
|
||||
else
|
||||
echo "$(curl -s https://keybase.io/codecovsecurity/pgp_keys.asc)" | \
|
||||
gpg --no-default-keyring --import
|
||||
# One-time step
|
||||
gpg_key_url="https://keybase.io/codecovsecops/pgp_keys.asc"
|
||||
gpg_import_ok=false
|
||||
for gpg_attempt in 1 2 3; do
|
||||
if curl -sf $retry "$gpg_key_url" | gpg --no-default-keyring --import; then
|
||||
gpg_import_ok=true
|
||||
break
|
||||
fi
|
||||
if [ "$gpg_attempt" -lt 3 ]; then
|
||||
say "$r ->$x GPG key import attempt $gpg_attempt failed, retrying..."
|
||||
sleep 2
|
||||
fi
|
||||
done
|
||||
if [ "$gpg_import_ok" != "true" ]; then
|
||||
exit_if_error "Could not import GPG verification key after 3 attempts. Please contact Codecov if problem continues"
|
||||
fi
|
||||
say "$g==>$x Verifying GPG signature integrity"
|
||||
sha_url="https://cli.codecov.io"
|
||||
sha_url="${sha_url}/${CC_VERSION}/${CC_OS}"
|
||||
@@ -120,14 +147,14 @@ else
|
||||
say "$g ->$x Downloading $b${sha_url}$x"
|
||||
say "$g ->$x Downloading $b${sha_url}.sig$x"
|
||||
say " "
|
||||
curl -Os $retry --connect-timeout 2 "$sha_url"
|
||||
curl -Os $retry --connect-timeout 2 "${sha_url}.sig"
|
||||
if ! gpg --verify "${CC_FILENAME}.SHA256SUM.sig" "${CC_FILENAME}.SHA256SUM";
|
||||
curl -o "$CC_DOWNLOAD_DIR/${CC_FILENAME}.SHA256SUM" -s $retry --connect-timeout 2 "$sha_url"
|
||||
curl -o "$CC_DOWNLOAD_DIR/${CC_FILENAME}.SHA256SUM.sig" -s $retry --connect-timeout 2 "${sha_url}.sig"
|
||||
if ! gpg --verify "$CC_DOWNLOAD_DIR/${CC_FILENAME}.SHA256SUM.sig" "$CC_DOWNLOAD_DIR/${CC_FILENAME}.SHA256SUM";
|
||||
then
|
||||
exit_if_error "Could not verify signature. Please contact Codecov if problem continues"
|
||||
fi
|
||||
if ! (shasum -a 256 -c "${CC_FILENAME}.SHA256SUM" 2>/dev/null || \
|
||||
sha256sum -c "${CC_FILENAME}.SHA256SUM");
|
||||
if ! (cd "$CC_DOWNLOAD_DIR" && (shasum -a 256 -c "${CC_FILENAME}.SHA256SUM" 2>/dev/null || \
|
||||
sha256sum -c "${CC_FILENAME}.SHA256SUM"));
|
||||
then
|
||||
exit_if_error "Could not verify SHASUM. Please contact Codecov if problem continues"
|
||||
fi
|
||||
@@ -137,11 +164,16 @@ else
|
||||
fi
|
||||
if [ -n "$CC_BINARY_LOCATION" ];
|
||||
then
|
||||
mkdir -p "$CC_BINARY_LOCATION" && mv "$CC_FILENAME" $_
|
||||
mkdir -p "$CC_BINARY_LOCATION" && mv "$CC_COMMAND" "$CC_BINARY_LOCATION/$CC_FILENAME"
|
||||
CC_COMMAND="$CC_BINARY_LOCATION/$CC_FILENAME"
|
||||
say "$g==>$x ${CC_CLI_TYPE} binary moved to ${CC_BINARY_LOCATION}"
|
||||
fi
|
||||
if [ "$CC_DOWNLOAD_ONLY" = "true" ];
|
||||
then
|
||||
if [ "$CC_CLEANUP" == "true" ] && [ -z "$CC_BINARY_LOCATION" ]; then
|
||||
cp "$CC_COMMAND" "./$CC_FILENAME"
|
||||
CC_COMMAND="./$CC_FILENAME"
|
||||
fi
|
||||
say "$g==>$x ${CC_CLI_TYPE} download only called. Exiting..."
|
||||
exit
|
||||
fi
|
||||
|
||||
+1
-1
Submodule src/scripts updated: 473e292469...ce44ce7e24
+1
-1
@@ -1 +1 @@
|
||||
5.5.1
|
||||
7.1.0
|
||||
|
||||
Reference in New Issue
Block a user