Skip to content

Authenticate coverage uploads with OIDC - #368

Merged
quinnj merged 1 commit into
masterfrom
maintenance/sqlite-coverage-auth
Oct 4, 2026
Merged

quinnj merged 1 commit into
masterfrom
maintenance/sqlite-coverage-auth

Conversation

@quinnj

@quinnj quinnj commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Coverage uploads on the latest main run are rejected because Codecov requires authentication, but the uploader still lets every job pass. This makes successful CI hide missing coverage reports.

Use the Codecov action's OIDC authentication for pushes and same-repository PRs, with the required test-job permissions. Public fork PRs keep tokenless uploads. Upgrade the uploader to v7, pass the generated lcov.info through its supported files input, and fail the job when an upload fails.

Verified all five main jobs in run 37146475075 reject commit, report, and upload creation with Token required because branch is protected. The candidate workflow parses successfully and its inputs match the official v7 action metadata. All nine exact-head checks passed: five platform/version suites, the compiled native core, documentation, and both coverage checks. All five uploader logs explicitly accept the correct SQLite commit ff31698a0989629fe3d9b5040f87f8e38bcf4ed9; the public report is complete with five sessions and 96.76% coverage. Package source, tests, and coverage thresholds are unchanged.

Co-authored by Codex

AI disclosure: This work was prepared with assistance from OpenAI Codex.

AI disclosure: This work was prepared with assistance from OpenAI Codex.
@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 96.76%. Comparing base (95131f8) to head (ff31698).
⚠️ Report is 30 commits behind head on master.

Additional details and impacted files
@@            Coverage Diff             @@
##           master     #368      +/-   ##
==========================================
+ Coverage   94.13%   96.76%   +2.62%     
==========================================
  Files           4        5       +1     
  Lines         563      773     +210     
==========================================
+ Hits          530      748     +218     
+ Misses         33       25       -8     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@quinnj quinnj left a comment

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified exact head ff31698a0989629fe3d9b5040f87f8e38bcf4ed9: all nine checks pass. All five platform/version jobs use OIDC and their accepted upload URLs identify this SQLite repository and exact commit; the public report is complete with five sessions. The compiled native core and documentation checks also pass.

The change is confined to upload configuration. The public-fork condition preserves tokenless uploads, and authentication/upload failures now fail the job. Fresh main/head/draft/review/rule checks have no remaining gate; this is a comment review, not an approval.

AI disclosure: This work was prepared with assistance from OpenAI Codex.

@quinnj
quinnj merged commit 92eedaf into master Oct 4, 2026
9 checks passed
@quinnj
quinnj deleted the maintenance/sqlite-coverage-auth branch October 4, 2026 11:02
@quinnj

quinnj commented Oct 4, 2026

Copy link
Copy Markdown
Member Author

Verified the normal merge 92eedafc66981f05ff151f2c204a93d23b0e059b on main CI: all seven jobs passed, including the five platform/version suites, compiled native core, and documentation.

All five uploader logs explicitly accept reports for this repository and exact merged commit. The public coverage report is complete with five sessions and 96.76% coverage. This verifies that authentication works on main as well as the PR; the previous green run's rejected uploads are no longer being mistaken for accepted coverage.

AI disclosure: This work was prepared with assistance from OpenAI Codex.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant