Skip to content

ci: bump codecov-action to v6 and fail CI on upload error - #12

Open
timtreis wants to merge 1 commit into
scverse:mainfrom
timtreis:fix/codecov-action-v6-signature
Open

timtreis wants to merge 1 commit into
scverse:mainfrom
timtreis:fix/codecov-action-v6-signature

Conversation

@timtreis

@timtreis timtreis commented Jun 8, 2026

Copy link
Copy Markdown
Member

Two changes to every codecov upload step in this repo:

  1. codecov-action -> @v6. Versions below 6.0.2 verify the codecov CLI binary against Codecov's old Keybase key, which they bricked after migrating accounts, so uploads now fail with Could not verify signature. @v6 (= 6.0.2) ships the updated key.
  2. fail_ci_if_error: true. Matches the cookiecutter-scverse template default so a broken upload fails CI loudly instead of passing silently.

Ref: codecov/codecov-action#1956

codecov-action below v6.0.2 verifies the codecov CLI against Codecov's
old Keybase key, which they bricked after migrating accounts, so uploads
now fail with "Could not verify signature". v6 (= 6.0.2) ships the
updated key.

Also sets fail_ci_if_error: true (the cookiecutter-scverse template
default) so a broken coverage upload surfaces as a CI failure instead of
passing silently.

Ref: codecov/codecov-action#1956

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant