Skip to content

test(ci): verify tokenless fork coverage upload - #8

Closed
Eli Pinkerton (wallstop) wants to merge 1 commit into
Ambiguous-Interactive:agent/remove-inherited-codecov-literalfrom
wallstop:canary/fork-tokenless-codecov
Closed

test(ci): verify tokenless fork coverage upload#8
Eli Pinkerton (wallstop) wants to merge 1 commit into
Ambiguous-Interactive:agent/remove-inherited-codecov-literalfrom
wallstop:canary/fork-tokenless-codecov

Conversation

@wallstop

@wallstop Eli Pinkerton (wallstop) commented Jul 18, 2026

Copy link
Copy Markdown

Live acceptance canary for Ambiguous-Interactive/ambiguous-organization-build-lock#45.

This fork PR changes documentation only. Its purpose is to prove that untrusted fork CI receives no Codecov secret or OIDC permission and that the pinned Codecov action succeeds through the explicit tokenless, colon-qualified PR branch path.

Do not merge; close after the exact-head checks and upload logs are verified. No licensed Unity job should run.


Note

Low Risk
Documentation-only comment with no runtime, auth, or build behavior changes.

Overview
Docs-only canary for fork pull-request CI: adds a hidden HTML comment at the end of README.md so a fork PR can run workflows without touching application code.

The change exists to validate that untrusted fork runs get no Codecov secret or OIDC, and that coverage upload still succeeds via the tokenless, colon-qualified PR branch path in integrity-check (upload-tokenless-pr-coverage). Intended to be closed after checks and upload logs are verified—not merged.

Reviewed by Cursor Bugbot for commit 7880ba8. Bugbot is set up for automated code reviews on this repo. Configure here.

Copy link
Copy Markdown
Author

Acceptance canary passed at exact head 7880ba860b87adf18b64ac17bdf8d742a711a7db in Integrity run 29666123092:

  • Tests passed.
  • Upload fork and Dependabot coverage without a token passed.
  • Trusted OIDC upload was skipped.
  • Job permissions contained contents: read and no id-token permission.
  • Codecov reported token length 0, used branch pr8:canary/fork-tokenless-codecov, and queued the upload successfully with fail-on-error enabled.
  • No licensed Unity job ran.

Closing without merge as designed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant