Fix Codecov badge by adding OIDC permission for tokenless upload #1551
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Test | |
| on: [push, pull_request] | |
| # Cancels all previous workflow runs for pull requests that have not completed. | |
| concurrency: | |
| # The concurrency group contains the workflow name and the branch name for pull requests | |
| # or the commit hash for any other events. | |
| group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.head_ref || github.sha }} | |
| cancel-in-progress: true | |
| # Disable permissions for all available scopes by default. | |
| # Any needed permissions should be configured at the job level. | |
| permissions: {} | |
| jobs: | |
| lint-js-css: | |
| name: Lint JS & CSS | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| permissions: | |
| contents: read # Required to clone the repo. | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 | |
| - name: Setup Node | |
| uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0 | |
| with: | |
| cache: 'npm' | |
| node-version-file: '.nvmrc' | |
| - name: Install NPM dependencies | |
| run: npm install | |
| - name: Lint JS | |
| run: npm run lint:js | |
| - name: Lint CSS | |
| run: npm run lint:css | |
| lint-php-and-compatibility: | |
| name: Lint PHP & PHP Compatibility checks. | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| permissions: | |
| contents: read # Required to clone the repo. | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 | |
| - name: Setup PHP and Composer | |
| uses: shivammathur/setup-php@accd6127cb78bee3e8082180cb391013d204ef9f # v2.37.0 | |
| with: | |
| php-version: '8.3' | |
| - name: Setup Node | |
| uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0 | |
| with: | |
| cache: 'npm' | |
| node-version-file: '.nvmrc' | |
| - name: Install NPM dependencies | |
| run: npm install | |
| - name: Lint PHP | |
| run: npm run lint:php || true # Ignore for now. | |
| - name: Lint PHP Compatibility | |
| run: composer lint-compat | |
| - name: PHPStan | |
| run: npm run lint:phpstan | |
| test-php: | |
| name: Test PHP ${{ matrix.php }} ${{ matrix.wp != '' && format( ' (WP {0}) ', matrix.wp ) || '' }} | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| permissions: | |
| contents: read # Required to clone the repo. | |
| strategy: | |
| matrix: | |
| php: | |
| - '8.5' | |
| - '8.4' | |
| - '8.3' | |
| - '8.2' | |
| - '8.1' | |
| - '8.0' | |
| - '7.4' | |
| - '7.3' | |
| - '7.2' | |
| wp: | |
| - latest | |
| - trunk | |
| - '6.9' | |
| exclude: | |
| - php: '7.3' | |
| wp: trunk | |
| - php: '7.2' | |
| wp: trunk | |
| - php: '7.3' | |
| wp: latest | |
| - php: '7.2' | |
| wp: latest | |
| env: | |
| WP_ENV_PHP_VERSION: ${{ matrix.php }} | |
| WP_ENV_CORE: ${{ matrix.wp == 'trunk' && 'WordPress/WordPress' || format( 'https://wordpress.org/wordpress-{0}.zip', matrix.wp ) }} | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 | |
| - name: Setup PHP | |
| uses: shivammathur/setup-php@accd6127cb78bee3e8082180cb391013d204ef9f # v2.37.0 | |
| with: | |
| php-version: '8.3' | |
| - name: Setup Node | |
| uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0 | |
| with: | |
| cache: 'npm' | |
| node-version-file: '.nvmrc' | |
| - name: Install NPM dependencies | |
| run: npm install | |
| - name: Start the Docker testing environment | |
| uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0 | |
| with: | |
| timeout_minutes: 10 | |
| max_attempts: 3 | |
| command: npm run env start -- --xdebug=coverage | |
| - name: Composer install | |
| run: | | |
| rm composer.lock || true # We need to install fresh. | |
| # The composer.json platform override (php: 7.2.24) installs PHPUnit 8.5, which | |
| # cannot generate code coverage on PHP 8. For the coverage build only, bypass the | |
| # platform check so Composer installs PHPUnit 9.6. All other matrix jobs keep the | |
| # default dependency set. | |
| if [[ "${{ matrix.php }}" == "8.3" && "${{ matrix.wp }}" == "latest" ]]; then | |
| npm run composer -- install --ignore-platform-req=php | |
| else | |
| npm run composer install | |
| fi | |
| - name: Versions | |
| run: | | |
| npm run env run cli php -- -v | |
| npm run env run cli wp core version | |
| - name: Test | |
| run: | | |
| npm run env run tests-cli --env-cwd=wp-content/plugins/two-factor -- mkdir -p tests/logs | |
| npm run test | |
| - name: Upload coverage report artifact | |
| if: ${{ matrix.php == '8.3' && matrix.wp == 'latest' }} | |
| uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1 | |
| with: | |
| name: coverage-report | |
| path: tests/logs/clover.xml | |
| if-no-files-found: error # Coverage silently going missing is the bug this is meant to fix. | |
| # Uploading to Codecov without a CODECOV_TOKEN requires OIDC (`id-token: write`). | |
| # That permission is kept out of the test jobs, which run npm/Composer dependencies | |
| # and the test suite; this job only runs the pinned actions below. The Codecov badge | |
| # reflects the default branch, so uploading on pushes is sufficient and no PR-triggered | |
| # run ever holds the permission. | |
| coverage: | |
| name: Upload code coverage | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 10 | |
| needs: test-php | |
| if: ${{ github.event_name == 'push' }} | |
| permissions: | |
| contents: read # Required to clone the repo, which Codecov uses to attribute the report. | |
| id-token: write # Required for tokenless (OIDC) upload to Codecov. | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 | |
| - name: Download coverage report artifact | |
| uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1 | |
| with: | |
| name: coverage-report | |
| path: tests/logs | |
| - name: Upload code coverage report | |
| uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de | |
| with: | |
| use_oidc: true | |
| files: tests/logs/clover.xml | |
| flags: phpunit | |
| fail_ci_if_error: false | |
| build: | |
| name: Build | |
| runs-on: ubuntu-24.04 | |
| timeout-minutes: 20 | |
| permissions: | |
| contents: read # Required to clone the repo. | |
| steps: | |
| - name: Checkout | |
| uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0 | |
| - name: Setup PHP | |
| uses: shivammathur/setup-php@accd6127cb78bee3e8082180cb391013d204ef9f # v2.37.0 | |
| with: | |
| php-version: '8.3' | |
| - name: Setup Node | |
| uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0 | |
| with: | |
| cache: 'npm' | |
| node-version-file: '.nvmrc' | |
| - name: Install NPM dependencies | |
| run: npm install | |
| - name: Build | |
| run: npm run build |