Skip to content

Fix Codecov badge by adding OIDC permission for tokenless upload #1551

Fix Codecov badge by adding OIDC permission for tokenless upload

Fix Codecov badge by adding OIDC permission for tokenless upload #1551

Workflow file for this run

name: Test
on: [push, pull_request]
# Cancels all previous workflow runs for pull requests that have not completed.
concurrency:
# The concurrency group contains the workflow name and the branch name for pull requests
# or the commit hash for any other events.
group: ${{ github.workflow }}-${{ github.event_name == 'pull_request' && github.head_ref || github.sha }}
cancel-in-progress: true
# Disable permissions for all available scopes by default.
# Any needed permissions should be configured at the job level.
permissions: {}
jobs:
lint-js-css:
name: Lint JS & CSS
runs-on: ubuntu-24.04
timeout-minutes: 20
permissions:
contents: read # Required to clone the repo.
steps:
- name: Checkout
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
- name: Setup Node
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
cache: 'npm'
node-version-file: '.nvmrc'
- name: Install NPM dependencies
run: npm install
- name: Lint JS
run: npm run lint:js
- name: Lint CSS
run: npm run lint:css
lint-php-and-compatibility:
name: Lint PHP & PHP Compatibility checks.
runs-on: ubuntu-24.04
timeout-minutes: 20
permissions:
contents: read # Required to clone the repo.
steps:
- name: Checkout
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
- name: Setup PHP and Composer
uses: shivammathur/setup-php@accd6127cb78bee3e8082180cb391013d204ef9f # v2.37.0
with:
php-version: '8.3'
- name: Setup Node
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
cache: 'npm'
node-version-file: '.nvmrc'
- name: Install NPM dependencies
run: npm install
- name: Lint PHP
run: npm run lint:php || true # Ignore for now.
- name: Lint PHP Compatibility
run: composer lint-compat
- name: PHPStan
run: npm run lint:phpstan
test-php:
name: Test PHP ${{ matrix.php }} ${{ matrix.wp != '' && format( ' (WP {0}) ', matrix.wp ) || '' }}
runs-on: ubuntu-24.04
timeout-minutes: 20
permissions:
contents: read # Required to clone the repo.
strategy:
matrix:
php:
- '8.5'
- '8.4'
- '8.3'
- '8.2'
- '8.1'
- '8.0'
- '7.4'
- '7.3'
- '7.2'
wp:
- latest
- trunk
- '6.9'
exclude:
- php: '7.3'
wp: trunk
- php: '7.2'
wp: trunk
- php: '7.3'
wp: latest
- php: '7.2'
wp: latest
env:
WP_ENV_PHP_VERSION: ${{ matrix.php }}
WP_ENV_CORE: ${{ matrix.wp == 'trunk' && 'WordPress/WordPress' || format( 'https://wordpress.org/wordpress-{0}.zip', matrix.wp ) }}
steps:
- name: Checkout
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
- name: Setup PHP
uses: shivammathur/setup-php@accd6127cb78bee3e8082180cb391013d204ef9f # v2.37.0
with:
php-version: '8.3'
- name: Setup Node
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
cache: 'npm'
node-version-file: '.nvmrc'
- name: Install NPM dependencies
run: npm install
- name: Start the Docker testing environment
uses: nick-fields/retry@ad984534de44a9489a53aefd81eb77f87c70dc60 # v4.0.0
with:
timeout_minutes: 10
max_attempts: 3
command: npm run env start -- --xdebug=coverage
- name: Composer install
run: |
rm composer.lock || true # We need to install fresh.
# The composer.json platform override (php: 7.2.24) installs PHPUnit 8.5, which
# cannot generate code coverage on PHP 8. For the coverage build only, bypass the
# platform check so Composer installs PHPUnit 9.6. All other matrix jobs keep the
# default dependency set.
if [[ "${{ matrix.php }}" == "8.3" && "${{ matrix.wp }}" == "latest" ]]; then
npm run composer -- install --ignore-platform-req=php
else
npm run composer install
fi
- name: Versions
run: |
npm run env run cli php -- -v
npm run env run cli wp core version
- name: Test
run: |
npm run env run tests-cli --env-cwd=wp-content/plugins/two-factor -- mkdir -p tests/logs
npm run test
- name: Upload coverage report artifact
if: ${{ matrix.php == '8.3' && matrix.wp == 'latest' }}
uses: actions/upload-artifact@043fb46d1a93c77aae656e7c1c64a875d1fc6a0a # v7.0.1
with:
name: coverage-report
path: tests/logs/clover.xml
if-no-files-found: error # Coverage silently going missing is the bug this is meant to fix.
# Uploading to Codecov without a CODECOV_TOKEN requires OIDC (`id-token: write`).
# That permission is kept out of the test jobs, which run npm/Composer dependencies
# and the test suite; this job only runs the pinned actions below. The Codecov badge
# reflects the default branch, so uploading on pushes is sufficient and no PR-triggered
# run ever holds the permission.
coverage:
name: Upload code coverage
runs-on: ubuntu-24.04
timeout-minutes: 10
needs: test-php
if: ${{ github.event_name == 'push' }}
permissions:
contents: read # Required to clone the repo, which Codecov uses to attribute the report.
id-token: write # Required for tokenless (OIDC) upload to Codecov.
steps:
- name: Checkout
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
- name: Download coverage report artifact
uses: actions/download-artifact@3e5f45b2cfb9172054b4087a40e8e0b5a5461e7c # v8.0.1
with:
name: coverage-report
path: tests/logs
- name: Upload code coverage report
uses: codecov/codecov-action@671740ac38dd9b0130fbe1cec585b89eea48d3de
with:
use_oidc: true
files: tests/logs/clover.xml
flags: phpunit
fail_ci_if_error: false
build:
name: Build
runs-on: ubuntu-24.04
timeout-minutes: 20
permissions:
contents: read # Required to clone the repo.
steps:
- name: Checkout
uses: actions/checkout@1af3b93b6815bc44a9784bd300feb67ff0d1eeb3 # v6.0.0
- name: Setup PHP
uses: shivammathur/setup-php@accd6127cb78bee3e8082180cb391013d204ef9f # v2.37.0
with:
php-version: '8.3'
- name: Setup Node
uses: actions/setup-node@a0853c24544627f65ddf259abe73b1d18a591444 # v5.0.0
with:
cache: 'npm'
node-version-file: '.nvmrc'
- name: Install NPM dependencies
run: npm install
- name: Build
run: npm run build