Repository navigation
ci: bump codecov-action to v7.1.1 to fix Codecov CLI signature checks - #43999
Closed
pylaterreur wants to merge 1 commit into
Closed
pylaterreur wants to merge 1 commit into
pylaterreur wants to merge 1 commit into
Conversation
Codecov lost the ability to update its keybase.io/codecovsecurity account in June 2026, deleted it, and now serves the same CLI signing key from keybase.io/codecovsecops. codecov-action v5.5.4 still downloads the key from the old URL, which now returns a 404, so gpg imports nothing and cannot verify the signature on the CLI's SHA256SUM file The Lens database coverage upload added in BerriAI#43889 is the only upload with fail_ci_if_error set to true, so it exits 1 there and has kept the proxy-behavior job of Postgres Tests red on main since that merge. The other three uploads log the same error, then run the CLI after checking it only against a checksum fetched from the same server, and upload anyway Bump all four pins to v7.1.1, which reads the key from the new account and retries the download, and pin the CLI to v11.3.1 instead of latest, the version .circleci/tests.yml already pins. This is the CI part of BerriAI#43881 on its own, line for line. The releases in between also move the action's internal github-script step to Node 24, which hosted runners already force, and stop expanding inputs directly inside its shell steps. Every input these steps passed before is unchanged
Contributor
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Author
|
Closing as superseded by #43983, which fixed the same Codecov signature failure |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
TLDR
Problem this solves:
How it solves it:
fail_ci_if_error: trueon the Lens upload, as feat(lens): analyze agent activity with a separate worker #43889 set itThis is the CI hunk of #43881 on its own, line for line, so main can go green without waiting on that feature PR. The best-effort uploads hid the problem since Codecov moved the key in early June, because codecov-action only logs a failed signature check when
fail_ci_if_erroris falseUser Flow
Before: a contributor's pull request gets a red Postgres Tests check that has nothing to do with their change
proxy-behaviorjobUpload Lens database coverageprintsgpg: Can't check signature: No public keyCould not verify signature. Please contact Codecov if problem continuesand the check goes redAfter: the same pull request gets a green check and its Lens coverage reaches Codecov
proxy-behaviorjobUpload Lens database coverageprintsgpg: Good signaturefor the Codecov Uploader keyUpload queued for processing completeand the check stays greenRelevant issues
Same CI change as #43881, split out of that feature PR
The red check started with #43889, which added the first upload with
fail_ci_if_error: trueCodecov's announcement of the key move: codecov/codecov-action#1956
Pre-Submission checklist
Please complete all items before asking a LiteLLM maintainer to review your PR
uv run pytest tests/unit/<your_test_file>.py -v. Leave the suites (make test-unit-*,make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more@greptileaito re-request a review after pushing changes)No tests, since the change only moves action and CLI pins. The CI runs under Proof of Fix are the check.
check_workflow_startup_safety.py,check_workflow_job_name_collisions.pyandassert_workflow_dir_hygiene.pypass, and zizmor 1.24.1 with online audits and actionlint 1.7.12 report nothing new on the three workflowsDelays in PR merge?
If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).
Screenshots / Proof of Fix
This PR changes the same three files, line for line, as the CI part of #43881
Before (0980f75)
Lens database coverage upload
proxy-behaviorin Postgres Tests on the main push, job 110240402606Upload Lens database coveragelogsgpg: no valid OpenPGP data found.and thengpg: Can't check signature: No public keyCould not verify signature. Please contact Codecov if problem continuesandExiting..., so the job failsBest-effort unit coverage upload
core-utils / Upload coverage to Codecovon the same main commit, job 110241712324Could not verify signature. Please contact Codecov if problem continuesCLI integrity verified, which only compares a checksum from the same server, thenUpload queued for processing complete, and the job passesAfter (788f4ca)
Lens database coverage upload
proxy-behaviorin Postgres Tests on this PR, job 110312025939Upload Lens database coveragelogsVersion: v11.3.1andgpg: key 806BB28AED779869: public key "Codecov Uploader (Codecov Uploader Verification Key) <security@codecov.io>" importedgpg: Good signature,CLI integrity verifiedandUpload queued for processing complete, so the job passesBest-effort unit coverage upload
core-utils / Upload coverage to Codecovon this PR, job 110314978279gpg: Good signaturelinesUpload queued for processing complete, and the job passesType
Infrastructure
Caveats (if any)
Low
cleanupversionbumpfail_ci_if_error: true