Skip to content

ci: bump codecov-action to v7.1.1 to fix Codecov CLI signature checks - #43999

Closed
pylaterreur wants to merge 1 commit into
BerriAI:mainfrom
pylaterreur:fix-codecov-gpg-verification
Closed

pylaterreur wants to merge 1 commit into
BerriAI:mainfrom
pylaterreur:fix-codecov-gpg-verification

Conversation

@pylaterreur

@pylaterreur pylaterreur commented Oct 1, 2026 •

Copy link
Copy Markdown

TLDR

Problem this solves:

  • Codecov moved its CLI signing key to a new keybase.io account
  • codecov-action v5.5.4 still fetches the old URL, which now returns 404
  • Postgres Tests fails on main and PRs at the strict Lens upload
  • The three best-effort uploads log the same error and upload anyway

How it solves it:

This is the CI hunk of #43881 on its own, line for line, so main can go green without waiting on that feature PR. The best-effort uploads hid the problem since Codecov moved the key in early June, because codecov-action only logs a failed signature check when fail_ci_if_error is false

User Flow

Before: a contributor's pull request gets a red Postgres Tests check that has nothing to do with their change

  1. They open a pull request against main and Postgres Tests runs its proxy-behavior job
  2. The tests pass, then Upload Lens database coverage prints gpg: Can't check signature: No public key
  3. The step stops with Could not verify signature. Please contact Codecov if problem continues and the check goes red

After: the same pull request gets a green check and its Lens coverage reaches Codecov

  1. They open a pull request against main and Postgres Tests runs its proxy-behavior job
  2. The tests pass, then Upload Lens database coverage prints gpg: Good signature for the Codecov Uploader key
  3. The step ends with Upload queued for processing complete and the check stays green

Relevant issues

Same CI change as #43881, split out of that feature PR

The red check started with #43889, which added the first upload with fail_ci_if_error: true

Codecov's announcement of the key move: codecov/codecov-action#1956

Pre-Submission checklist

Please complete all items before asking a LiteLLM maintainer to review your PR

  • I have added meaningful tests
  • The handful of test files covering my change pass locally, e.g. uv run pytest tests/unit/<your_test_file>.py -v. Leave the suites (make test-unit-*, make test-unit) to CI: it finishes in ~15 minutes where a laptop takes an hour or more
  • My PR passes all required CI/CD checks (e.g., lint, schema.d.ts sync check, etc.)
  • My PR's scope is as isolated as possible; it only solves 1 specific problem
  • I have received a Greptile Confidence Score of at least 4/5 before requesting a maintainer review (Greptile reviews automatically once the PR is opened; only comment @greptileai to re-request a review after pushing changes)

No tests, since the change only moves action and CLI pins. The CI runs under Proof of Fix are the check. check_workflow_startup_safety.py, check_workflow_job_name_collisions.py and assert_workflow_dir_hygiene.py pass, and zizmor 1.24.1 with online audits and actionlint 1.7.12 report nothing new on the three workflows

Delays in PR merge?

If you're seeing a delay in your PR being merged, ping the LiteLLM Team on Slack (#pr-review).

Screenshots / Proof of Fix

This PR changes the same three files, line for line, as the CI part of #43881

Before (0980f75)

Lens database coverage upload

  1. proxy-behavior in Postgres Tests on the main push, job 110240402606
  2. Upload Lens database coverage logs gpg: no valid OpenPGP data found. and then gpg: Can't check signature: No public key
  3. It stops with Could not verify signature. Please contact Codecov if problem continues and Exiting..., so the job fails

Best-effort unit coverage upload

  1. core-utils / Upload coverage to Codecov on the same main commit, job 110241712324
  2. It logs the same two gpg lines and Could not verify signature. Please contact Codecov if problem continues
  3. It carries on to CLI integrity verified, which only compares a checksum from the same server, then Upload queued for processing complete, and the job passes

After (788f4ca)

Lens database coverage upload

  1. proxy-behavior in Postgres Tests on this PR, job 110312025939
  2. Upload Lens database coverage logs Version: v11.3.1 and gpg: key 806BB28AED779869: public key "Codecov Uploader (Codecov Uploader Verification Key) <security@codecov.io>" imported
  3. It logs gpg: Good signature, CLI integrity verified and Upload queued for processing complete, so the job passes

Best-effort unit coverage upload

  1. core-utils / Upload coverage to Codecov on this PR, job 110314978279
  2. It logs the same CLI version, key import and gpg: Good signature lines
  3. It ends with Upload queued for processing complete, and the job passes

Type

Infrastructure

Caveats (if any)

Low

  • Major bump from v5 to v7, with every input used here unchanged
    • v6 moved the action's internal github-script step to Node 24
    • v7 changed the key URL, v7.1 added retries and an opt-in cleanup
    • v5.5.5 has only the key URL fix, if staying on v5 matters
  • New CLI releases now need a manual version bump
  • Best-effort uploads still run the CLI if its signature check fails
    • codecov-action only stops on a bad signature with fail_ci_if_error: true
  • The Lens upload stays strict, so a keybase.io outage still fails it
    • v7.1.1 retries the key download three times before giving up

Codecov lost the ability to update its keybase.io/codecovsecurity
account in June 2026, deleted it, and now serves the same CLI signing
key from keybase.io/codecovsecops. codecov-action v5.5.4 still
downloads the key from the old URL, which now returns a 404, so gpg
imports nothing and cannot verify the signature on the CLI's SHA256SUM
file

The Lens database coverage upload added in BerriAI#43889 is the only upload
with fail_ci_if_error set to true, so it exits 1 there and has kept the
proxy-behavior job of Postgres Tests red on main since that merge. The
other three uploads log the same error, then run the CLI after checking
it only against a checksum fetched from the same server, and upload
anyway

Bump all four pins to v7.1.1, which reads the key from the new account
and retries the download, and pin the CLI to v11.3.1 instead of latest,
the version .circleci/tests.yml already pins. This is the CI part of
BerriAI#43881 on its own, line for line. The releases in between also move
the action's internal github-script step to Node 24, which hosted
runners already force, and stop expanding inputs directly inside its
shell steps. Every input these steps passed before is unchanged
@pylaterreur
pylaterreur requested a review from a team October 1, 2026 09:44
@greptile-apps

greptile-apps Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Updates CI workflow dependency to codecov action.

The PR appears safe to merge; no actionable regression was identified.

Summary

This PR updates all four GitHub Actions Codecov uploads to codecov-action v7.1.1 and pins their CLI to v11.3.1. It preserves the existing upload inputs and the strict failure setting for Lens coverage.

Reviews (1) · Last reviewed commit: "ci: bump codecov-action to v7.1.1 to fix..."

@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@pylaterreur

Copy link
Copy Markdown
Author

Closing as superseded by #43983, which fixed the same Codecov signature failure

@pylaterreur pylaterreur closed this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant