From 788f4ca5aad21195bbd4bdc91dbb0180d97c4875 Mon Sep 17 00:00:00 2001 From: Pierre-Yves Le Borgne Date: Thu, 1 Oct 2026 01:03:13 +0100 Subject: [PATCH] ci: bump codecov-action to v7.1.1 to fix Codecov CLI signature checks Codecov lost the ability to update its keybase.io/codecovsecurity account in June 2026, deleted it, and now serves the same CLI signing key from keybase.io/codecovsecops. codecov-action v5.5.4 still downloads the key from the old URL, which now returns a 404, so gpg imports nothing and cannot verify the signature on the CLI's SHA256SUM file The Lens database coverage upload added in #43889 is the only upload with fail_ci_if_error set to true, so it exits 1 there and has kept the proxy-behavior job of Postgres Tests red on main since that merge. The other three uploads log the same error, then run the CLI after checking it only against a checksum fetched from the same server, and upload anyway Bump all four pins to v7.1.1, which reads the key from the new account and retries the download, and pin the CLI to v11.3.1 instead of latest, the version .circleci/tests.yml already pins. This is the CI part of #43881 on its own, line for line. The releases in between also move the action's internal github-script step to Node 24, which hosted runners already force, and stop expanding inputs directly inside its shell steps. Every input these steps passed before is unchanged --- .github/workflows/_test-unit-base.yml | 6 ++++-- .github/workflows/test-postgres.yml | 3 ++- .github/workflows/test-redis-compat.yml | 3 ++- 3 files changed, 8 insertions(+), 4 deletions(-) diff --git a/.github/workflows/_test-unit-base.yml b/.github/workflows/_test-unit-base.yml index fac0d766535c..4c3a561e8596 100644 --- a/.github/workflows/_test-unit-base.yml +++ b/.github/workflows/_test-unit-base.yml @@ -274,8 +274,9 @@ jobs: - name: Upload to Codecov id: codecov-upload continue-on-error: true - uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5.5.4 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: + version: v11.3.1 use_oidc: true directory: coverage-reports root_dir: ${{ github.workspace }} @@ -285,8 +286,9 @@ jobs: - name: Upload to Codecov (retry) if: steps.codecov-upload.outcome == 'failure' continue-on-error: true - uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5.5.4 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: + version: v11.3.1 use_oidc: true directory: coverage-reports root_dir: ${{ github.workspace }} diff --git a/.github/workflows/test-postgres.yml b/.github/workflows/test-postgres.yml index 1ffb7f67f16f..f90e9aa0c497 100644 --- a/.github/workflows/test-postgres.yml +++ b/.github/workflows/test-postgres.yml @@ -145,8 +145,9 @@ jobs: - name: Upload Lens database coverage if: steps.changes.outputs.decision != 'skip' && matrix.shard == 'proxy-behavior' && !cancelled() - uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5.5.4 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: + version: v11.3.1 use_oidc: true files: coverage-lens-postgres.xml flags: lens-postgres diff --git a/.github/workflows/test-redis-compat.yml b/.github/workflows/test-redis-compat.yml index 0423b014ec58..c779674f6961 100644 --- a/.github/workflows/test-redis-compat.yml +++ b/.github/workflows/test-redis-compat.yml @@ -98,8 +98,9 @@ jobs: - name: Upload Redis coverage if: matrix.redis-version == '5.3.1' - uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5.5.4 + uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1 with: + version: v11.3.1 use_oidc: true files: coverage-redis.xml flags: redis-compat