Compare commits

...

12 Commits

Author SHA1 Message Date
dependabot[bot]
b9c1e392ac build(deps): bump actions/checkout from 5.0.0 to 6.0.1
Bumps [actions/checkout](https://github.com/actions/checkout) from 5.0.0 to 6.0.1.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v5.0.0...v6.0.1)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 6.0.1
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2025-12-08 04:01:36 +00:00
Miguel Angel Rojo
96b38e9e60 chore: disable_search alignment (#1881)
chore: disable_search alignment
2025-11-19 18:34:32 +05:00
maxweng-sentry
9b6d1f84bd check gpg only when skip-validation = false (#1894) 2025-11-11 14:37:52 -08:00
Tom Hu
5a1091511a chore(release): 5.5.1 (#1873) 2025-09-04 16:35:45 +02:00
Tom Hu
3e0ce21cac fix: overwrite pr number on fork (#1871) 2025-09-04 16:28:19 +02:00
dependabot[bot]
c4741c8197 build(deps): bump actions/checkout from 4.2.2 to 5.0.0 (#1868)
Bumps [actions/checkout](https://github.com/actions/checkout) from 4.2.2 to 5.0.0.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](https://github.com/actions/checkout/compare/v4.2.2...v5.0.0)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: 5.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-04 16:28:07 +02:00
dependabot[bot]
17370e8add build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 (#1867)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.29.9 to 3.29.11.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v3.29.9...v3.29.11)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 3.29.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-09-04 16:27:59 +02:00
Tom Hu
18fdacf0ce fix: update to use local app/ dir (#1872)
* fix: update to use local app/ dir

* fix: update if statement on macos xlarge
2025-09-04 16:18:57 +02:00
Min
206148c4b8 docs: fix typo in README (#1866)
fix typo
2025-09-04 14:39:40 +02:00
🇺🇦 Sviatoslav Sydorenko (Святослав Сидоренко)
3cb13a1234 Document a codecov-cli version reference example (#1774)
* Document a `codecov-cli` version reference example

* Recover the mention of `v` in the text
2025-08-20 17:21:20 +02:00
dependabot[bot]
a4803c1f8d build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 (#1861)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.28.18 to 3.29.9.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](https://github.com/github/codeql-action/compare/v3.28.18...v3.29.9)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 3.29.9
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-20 17:18:57 +02:00
dependabot[bot]
3139621497 build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 (#1833)
Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.1 to 2.4.2.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- [Commits](f49aabe0b5...05b42c6244)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-version: 2.4.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2025-08-20 17:18:38 +02:00
12 changed files with 100 additions and 27 deletions

View File

@@ -37,11 +37,11 @@ jobs:
steps: steps:
- name: Checkout repository - name: Checkout repository
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
# Initializes the CodeQL tools for scanning. # Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL - name: Initialize CodeQL
uses: github/codeql-action/init@v3.28.18 uses: github/codeql-action/init@v3.30.0
with: with:
languages: ${{ matrix.language }} languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file. # If you wish to specify custom queries, you can do so here or in a config file.
@@ -52,7 +52,7 @@ jobs:
# Autobuild attempts to build any compiled languages (C/C++, C#, or Java). # Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below) # If this step fails, then you should remove it and run the build manually (see below)
- name: Autobuild - name: Autobuild
uses: github/codeql-action/autobuild@v3.28.18 uses: github/codeql-action/autobuild@v3.30.0
# Command-line programs to run using the OS shell. # Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl # 📚 https://git.io/JvXDl
@@ -66,4 +66,4 @@ jobs:
# make release # make release
- name: Perform CodeQL Analysis - name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3.28.18 uses: github/codeql-action/analyze@v3.30.0

View File

@@ -12,13 +12,13 @@ jobs:
os: [macos-latest, windows-latest, ubuntu-latest] os: [macos-latest, windows-latest, ubuntu-latest]
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
with: with:
submodules: "true" submodules: "true"
- name: Install dependencies - name: Install dependencies
run: pip install -r src/scripts/app/requirements.txt run: pip install -r app/requirements.txt
- name: Run tests and collect coverage - name: Run tests and collect coverage
run: pytest src/scripts/app/ --cov run: pytest app/ --cov
- name: Upload coverage to Codecov (script) - name: Upload coverage to Codecov (script)
uses: ./ uses: ./
@@ -50,17 +50,17 @@ jobs:
token: ${{ secrets.CODECOV_TOKEN }} token: ${{ secrets.CODECOV_TOKEN }}
run-macos-latest-xlarge: run-macos-latest-xlarge:
if: github.head.repo.full_name == 'codecov/codecov-action' if: github.event.pull_request.head.repo.full_name == 'codecov/codecov-action'
runs-on: macos-latest-xlarge runs-on: macos-latest-xlarge
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
with: with:
submodules: "true" submodules: "true"
- name: Install dependencies - name: Install dependencies
run: pip install -r src/scripts/app/requirements.txt run: pip install -r app/requirements.txt
- name: Run tests and collect coverage - name: Run tests and collect coverage
run: pytest src/scripts/app/ --cov run: pytest app/ --cov
- name: Upload coverage to Codecov (script) - name: Upload coverage to Codecov (script)
uses: ./ uses: ./
with: with:
@@ -103,7 +103,7 @@ jobs:
container: python:latest container: python:latest
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
with: with:
submodules: "true" submodules: "true"
- name: Install deps - name: Install deps
@@ -144,7 +144,7 @@ jobs:
run: | run: |
apk add git apk add git
- name: Checkout - name: Checkout
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
with: with:
submodules: "true" submodules: "true"
- name: Upload coverage to Codecov (should fail due to missing dependencies) - name: Upload coverage to Codecov (should fail due to missing dependencies)
@@ -175,7 +175,7 @@ jobs:
run: | run: |
apk add git curl gnupg bash apk add git curl gnupg bash
- name: Checkout - name: Checkout
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
with: with:
submodules: "true" submodules: "true"
- name: Upload coverage to Codecov (should succeed) - name: Upload coverage to Codecov (should succeed)
@@ -212,7 +212,7 @@ jobs:
run: | run: |
apk add git curl apk add git curl
- name: Checkout - name: Checkout
uses: actions/checkout@v4.2.2 uses: actions/checkout@v6.0.1
with: with:
submodules: "true" submodules: "true"
- name: Upload coverage to Codecov (should fail due to missing gpg and bash) - name: Upload coverage to Codecov (should fail due to missing gpg and bash)

View File

@@ -25,12 +25,12 @@ jobs:
steps: steps:
- name: "Checkout code" - name: "Checkout code"
uses: actions/checkout@v4.2.2 # v3.0.0 uses: actions/checkout@v6.0.1 # v3.0.0
with: with:
persist-credentials: false persist-credentials: false
- name: "Run analysis" - name: "Run analysis"
uses: ossf/scorecard-action@f49aabe0b5af0936a0987cfb85d86b75731b0186 # v2.4.1 uses: ossf/scorecard-action@05b42c624433fc40578a4040d5cf5e36ddca8cde # v2.4.2
with: with:
results_file: results.sarif results_file: results.sarif
results_format: sarif results_format: sarif
@@ -57,6 +57,6 @@ jobs:
# Upload the results to GitHub's code scanning dashboard. # Upload the results to GitHub's code scanning dashboard.
- name: "Upload to code-scanning" - name: "Upload to code-scanning"
uses: github/codeql-action/upload-sarif@v3.28.18 # v1.0.26 uses: github/codeql-action/upload-sarif@v3.30.0 # v1.0.26
with: with:
sarif_file: results.sarif sarif_file: results.sarif

3
.gitignore vendored
View File

@@ -93,3 +93,6 @@ public/
# macOS Finder metadata # macOS Finder metadata
.DS_Store .DS_Store
# pycache dirs
__pycache__/

View File

@@ -1,3 +1,19 @@
## v5.5.1
### What's Changed
* fix: overwrite pr number on fork by @thomasrockhu-codecov in https://github.com/codecov/codecov-action/pull/1871
* build(deps): bump actions/checkout from 4.2.2 to 5.0.0 by @app/dependabot in https://github.com/codecov/codecov-action/pull/1868
* build(deps): bump github/codeql-action from 3.29.9 to 3.29.11 by @app/dependabot in https://github.com/codecov/codecov-action/pull/1867
* fix: update to use local app/ dir by @thomasrockhu-codecov in https://github.com/codecov/codecov-action/pull/1872
* docs: fix typo in README by @datalater in https://github.com/codecov/codecov-action/pull/1866
* Document a `codecov-cli` version reference example by @webknjaz in https://github.com/codecov/codecov-action/pull/1774
* build(deps): bump github/codeql-action from 3.28.18 to 3.29.9 by @app/dependabot in https://github.com/codecov/codecov-action/pull/1861
* build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 by @app/dependabot in https://github.com/codecov/codecov-action/pull/1833
**Full Changelog**: https://github.com/codecov/codecov-action/compare/v5.5.0..v5.5.1
## v5.5.0 ## v5.5.0
### What's Changed ### What's Changed

View File

@@ -14,8 +14,8 @@
The `v5` release also coincides with the opt-out feature for tokens for public repositories. In the `Global Upload Token` section of the settings page of an organization in codecov.io, you can set the ability for Codecov to receive a coverage reports from any source. This will allow contributors or other members of a repository to upload without needing access to the Codecov token. For more details see [how to upload without a token](https://docs.codecov.com/docs/codecov-tokens#uploading-without-a-token). The `v5` release also coincides with the opt-out feature for tokens for public repositories. In the `Global Upload Token` section of the settings page of an organization in codecov.io, you can set the ability for Codecov to receive a coverage reports from any source. This will allow contributors or other members of a repository to upload without needing access to the Codecov token. For more details see [how to upload without a token](https://docs.codecov.com/docs/codecov-tokens#uploading-without-a-token).
> [!WARNING] > **The following arguments have been changed** > [!WARNING]
> > **The following arguments have been changed**
> - `file` (this has been deprecated in favor of `files`) > - `file` (this has been deprecated in favor of `files`)
> - `plugin` (this has been deprecated in favor of `plugins`) > - `plugin` (this has been deprecated in favor of `plugins`)
@@ -140,7 +140,7 @@ Codecov's Action supports inputs from the user. These inputs, along with their d
| `env_vars` | Environment variables to tag the upload with (e.g. PYTHON \| OS,PYTHON) | Optional | `env_vars` | Environment variables to tag the upload with (e.g. PYTHON \| OS,PYTHON) | Optional
| `exclude` | Comma-separated list of folders to exclude from search. | Optional | `exclude` | Comma-separated list of folders to exclude from search. | Optional
| `fail_ci_if_error` | On error, exit with non-zero code | Optional | `fail_ci_if_error` | On error, exit with non-zero code | Optional
| `files` | Comma-separated explicit list of files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using "disable-search" to disable uploading other files. | Optional | `files` | Comma-separated explicit list of files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using "disable_search" to disable uploading other files. | Optional
| `flags` | Comma-separated list of flags to upload to group coverage metrics. | Optional | `flags` | Comma-separated list of flags to upload to group coverage metrics. | Optional
| `force` | Only used for empty-upload run command | Optional | `force` | Only used for empty-upload run command | Optional
| `git_service` | Override the git_service (e.g. github_enterprise) | Optional | `git_service` | Override the git_service (e.g. github_enterprise) | Optional
@@ -174,7 +174,7 @@ Codecov's Action supports inputs from the user. These inputs, along with their d
| `use_oidc` | Use OIDC instead of token. This will ignore any token supplied | Optional | `use_oidc` | Use OIDC instead of token. This will ignore any token supplied | Optional
| `use_pypi` | Use the pypi version of the CLI instead of from cli.codecov.io. If specified, integrity checking will be bypassed. | Optional | `use_pypi` | Use the pypi version of the CLI instead of from cli.codecov.io. If specified, integrity checking will be bypassed. | Optional
| `verbose` | Enable verbose logging | Optional | `verbose` | Enable verbose logging | Optional
| `version` | Which version of the Codecov CLI to use (defaults to 'latest') | Optional | `version` | Which version of the Codecov CLI to use (defaults to 'latest', must start with a leading 'v'; example: `v10.0.1`) | Optional
| `working-directory` | Directory in which to execute codecov.sh | Optional | `working-directory` | Directory in which to execute codecov.sh | Optional
### Example `workflow.yml` with Codecov Action ### Example `workflow.yml` with Codecov Action

View File

@@ -50,7 +50,7 @@ inputs:
required: false required: false
default: 'false' default: 'false'
files: files:
description: 'Comma-separated list of explicit files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using disable-search to disable uploading other files.' description: 'Comma-separated list of explicit files to upload. These will be added to the coverage files found for upload. If you wish to only upload the specified files, please consider using disable_search to disable uploading other files.'
required: false required: false
flags: flags:
description: 'Comma-separated list of flags to upload to group coverage metrics.' description: 'Comma-separated list of flags to upload to group coverage metrics.'
@@ -180,13 +180,20 @@ runs:
run: | run: |
missing_deps="" missing_deps=""
# Check for required commands # Check for always-required commands
for cmd in bash git curl gpg; do for cmd in bash git curl; do
if ! command -v "$cmd" >/dev/null 2>&1; then if ! command -v "$cmd" >/dev/null 2>&1; then
missing_deps="$missing_deps $cmd" missing_deps="$missing_deps $cmd"
fi fi
done done
# Check for gpg only if validation is not being skipped
if [ "${{ inputs.skip_validation }}" != "true" ]; then
if ! command -v gpg >/dev/null 2>&1; then
missing_deps="$missing_deps gpg"
fi
fi
# Report missing required dependencies # Report missing required dependencies
if [ -n "$missing_deps" ]; then if [ -n "$missing_deps" ]; then
echo "Error: The following required dependencies are missing:$missing_deps" echo "Error: The following required dependencies are missing:$missing_deps"
@@ -282,7 +289,7 @@ runs:
then then
CC_SHA="$GITHUB_EVENT_PULL_REQUEST_HEAD_SHA" CC_SHA="$GITHUB_EVENT_PULL_REQUEST_HEAD_SHA"
fi fi
if [ -z "$CC_PR" ] && [ "${GITHUB_EVENT_NAME}" == "pull_request_target" ]; if [ -z "$CC_PR" ] && [ "$CC_FORK" == 'true' ];
then then
CC_PR="$GITHUB_EVENT_NUMBER" CC_PR="$GITHUB_EVENT_NUMBER"
fi fi

0
app/__init__.py Normal file
View File

15
app/calculator.py Normal file
View File

@@ -0,0 +1,15 @@
class Calculator:
def add(x, y):
return x + y
def subtract(x, y):
return x - y
def multiply(x, y):
return x * y
def divide(x, y):
if y == 0:
return 'Cannot divide by 0'
return x * 1.0 / y

1
app/requirements.txt Normal file
View File

@@ -0,0 +1 @@
pytest-cov

31
app/test_calculator.py Normal file
View File

@@ -0,0 +1,31 @@
from .calculator import Calculator
def test_add():
assert Calculator.add(1, 2) == 3.0
assert Calculator.add(1.0, 2.0) == 3.0
assert Calculator.add(0, 2.0) == 2.0
assert Calculator.add(2.0, 0) == 2.0
assert Calculator.add(-4, 2.0) == -2.0
def test_subtract():
assert Calculator.subtract(1, 2) == -1.0
assert Calculator.subtract(2, 1) == 1.0
assert Calculator.subtract(1.0, 2.0) == -1.0
assert Calculator.subtract(0, 2.0) == -2.0
assert Calculator.subtract(2.0, 0.0) == 2.0
assert Calculator.subtract(-4, 2.0) == -6.0
def test_multiply():
assert Calculator.multiply(1, 2) == 2.0
assert Calculator.multiply(1.0, 2.0) == 2.0
assert Calculator.multiply(0, 2.0) == 0.0
assert Calculator.multiply(2.0, 0.0) == 0.0
assert Calculator.multiply(-4, 2.0) == -8.0
def test_divide():
# assert Calculator.divide(1, 2) == 0.5
assert Calculator.divide(1.0, 2.0) == 0.5
assert Calculator.divide(0, 2.0) == 0
assert Calculator.divide(-4, 2.0) == -2.0
# assert Calculator.divide(2.0, 0.0) == 'Cannot divide by 0'

View File

@@ -1 +1 @@
5.5.0 5.5.1