From b45d9c851488cb8e3545328354e49c0717cca104 Mon Sep 17 00:00:00 2001 From: Kevin Tang <73975146+vt128@users.noreply.github.com> Date: Sun, 20 Sep 2026 01:32:15 +0800 Subject: [PATCH 1/2] [ci] authenticate coverage uploads with GitHub OIDC --- .github/workflows/go-ci.yml | 5 ++++- .github/workflows/selftest.yml | 3 +++ 2 files changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/go-ci.yml b/.github/workflows/go-ci.yml index 59bf408..5c64722 100644 --- a/.github/workflows/go-ci.yml +++ b/.github/workflows/go-ci.yml @@ -16,6 +16,8 @@ name: Go CI # ubuntu-22.04 / macos-14 / windows-2022. Static checks (vet, gofmt, # go mod tidy) and govulncheck run once, on the latest-Go Linux leg; # coverage uploads run on the floor Linux leg (the established report leg). +# Callers must grant contents: read and id-token: write to the calling job; +# Codecov authenticates the short-lived GitHub OIDC identity, not a stored token. # # This workflow is self-tested in meta itself: .github/workflows/selftest.yml # calls it against the selftest/ fixture, so changes here are validated before @@ -97,6 +99,7 @@ jobs: - "1.27.x" permissions: contents: read + id-token: write steps: - uses: actions/checkout@v5 - name: Set up Go @@ -165,7 +168,7 @@ jobs: continue-on-error: true uses: codecov/codecov-action@v5 with: - token: ${{ secrets.CODECOV_TOKEN }} + use_oidc: true files: ${{ inputs.working-directory }}/coverage.txt - name: Upload Coverage Reports to Codacy if: ${{ fromJSON(env.IS_REPORT) }} diff --git a/.github/workflows/selftest.yml b/.github/workflows/selftest.yml index 75ca9f9..72720bb 100644 --- a/.github/workflows/selftest.yml +++ b/.github/workflows/selftest.yml @@ -14,6 +14,9 @@ permissions: read-all jobs: selftest: + permissions: + contents: read + id-token: write uses: ./.github/workflows/go-ci.yml with: go-floor: "1.19" From f17052ddaaae6df5e08703b3cc418619ab4c72a8 Mon Sep 17 00:00:00 2001 From: Kevin Tang <73975146+vt128@users.noreply.github.com> Date: Sun, 20 Sep 2026 01:36:12 +0800 Subject: [PATCH 2/2] [ci] limit reusable workflow permission requests --- .github/workflows/go-ci.yml | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/.github/workflows/go-ci.yml b/.github/workflows/go-ci.yml index 5c64722..1931295 100644 --- a/.github/workflows/go-ci.yml +++ b/.github/workflows/go-ci.yml @@ -70,7 +70,9 @@ on: CODACY_PROJECT_TOKEN: required: false -permissions: read-all +permissions: + contents: read + id-token: write jobs: build: