Skip to content

fix(ci): use allow-listed codecov-action@v4 ref instead of a SHA pin#306

Open
demolaf wants to merge 3 commits into
mainfrom
fix/ci-codecov-action-allowlist
Open

fix(ci): use allow-listed codecov-action@v4 ref instead of a SHA pin#306
demolaf wants to merge 3 commits into
mainfrom
fix/ci-codecov-action-allowlist

Conversation

@demolaf

@demolaf demolaf commented Jul 23, 2026

Copy link
Copy Markdown
Member

No description provided.

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Note

Gemini is unable to generate a review for this pull request due to the file types involved not being currently supported.

@github-actions

Copy link
Copy Markdown

Coverage Report

✅ Coverage 75.48% meets 40% threshold

Total Coverage: 75.48%
Lines Covered: 5208/6900

Package Breakdown

Package Coverage
firebase_admin_sdk 72.66%
google_cloud_firestore 78.68%

Minimum threshold: 40%

@wiz-9635d3485b

wiz-9635d3485b Bot commented Jul 23, 2026

Copy link
Copy Markdown

Wiz Scan Summary

Scanner Findings
Vulnerability Finding Vulnerabilities -
Data Finding Sensitive Data -
Secret Finding Secrets -
IaC Misconfiguration IaC Misconfigurations 1 Low
SAST Finding SAST Findings -
Software Management Finding Software Management Findings -
Total 1 Low

View scan details in Wiz

To detect these findings earlier in the dev lifecycle, try using Wiz Code VS Code Extension.

@demolaf

demolaf commented Jul 23, 2026

Copy link
Copy Markdown
Member Author

The org's Actions allow-list only permits the literal ref codecov/codecov-action@v4, but this repo's zizmor scan mandates every action be SHA-pinned — and confirmed empirically, the allow-list rejects any SHA for this action, even the exact commit v4 points to.

These two policies directly conflict for this one action; someone with access to either the org allow-list or the zizmor mandatory-checks config needs to grant an exception.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant