Skip to content

Commit e01e9e7

Browse files
committed
CI: use OIDC for CodeCov
This uses a short-lived token which is better for security.
1 parent 7ad2b3d commit e01e9e7

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

.github/workflows/main.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,8 @@ jobs:
6666
6767
test-wheels:
6868
runs-on: ubuntu-latest
69+
permissions:
70+
id-token: write
6971
container:
7072
image: ghcr.io/opendatacube/odc-stats:latest
7173
credentials:
@@ -151,6 +153,6 @@ jobs:
151153
152154
uses: codecov/codecov-action@18283e04ce6e62d37312384ff67231eb8fd56d24 # v5.4.3
153155
with:
154-
token: ${{ secrets.CODECOV_TOKEN }}
156+
use_oidc: true
155157
fail_ci_if_error: false
156158
verbose: false

0 commit comments

Comments
 (0)