Skip to content

Commit fd4fdfc

Browse files
committed
CI: use OIDC for CodeCov
This uses a short-lived token which is better for security.
1 parent c06331b commit fd4fdfc

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

.github/workflows/main.yml

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -69,6 +69,8 @@ jobs:
6969
7070
test-wheels:
7171
runs-on: ubuntu-latest
72+
permissions:
73+
id-token: write
7274
container:
7375
image: ${{ env.DOCKER_IMAGE }}:latest
7476
credentials:
@@ -154,6 +156,6 @@ jobs:
154156
155157
uses: codecov/codecov-action@18283e04ce6e62d37312384ff67231eb8fd56d24 # v5.4.3
156158
with:
157-
token: ${{ secrets.CODECOV_TOKEN }}
159+
use_oidc: true
158160
fail_ci_if_error: false
159161
verbose: false

0 commit comments

Comments
 (0)