Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[UX] "Branch `main` is protected but no token was provided" is a lie

Abierto
#801 2 comentarios 1 reacción 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
3/5
Tiempo estimado
1-2 días
Aptitud para principiantes
59/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
github-actions, python

Línea de trabajo

Start by reading codecov_cli/services/commit/__init__.py at the linked warning location, then trace how the CLI handles token requirements for GitHub Actions and where the backend/API error is produced. The issue suggests clarifying the message to direct users to check OIDC permissions; done means the messages no longer falsely attribute the missing token to branch protection.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

bug

Describe the bug

This was mentioned in the action @ https://github.com/codecov/codecov-action/issues/1918, and I've seen it before, I think.
Today, I saw it my CI, when I was wiring new repo, so I decided to take a closer look.

The uploader is pretty sure that the branch is not protected and claims so in this warning: https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492. Then, it uses that as an excuse to explain why the token is needed saying that Token required because branch is protected in the error a few lines below.

The token might be expected, but the cause in the messages is untrue. The repository is new and doesn't have branch protection or rulesets configured. I think, this is what's been confusing people.

So it's sort of a UX problem. But also, it's a bit of an abstraction leak because people using GHA expect that the problem is in the action because they see the action printing out the error while the code is in the CLI which is kinda separate 🤷‍♂️

Expected behavior

I suppose the error message could be made cleaner to tell people to check if they'd enabled OIDC in the permissions key in the job definition if they use GitHub Actions CI/CD.

Regression

It's been like this since inception I recon 🤷‍♂️

Screenshots

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Product Area

coverage and test data uploaders

Versions

  • OS: N/A
  • Git Host: GitHub
  • CI/CD: GitHub Actions CI/CD
  • Uploader: codecov-action@v7

Commit and CI link

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Additional context

Here's where the warning is lying: https://github.com/codecov/codecov-cli/blame/c7e7bc0ce4fd57b0e349b3e09fcfed7e16f69637/codecov_cli/services/commit/__init__.py#L66

And the error lie is coming from the backend/API.

Lenguaje dominante
Python
Estrellas
90
Forks
65
Métricas de merge de PR
Sin PR fusionados en 30 d

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de codecov/codecov-cli

Todos los issues de codecov/codecov-cli

Issues similares

Más issues de Python

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.