Hacktoberfest 2026 : les issues que les mainteneurs ont marquées pour octobre, ouvertes et accessibles aux débutants. Parcourir les issues Hacktoberfest

[UX] "Branch `main` is protected but no token was provided" is a lie

Ouverte
#801 2 commentaires 1 réaction 0 personnes assignées Voir sur GitHub

Personne n'a encore pris cette issue.

Évaluation

Difficulté
3/5
Temps estimé
1-2 jours
Accessibilité débutants
59/100
Type d'issue
Bug
Clarté
Plutôt claire
Activité
Active
Stack technique
github-actions, python

Piste de recherche

Start by reading codecov_cli/services/commit/__init__.py at the linked warning location, then trace how the CLI handles token requirements for GitHub Actions and where the backend/API error is produced. The issue suggests clarifying the message to direct users to check OIDC permissions; done means the messages no longer falsely attribute the missing token to branch protection.

Rédigé par le modèle d'indexation à partir du texte de l'issue.

Description

bug

Describe the bug

This was mentioned in the action @ https://github.com/codecov/codecov-action/issues/1918, and I've seen it before, I think.
Today, I saw it my CI, when I was wiring new repo, so I decided to take a closer look.

The uploader is pretty sure that the branch is not protected and claims so in this warning: https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492. Then, it uses that as an excuse to explain why the token is needed saying that Token required because branch is protected in the error a few lines below.

The token might be expected, but the cause in the messages is untrue. The repository is new and doesn't have branch protection or rulesets configured. I think, this is what's been confusing people.

So it's sort of a UX problem. But also, it's a bit of an abstraction leak because people using GHA expect that the problem is in the action because they see the action printing out the error while the code is in the CLI which is kinda separate 🤷‍♂️

Expected behavior

I suppose the error message could be made cleaner to tell people to check if they'd enabled OIDC in the permissions key in the job definition if they use GitHub Actions CI/CD.

Regression

It's been like this since inception I recon 🤷‍♂️

Screenshots

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Product Area

coverage and test data uploaders

Versions

  • OS: N/A
  • Git Host: GitHub
  • CI/CD: GitHub Actions CI/CD
  • Uploader: codecov-action@v7

Commit and CI link

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Additional context

Here's where the warning is lying: https://github.com/codecov/codecov-cli/blame/c7e7bc0ce4fd57b0e349b3e09fcfed7e16f69637/codecov_cli/services/commit/__init__.py#L66

And the error lie is coming from the backend/API.

Langage dominant
Python
Étoiles
90
Forks
65
Métriques de merge des PR
Aucune PR mergée en 30 j

Préparer son environnement

Ce projet ne fournit ni conteneur de développement, ni Dockerfile, ni guide de contribution : l'installation est à votre charge. Commencez par son README, et consultez notre guide de la première contribution pour les étapes générales.

Par où commencer

  1. Lisez l'issue en entier, puis le guide de contribution du projet.
  2. Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
  3. Forkez le dépôt et travaillez sur une branche.
  4. Ouvrez une pull request qui référence le numéro de l'issue.

Autres issues de codecov/codecov-cli

Toutes les issues de codecov/codecov-cli

Issues similaires

Plus d'issues Python

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.