Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[UX] "Branch `main` is protected but no token was provided" is a lie

Aperta
#801 2 commenti 1 reazione 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
59/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
github-actions, python

Direzione di ricerca

Start by reading codecov_cli/services/commit/__init__.py at the linked warning location, then trace how the CLI handles token requirements for GitHub Actions and where the backend/API error is produced. The issue suggests clarifying the message to direct users to check OIDC permissions; done means the messages no longer falsely attribute the missing token to branch protection.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

bug

Describe the bug

This was mentioned in the action @ https://github.com/codecov/codecov-action/issues/1918, and I've seen it before, I think.
Today, I saw it my CI, when I was wiring new repo, so I decided to take a closer look.

The uploader is pretty sure that the branch is not protected and claims so in this warning: https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492. Then, it uses that as an excuse to explain why the token is needed saying that Token required because branch is protected in the error a few lines below.

The token might be expected, but the cause in the messages is untrue. The repository is new and doesn't have branch protection or rulesets configured. I think, this is what's been confusing people.

So it's sort of a UX problem. But also, it's a bit of an abstraction leak because people using GHA expect that the problem is in the action because they see the action printing out the error while the code is in the CLI which is kinda separate 🤷‍♂️

Expected behavior

I suppose the error message could be made cleaner to tell people to check if they'd enabled OIDC in the permissions key in the job definition if they use GitHub Actions CI/CD.

Regression

It's been like this since inception I recon 🤷‍♂️

Screenshots

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Product Area

coverage and test data uploaders

Versions

  • OS: N/A
  • Git Host: GitHub
  • CI/CD: GitHub Actions CI/CD
  • Uploader: codecov-action@v7

Commit and CI link

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Additional context

Here's where the warning is lying: https://github.com/codecov/codecov-cli/blame/c7e7bc0ce4fd57b0e349b3e09fcfed7e16f69637/codecov_cli/services/commit/__init__.py#L66

And the error lie is coming from the backend/API.

Lingua principale
Python
Stelle
90
Fork
65
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di codecov/codecov-cli

Tutte le issue di codecov/codecov-cli

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.