Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[UX] "Branch `main` is protected but no token was provided" is a lie

Đang mở
#801 2 bình luận 1 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
3/5
Thời gian dự kiến
1-2 ngày
Mức phù hợp với người mới
59/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
github-actions, python
Lĩnh vực
cli, developer-experience

Hướng nghiên cứu

Start by reading codecov_cli/services/commit/__init__.py at the linked warning location, then trace how the CLI handles token requirements for GitHub Actions and where the backend/API error is produced. The issue suggests clarifying the message to direct users to check OIDC permissions; done means the messages no longer falsely attribute the missing token to branch protection.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

bug

Describe the bug

This was mentioned in the action @ https://github.com/codecov/codecov-action/issues/1918, and I've seen it before, I think.
Today, I saw it my CI, when I was wiring new repo, so I decided to take a closer look.

The uploader is pretty sure that the branch is not protected and claims so in this warning: https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492. Then, it uses that as an excuse to explain why the token is needed saying that Token required because branch is protected in the error a few lines below.

The token might be expected, but the cause in the messages is untrue. The repository is new and doesn't have branch protection or rulesets configured. I think, this is what's been confusing people.

So it's sort of a UX problem. But also, it's a bit of an abstraction leak because people using GHA expect that the problem is in the action because they see the action printing out the error while the code is in the CLI which is kinda separate 🤷‍♂️

Expected behavior

I suppose the error message could be made cleaner to tell people to check if they'd enabled OIDC in the permissions key in the job definition if they use GitHub Actions CI/CD.

Regression

It's been like this since inception I recon 🤷‍♂️

Screenshots

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Product Area

coverage and test data uploaders

Versions

  • OS: N/A
  • Git Host: GitHub
  • CI/CD: GitHub Actions CI/CD
  • Uploader: codecov-action@v7

Commit and CI link

https://github.com/tox-dev/tox-pre-commit/actions/runs/37032575031/job/110924028521#step:24:492

Additional context

Here's where the warning is lying: https://github.com/codecov/codecov-cli/blame/c7e7bc0ce4fd57b0e349b3e09fcfed7e16f69637/codecov_cli/services/commit/__init__.py#L66

And the error lie is coming from the backend/API.

Ngôn ngữ chính
Python
Star
90
Fork
65
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Chuẩn bị môi trường

Dự án này không cung cấp dev container, Dockerfile hay hướng dẫn đóng góp, nên bạn cần tự thiết lập môi trường: hãy bắt đầu từ README và xem hướng dẫn đóng góp lần đầu của chúng tôi để biết các bước chung.

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của codecov/codecov-cli

Tất cả issue của codecov/codecov-cli

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.