Skip to content

chore: bump codecov/codecov-action from 7.0.0 to 7.1.1 - #790

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/codecov/codecov-action-7.1.1
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/codecov/codecov-action-7.1.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps codecov/codecov-action from 7.0.0 to 7.1.1.

Release notes

Sourced from codecov/codecov-action's releases.

v7.1.1

What's Changed

Full Changelog: codecov/codecov-action@v7.1.0...v7.1.1

v7.1.0

What's Changed

Full Changelog: codecov/codecov-action@v7.0.0...v7.1.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 7.0.0 to 7.1.1.
- [Release notes](https://github.com/codecov/codecov-action/releases)
- [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md)
- [Commits](codecov/codecov-action@v7.0.0...303a32d)

---
updated-dependencies:
- dependency-name: codecov/codecov-action
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 1, 2026
Copilot AI balanced review requested due to automatic review settings October 1, 2026 21:47
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code labels Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Directly editing Anvil-generated files without regenerating their lock entries disables automatic updates.

Review effort: Balanced
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates Codecov coverage uploads to codecov-action v7.1.1.

Changes:

  • Pins Codecov to commit 303a32d in PR and scheduled workflows.
  • Applies the same version across coverage jobs.
File Description
.github/​workflows/​anvil-scheduled-impl.yml Updates scheduled coverage uploads.
.github/​workflows/​anvil-pr-impl.yml Updates PR coverage uploads.

💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

# configurations; one multi-pattern call would accept a partial pair.
if: always() && matrix.os != 'windows-arm' && hashFiles('target/coverage/lcov-all-features.info') != '' && hashFiles('target/coverage/lcov-no-default.info') != ''
uses: codecov/codecov-action@v7.0.0 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
# uploads while still tracking each platform separately.
if: always() && matrix.os != 'windows-arm' && hashFiles('target/coverage/lcov-all-features.info') != '' && hashFiles('target/coverage/lcov-no-default.info') != ''
uses: codecov/codecov-action@v7.0.0 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown

⚠️ SemVer check advisory

Inconclusive comparisons

cargo semver-checks could not complete the following comparisons. These failures are informational because an unbuildable baseline is not evidence of a breaking API change.

metabench (exit 101)

     Cloning 03108d3ecb0bb57b3d23170468dd40224c2bb9fc
    Building metabench v0.1.1 (current)
error: running cargo-doc on crate 'metabench' failed with output:
-----
   Compiling proc-macro2 v1.0.107
   Compiling quote v1.0.47
   Compiling unicode-ident v1.0.26
   Compiling serde_core v1.0.229
   Compiling zmij v1.0.23
   Compiling serde v1.0.229
   Compiling serde_json v1.0.151
   Compiling libc v0.2.189
    Checking cfg-if v1.0.5
    Checking memchr v2.8.3
    Checking itoa v1.0.18
   Compiling syn v3.0.6
   Compiling syn v2.0.119
   Compiling zerocopy v0.8.59
    Checking bitflags v2.13.2
   Compiling equivalent v1.0.2
   Compiling find-msvc-tools v0.1.14
   Compiling shlex v2.0.1
   Compiling hashbrown v0.17.1
   Compiling semver v1.0.28
   Compiling winnow v1.0.4
   Compiling rustversion v1.0.23
   Compiling indexmap v2.14.2
   Compiling rustc_version v0.4.1
   Compiling toml_parser v1.1.3+spec-1.1.0
   Compiling cc v1.5.1
   Compiling serde_derive v1.0.229
   Compiling zerocopy-derive v0.8.59
   Compiling derive_more-impl v2.1.1
   Compiling autocfg v1.5.1
   Compiling rustix v1.1.5
   Compiling toml_datetime v1.1.1+spec-1.1.0
   Compiling num-traits v0.2.19
   Compiling toml_edit v0.25.15+spec-1.1.0
   Compiling alloca v0.4.0
   Compiling gungraun-macros v0.9.1
   Compiling proc-macro-error-attr3 v3.1.1
    Checking either-or-both v0.3.1
   Compiling thiserror v2.0.21
   Compiling cfg_aliases v0.2.2
   Compiling getrandom v0.4.3
   Compiling bincode-next v3.1.1
    Checking ciborium-io v0.2.2
    Checking either v1.18.0
    Checking regex-syntax v0.8.11
    Checking linux-raw-sys v0.12.1
    Checking anstyle v1.0.14
    Checking clap_lex v1.1.1
    Checking clap_builder v4.6.7
    Checking regex-automata v0.4.18
    Checking itertools v0.13.0
    Checking half v2.7.1
    Checking ciborium-ll v0.2.2
   Compiling nix v0.31.3
   Compiling proc-macro-error3 v3.1.1
    Checking rapidhash v4.5.1
   Compiling proc-macro-crate v3.5.0
   Compiling derive_more v2.1.1
   Compiling thiserror-impl v2.0.21
   Compiling pastey v0.2.3
    Checking same-file v1.0.6
    Checking cast v0.3.0
    Checking unty-next v0.1.2
   Compiling gungraun v0.19.4
    Checking criterion-plot v0.8.2
    Checking walkdir v2.5.0
   Compiling metabench_macros_impl v0.1.1 (/home/runner/work/oxidizer/oxidizer/crates/metabench_macros_impl)
    Checking ciborium v0.2.2
    Checking gungraun-runner v0.20.0
    Checking regex v1.13.1
    Checking clap v4.6.7
    Checking gungraun-runner v0.19.4
    Checking folo_utils v0.1.14
    Checking tinytemplate v1.2.1
    Checking nix v0.27.1
    Checking page_size v0.6.0
    Checking once_cell v1.21.4
    Checking oorandom v11.1.5
    Checking jiff-core v0.1.1
    Checking anes v0.1.6
    Checking fastrand v2.5.0
   Compiling metabench v0.1.1 (/home/runner/work/oxidizer/oxidizer/crates/metabench)
    Checking tempfile v3.27.0
    Checking command-group v5.0.1
    Checking jiff v0.2.37
    Checking criterion v0.8.2
    Checking gungraun-summary v6.0.0
error[E0432]: unresolved import `gungraun_runner::api::ValgrindTool`
  --> /home/runner/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/gungraun-summary-6.0.0/src/v6.rs:10:59
   |
10 |     CachegrindMetric, DhatMetric, ErrorMetric, EventKind, ValgrindTool,
   |                                                           ^^^^^^^^^^^^ no `ValgrindTool` in `api`

error[E0432]: unresolved imports `gungraun_runner::metrics::model::MetricsDiff`, `gungraun_runner::metrics::model::MetricsSummary`
  --> /home/runner/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/gungraun-summary-6.0.0/src/v6.rs:12:63
   |
12 | pub use gungraun_runner::metrics::model::{Metric, MetricKind, MetricsDiff, MetricsSummary};
   |                                                               ^^^^^^^^^^^  ^^^^^^^^^^^^^^ no `MetricsSummary` in `metrics::model`
   |                                                               |
   |                                                               no `MetricsDiff` in `metrics::model`

error[E0432]: unresolved imports `gungraun_runner::summary::model::Diffs`, `gungraun_runner::summary::model::FlamegraphSummary`, `gungraun_runner::summary::model::ProfileInfo`, `gungraun_runner::summary::model::SummaryFormat`, `gungraun_runner::summary::model::SummaryOutput`, `gungraun_runner::summary::model::ToolMetricSummary`
  --> /home/runner/.cargo/registry/src/index.crates.io-1949cf8c6b5b557f/gungraun-summary-6.0.0/src/v6.rs:14:38
   |
14 |     BenchmarkKind, BenchmarkSummary, Diffs, FlamegraphSummary, Profile, ProfileData, ProfileInfo,
   |                                      ^^^^^  ^^^^^^^^^^^^^^^^^                        ^^^^^^^^^^^ no `ProfileInfo` in `summary::model`
   |                                      |      |
   |                                      |      no `FlamegraphSummary` in `summary::model`
   |                                      no `Diffs` in `summary::model`
15 |     ProfilePart, ProfileTotal, Profiles, SCHEMA_VERSION, SummaryFormat, SummaryOutput,
   |                                                          ^^^^^^^^^^^^^  ^^^^^^^^^^^^^ no `SummaryOutput` in `summary::model`
   |                                                          |
   |                                                          no `SummaryFormat` in `summary::model`
16 |     ToolMetricSummary, ToolRegression,
   |     ^^^^^^^^^^^^^^^^^ no `ToolMetricSummary` in `summary::model`

   Compiling metabench_macros v0.1.1 (/home/runner/work/oxidizer/oxidizer/crates/metabench_macros)
For more information about this error, try `rustc --explain E0432`.
error: could not compile `gungraun-summary` (lib) due to 3 previous errors
warning: build failed, waiting for other jobs to finish...

-----

error: failed to build rustdoc for crate metabench v0.1.1
note: this is usually due to a compilation error in the crate,
      and is unlikely to be a bug in cargo-semver-checks
note: the following command can be used to reproduce the error:
      cargo new --lib example &&
          cd example &&
          echo '[workspace]' >> Cargo.toml &&
          cargo add --path /home/runner/work/oxidizer/oxidizer/crates/metabench &&
          cargo check &&
          cargo doc

error: aborting due to failure to build rustdoc for crate metabench v0.1.1

@martintmk

Copy link
Copy Markdown
Member

Posted by an AI agent

Human review is required for head 2c0b41fee32772105de9e4a784926c0d2deb2830: .github/workflows/anvil-pr-impl.yml and .github/workflows/anvil-scheduled-impl.yml are marked GENERATED BY cargo-anvil and say repository-specific edits stop automatic updates, while .anvil.lock still contains their previous checksums. Please update the cargo-anvil source/catalog and regenerate both workflows and the lock manifest before approval. PR · head commit

@martintmk martintmk added the human-review-required Human review required before automated approval. label Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.0%. Comparing base (27a8b19) to head (2c0b41f).
⚠️ Report is 1 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #790   +/-   ##
=======================================
  Coverage   100.0%   100.0%           
=======================================
  Files         738      736    -2     
  Lines       98623    98578   -45     
=======================================
- Hits        98623    98578   -45     
Flag Coverage Δ
linux 100.0% <ø> (ø)
linux-arm 100.0% <ø> (ø)
scheduled ?
windows 100.0% <ø> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@martintmk

Copy link
Copy Markdown
Member

AI review preparation has started for #790 at head 2c0b41fee32772105de9e4a784926c0d2deb2830.

The submitted GitHub review will contain the result.

@martintmk martintmk left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Posted by an AI agent

Verdict: changes requested. I reviewed the workflow action references, coverage-upload orchestration, generated-file consistency, and the unchanged test gates. The previously reported generated workflow/lock inconsistency remains unresolved; I have not repeated that finding. The inline comment notes a separate minor documentation mismatch.

Public API, performance, naming, telemetry, and resilience are not applicable to this workflow-only change: no Rust API or runtime surfaces changed. I did not run tests or builds locally. The CI checks at the reviewed commit completed successfully.

# configurations; one multi-pattern call would accept a partial pair.
if: always() && matrix.os != 'windows-arm' && hashFiles('target/coverage/lcov-all-features.info') != '' && hashFiles('target/coverage/lcov-no-default.info') != ''
uses: codecov/codecov-action@v7.0.0 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)
uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit)

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Posted by an AI agent · Nit

Workflow pin comments still describe tag-based pinning

Problem Both changed Codecov uses: refs at .github/workflows/anvil-pr-impl.yml:219 and .github/workflows/anvil-scheduled-impl.yml:76 now use full commit SHA 303a32d7a59b442fa8d48b6a1cc6825c09c847a5, but their adjacent comment still says “pinned by tag.”

Why this matters The comment gives maintainers an inaccurate explanation of how the action refs are pinned.

Suggested fix Change both comments to say “pinned by commit SHA,” or remove the pinning rationale.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file github_actions Pull requests that update GitHub Actions code human-review-required Human review required before automated approval.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants