Repository navigation
chore: bump codecov/codecov-action from 7.0.0 to 7.1.1 - #790
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 7.0.0 to 7.1.1. - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@v7.0.0...303a32d) --- updated-dependencies: - dependency-name: codecov/codecov-action dependency-version: 7.1.1 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Directly editing Anvil-generated files without regenerating their lock entries disables automatic updates.
Review effort: Balanced
Findings: 2
Open (2)
What changed in this PR
Updates Codecov coverage uploads to codecov-action v7.1.1.
Changes:
- Pins Codecov to commit
303a32din PR and scheduled workflows. - Applies the same version across coverage jobs.
| File | Description |
|---|---|
.github/workflows/anvil-scheduled-impl.yml |
Updates scheduled coverage uploads. |
.github/workflows/anvil-pr-impl.yml |
Updates PR coverage uploads. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| # configurations; one multi-pattern call would accept a partial pair. | ||
| if: always() && matrix.os != 'windows-arm' && hashFiles('target/coverage/lcov-all-features.info') != '' && hashFiles('target/coverage/lcov-no-default.info') != '' | ||
| uses: codecov/codecov-action@v7.0.0 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) | ||
| uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) |
| # uploads while still tracking each platform separately. | ||
| if: always() && matrix.os != 'windows-arm' && hashFiles('target/coverage/lcov-all-features.info') != '' && hashFiles('target/coverage/lcov-no-default.info') != '' | ||
| uses: codecov/codecov-action@v7.0.0 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) | ||
| uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) |
|
|
Posted by an AI agent Human review is required for head |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #790 +/- ##
=======================================
Coverage 100.0% 100.0%
=======================================
Files 738 736 -2
Lines 98623 98578 -45
=======================================
- Hits 98623 98578 -45
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
AI review preparation has started for #790 at head The submitted GitHub review will contain the result. |
martintmk
left a comment
There was a problem hiding this comment.
Posted by an AI agent
Verdict: changes requested. I reviewed the workflow action references, coverage-upload orchestration, generated-file consistency, and the unchanged test gates. The previously reported generated workflow/lock inconsistency remains unresolved; I have not repeated that finding. The inline comment notes a separate minor documentation mismatch.
Public API, performance, naming, telemetry, and resilience are not applicable to this workflow-only change: no Rust API or runtime surfaces changed. I did not run tests or builds locally. The CI checks at the reviewed commit completed successfully.
| # configurations; one multi-pattern call would accept a partial pair. | ||
| if: always() && matrix.os != 'windows-arm' && hashFiles('target/coverage/lcov-all-features.info') != '' && hashFiles('target/coverage/lcov-no-default.info') != '' | ||
| uses: codecov/codecov-action@v7.0.0 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) | ||
| uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # pinned by tag: this release is an immutable release (GitHub locks the tag to a commit) |
There was a problem hiding this comment.
Posted by an AI agent · Nit
Workflow pin comments still describe tag-based pinning
Problem Both changed Codecov uses: refs at .github/workflows/anvil-pr-impl.yml:219 and .github/workflows/anvil-scheduled-impl.yml:76 now use full commit SHA 303a32d7a59b442fa8d48b6a1cc6825c09c847a5, but their adjacent comment still says “pinned by tag.”
Why this matters The comment gives maintainers an inaccurate explanation of how the action refs are pinned.
Suggested fix Change both comments to say “pinned by commit SHA,” or remove the pinning rationale.

Bumps codecov/codecov-action from 7.0.0 to 7.1.1.
Release notes
Sourced from codecov/codecov-action's releases.
Commits
303a32dchore(release): 7.1.1 (#1973)0b35c9echore(release): 7.1.0 (#1971)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)