Skip to content

Verify the upstream signature on every run and add zizmor and cargo-deny #20

Verify the upstream signature on every run and add zizmor and cargo-deny

Verify the upstream signature on every run and add zizmor and cargo-deny #20

Workflow file for this run

---
name: Coverage
"on":
pull_request:
push:
branches:
- main
permissions:
contents: read
concurrency:
group: ${{ github.workflow }}-${{ github.ref }}
cancel-in-progress: ${{ github.ref != 'refs/heads/main' }}
env:
CARGO_TERM_COLOR: always
jobs:
coverage:
name: Coverage
runs-on: ubuntu-latest
timeout-minutes: 30
# Neither a fork's pull request nor a Dependabot run can read CODECOV_TOKEN.
if: >-
github.event_name == 'push' ||
(github.event.pull_request.head.repo.full_name == github.repository &&
github.event.pull_request.user.login != 'dependabot[bot]')
steps:
- uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
with:
persist-credentials: false
- name: Install stable toolchain with llvm-tools
run: |
rustup toolchain install stable \
--profile minimal \
--component llvm-tools-preview
- uses: taiki-e/install-action@7623a79cdfecb99d681017af368ca353d9f49bb5 # v2.87.19
with:
tool: cargo-llvm-cov
- name: Test coverage
run: cargo +stable llvm-cov --all-targets --codecov --output-path codecov.json
- uses: codecov/codecov-action@303a32d7a59b442fa8d48b6a1cc6825c09c847a5 # v7.1.1
with:
files: codecov.json
token: ${{ secrets.CODECOV_TOKEN }}
fail_ci_if_error: true