Skip to content

chore: migrate coverage reporting from Codecov to Aikido - #1494

Merged
Wikid82 merged 3 commits into
developmentfrom
chore/codecov-to-aikido-coverage
Oct 5, 2026
Merged

Wikid82 merged 3 commits into
developmentfrom
chore/codecov-to-aikido-coverage

Conversation

@Wikid82

@Wikid82 Wikid82 commented Oct 5, 2026

Copy link
Copy Markdown
Owner

Summary

Replaces Codecov with the Aikido code-coverage action so Aikido PR checks receive the coverage report.

  • Backend and agent Go coverage is converted to LCOV (gcov2lcov); frontend already emits LCOV.
  • Each coverage job uploads its report as an artifact; one Upload Coverage to Aikido job combines them into a single upload per commit, as the action recommends.
  • The action authenticates with GitHub OIDC (id-token: write on the upload job only); no repository secret is needed.
  • The existing 85% coverage gates in scripts/*-coverage.sh are unchanged.
  • Removed codecov.yml, the Codecov upload steps, the Codecov trigger-parity guard, and Codecov-specific helper prompts/examples. Docs updated.
  • Workflow renamed to aikido-coverage.yml; nightly and weekly-promotion dispatches retargeted. Renovate trackers updated.

Notes for reviewers

  • Job names changed (Backend Coverage, Frontend Coverage, Agent Coverage, Upload Coverage to Aikido). Update branch protection if it requires the old names or codecov/* statuses.
  • The action defaults to the eu region; set region on the step if the workspace is elsewhere.
  • The upload is skipped for fork and Dependabot PRs (no OIDC token).
  • The real upload is untested until the first CI run; check the repository_source_paths log line and the Aikido UI.

Testing

actionlint and lefthook pre-commit pass locally; gcov2lcov output verified against existing coverage files.

Claude Code was used to help produce this change.

Replace the Codecov upload workflow with aikido-coverage.yml: backend and
agent Go profiles are converted to LCOV (gcov2lcov), the frontend LCOV is
reused, and a single OIDC-authenticated job uploads all reports to Aikido.
Remove codecov.yml and the Codecov trigger parity guard, and retarget the
Renovate trackers and nightly/promotion dispatchers.
@github-advanced-security

Copy link
Copy Markdown
Contributor

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

✅ Supply Chain Verification Results

✅ PASSED

📦 SBOM Summary

  • Components: 1870

🔍 Vulnerability Scan

Severity Count
🔴 Critical 0
🟠 High 0
🟡 Medium 0
🟢 Low 0
Total 0

📎 Artifacts

  • SBOM (CycloneDX JSON) and Grype results available in workflow artifacts

Generated by Supply Chain Verification workflow • View Details

@Wikid82
Wikid82 merged commit ae28bc8 into development Oct 5, 2026
71 of 83 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants