# Integrate using GitLab CI

**URL:** <https://community.codecov.com/t/integrate-using-gitlab-ci/120>\
**Category:** Support\
**Created:** [April 14, 2019, 4:20am UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120 "2019-04-14T04:20:19Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![mittalyashu](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/mittalyashu/32/68_2.png) [@mittalyashu](https://community.codecov.com/u/mittalyashu)\
**Post date:** [April 14, 2019, 4:20am UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/1 "2019-04-14T04:20:19Z")

</div>

### Description

I did tried to read the docs, but I am still not able to understand from where to get started.

How to integrate CodeCov with Gitlab CI?

---

<div class="post-metadata">

**Author:** ![eddiemoore](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/eddiemoore/32/12_2.png) [@eddiemoore](https://community.codecov.com/u/eddiemoore)\
**Post date:** [April 15, 2019, 1:41am UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/2 "2019-04-15T01:41:40Z")

</div>

In your test stage in the gitlab-ci.yml add in

```auto
after_script:
    - bash <(curl -s https://codecov.io/bash)

```

This will send the code coverage to Codecov after the `script` section has run

---

<div class="post-metadata">

**Author:** ![mittalyashu](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/mittalyashu/32/68_2.png) [@mittalyashu](https://community.codecov.com/u/mittalyashu)\
**Post date:** [April 15, 2019, 12:03pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/3 "2019-04-15T12:03:00Z")

</div>

What about the token?

Just by adding token as environment variable, will it work?

---

<div class="post-metadata">

**Author:** ![eddiemoore](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/eddiemoore/32/12_2.png) [@eddiemoore](https://community.codecov.com/u/eddiemoore)\
**Post date:** [April 16, 2019, 12:24am UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/4 "2019-04-16T00:24:15Z")

</div>

Yep. Either use the environment variable, or pass in the token to the script via `-t <TOKEN>`

```auto
bash <(curl -s https://codecov.io/bash) -t <TOKEN>

```

---

<div class="post-metadata">

**Author:** ![mittalyashu](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/mittalyashu/32/68_2.png) [@mittalyashu](https://community.codecov.com/u/mittalyashu)\
**Post date:** [April 16, 2019, 7:21am UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/5 "2019-04-16T07:21:12Z")

</div>

Hmm… seems like it worked.

But it didn’t upload any reports to the codecov dashboard.

![image](https://cdck-file-uploads-canada1.s3.dualstack.ca-central-1.amazonaws.com/flex029/uploads/codecov/original/1X/86d7903d2a88e847c44283c6d4495085843b8d82.png)

---

<div class="post-metadata">

**Author:** ![eddiemoore](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/eddiemoore/32/12_2.png) [@eddiemoore](https://community.codecov.com/u/eddiemoore)\
**Post date:** [April 16, 2019, 11:22pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/6 "2019-04-16T23:22:27Z")

</div>

Has your test runner produced the coverage reports?

---

<div class="post-metadata">

**Author:** ![mittalyashu](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/mittalyashu/32/68_2.png) [@mittalyashu](https://community.codecov.com/u/mittalyashu)\
**Post date:** [April 17, 2019, 9:03am UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/7 "2019-04-17T09:03:27Z")

</div>

It is not showing any kind of reports inside the dashboard.

![msedge_phj2KsZBpg](https://cdck-file-uploads-canada1.s3.dualstack.ca-central-1.amazonaws.com/flex029/uploads/codecov/original/1X/2b88f921db479792eee6a8d0316db885d30c42ef.png)

---

<div class="post-metadata">

**Author:** ![eddiemoore](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/eddiemoore/32/12_2.png) [@eddiemoore](https://community.codecov.com/u/eddiemoore)\
**Post date:** [April 17, 2019, 12:06pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/8 "2019-04-17T12:06:20Z")

</div>

What are you using to generate the coverage report? In JavaScript there is Istanbul, NYC and some others. Jest also comes with it built in.

For example, to cover you code using Jest:

```auto
jest --coverage

```

---

<div class="post-metadata">

**Author:** ![mittalyashu](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/mittalyashu/32/68_2.png) [@mittalyashu](https://community.codecov.com/u/mittalyashu)\
**Post date:** [April 17, 2019, 3:18pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/9 "2019-04-17T15:18:03Z")

</div>

I am using this config file to run codecov in CI

```auto
codecov:
  notify:
    require_ci_to_pass: yes

coverage:
  precision: 2
  round: down
  range: "70...100"

  status:
    project: yes
    patch: yes
    changes: no

parsers:
  gcov:
    branch_detection:
      conditional: yes
      loop: yes
      method: no
      macro: no

comment:
  layout: "header, diff"
  behavior: default
  require_changes: no

```

I found this file content in the codecov docs.

---

<div class="post-metadata">

**Author:** ![mittalyashu](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/mittalyashu/32/68_2.png) [@mittalyashu](https://community.codecov.com/u/mittalyashu)\
**Post date:** [April 20, 2019, 1:14pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/10 "2019-04-20T13:14:48Z")

</div>

Even after using the above file doesn’t give any results in the CodeCov dashboard.

---

<div class="post-metadata">

**Author:** ![Farwaykorse](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/farwaykorse/32/79_2.png) [@Farwaykorse](https://community.codecov.com/u/Farwaykorse)\
**Post date:** [April 20, 2019, 9:44pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/11 "2019-04-20T21:44:19Z")

</div>

You need to reread @eddiemoore’s last two commends.

If there is no coverage data generated by your test-suite there is nothing to upload to [codecov.io](http://codecov.io) and therefore nothing to show on the website.

Check the examples linked from [Codecov uploader and supported languages](https://docs.codecov.io/docs/supported-languages)

---

<div class="post-metadata">

**Author:** ![jaraco](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/jaraco/32/90_2.png) [@jaraco](https://community.codecov.com/u/jaraco)\
**Post date:** [April 22, 2019, 2:22pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/12 "2019-04-22T14:22:11Z")

</div>

In one of our GitLab projects, we have [an issue](https://gitlab.com/python-devs/importlib_metadata/issues/53) - we’ve installed the token with the project but the token is not visible to non-maintainers of the project, so everybody who submits a Merge Request gets a failed pipeline.

The variable is configured in GitLab’s CI/CD Settings Variables without protection or masking.

It’s not clear to me how protected that token should be. What is the harm if a non-maintainer gains access to that token? Are you aware of any way to allow codecov to run in a GitLab pipeline for a merge request from a non-maintainer?

---

<div class="post-metadata">

**Author:** ![Farwaykorse](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/farwaykorse/32/79_2.png) [@Farwaykorse](https://community.codecov.com/u/Farwaykorse)\
**Post date:** [April 24, 2019, 7:09pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/13 "2019-04-24T19:09:22Z")

</div>

@jaraco

As long as we’re talking about the project’s " Repository Upload Token", there are no real security concerns.

With the token someone can push reports to the project on codecov, this could potentially mess-up your coverage history.

Such issues are most likely to occur with forked projects. Any commit to a fork could be added to the coverage history of the original project.  
But since the commit hashes are different and not present in the main repository they should just show up as unknown commits. (At least that is what happens with GitHub hosted projects.)

* * *

**GitLab**  
I have no experience with GitLab pipelines, but as long as they are run for the merge request, there should be no codecov specific issues.

**p.s.** There are three ways to supply the token.

- Hard-coded (or as variable) supplied to the upload script (or bash uploader)  
`-t xxxxxxx-xxxxxx...`.

- By setting it in an environment variable called `CODECOV_TOKEN`.

- Or in the `codecov.yml` file as:

Maybe one of these works better for your situation.

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [June 7, 2019, 6:20pm UTC](https://community.codecov.com/t/integrate-using-gitlab-ci/120/14 "2019-06-07T18:20:04Z")

</div>


