# Upload Issues (\`Unable to locate build via Github Actions API\`)

**URL:** <https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954>\
**Category:** Support\
**Created:** [November 3, 2022, 8:02pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954 "2022-11-03T20:02:31Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [November 3, 2022, 8:02pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/1 "2022-11-03T20:02:32Z")

</div>

Hi everyone,

We have recently seen an influx in issues regarding uploading with the error message `Unable to locate build via Github Actions API`. The reason for the failed uploads is due to Codecov’s inability to check the validity of a coverage upload when using tokenless uploads. The underlying issue is rate-limiting from GitHub.

**Am I having this problem?**  
If you are not using GitHub Actions, this problem should not affect you. The best way to find out is to see if you have had any failed GitHub Actions checks with the following error message `Unable to locate build via Github Actions API` in the Codecov upload step.

**What should I do about it?**  
Although there is no 100% way of guaranteeing success, we recommend two ways of dramatically increasing successful uploads:

1. Add in the [Codecov upload token](https://docs.codecov.com/docs/codecov-uploader#upload-token) even if your project is public. It is recommended to add it as an environment secret as opposed to hard-coding.
2. Re-trying the upload step in CI/CD.

**What is Codecov doing about it?**  
Right now, we are exploring various options to decrease our use of GitHub’s API. We anticipate a longer-term solution in the next few weeks.

* * *

**EDIT 2023-03-13** :  
The issue is still ongoing, and we are taking steps to decrease our GitHub API use. At this point, we strongly recommend using the Codecov upload token to upload to Codecov.

Public repositories that rely on PRs via forks will find that they cannot effectively use Codecov if the token is stored as a GitHub secret. The scope of the Codecov token is **only** to confirm that the coverage uploaded comes from a specific repository, not to pull down source code or make any code changes.

For this reason, we recommend that teams with public repositories that rely on PRs via forks consider the security ramifications of making the Codecov token available as opposed to being in a secret.

_A malicious actor would be able to upload incorrect or misleading coverage reports to a specific repository if they have access to your upload token, but would not be able to pull down source code or make any code changes._

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [November 3, 2022, 8:02pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/2 "2022-11-03T20:02:40Z")

</div>



---

<div class="post-metadata">

**Author:** ![briantist](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/briantist/32/1606_2.png) [@briantist](https://community.codecov.com/u/briantist)\
**Post date:** [November 3, 2022, 8:18pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/3 "2022-11-03T20:18:43Z")

</div>

> **[GitHub - ansible-collections/community.hashi\_vault: Ansible collection for...](https://github.com/ansible-collections/community.hashi_vault/)**
>
> Ansible collection for managing and working with HashiCorp Vault. - GitHub - ansible-collections/community.hashi\_vault: Ansible collection for managing and working with HashiCorp Vault.

(this is the repository most affected for me, but I use codecov on several repositories)

> **[briantist - Overview](https://github.com/briantist)**
>
> briantist has 65 repositories available. Follow their code on GitHub.

---

<div class="post-metadata">

**Author:** ![melink14](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/melink14/32/2729_2.png) [@melink14](https://community.codecov.com/u/melink14)\
**Post date:** [November 7, 2022, 11:27am UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/4 "2022-11-07T11:27:16Z")

</div>

Hit this again when I had to retry twice to get this setp to pass. A side effect of retrying manually though is that the check which waits for Codecov’s analysis never seems to pass and I had to override and merge without waiting for codecov’s results.

Repo: [https://github.com/melink14/rikaikun](https://github.com/melink14/rikaikun)  
user: melink14

---

<div class="post-metadata">

**Author:** ![joanise](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@joanise](https://community.codecov.com/u/joanise)\
**Post date:** [November 7, 2022, 3:57pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/5 "2022-11-07T15:57:32Z")

</div>

Thank you for offering to keep us posted. We’ve been affected too. We’ll be happy to get the follow ups on repo [https://github.com/ReadAlongs/Studio](https://github.com/ReadAlongs/Studio) . My GitHub user name is `joanise`.

I’ve added my codecov token to GH Actions, and so far that worked well, so thanks for that.

Your second suggestion is to retry the upload step, but we use `codecov/codecov-action@v3` and I don’t see a retry parameter in there. Is there a straightforward way to retry while keeping that action plugin?

---

<div class="post-metadata">

**Author:** ![joanise](https://avatars.discourse-cdn.com/v4/letter/j/cc9497/32.png) [@joanise](https://community.codecov.com/u/joanise)\
**Post date:** [November 7, 2022, 4:06pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/6 "2022-11-07T16:06:59Z")

</div>

One more question: Am I correct in assuming that when I use my CODECOV\_TOKEN, the upload is actually more efficient because it’s pre-authentified and no further validation is required?

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [November 14, 2022, 5:03pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/7 "2022-11-14T17:03:36Z")

</div>

@jonny7 that is roughly correct

---

<div class="post-metadata">

**Author:** ![derekpierre](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/derekpierre/32/2739_2.png) [@derekpierre](https://community.codecov.com/u/derekpierre)\
**Post date:** [November 16, 2022, 8:59pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/8 "2022-11-16T20:59:14Z")

</div>

Any update? This affects our repos as well:

- GitHub repos: [https://github.com/nucypher/nucypher](https://github.com/nucypher/nucypher)
- GitHub username: [https://github.com/derekpierre](https://github.com/derekpierre)

We use a codecov token, and we were able to upload earlier today, but the failure is consistently happening now, after multiple retries.

---

<div class="post-metadata">

**Author:** ![adrinjalali](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/adrinjalali/32/2769_2.png) [@adrinjalali](https://community.codecov.com/u/adrinjalali)\
**Post date:** [December 15, 2022, 3:18pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/9 "2022-12-15T15:18:04Z")

</div>

We see this more or less on a daily basis on this repo: [GitHub - skops-dev/skops: skops is a Python library helping you share your scikit-learn based models and put them in production](https://github.com/skops-dev/skops/)

GH username: `adrinjalali` ([adrinjalali (Adrin Jalali) · GitHub](https://github.com/adrinjalali/))

We have added the token to the GH action, but the issue still persists. It doesn’t seem like a rate limit issue though.

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [January 16, 2023, 5:23am UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/10 "2023-01-16T05:23:05Z")

</div>

@adrinjalali, I don’t believe you are passing in a token, see this [log](https://github.com/skops-dev/skops/actions/runs/3911426510/jobs/6684805844#step:11:105)

---

<div class="post-metadata">

**Author:** ![adrinjalali](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/adrinjalali/32/2769_2.png) [@adrinjalali](https://community.codecov.com/u/adrinjalali)\
**Post date:** [January 19, 2023, 4:52pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/11 "2023-01-19T16:52:02Z")

</div>

but we are passing the token here: [skops/build-test.yml at 78c5ef4ff27f928b92c981a76a1278033212a170 · skops-dev/skops · GitHub](https://github.com/skops-dev/skops/blob/78c5ef4ff27f928b92c981a76a1278033212a170/.github/workflows/build-test.yml#L94)

And we’re getting errors again all over: [Fix for metadata having model format · skops-dev/skops@08cbffd · GitHub](https://github.com/skops-dev/skops/actions/runs/3960269419/jobs/6784189336)

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [January 19, 2023, 9:49pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/12 "2023-01-19T21:49:30Z")

</div>

@adrinjalali I believe there might be an issue with how you have set the token in GitHub. I’m seeing [this log](https://github.com/skops-dev/skops/actions/runs/3960269419/jobs/6784189336#step:11:71) that no token is being passed in.

---

<div class="post-metadata">

**Author:** ![dilanSachi](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/dilansachi/32/2835_2.png) [@dilanSachi](https://community.codecov.com/u/dilanSachi)\
**Post date:** [January 26, 2023, 6:26am UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/13 "2023-01-26T06:26:57Z")

</div>

Github username - dilanSachi  
Repository - ballerina-platform/module-ballerina-ftp

---

<div class="post-metadata">

**Author:** ![danepowell](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/danepowell/32/2877_2.png) [@danepowell](https://community.codecov.com/u/danepowell)\
**Post date:** [February 8, 2023, 7:46pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/14 "2023-02-08T19:46:50Z")

</div>

@tom in November you said you hoped to have a long-term solution in a few weeks, do you have any update on this? It seems to still affect dozens of users, including our repo: [GitHub - typhonius/acquia-php-sdk-v2: A PHP SDK for Acquia Cloud API v2 https://cloud.acquia.com/api-docs/#](https://github.com/typhonius/acquia-php-sdk-v2)

Also just cross-referencing this GH sister issue: ["Unable to locate build via Github Actions API" for the public repository · Issue #837 · codecov/codecov-action · GitHub](https://github.com/codecov/codecov-action/issues/837)

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [February 8, 2023, 7:48pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/15 "2023-02-08T19:48:55Z")

</div>

@danepowell I don’t have any updates, we are still working with the GitHub team to try to make tokenless work for our users.

If this is not working for you, please add the Codecov token to your CI environment variables

---

<div class="post-metadata">

**Author:** ![arthurio](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/arthurio/32/2924_2.png) [@arthurio](https://community.codecov.com/u/arthurio)\
**Post date:** [February 28, 2023, 4:04pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/16 "2023-02-28T16:04:01Z")

</div>

@tom I think saying “Adding in the [Codecov upload token](https://docs.codecov.com/docs/codecov-uploader#upload-token) even if your project is public.” is a bit misleading and I have seen a fair amount of people mentioning hard coding that secret. Would it be possible to rephrase to encourage good practice and using an environment variable (whatever the CI tool might be)?

---

<div class="post-metadata">

**Author:** ![tom](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/tom/32/8_2.png) [@tom](https://community.codecov.com/u/tom)\
**Post date:** [March 2, 2023, 3:55am UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/17 "2023-03-02T03:55:49Z")

</div>

Updated @arthurio, let me know if that makes sense.

---

<div class="post-metadata">

**Author:** ![AlekSi](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/aleksi/32/2651_2.png) [@AlekSi](https://community.codecov.com/u/AlekSi)\
**Post date:** [March 2, 2023, 3:52pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/18 "2023-03-02T15:52:20Z")

</div>

> [@arthurio](#):
>
> I have seen a fair amount of people mentioning hard coding that secret

That’s the only possible way for GitHub Actions, public repos and PRs from forks – they don’t have access to secrets: [Events that trigger workflows - GitHub Docs](https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflows-in-forked-repositories)

---

<div class="post-metadata">

**Author:** ![arthurio](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/arthurio/32/2924_2.png) [@arthurio](https://community.codecov.com/u/arthurio)\
**Post date:** [March 3, 2023, 6:10pm UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/19 "2023-03-03T18:10:43Z")

</div>

> [@AlekSi](#):
>
> That’s the only possible way for GitHub Actions, public repos and PRs from forks – they don’t have access to secrets: [Events that trigger workflows - GitHub Docs](https://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflows-in-forked-repositories)

I know, but Github Actions is not the only one CI provider 😉 That’s why I used the word “encourage”. Also, for Github, my understanding is that pull requests from forks to the main repo will trigger the actions from the main repo, which means they do have access to that secret. I’m not sure I see a benefit to letting forks upload coverage against your main repo if it’s not a PR for merging upstream, or am I missing something?

---

<div class="post-metadata">

**Author:** ![AlekSi](https://yyz1.discourse-cdn.com/flex029/user_avatar/community.codecov.com/aleksi/32/2651_2.png) [@AlekSi](https://community.codecov.com/u/AlekSi)\
**Post date:** [March 4, 2023, 11:29am UTC](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954/20 "2023-03-04T11:29:38Z")

</div>

> I know, but Github Actions is not the only one CI provider 😉

This topic is about Github Actions, though

> Also, for Github, my understanding is that pull requests from forks to the main repo will trigger the actions from the main repo, which means they do have access to that secret.

From the link I provided above: " With the exception of `GITHUB_TOKEN` , secrets are not passed to the runner when a workflow is triggered from a forked repository." That’s from the section `pull_request`.

[Next page](https://community.codecov.com/t/upload-issues-unable-to-locate-build-via-github-actions-api/3954.md?page=2)
