From 940562c0b6f19825c345ff4b1a85923b6b1f9ac2 Mon Sep 17 00:00:00 2001 From: "sentry[bot]" <39604003+sentry[bot]@users.noreply.github.com> Date: Thu, 1 Oct 2026 16:33:24 +0000 Subject: [PATCH] fix: prevent empty commit SHA from being sent to API --- codecov_cli/commands/empty_upload.py | 5 +++++ codecov_cli/fallbacks.py | 15 ++++++++++++--- codecov_cli/helpers/ci_adapters/bitrise_ci.py | 5 ++++- 3 files changed, 21 insertions(+), 4 deletions(-) diff --git a/codecov_cli/commands/empty_upload.py b/codecov_cli/commands/empty_upload.py index 463fd81c5..d3701d1a8 100644 --- a/codecov_cli/commands/empty_upload.py +++ b/codecov_cli/commands/empty_upload.py @@ -55,6 +55,11 @@ def empty_upload( enterprise_url = ctx.obj.get("enterprise_url") args = get_cli_args(ctx) + if not commit_sha or not str(commit_sha).strip(): + raise click.UsageError( + "Unable to determine the commit SHA. Please provide it explicitly with -C/--sha/--commit-sha." + ) + logger.debug("Attempting to Create Commit before doing an empty upload.") create_commit_logic( commit_sha, diff --git a/codecov_cli/fallbacks.py b/codecov_cli/fallbacks.py index 099b391db..22128a23a 100644 --- a/codecov_cli/fallbacks.py +++ b/codecov_cli/fallbacks.py @@ -27,6 +27,15 @@ class FallbackFieldEnum(Enum): ) +def _is_missing(value: typing.Any) -> bool: + """A value is considered missing if it is None or a blank string.""" + if value is None: + return True + if isinstance(value, str) and not value.strip(): + return True + return False + + class CodecovOption(click.Option): fallback_fields: typing.Optional[tuple[FallbackFieldEnum, ...]] @@ -45,20 +54,20 @@ def get_default( self, ctx: click.Context, call: bool = True ) -> typing.Optional[typing.Union[typing.Any, typing.Callable[[], typing.Any]]]: res = super().get_default(ctx, call=call) - if res is not None: + if not _is_missing(res): return res if self.fallback_fields is not None: for field in self.fallback_fields: if ctx.obj.get("ci_adapter") is not None: res = ctx.obj.get("ci_adapter").get_fallback_value(field) - if res is not None: + if not _is_missing(res): return res if ( ctx.obj.get("versioning_system") is not None and field in _FIELDS_WITH_VERSIONING_FALLBACK ): res = ctx.obj.get("versioning_system").get_fallback_value(field) - if res is not None: + if not _is_missing(res): return res return None diff --git a/codecov_cli/helpers/ci_adapters/bitrise_ci.py b/codecov_cli/helpers/ci_adapters/bitrise_ci.py index c815efb6d..481d4afc7 100644 --- a/codecov_cli/helpers/ci_adapters/bitrise_ci.py +++ b/codecov_cli/helpers/ci_adapters/bitrise_ci.py @@ -10,7 +10,10 @@ def detect(self) -> bool: return bool(os.getenv("CI")) and bool(os.getenv("BITRISE_IO")) def _get_commit_sha(self): - return os.getenv("GIT_CLONE_COMMIT_HASH") + commit_sha = os.getenv("GIT_CLONE_COMMIT_HASH") + if commit_sha is None or not commit_sha.strip(): + return None + return commit_sha.strip() def _get_build_url(self): return os.getenv("BITRISE_BUILD_URL")