Repository navigation
Installation fails on macOS with recent Homebrew changes #264
Description
Activity
Thanks, @mtl1979. We'll check it out.
What happened
Homebrew
6.0.0(released today, June 11) made a breaking security change: third-party taps are no longer loaded until the user explicitly trusts them, because a tap is arbitrary unsandboxed Ruby that runs with user privileges. Official Homebrew taps stay trusted by default; everything else — includingcoverallsapp/coveralls— now refuses to load until trusted. There is nothing wrong with the tap, but nothing the tap itself can do to mark itself trusted (that would defeat the purpose). Trust is granted on the client, in one of three ways:brew install <user/repo/formula>— a fully-qualified install auto-trusts just that formulabrew trust --formula <user/repo/formula>— trust one formulabrew trust <user/repo>— trust the whole tap
The fix
We will fix this in the Coveralls GitHub Action (this repo) asap since it is the "client" in this scenario, automatically installing the Coveralls Homebrew Formula when it recognizes CI runners running
macos.Until that's ready, here is a workaround:
Workaround
Immediate workaround for users with issue #264
Users who can't wait for the new release of the Coveralls GitHub Action (or who pin exact versions) can add one step before the action in their workflow:- name: Trust Coveralls Homebrew tap (Homebrew 6 requirement) if: runner.os == 'macOS' run: brew trust coverallsapp/coveralls - uses: coverallsapp/github-action@v2Reacted by Chris Butler, Trevor James Smith and Sarah BluntOpen PR for fix here:
#265- added a commit that references this issue
on Jun 30, 2026 - added a commit that references this issue
on Jul 14, 2026 - added 2 commits that reference this issue
on Jul 21, 2026 Any plans to merge it?
Reacted by James KesslerFixed in v2.3.8: if you use
coverallsapp/github-action@v2, you'll pick it up automatically on your next CI run, no workflow changes needed.Cause: Homebrew 6.0.0 introduced a tap trust requirement: formulae from third-party taps refuse to load until trusted. The action now installs via the fully-qualified formula name (
brew install coverallsapp/coveralls/coveralls), which trusts the formula automatically and works on both old and new Homebrew (#265).Verified end-to-end on current
macos-latest(macOS 26) andmacos-15images using the published@v2tag: smoke test run — Homebrew 6 trust enforcement active, formula auto-trusted, bottle poured, coverage report uploaded successfully.If you pin an exact version or SHA, either bump to v2.3.8 or add this step before the action:
- name: Trust Coveralls Homebrew tap (Homebrew 6 requirement) if: runner.os == 'macOS' run: brew trust coverallsapp/coveralls
Thanks for the report and your patience!
- added a commit that references this issue
on Jul 27, 2026 - added a commit that references this issue
on Jul 27, 2026
Homebrew 6.0.0 was released few hours ago, but even after upgrading Homebrew, we still get this error message: