Skip to content

Installation fails on macOS with recent Homebrew changes #264

Description

@mtl1979

Homebrew 6.0.0 was released few hours ago, but even after upgrading Homebrew, we still get this error message:

Error: Refusing to load formula coverallsapp/coveralls/coveralls from untrusted tap coverallsapp/coveralls.
Run `brew trust --formula coverallsapp/coveralls/coveralls` or `brew trust coverallsapp/coveralls` to trust it.
Failed to install coveralls via Homebrew (macOS).
Error: Process completed with exit code 1.

Activity

  1. afinetooth commented on Jun 11, 2026

    @afinetooth
    Member

    Thanks, @mtl1979. We'll check it out.

  2. afinetooth commented on Jun 11, 2026

    @afinetooth
    Member

    What happened

    Homebrew 6.0.0 (released today, June 11) made a breaking security change: third-party taps are no longer loaded until the user explicitly trusts them, because a tap is arbitrary unsandboxed Ruby that runs with user privileges. Official Homebrew taps stay trusted by default; everything else — including coverallsapp/coveralls — now refuses to load until trusted. There is nothing wrong with the tap, but nothing the tap itself can do to mark itself trusted (that would defeat the purpose). Trust is granted on the client, in one of three ways:

    • brew install <user/repo/formula> — a fully-qualified install auto-trusts just that formula
    • brew trust --formula <user/repo/formula> — trust one formula
    • brew trust <user/repo> — trust the whole tap

    The fix

    We will fix this in the Coveralls GitHub Action (this repo) asap since it is the "client" in this scenario, automatically installing the Coveralls Homebrew Formula when it recognizes CI runners running macos.

    Until that's ready, here is a workaround:

    Workaround

    Immediate workaround for users with issue #264
    Users who can't wait for the new release of the Coveralls GitHub Action (or who pin exact versions) can add one step before the action in their workflow:

    - name: Trust Coveralls Homebrew tap (Homebrew 6 requirement)
      if: runner.os == 'macOS'
      run: brew trust coverallsapp/coveralls
    - uses: coverallsapp/github-action@v2
    
  3. afinetooth commented on Jun 11, 2026

    @afinetooth
    Member

    Open PR for fix here:
    #265

  4. added a commit that references this issue on Jul 14, 2026
  5. Giorgi commented on Jul 25, 2026

    @Giorgi

    Any plans to merge it?

  6. afinetooth commented on Jul 27, 2026

    @afinetooth
    Member

    Fixed in v2.3.8: if you use coverallsapp/github-action@v2, you'll pick it up automatically on your next CI run, no workflow changes needed.

    Cause: Homebrew 6.0.0 introduced a tap trust requirement: formulae from third-party taps refuse to load until trusted. The action now installs via the fully-qualified formula name (brew install coverallsapp/coveralls/coveralls), which trusts the formula automatically and works on both old and new Homebrew (#265).

    Verified end-to-end on current macos-latest (macOS 26) and macos-15 images using the published @v2 tag: smoke test run — Homebrew 6 trust enforcement active, formula auto-trusted, bottle poured, coverage report uploaded successfully.

    If you pin an exact version or SHA, either bump to v2.3.8 or add this step before the action:

    - name: Trust Coveralls Homebrew tap (Homebrew 6 requirement)
      if: runner.os == 'macOS'
      run: brew trust coverallsapp/coveralls

    Thanks for the report and your patience!

  7. added a commit that references this issue on Jul 27, 2026
    8d6379e
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions