Direct Answers
Does public: true in codecov.yml override provider private visibility on Codecov SaaS? No. The provider's repository visibility (private on GitHub, GitLab, or Bitbucket) is the documented source of truth. A public key in codecov.yml is not a documented override and should not be relied on to expose a private repository's coverage reports.
Does the YAML schema version change how the public key is parsed for privacy settings? No. Neither the legacy nested format (settings under a top-level codecov: block) nor the current top-level format defines a supported public privacy key. The key is at best ignored or flagged by validation; its effect is undefined and not a stable contract.
Does changing visibility in the Codecov UI affect a public flag set in codecov.yml? Yes. UI-level visibility controls act on the repository record itself and take precedence for what is actually exposed. Changing the UI setting changes effective visibility regardless of codecov.yml, which Codecov treats as upload and processing configuration.
Likely Explanation for Your Case
A configuration template written for public repositories carries keys that either do nothing on a private repository or trip YAML validation. The private repository stays private unless someone changes visibility at the provider level or in the Codecov UI.
Codecov Enterprise Server Differences
Enterprise Server adds deployment-level defaults for repository visibility controlled by instance admins. Defaults and available UI controls can differ from SaaS and between Enterprise versions. Check your installed version's own documentation.
Verification Steps (Run These)
- Open the repository's settings in the Codecov UI and record the current visibility or "Public Reports" state. This shows the effective runtime setting.
- Open a commit coverage report URL for the private repository in a logged-out or incognito browser. If it renders, reports are effectively public.
- Check the
codecov.yml configuration reference for your deployment (SaaS docs or your Enterprise version) to confirm whether any visibility key is supported. - In a disposable private repository, add
public: true, upload coverage, repeat the logged-out access test, then remove the key afterward.
Assumptions and Uncertainty
- The
public: key and "Public Reports" control name come from the question text; neither is confirmed as a documented Codecov setting from model knowledge. - Codecov YAML schema versioning is not a stable public contract; avoid reasoning from version labels and instead test the actual file against your deployment.
- Never treat an ignored or undocumented YAML key as a security control in either direction; verify effective access with a logged-out check.
One missing diagnostic detail: which Codecov deployment are you using (SaaS or Enterprise Server, and if Enterprise, the version)? This changes whether deployment-level admin defaults apply.