Skip to content
| Marketplace
Sign in
Azure DevOps>Azure Pipelines>Aikido Code Coverage
Aikido Code Coverage

Aikido Code Coverage

Aikido Security

aikido.dev
|
1 install
| (0) | Free
Collect LCOV or Cobertura coverage reports and upload them to Aikido.
Get it free

Aikido Code Coverage Azure Pipelines Task

Collect LCOV or Cobertura XML code coverage reports produced by your test suite and upload them to Aikido.

The task reads one or more reports from the paths you provide and uploads them, together with:

  • a repository_source_paths list (filtered repo source paths) for path matching on the backend
  • an EOF map (line counts for covered source files) so the backend can drop coverage past end-of-file

Authentication uses Azure DevOps OIDC (workload identity federation).

Usage

Install the task from the Visual Studio Marketplace, run your tests with coverage, then add the task to your pipeline YAML. The upload job must check out the repository so source paths and EOF metadata can be collected.

Example YAML file:

trigger:
  - main

pool:
  vmImage: ubuntu-latest

steps:
  - checkout: self

  - task: NodeTool@0
    inputs:
      versionSpec: '20.x'

  - script: npm ci
    displayName: Install dependencies

  - script: npm test -- --coverage
    displayName: Run tests

  - task: AikidoCodeCoverage@1
    displayName: Upload coverage to Aikido
    inputs:
      filePaths: coverage/lcov.info

Cobertura XML

- task: AikidoCodeCoverage@1
  inputs:
    filePaths: coverage/cobertura.xml

Uploading multiple reports

Provide more than one path when separate packages or CI shards each emit their own report. Mixed LCOV and Cobertura inputs are supported; the backend merges them.

- task: AikidoCodeCoverage@1
  inputs:
    filePaths: |
      packages/a/coverage/lcov.info
      packages/b/coverage/cobertura.xml

Parallel jobs with published artifacts

When each package runs in its own job, coverage files live on separate agents. Publish coverage artifacts, download them in a final job that also checks out the repo, then upload once to Aikido.

Upload from every test job separately would send partial coverage and can race — always collect into a single upload per commit.

jobs:
  - job: Test
    strategy:
      matrix:
        PackageA:
          PACKAGE: packages/a
        PackageB:
          PACKAGE: packages/b
    steps:
      - checkout: self
      - script: npm test --workspace=$(PACKAGE) -- --coverage
      - publish: $(PACKAGE)/coverage/lcov.info
        artifact: coverage-$(PACKAGE)

  - job: UploadCoverage
    dependsOn: Test
    steps:
      - checkout: self

      - task: DownloadPipelineArtifact@2
        inputs:
          artifact: coverage-packages/a
          path: coverage-reports/packages/a

      - task: DownloadPipelineArtifact@2
        inputs:
          artifact: coverage-packages/b
          path: coverage-reports/packages/b

      - task: AikidoCodeCoverage@1
        inputs:
          filePaths: |
            coverage-reports/packages/a/lcov.info
            coverage-reports/packages/b/lcov.info

Use paths relative to the job working directory (absolute paths and .. segments are rejected). Adjust artifact names and paths to match your repository layout.

Inputs

Input Required Default Description
filePaths yes — Path(s) to coverage report(s). Newline-, space-, or comma-separated. Format detected from filename.
region no eu Aikido region for upload: eu, us, au, or us-gov.
failOnError no true Fail the task if reading or upload fails. Set to false to emit a warning instead.

Region

Set region to match your Aikido workspace. The value selects the API host.

- task: AikidoCodeCoverage@1
  inputs:
    filePaths: coverage/lcov.info
    region: us

Authentication

The task requests an OIDC idToken from Azure DevOps (System.OidcRequestUri).

Requirements:

  1. Azure DevOps Services (cloud) YAML pipelines with workload identity federation available in the organization.
  2. Trust configured in Aikido for your Azure DevOps OIDC issuer (https://vstoken.dev.azure.com/{org-id}) and subject (p://{org}/{project}/{pipeline}).

The token audience is the Azure DevOps default (api://AzureADTokenExchange).

  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft