Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Codecov GH action: security issue with bash uploader #312

Closed
mdelapenya opened this issue Apr 15, 2021 · 0 comments · Fixed by #526
Closed

Codecov GH action: security issue with bash uploader #312

mdelapenya opened this issue Apr 15, 2021 · 0 comments · Fixed by #526
Labels
security Vulnerabilities in dependencies or in the library itself

Comments

@mdelapenya
Copy link
Collaborator

Please see codecov/codecov-action#281

From Codecov's blog post:

Recommend Actions for Affected Users
Because of our commitment to trust and transparency, we have worked diligently to determine the potential impact to our customers and identify customers who may have used the Bash Uploaders during the relevant time periods. For affected users, we have emailed you on April 15th using you email address on file from Github / Gitlab / Bitbucket, and there is a notification banner after you log in to Codecov.

We strongly recommend affected users immediately re-roll all of their credentials, tokens, or keys located in the environment variables in their CI processes that used one of Codecov’s Bash Uploaders.

@mdelapenya mdelapenya added the security Vulnerabilities in dependencies or in the library itself label Apr 15, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Vulnerabilities in dependencies or in the library itself
Projects
None yet
1 participant