Codecov Bash Uploader compromised 5 years ago
And they did not fix the code of their own runners (like GHA) to check the SHA sum either..
HN user
And they did not fix the code of their own runners (like GHA) to check the SHA sum either..
The e-mail they sent includes "Unfortunately, we can confirm that you were impacted by this security event." which means that they know. I guess there is an API endpoint that is specific to Bash Uploader and they use that + dates of API requests to figure out who was impacted. This must also contain the repository info (and they just confirmed that they can figure this out).
Can you please tell users which repositories were affected? This situation is ridiculous for users with dozens repositories, using various CIs and various code coverage providers. A lot of checking, cleaning, rotating. The way you disclosed the issue is not helpful.