-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🏗 Update dependency codecov to v3.7.1 [SECURITY] #33
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/npm-codecov-vulnerability
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files |
renovate
bot
changed the title
🏗 Update dependency codecov to v3.6.5 [SECURITY]
🏗 Update dependency codecov to v3.6.5 [SECURITY]
Mar 14, 2020
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
May 3, 2020 11:00
e1e7be9
to
d144f85
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
July 1, 2020 05:58
d144f85
to
5dfbcdd
Compare
renovate
bot
changed the title
🏗 Update dependency codecov to v3.6.5 [SECURITY]
🏗 Update dependency codecov to v3.6.5 [SECURITY]
Jul 1, 2020
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
July 10, 2020 09:57
5dfbcdd
to
ed1ba69
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
August 24, 2020 20:59
ed1ba69
to
d424acb
Compare
renovate
bot
changed the title
🏗 Update dependency codecov to v3.6.5 [SECURITY]
🏗 Update dependency codecov to v3.7.1 [SECURITY]
Aug 24, 2020
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
October 28, 2020 11:59
d424acb
to
07fc447
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
November 26, 2020 20:51
07fc447
to
6b4ff11
Compare
renovate
bot
changed the title
🏗 Update dependency codecov to v3.7.1 [SECURITY]
🏗 Update dependency codecov to v3.7.1 [SECURITY]
Nov 26, 2020
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
December 8, 2020 08:58
6b4ff11
to
8fadc3e
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
January 7, 2021 00:59
8fadc3e
to
51197f8
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
April 26, 2021 14:53
51197f8
to
4aa814d
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
May 9, 2021 22:46
4aa814d
to
035445b
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
March 7, 2022 10:03
035445b
to
504ebf0
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
March 26, 2022 15:29
504ebf0
to
c366a59
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
April 24, 2022 21:34
c366a59
to
275b417
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
June 18, 2022 18:34
275b417
to
ec12f7f
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
2 times, most recently
from
March 24, 2023 17:59
31917cb
to
ac6b79c
Compare
renovate
bot
changed the title
🏗 Update dependency codecov to v3.7.1 [SECURITY]
🏗 Update dependency codecov to v3.6.2 [SECURITY]
Apr 17, 2023
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
April 17, 2023 11:30
ac6b79c
to
5af5e9a
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
May 28, 2023 10:39
5af5e9a
to
45a3b01
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
July 6, 2023 10:23
45a3b01
to
a53f13f
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
2 times, most recently
from
August 27, 2023 10:15
95543b5
to
7b1931e
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
June 4, 2024 14:26
7b1931e
to
3dcf71b
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
August 6, 2024 08:52
3dcf71b
to
dfe66fb
Compare
renovate
bot
changed the title
🏗 Update dependency codecov to v3.6.2 [SECURITY]
🏗 Update dependency codecov to v3.7.1 [SECURITY]
Aug 6, 2024
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
October 9, 2024 10:25
dfe66fb
to
6cdd1dd
Compare
renovate
bot
force-pushed
the
renovate/npm-codecov-vulnerability
branch
from
January 23, 2025 17:07
6cdd1dd
to
0efe541
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Labels
None yet
0 participants
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
3.2.0
->3.7.1
GitHub Vulnerability Alerts
CVE-2020-7597
codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.
CVE-2020-15123
Impact
The
upload
method has a command injection vulnerability. Clients of thecodecov-node
library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability.A similar CVE was issued: CVE-2020-7597, but the fix was incomplete. It only blocked
&
, and command injection is still possible using backticks instead to bypass the sanitizer.We have written a CodeQL query, which automatically detects this vulnerability. You can see the results of the query on the
codecov-node
project here.Patches
This has been patched in version 3.7.1
Workarounds
None, however, the attack surface is low in this case. Particularly in the standard use of codecov, where the module is used directly in a build pipeline, not built against as a library in another application that may supply malicious input and perform command injection.
References
For more information
If you have any questions or comments about this advisory:
CVE-2020-7596
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
Release Notes
codecov/codecov-node (codecov)
v3.7.1
Compare Source
v3.7.0
Compare Source
v3.6.5
Compare Source
v3.6.4
Compare Source
v3.6.3
Compare Source
v3.6.2
Compare Source
v3.6.1
Compare Source
v3.6.0
Compare Source
v3.5.0
Compare Source
v3.4.0
Compare Source
v3.3.0
Compare Source
--pipe
,-l
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.