Skip to content

Security discussion: Codecov event #1007

Closed
@effigies

Description

@effigies

This morning (15 April 2021), I received a security update from CodeCov: https://about.codecov.io/security-update/

NiBabel was affected by this issue because we use the CodeCov GitHub action, which means tokens were potentially exposed. However, we have no authentication tokens set in our environment, so my assessment is that there was no potential for exploitation.

This thread will remain open for ~1 week to give others a chance to assess the situation and dispute my conclusion that we do not need to take any action.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions