4 ms·
I'm Jerrod Engelberg, CEO of Codecov, and I'm confirming the above is factual. Sorry about the outage on the details page.
by jerrod 5y ago
I'm Jerrod Engelberg, CEO of Codecov, and I'm confirming the above is factual. Sorry about the outage on the details page.
- cdmckay 5y agoWhy did you wait 2 weeks to notify us?
- Waylander_k 5y agoCould you tell us how you determined who has or has not been affected?
- mikedd65 5y agoCan you please tell users which repositories were affected? This situation is ridiculous for users with dozens repositories, using various CIs and various code coverage providers. A lot of checking, cleaning, rotating. The way you disclosed the issue is not helpful.
- dbrgn 5y agoHow would they do that? The bash script is a static file on a public host. Users can simply download it, without Codecov knowing about the repos it's being used in. Never automatically download any remote code without at least checking the checksum.
- mikedd65 5y agoThe e-mail they sent includes "Unfortunately, we can confirm that you were impacted by this security event." which means that they know. I guess there is an API endpoint that is specific to Bash Uploader and they use that + dates of API requests to figure out who was impacted. This must also contain the repository info (and they just confirmed that they can figure this out).
- celticninja 5y agoThat may be wrong. I use the ruby gem and the email says that would not be affected but at the same time the email says I was affected. I'm re-rolling to be sure, but it would help not having conflicting information in the same email.
- jerrod 5y agoHey, yes we can help you with figuring out which repos, there is an FAQ in the post about this, or you can email us at security [at] codecov.io.
- throwawaaaaaaay 5y agoHe's a Forbes 30u30 guy - go figure. Experience in VC and an investment banker from Wharton. I suggest buying development tools from a CEO from MIT with a coding background, not someone who only learned how to make money.