Skip to content

Commit

Permalink
Moved codecov citation outside block quotes.
Browse files Browse the repository at this point in the history
  • Loading branch information
import-pandas-as-numpy committed Aug 3, 2023
1 parent 341624e commit 7a50704
Showing 1 changed file with 1 addition and 0 deletions.
1 change: 1 addition & 0 deletions src/content/post/dependency-dilemma.md
Original file line number Diff line number Diff line change
Expand Up @@ -122,6 +122,7 @@ Are you thinking about supply chain security yet?
On January 31st 2021, a threat actor gained access to Codecov's Bash Uploader script credentials and modified it without their permission.

> The actor gained access because of an error in Codecov's Docker image creation process that allowed the actor to extract the credential required to modify our Bash Uploader Script
*[Codecov Security Update](https://about.codecov.io/security-update/)*

This attack utilized a CI/CD tool to compromise user credentials and exfiltrate them to an external service. The attack was able to make numerous changes to the original repository (and subsequently any repositories or codebases that might be affected in these credential breaches). Moreso, this code was repeatedly inserted into the codebase until an observant Codecov consumer noted that the hash for the Bash Uploader script did not match the reported hash.
Expand Down

0 comments on commit 7a50704

Please sign in to comment.