# Codecov Bash uploader security notice

**URL:** <https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408>\
**Category:** Tooling\
**Tags:** question\
**Created:** [April 16, 2021, 12:37pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408 "2021-04-16T12:37:19Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 16, 2021, 12:37pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/1 "2021-04-16T12:37:19Z")

</div>

Yesterday I got an e-mail from Codecov about an [incident that concerns their Bash uploader](https://about.codecov.io/security-update/).

I read the relevant page and their docs, and just want to check the following: if I am only using Codecov for _public repos, via the standard Julia CI scripts_ (formerly Travis CI, now mostly Github actions), and thus never had to provide any tokens, then I am unaffected and I don’t need to do anything. Is this correct?

---

<div class="post-metadata">

**Author:** ![oheil](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/oheil/32/220745_2.png) [@oheil](https://discourse.julialang.org/u/oheil)\
**Post date:** [April 16, 2021, 2:08pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/2 "2021-04-16T14:08:59Z")

</div>

@giordano or @christopher-dG can answer this I think.  
Or you check Slack discussion: [Slack](https://julialang.slack.com/archives/C680MM7D4/p1618492108453100)  
if you like. I didn’t get this email so I didn’t follow all the implications and can’t answer this for sure.

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [April 16, 2021, 2:17pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/3 "2021-04-16T14:17:31Z")

</div>

Yeah in general you should be fine. For the “average” public Julia project, the only secret in the workflow was the `DOCUMENTER_KEY`, but access to that is isolated to the docs job, where the Codecov action does not run.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 16, 2021, 2:27pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/4 "2021-04-16T14:27:46Z")

</div>

Thanks. I still don’t understand why Codecov thinks that I am affected then.

Out of curiosity, what’s the worst that can happen if a malicious attacker gets hold of a `DOCUMENTER_KEY`? Do they get to rewrite the generated docs? (which could be quite serious, eg adding links to malicious sites, etc).

Could notification this be a leftover from having used Travis CI scripts in the past?

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [April 16, 2021, 2:38pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/5 "2021-04-16T14:38:12Z")

</div>

`DOCUMENTER_KEY` is an SSH key with write access to your repository, so they can push to anywhere on your repo, including your main branch if it’s not protected in GH settings.

> I still don’t understand why Codecov thinks that I am affected then.

Codecov has no way to analyze everyone’s usage of their script, all they can do is identify whether or not you used the compromised script on one of your repos.

---

<div class="post-metadata">

**Author:** ![ctkelley](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ctkelley/32/10684_2.png) [@ctkelley](https://discourse.julialang.org/u/ctkelley)\
**Post date:** [April 25, 2021, 8:39pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/6 "2021-04-25T20:39:59Z")

</div>

The codecov failed in my latest CI, which is how I found out about this. Will this fix itself or do I need to do something? When I clicked on the failed run I would up at a web page with said

**Action Required: You were Impacted by Codecov’s Bash Uploader Security Issue.  
Codecov recently disclosed a security issue. Based on our records, we believe you were impacted and should take immediate action.**

which told me about the problem. “learn more” was not helpful, at least for me. The way I use codecov is these lines in .github/workflows/ci.yml

```julia
      - uses: codecov/codecov-action@v1
        with:
          file: lcov.info

```

Should I be doing something else? This has been working fine until now.

---

<div class="post-metadata">

**Author:** ![christopher-dG](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/christopher-dg/32/7387_2.png) [@christopher-dG](https://discourse.julialang.org/u/christopher-dG)\
**Post date:** [April 26, 2021, 12:58am UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/7 "2021-04-26T00:58:59Z")

</div>

If you could link to the failed workflow run, we could do a better job of diagnosing what went wrong with the codecov action.

---

<div class="post-metadata">

**Author:** ![ctkelley](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ctkelley/32/10684_2.png) [@ctkelley](https://discourse.julialang.org/u/ctkelley)\
**Post date:** [April 26, 2021, 1:10am UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/8 "2021-04-26T01:10:26Z")

</div>

I tried, but every link I click either (1) shows a codecov report that looks normal and accurate or (2) tells me about **Action Required**. I cannot get something that looks anything like a normal CI failure report.

It’s typical for me that codecov can take a long time to come up with its report. However, it usually does ot report a failure while I wait.

I will give up and hope this problem goes away on its own.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [April 30, 2021, 12:05pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/9 "2021-04-30T12:05:31Z")

</div>

Just got an update from CodeCov this morning by e-mail. Their corresponding [blog post](https://about.codecov.io/security-update/) [updated] says

> We have recently obtained a non-exhaustive, redacted set of environment variables that we have evidence were compromised. We also have evidence on how these compromised variables may have been used. Please log-in to Codecov as soon as possible to see if you are in this affected population.

and I logged in, but I am uncertain what I should be seeing, it just shows my overview.

(Sorry to be asking these questions here, I also asked their support but got no reply yet, so I am hoping someone else will figure this out and I get to freeride on their effort 😉)

---

<div class="post-metadata">

**Author:** ![ctkelley](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/ctkelley/32/10684_2.png) [@ctkelley](https://discourse.julialang.org/u/ctkelley)\
**Post date:** [May 2, 2021, 9:27pm UTC](https://discourse.julialang.org/t/codecov-bash-uploader-security-notice/59408/10 "2021-05-02T21:27:27Z")

</div>

Bizzare. The failure signal I got seemed to be about a decrease in my codecov percentage and went away the next time I ran CI. I am now prepared for this and actually appreciate it.

I could have used better and more informative messages from codecov. The ones I got were/are very hard to understand and use to take action.
