Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci: disable codecov from build #247

Open
phanak-sap opened this issue Apr 17, 2023 · 1 comment
Open

ci: disable codecov from build #247

phanak-sap opened this issue Apr 17, 2023 · 1 comment
Assignees
Labels

Comments

@phanak-sap
Copy link
Contributor

phanak-sap commented Apr 17, 2023

codecov dissapeard from pypi, breaking billions of builds at once.
Possible security related problem is "anyone can now snap up codecov with a malicious package that would be installed on many systems currently depending on codecov."

This seems to be handled by pypi admins, but still it is breaking the builds

Hi, PyPI administrator here. Just wanted to confirm that the entire codecov project was removed by the project maintainers at 2023-04-12 12:41:12 UTC. The 0.0.0a2 release was later uploaded by an unrelated third party that was helpfully trying to prevent the released project name from being acquired by attackers and distributing malware. That version has since been removed and the name prohibited from re-registration.

codecov/python-standard#31
https://community.codecov.com/t/codecov-yanked-from-pypi-all-versions/4259

@phanak-sap phanak-sap self-assigned this Apr 17, 2023
phanak-sap added a commit to phanak-sap/python-pyodata that referenced this issue Apr 17, 2023
phanak-sap added a commit to phanak-sap/python-pyodata that referenced this issue Apr 17, 2023
phanak-sap added a commit that referenced this issue Apr 17, 2023
* chore: remove codecov from dev-requirements.txt
* ci: remove codecov step from gh-action

Issue #247
@phanak-sap
Copy link
Contributor Author

phanak-sap commented Apr 17, 2023

Builds are green again. Let's wait a bit how the situation around codecov will resolve.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant