Automatic code coverage analysis has proven valuable when integrated with the CI pipeline. It can notify you automatically if your changes are about to drop the coverage.
Monitoring total coverage is the most helpful; patch coverage tends to report too many false positives.
#codecov has withdrew its position on #opensource matter. They have admitted their mistake and also made amends by retracting all false advertising. The case is closed.
This is pretty cool. #Codecov is now open source. #OpenSource https://about.codecov.io/blog/codecov-is-now-open-source/
Ouch... https://about.codecov.io/blog/message-regarding-the-pypi-package/
If you used the #codecov #python package, you need to migrate.
Anyone experiencing issue with #codecov ?
Their #dotnet #tool only supports #netcore 2.1, 3.1 and #dotnet5 (all currently out of support) and since linux #github agent only has #dotnet6 and #dotnet7 sdks.
Anyone out there with a better option than installing a deprecated sdk ?
I'm using #nuke and would very much like not to have to customize the generated YAML file.
The project : github.com/candoumbe/candoumbe.types
#codecov #dotnet #tool #NETCore #dotnet5 #github #dotnet6 #dotnet7 #nuke #opensource
Sure, entire orgs are losing days to a week rotating creds due to the #CircleCI breach, if they are even resourced to do so, but I am choosing to see this as an opportunity to expand justifications for prioritizing work with "as resulted from breaches of #CodeCov _and CircleCI_". 😭 😭 😭
#circleci #codecov #etoomanysecrets #infosec
#codecov is Joining Sentry https://about.codecov.io/blog/codecov-is-joining-sentry-heres-what-you-need-to-know/
Bringing #codecov into the Sentry Family: Where #code Coverage Meets Am https://blog.sentry.io/2022/11/30/bringing-codecov-into-the-sentry-family-where-code-coverage-meets-application-monitoring/
Bringing Codecov into the Sentry Familiy, https://blog.sentry.io/2022/11/30/bringing-codecov-into-the-sentry-family-where-code-coverage-meets-application-monitoring/.
Codecov is now part of Sentry.
#sentry #codecov #test #quality
Un de ces trucs, vous vous en doutez, est #Codecov https://about.codecov.io/security-update/ que des milliers de projets utilisent, parfois sans le savoir.
Bref, on a maintenant des chaines de compilation tellement complexes qu'on n'a plus aucun moyen de s'assurer de ce qui a été fait, et par qui.
RT @cyb3rops
I am bit surprised about the low response to the #Codecov hack - do I miss something or do you?
Their statement
https://about.codecov.io/security-update/
Article by @campuscodi
https://therecord.media/codecov-discloses-2-5-month-long-supply-chain-attack/
Affected projects @_fel1x
https://twitter.com/_fel1x/status/1383050036397871108
My IOC & YARA rule
https://twitter.com/cyb3rops/status/1383065580379516928
https://about.codecov.io/security-update/# #CyberSecurity : "On Thursday, April 1, 2021, #CodeCov learned that someone had gained unauthorized access to script and modified it..." brilliant evil idea to target April 1st for this kind of attack...