codecov-2021 · Disclosed 2021-04-15
Codecov: leaked image credential and CI script tampering
A credential in a public Docker image layer enabled tampering with the Bash Uploader. The modified script exported CI environment information from affected users.
Outcome: Confirmed breach
Entry path and evidence
Timeline
Reported response
- Reported fact
Credentials were revoked and rotated; public image build practices were changed.
[s2]Recovery
Evidence relevant to prevention
Operational controls to inspect
Deleting a secret from the final filesystem can leave it in layers. Inspect distributed artifacts and CI execution permissions.
Editorial assessment; not a determination of liability. [s1][s2]
Unknowns and AI involvement
The cited primary sources do not establish AI involvement. This does not establish that AI was absent.
Customer exposure depends on the CI environment and execution history.
Sources
[s1] Codecov · Primary source
Bash Uploader Security Update ↗Published 2021-04-15 · Reviewed 2026-10-02
[s2] Codecov · Primary source
Post-Mortem / Root Cause Analysis (April 2021) ↗Reviewed 2026-10-02