summaryrefslogtreecommitdiff
path: root/.azure-pipelines
diff options
context:
space:
mode:
authorSam Doran <sdoran@redhat.com>2021-05-16 22:48:10 -0400
committerGitHub <noreply@github.com>2021-05-16 21:48:10 -0500
commita2fabbe38b2705fd7ed34618ce07953eda3bb12e (patch)
treedfbdf40ac444119c8e00598c0e31b5dfbf5e1bee /.azure-pipelines
parent6fe7640fa5605cdac9e1a03930ec4804fa8bbacc (diff)
downloadansible-a2fabbe38b2705fd7ed34618ce07953eda3bb12e.tar.gz
[stable-2.9] Use our own copy of the Codecov uploader (#74460) (#74493)
Due to the recent security incident, use our own copy hosted in S3 to mitigate future risk from running an arbitrary script downloaded from a remote and untrtusted server. (cherry picked from commit aa12af1d34) Co-authored-by: Sam Doran <sdoran@redhat.com>
Diffstat (limited to '.azure-pipelines')
-rwxr-xr-x.azure-pipelines/scripts/publish-codecov.sh2
1 files changed, 1 insertions, 1 deletions
diff --git a/.azure-pipelines/scripts/publish-codecov.sh b/.azure-pipelines/scripts/publish-codecov.sh
index 7aeabda0c0..6d184f0b8d 100755
--- a/.azure-pipelines/scripts/publish-codecov.sh
+++ b/.azure-pipelines/scripts/publish-codecov.sh
@@ -7,7 +7,7 @@ set -o pipefail -eu
output_path="$1"
-curl --silent --show-error https://codecov.io/bash > codecov.sh
+curl --silent --show-error https://ansible-ci-files.s3.us-east-1.amazonaws.com/codecov/codecov.sh > codecov.sh
for file in "${output_path}"/reports/coverage*.xml; do
name="${file}"