brisvag / blik

Python tool for visualising and interacting with cryo-ET and subtomogram averaging data.
https://brisvag.github.io/blik/
GNU General Public License v3.0
23 stars 8 forks source link

check env exposed in codecov breach #82

Closed brisvag closed 3 years ago

brisvag commented 3 years ago

Codecov had a security breach. They suggested to check which env variables were surfaced to the CI and to reroll anything that might be considered sensitive. At first glance here, it does not seem like any of the secret tokens (PyPI and codecov) are actually stodes as variables... I'm not sure whether that means that we're fine, or if I'm misunderstanding.

alisterburt commented 3 years ago

Thanks for this! Had a look and think we're in the clear, good to know about for sure