-
Notifications
You must be signed in to change notification settings - Fork 259
Permalink
Choose a base ref
{{ refName }}
default
Choose a head ref
{{ refName }}
default
Comparing changes
Choose two branches to see what’s changed or to start a new pull request.
If you need to, you can also or
learn more about diff comparisons.
Open a pull request
Create a new pull request by comparing changes across two branches. If you need to, you can also .
Learn more about diff comparisons here.
base repository: codecov/codecov-action
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: v5
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}
default
Loading
...
head repository: codecov/codecov-action
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: v7
Could not load branches
Nothing to show
Loading
Could not load tags
Nothing to show
{{ refName }}
default
Loading
- 8 commits
- 7 files changed
- 3 contributors
Commits on Mar 26, 2026
-
Revert "Revert "build(deps): bump actions/github-script from 7.0.1 to…
Configuration menu - View commit details
-
Copy full SHA for f67d33d - Browse repository at this point
Copy the full SHA f67d33dView commit details -
* chore(release): 5.5.4 * chore(release): 6.0.0 * fix: small fixes --------- Co-authored-by: Tom Hu <tomhu1096@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 57e3a13 - Browse repository at this point
Copy the full SHA 57e3a13View commit details
Commits on May 13, 2026
-
fix: prevent template injection in run: steps (VULN-1652) (#1947)
Replace direct ${{ inputs.skip_validation }}, ${{ inputs.use_oidc }}, ${{ inputs.token }}, and ${{ env.CODECOV_TOKEN }} interpolation inside run: shell scripts with env-var indirection. GitHub Actions resolves template expressions before the shell sees the script, so any consumer workflow that passes user-controlled data into these inputs could achieve arbitrary command execution on the runner. Moving the values into env: entries and referencing them as $INPUT_* shell variables ensures the shell always treats them as data, not code.Configuration menu - View commit details
-
Copy full SHA for 51e6422 - Browse repository at this point
Copy the full SHA 51e6422View commit details
Commits on May 18, 2026
-
Configuration menu - View commit details
-
Copy full SHA for e79a696 - Browse repository at this point
Copy the full SHA e79a696View commit details
Commits on May 22, 2026
-
ci: remove Enforce License Compliance workflow (#1950)
Removes the Enforce License Compliance GitHub Actions workflow.
Configuration menu - View commit details
-
Copy full SHA for ca0a928 - Browse repository at this point
Copy the full SHA ca0a928View commit details
Commits on Jun 7, 2026
-
Bump the wrapper submodule (src/scripts) to the latest main (bad8df5), which fetches the Codecov Uploader PGP key from the codecovsecops Keybase account, and cut a new major version. Co-authored-by: Cursor <cursoragent@cursor.com>
1Configuration menu - View commit details
-
Copy full SHA for fb8b358 - Browse repository at this point
Copy the full SHA fb8b358View commit details
Commits on Sep 15, 2026
-
* chore(release): 7.1.0 Bump the wrapper submodule to 0.3.0 and expose the new cleanup input for downloading the CLI into a temporary directory. Co-authored-by: Cursor <cursoragent@cursor.com> * docs: drop release-note README copy Remove CircleCI and changelog-style release notes from README; input docs remain in action.yml, upload.yml, and step.yml. Co-authored-by: Cursor <cursoragent@cursor.com> --------- Co-authored-by: Cursor <cursoragent@cursor.com>
Configuration menu - View commit details
-
Copy full SHA for 0b35c9e - Browse repository at this point
Copy the full SHA 0b35c9eView commit details
Commits on Sep 17, 2026
-
Bump wrapper submodule to 0.3.1 and regenerate dist/codecov.sh. Co-authored-by: Cursor <cursoragent@cursor.com>
Configuration menu - View commit details
-
Copy full SHA for 303a32d - Browse repository at this point
Copy the full SHA 303a32dView commit details
Loading
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v5...v7