• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

screwdriver-cd / screwdriver / #3399
95%
master: 95%

Build:
Build:
LAST BUILD BRANCH: branch-specific-start-fix
DEFAULT BRANCH: master
Ran 15 Apr 2026 06:18PM UTC
Jobs 1
Files 182
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

15 Apr 2026 06:14PM UTC coverage: 95.276% (-0.1%) from 95.4%
#3399

Pull #3484

screwdriver

tomaioo
fix(security): missing resource-level authorization on build retr

The `GET /builds/{id}` handler returns build data (including environment and step details) without checking whether the caller can access the associated pipeline/build. This can allow authenticated users to enumerate and read build records outside their authorization boundary.

Signed-off-by: tomaioo <203048277+tomaioo@users.noreply.github.com>
Pull Request #3484: Security: Missing resource-level authorization on build retrieval endpoint (potential IDOR/data leak)

2233 of 2418 branches covered (92.35%)

Branch coverage included in aggregate %.

1 of 1 new or added line in 1 file covered. (100.0%)

8 existing lines in 1 file now uncovered.

5411 of 5605 relevant lines covered (96.54%)

110.62 hits per line

Coverage Regressions

Lines Coverage ∆ File
8
58.33
-41.67% plugins/builds/get.js
Jobs
ID Job ID Ran Files Coverage
1 #3399.1 15 Apr 2026 06:18PM UTC 182
95.28
Source Files on build #3399
  • Tree
  • List 182
  • Changed 1
  • Source Changed 0
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line Branch Hits Branch Misses
  • Back to Repo
  • Pull Request #3484
  • PR Base - master (#)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc