• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

pomerium / pomerium / 29757638862
53%

Build:
DEFAULT BRANCH: main
Ran 20 Jul 2026 04:25PM UTC
Jobs 1
Files 706
Run time 2min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

20 Jul 2026 03:59PM UTC coverage: 52.518% (-0.03%) from 52.548%
29757638862

push

github

web-flow
chore(deps): bump github.com/oapi-codegen/oapi-codegen/v2 from 2.5.0 to 2.7.1 (#6546)

Bumps
[github.com/oapi-codegen/oapi-codegen/v2](https://github.com/oapi-codegen/oapi-codegen)
from 2.5.0 to 2.7.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oapi-codegen/oapi-codegen/releases">github.com/oapi-codegen/oapi-codegen/v2's
releases</a>.</em></p>
<blockquote>
<h2>Security fix for Go code injection</h2>
<p>This is a security fix for a code injection vulnerability in v2.7.0,
please see:</p>
<p><a
href="https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr">https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr</a></p>
<blockquote>
<p>[!NOTE]
A vulnerability like this requires that it is missed in code review
<strong>and</strong> that you then call the malicious method.</p>
<p>Using an <code>init()</code> function could be enough to not require
a direct call to the code, and instead rely on you importing the
package, but either way, code review should be performed before any
<code>oapi-codegen</code> generated code is executed.</p>
<p>We <strong>strongly recommend</strong> all users to be reviewing
changes to their generated code before they execute anything within it,
to protect against supply chain attacks or malicious injected code.</p>
<p>This is also why we recommend <code>oapi-codegen</code> generated
code is committed to source control.</p>
</blockquote>
<p>We're more strict about escaping strings passed into the OpenAPI
specification, so that people can't inject Go code into generated
code.</p>
<p>The problem was that it was possible to craft a description for
server URL's which would emit arbitrary Go code, so if an attacker
controlled your specification, they could inject Go code into your
generated code which could do something malicious.</p>
<h2>v2.7.0: Squashing bugs, many bugs (and adding some features)</h2>
<h1>Many improvements and ev... (continued)

37219 of 70869 relevant lines covered (52.52%)

461.42 hits per line

Coverage Regressions

Lines Coverage ∆ File
10
75.99
-2.64% pkg/storage/postgres/backend.go
4
88.08
-0.88% pkg/storage/postgres/postgres.go
3
93.56
-1.49% config/config_source.go
3
95.83
-3.13% pkg/identity/manager/schedulers.go
2
48.66
0.18% internal/databroker/server_clustered_follower.go
2
85.67
-0.62% pkg/databrokerutil/syncer.go
2
94.55
0.0% pkg/fanout/receive.go
Jobs
ID Job ID Ran Files Coverage
1 29757638862.1 20 Jul 2026 04:25PM UTC 706
52.52
GitHub Action Run
Source Files on build 29757638862
  • Tree
  • List 706
  • Changed 7
  • Source Changed 0
  • Coverage Changed 7
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #29757638862
  • 596b0080 on github
  • Prev Build on main (#29596348503)
  • Next Build on main (#29774203356)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc