• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In
Warning: This build has drifted.
The coverage report for this pull request build may be inaccurate because its base commit is no longer the HEAD of its target branch.
This means it includes changes from outside the original pull request, including, potentially, unrelated coverage changes.

    • Learn more: For more information on this, see Tracking coverage changes for pull request builds.
    • Fix now: For a quick fix, rebase this PR at GitHub. Your next report should be accurate.
    • Prevent going forward: To avoid this issue with future PRs, see these Recommended CI Configurations.
New Repo Setting:
INCLUDE COVERAGE % WITH WARNINGS ABOUT DRIFTED BUILDS?

Enabling this setting will include a (potentially inaccurate) coverage % with warning messages in status updates for drifted builds.

Adjust setting

tensorchord / envd / 36320185237
42%
main: 42%

Build:
Build:
LAST BUILD BRANCH: gh-readonly-queue/main/pr-2114-9e2d2cd34173a150c642138630087d18132b2311
DEFAULT BRANCH: main
Ran 27 Sep 2026 12:55PM UTC
Jobs 1
Files 145
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

27 Sep 2026 12:47PM UTC coverage: 42.162% (-0.9%) from 43.07%
36320185237

Pull #2112

github

kemingy
fix: restrict install.python_packages paths to the build context

The requirements file and local wheels accepted arbitrary paths. The
requirements file was read on the host without any containment check,
so a path like ../../etc/passwd escaped the build context and its
content leaked into build logs and image metadata.

- frontend: resolve paths against the build context (thread-local),
  reject paths escaping it (absolute, .., symlinks), and normalize to
  a context-relative path for reuse inside the container
- compile: verify the symlink-resolved requirements file stays inside
  the build context before reading it on the host, which also covers
  graphs reloaded from image labels

Signed-off-by: Keming <kemingy94@gmail.com>
Pull Request #2112: fix: restrict install.python_packages paths to the build context

49 of 66 new or added lines in 4 files covered. (74.24%)

23 existing lines in 14 files now uncovered.

4820 of 11432 relevant lines covered (42.16%)

137.44 hits per line

Uncovered Changes

Lines Coverage ∆ File
8
79.49
pkg/lang/frontend/starlark/v1/install/util.go
6
49.25
-2.2% pkg/lang/frontend/starlark/v1/install/install.go
3
55.86
-0.99% pkg/lang/ir/v1/util.go

Coverage Regressions

Lines Coverage ∆ File
4
69.68
-2.51% pkg/builder/build.go
3
84.65
-0.52% pkg/progress/progressui/printer.go
2
58.23
-0.86% pkg/app/init.go
2
62.91
-1.14% pkg/app/up.go
2
9.62
-0.09% pkg/driver/docker/docker.go
2
51.69
-2.57% pkg/syncthing/syncthing.go
1
60.0
-6.67% pkg/autocomplete/bash.go
1
41.61
-0.64% pkg/envd/docker.go
1
75.0
-13.89% pkg/lang/ir/v1/cache.go
1
73.1
-2.05% pkg/lang/ir/v1/compile.go
1
63.83
-3.52% pkg/lang/ir/v1/user.go
1
65.91
1.39% pkg/lang/version/version.go
1
33.8
-1.78% pkg/progress/compileui/display.go
1
59.18
-3.11% pkg/version/version.go
Jobs
ID Job ID Ran Files Coverage
1 36320185237.1 27 Sep 2026 12:55PM UTC 145
42.16
GitHub Action Run
Source Files on build 36320185237
  • Tree
  • List 145
  • Changed 144
  • Source Changed 0
  • Coverage Changed 144
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Pull Request #2112
  • PR Base - main (#24920492426)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc