• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

pomerium / pomerium / 29757638862 / 1
53%
main: 53%

Build:
DEFAULT BRANCH: main
Ran 20 Jul 2026 04:25PM UTC
Files 706
Run time 22s
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

20 Jul 2026 03:59PM UTC coverage: 52.518% (-0.03%) from 52.548%
29757638862.1

push

github

web-flow
chore(deps): bump github.com/oapi-codegen/oapi-codegen/v2 from 2.5.0 to 2.7.1 (#6546)

Bumps
[github.com/oapi-codegen/oapi-codegen/v2](https://github.com/oapi-codegen/oapi-codegen)
from 2.5.0 to 2.7.1.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/oapi-codegen/oapi-codegen/releases">github.com/oapi-codegen/oapi-codegen/v2's
releases</a>.</em></p>
<blockquote>
<h2>Security fix for Go code injection</h2>
<p>This is a security fix for a code injection vulnerability in v2.7.0,
please see:</p>
<p><a
href="https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr">https://github.com/oapi-codegen/oapi-codegen/security/advisories/GHSA-rjwr-m7qx-3fjr</a></p>
<blockquote>
<p>[!NOTE]
A vulnerability like this requires that it is missed in code review
<strong>and</strong> that you then call the malicious method.</p>
<p>Using an <code>init()</code> function could be enough to not require
a direct call to the code, and instead rely on you importing the
package, but either way, code review should be performed before any
<code>oapi-codegen</code> generated code is executed.</p>
<p>We <strong>strongly recommend</strong> all users to be reviewing
changes to their generated code before they execute anything within it,
to protect against supply chain attacks or malicious injected code.</p>
<p>This is also why we recommend <code>oapi-codegen</code> generated
code is committed to source control.</p>
</blockquote>
<p>We're more strict about escaping strings passed into the OpenAPI
specification, so that people can't inject Go code into generated
code.</p>
<p>The problem was that it was possible to craft a description for
server URL's which would emit arbitrary Go code, so if an attacker
controlled your specification, they could inject Go code into your
generated code which could do something malicious.</p>
<h2>v2.7.0: Squashing bugs, many bugs (and adding some features)</h2>
<h1>Many improvements and ev... (continued)

37219 of 70869 relevant lines covered (52.52%)

461.42 hits per line

Source Files on job 29757638862.1
  • Tree
  • List 706
  • Changed 7
  • Source Changed 0
  • Coverage Changed 7
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Build 29757638862
  • 596b0080 on github
  • Prev Job for on main (#29596348503.1)
  • Next Job for on main (#29774203356.1)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc