Hi guys - Atlassian is named as a user of the CodeCov tool.
https://therecord.media/codecov-discloses-2-5-month-long-supply-chain-attack/
Do you know yet if Atlassian's products have been impacted and whether we should be concerned about the integrity or security of data we have online in Confluence or Jira?
Codecov is not used as part of the products, but it is used to check coverage on some of their code bases.
So, no, my understanding is that your data is not at risk of exposure, as it's a step away from where the security hole is. But Atlassian data about us might be.
I think this is one that Atlassian should answer, as they'll know exactly where they might have been clobbered - I've asked them to have a look.
Thanks Nic - I wasn't sure who to contact.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Frankly, nor am I.
I have been here a while, so I've picked up some of the names to ask for some problems, but not this one. I'm sure someone will see us soon (fwiw, my label flag is not the only "escalation"(
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Hi Trevor,
Check out our official response here: Atlassian's Response to the Codecov Breach
Cheers,
Daniel
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.