From 41aabcbd2326ae154a16a1a050ee01fb9a54bd19 Mon Sep 17 00:00:00 2001 From: Alex Gaynor Date: Wed, 9 Sep 2015 22:16:37 -0400 Subject: Don't use pipes Download the whole file first, @glyph points out that truncation attacks are a thing. --- .travis/upload_coverage.sh | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to '.travis') diff --git a/.travis/upload_coverage.sh b/.travis/upload_coverage.sh index 554116f7..62489560 100755 --- a/.travis/upload_coverage.sh +++ b/.travis/upload_coverage.sh @@ -6,5 +6,6 @@ set -x NO_COVERAGE_TOXENVS=(pypy pypy3 pep8 py3pep8 docs) if ! [[ "${NO_COVERAGE_TOXENVS[*]}" =~ "${TOXENV}" ]]; then source ~/.venv/bin/activate - bash <(curl -s https://codecov.io/bash) -e TRAVIS_OS_NAME,TOXENV,OPENSSL + wget https://codecov.io/bash -O codecov.sh + bash codecov.sh -e TRAVIS_OS_NAME,TOXENV,OPENSSL fi -- cgit v1.2.3