
Security News
arXiv Is Rate Limiting Authors Following a Flood of AI Slop Submissions
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.
mcp-server-codecov
Advanced tools
MCP server for querying Codecov coverage data with configurable URL support
A Model Context Protocol (MCP) server that provides tools for querying Codecov coverage data. Supports both codecov.io and self-hosted Codecov instances with configurable URL endpoints.
Important: Codecov has two different types of tokens:
This MCP server requires an API token, not an upload token. To create an API token:
https://codecov.io or your self-hosted URL)Install the MCP server globally via npm:
npm install -g mcp-server-codecov
After installation, the mcp-server-codecov command will be available in your PATH.
For development or contributing:
git clone https://github.com/egulatee/mcp-server-codecov.git
cd mcp-server-codecov
npm install
npm run build
The server is configured through environment variables:
CODECOV_BASE_URL (optional): Base URL for the Codecov instance. Defaults to https://codecov.ioCODECOV_TOKEN (optional): Authentication token for accessing private repositoriesAdd to your Claude Desktop configuration file:
macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
Windows: %APPDATA%\Claude\claude_desktop_config.json
{
"mcpServers": {
"codecov": {
"command": "mcp-server-codecov",
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}
For development/source installations:
{
"mcpServers": {
"codecov": {
"command": "node",
"args": ["/path/to/mcp-server-codecov/dist/index.js"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}
Use the Claude Code CLI to add the MCP server:
# If installed globally via npm (recommended)
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.io \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- mcp-server-codecov
# Or if installed from source
cd /path/to/codecov-mcp
npm install && npm run build
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.io \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- node /absolute/path/to/codecov-mcp/dist/index.js
This will automatically configure the server in your ~/.claude.json file.
Add to your Claude Code MCP settings file at ~/.claude.json:
{
"mcpServers": {
"codecov": {
"command": "mcp-server-codecov",
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}
For source installations:
{
"mcpServers": {
"codecov": {
"command": "node",
"args": ["/absolute/path/to/codecov-mcp/dist/index.js"],
"env": {
"CODECOV_BASE_URL": "https://codecov.io",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}
Notes:
args parameter${VAR} syntax${CODECOV_TOKEN} will be read from your shell environment (e.g., from ~/.zshrc or ~/.bashrc)For self-hosted Codecov instances, set the CODECOV_BASE_URL to your instance URL:
Claude Desktop:
{
"mcpServers": {
"codecov": {
"command": "mcp-server-codecov",
"env": {
"CODECOV_BASE_URL": "https://codecov.your-company.com",
"CODECOV_TOKEN": "your-codecov-token-here"
}
}
}
}
Claude Code (CLI):
claude mcp add --transport stdio codecov \
--env CODECOV_BASE_URL=https://codecov.your-company.com \
--env CODECOV_TOKEN=${CODECOV_TOKEN} \
-- mcp-server-codecov
Claude Code (Manual - ~/.claude.json):
{
"mcpServers": {
"codecov": {
"command": "mcp-server-codecov",
"env": {
"CODECOV_BASE_URL": "https://codecov.your-company.com",
"CODECOV_TOKEN": "${CODECOV_TOKEN}"
}
}
}
}
After configuring the MCP server, verify it's working correctly:
# List all configured MCP servers
claude mcp list
# Check the codecov server status
claude mcp get codecov
You should see:
codecov: node /path/to/codecov-mcp/dist/index.js - ✓ Connected
1. 401 Unauthorized Error
If you get a 401 Unauthorized error when using the tools:
CODECOV_TOKEN is set in the MCP server's env sectionCODECOV_BASE_URL2. Environment Variable Not Expanding
If ${CODECOV_TOKEN} isn't being replaced:
~/.zshrc or ~/.bashrc)echo $CODECOV_TOKEN3. HTTP vs HTTPS
Always use https:// for the CODECOV_BASE_URL, not http://:
https://codecov.egyrllc.comhttp://codecov.egyrllc.com4. Connection Failed
If the server shows as not connected:
dist/index.js is correct and absolutenpm run buildGet line-by-line coverage data for a specific file.
Parameters:
owner (required): Repository owner (username or organization)repo (required): Repository namefile_path (required): Path to the file within the repository (e.g., 'src/index.ts')ref (optional): Git reference (branch, tag, or commit SHA)Example:
Get coverage for src/index.ts in owner/repo on main branch
Get coverage data for a specific commit.
Parameters:
owner (required): Repository ownerrepo (required): Repository namecommit_sha (required): Commit SHAExample:
Get coverage for commit abc123 in owner/repo
Get overall coverage statistics for a repository.
Parameters:
owner (required): Repository ownerrepo (required): Repository namebranch (optional): Branch name (defaults to repository's default branch)Example:
Get overall coverage for owner/repo on main branch
This project maintains 97%+ code coverage with comprehensive unit tests using Vitest.
# Run tests once
npm test
# Run tests in watch mode
npm run test:watch
# Run tests with coverage report
npm run test:coverage
# Launch Vitest UI for debugging
npm run test:ui
All code changes must maintain a minimum of 90% coverage across all metrics:
Coverage reports are automatically generated in the coverage/ directory after running npm run test:coverage. Open coverage/index.html in your browser to view detailed coverage information.
Tests run automatically on:
main and develop branchesmain or developCoverage reports are uploaded to Codecov, and PR comments show coverage changes for each pull request.
Tests are located in src/__tests__/ and use Vitest with the following patterns:
Example test structure:
import { describe, it, expect } from 'vitest';
import { getConfig, CodecovClient } from '../index.js';
describe('getConfig', () => {
it('returns default configuration when no env vars set', () => {
const config = getConfig();
expect(config.baseUrl).toBe('https://codecov.io');
});
});
When contributing:
npm testnpm run test:coverage# Install dependencies
npm install
# Build the project
npm run build
# Watch mode for development
npm run watch
This server uses Codecov's API v2. The API endpoints follow this pattern:
/api/v2/gh/{owner}/repos/{repo}/file_report/{file_path}/api/v2/gh/{owner}/repos/{repo}/commits/{commit_sha}/api/v2/gh/{owner}/repos/{repo}Currently supports GitHub repositories (gh). Support for other providers (GitLab, Bitbucket) can be added by modifying the API paths.
MIT
FAQs
MCP server for querying Codecov coverage data with configurable URL support
The npm package mcp-server-codecov receives a total of 19 weekly downloads. As such, mcp-server-codecov popularity was classified as not popular.
We found that mcp-server-codecov demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
arXiv now limits authors to two submissions a month as AI slop overwhelms moderators, delays good papers, and sparks debate over applying the limit to everyone.

Research
/Security News
A new GhostAction wave hits hundreds of GitHub repos, expanding CI/CD secret theft to cloud and AI credentials in source code and git history.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.