This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method.
"https://github.com/pypa/advisory-database/blob/main/vulns/codecov/PYSEC-2022-238.yaml"