Skip to content

docs: document insecure configuration for GHSA-qqhq-8r2c-c3f5#6315

Merged
jeremylong merged 1 commit intomainfrom
scratch/doc-GHSA-qqhq-8r2c-c3f5
Dec 16, 2023
Merged

docs: document insecure configuration for GHSA-qqhq-8r2c-c3f5#6315
jeremylong merged 1 commit intomainfrom
scratch/doc-GHSA-qqhq-8r2c-c3f5

Conversation

@jeremylong
Copy link
Copy Markdown
Collaborator

Maven debug logging (e.g., -X) can expose any credentials stored in the pom.xml. The credentials should be stored in the settings.xml and referenced using the appropriate server id configuration option.

@boring-cyborg boring-cyborg Bot added the maven changes to the maven plugin label Dec 16, 2023
@jeremylong jeremylong added this to the 9.0.7 milestone Dec 16, 2023
@jeremylong jeremylong merged commit 1fee73a into main Dec 16, 2023
@jeremylong jeremylong deleted the scratch/doc-GHSA-qqhq-8r2c-c3f5 branch December 16, 2023 15:23
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Dec 10, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

maven changes to the maven plugin

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant