Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs: document insecure configuration for GHSA-qqhq-8r2c-c3f5 #6315

Merged
merged 1 commit into from
Dec 16, 2023

Conversation

jeremylong
Copy link
Owner

Maven debug logging (e.g., -X) can expose any credentials stored in the pom.xml. The credentials should be stored in the settings.xml and referenced using the appropriate server id configuration option.

@boring-cyborg boring-cyborg bot added the maven changes to the maven plugin label Dec 16, 2023
@jeremylong jeremylong added this to the 9.0.7 milestone Dec 16, 2023
@jeremylong jeremylong merged commit 1fee73a into main Dec 16, 2023
6 checks passed
@jeremylong jeremylong deleted the scratch/doc-GHSA-qqhq-8r2c-c3f5 branch December 16, 2023 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maven changes to the maven plugin
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant