-
-
Notifications
You must be signed in to change notification settings - Fork 9
Open
Description
Hello,
I've been testing the qcastel/github-actions-maven-release action and noticed that it cats the maven settings file. This exposes the credentials in the workflow logs. I'm referring to line 40 in qcastel/github-actions-maven-release/setup-maven-servers.sh. Is it necessary to cat that file, or can that line be removed?
Thanks,
Weldon
Metadata
Metadata
Assignees
Labels
No labels