Skip to content

Credentials exposed in logs #3

@wsams

Description

@wsams

Hello,

I've been testing the qcastel/github-actions-maven-release action and noticed that it cats the maven settings file. This exposes the credentials in the workflow logs. I'm referring to line 40 in qcastel/github-actions-maven-release/setup-maven-servers.sh. Is it necessary to cat that file, or can that line be removed?

Thanks,
Weldon

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions