gnodet opened a new pull request, #403:
URL: https://github.com/apache/maven-filtering/pull/403

   <!-- Describe your changes -->
   
   Fixes https://github.com/apache/maven-resources-plugin/issues/133 
([MRESOURCES-290](https://issues.apache.org/jira/browse/MRESOURCES-290)).
   
   ## Problem
   
   `BaseFilter.getDefaultFilterWrappers()` contained a debug block that dumped 
every key=value pair from `filterProperties` when `isDebugEnabled()` (i.e. `mvn 
-X`). The `filterProperties` map is built from system properties and session 
properties, which includes the full `env.*` namespace — meaning every 
environment variable is logged in plain text:
   
   ```
   [DEBUG] properties used:
   [DEBUG] env.AWS_SECRET_ACCESS_KEY: AKIAIOSFODNN7EXAMPLE/wJalrXUtnFEMI/K7MDENG
   [DEBUG] env.GITHUB_TOKEN: ghp_xxxxxxxxxxxxxxxxxxxx
   [DEBUG] env.DATABASE_URL: postgres://user:password@host/db
   ```
   
   This silently leaks credentials and PII to anyone who can read the build log 
— a common scenario in CI systems where `-X` is enabled to debug a resource 
filtering issue.
   
   ## Fix
   
   Replace the full value dump with a count-only message that retains 
diagnostic value without exposing secrets:
   
   ```
   [DEBUG] number of properties used for filtering: 342
   ```
   
   This tells you whether properties were loaded (useful to detect 
empty/misconfigured filter sets) without revealing any values.
   
   Note: the 3.x branch has the same issue and will be backported separately.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to