gnodet opened a new pull request, #403: URL: https://github.com/apache/maven-filtering/pull/403
<!-- Describe your changes --> Fixes https://github.com/apache/maven-resources-plugin/issues/133 ([MRESOURCES-290](https://issues.apache.org/jira/browse/MRESOURCES-290)). ## Problem `BaseFilter.getDefaultFilterWrappers()` contained a debug block that dumped every key=value pair from `filterProperties` when `isDebugEnabled()` (i.e. `mvn -X`). The `filterProperties` map is built from system properties and session properties, which includes the full `env.*` namespace — meaning every environment variable is logged in plain text: ``` [DEBUG] properties used: [DEBUG] env.AWS_SECRET_ACCESS_KEY: AKIAIOSFODNN7EXAMPLE/wJalrXUtnFEMI/K7MDENG [DEBUG] env.GITHUB_TOKEN: ghp_xxxxxxxxxxxxxxxxxxxx [DEBUG] env.DATABASE_URL: postgres://user:password@host/db ``` This silently leaks credentials and PII to anyone who can read the build log — a common scenario in CI systems where `-X` is enabled to debug a resource filtering issue. ## Fix Replace the full value dump with a count-only message that retains diagnostic value without exposing secrets: ``` [DEBUG] number of properties used for filtering: 342 ``` This tells you whether properties were loaded (useful to detect empty/misconfigured filter sets) without revealing any values. Note: the 3.x branch has the same issue and will be backported separately. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
