Hello Maven users,

I wrote a Maven extension people may find useful. It stores secrets in the
MacOS keychain, instead of plaintext on disk in settings.xml. Project is
here: https://github.com/exabrial/locksmith

If you're in a regulated environment, this makes your Maven settings.xml
FIPS-140 compliant.

This is useful to avoid your credentials (passwords, tokens, etc) getting
read silently, or sucked up into a misconfigured LLM. The extension is
written in a way where no project changes should be required from you, as
it's a tool-only change.

It can also read secrets into Maven properties which may be useful for
different scenario.

Also it can read secrets from a socket, allowing you to use a custom
password manager, or forward a socket over ssh for remote builds (to keep
credentials off remote machines).

Example for your settings.xml:

<servers>
  <server>
    <id>my-nexus</id>
    <username>your-nexus-username</username>
    <password>{[type=locksmith]
nexus.superbiz.example.com/your-nexus-username}</password>
  </server>
</servers>

I hope you find it useful. Feedback and other ideas welcome!

-- 
Jonathan | [email protected]
Pessimists, see a jar as half empty. Optimists, in contrast, see it as half
full.
Engineers, of course, understand the glass is twice as big as it needs to
be.

Reply via email to