Hello Maven users,
I wrote a Maven extension people may find useful. It stores secrets in the
MacOS keychain, instead of plaintext on disk in settings.xml. Project is
here: https://github.com/exabrial/locksmith
If you're in a regulated environment, this makes your Maven settings.xml
FIPS-140 compliant.
This is useful to avoid your credentials (passwords, tokens, etc) getting
read silently, or sucked up into a misconfigured LLM. The extension is
written in a way where no project changes should be required from you, as
it's a tool-only change.
It can also read secrets into Maven properties which may be useful for
different scenario.
Also it can read secrets from a socket, allowing you to use a custom
password manager, or forward a socket over ssh for remote builds (to keep
credentials off remote machines).
Example for your settings.xml:
<servers>
<server>
<id>my-nexus</id>
<username>your-nexus-username</username>
<password>{[type=locksmith]
nexus.superbiz.example.com/your-nexus-username}</password>
</server>
</servers>
I hope you find it useful. Feedback and other ideas welcome!
--
Jonathan | [email protected]
Pessimists, see a jar as half empty. Optimists, in contrast, see it as half
full.
Engineers, of course, understand the glass is twice as big as it needs to
be.