Howdy,

looks cool! Btw, maven 4+ uses new dispatcher, and this could be
nicely integrated into new sec dispatcher as well:
https://github.com/codehaus-plexus/plexus-sec-dispatcher

Thanks
T

On Wed, 9 Sept 2026 at 20:00, Jonathan S. Fisher <[email protected]> wrote:
>
> Hello Maven users,
>
> I wrote a Maven extension people may find useful. It stores secrets in the
> MacOS keychain, instead of plaintext on disk in settings.xml. Project is
> here: https://github.com/exabrial/locksmith
>
> If you're in a regulated environment, this makes your Maven settings.xml
> FIPS-140 compliant.
>
> This is useful to avoid your credentials (passwords, tokens, etc) getting
> read silently, or sucked up into a misconfigured LLM. The extension is
> written in a way where no project changes should be required from you, as
> it's a tool-only change.
>
> It can also read secrets into Maven properties which may be useful for
> different scenario.
>
> Also it can read secrets from a socket, allowing you to use a custom
> password manager, or forward a socket over ssh for remote builds (to keep
> credentials off remote machines).
>
> Example for your settings.xml:
>
> <servers>
>   <server>
>     <id>my-nexus</id>
>     <username>your-nexus-username</username>
>     <password>{[type=locksmith]
> nexus.superbiz.example.com/your-nexus-username}</password>
>   </server>
> </servers>
>
> I hope you find it useful. Feedback and other ideas welcome!
>
> --
> Jonathan | [email protected]
> Pessimists, see a jar as half empty. Optimists, in contrast, see it as half
> full.
> Engineers, of course, understand the glass is twice as big as it needs to
> be.

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to