Howdy, looks cool! Btw, maven 4+ uses new dispatcher, and this could be nicely integrated into new sec dispatcher as well: https://github.com/codehaus-plexus/plexus-sec-dispatcher
Thanks T On Wed, 9 Sept 2026 at 20:00, Jonathan S. Fisher <[email protected]> wrote: > > Hello Maven users, > > I wrote a Maven extension people may find useful. It stores secrets in the > MacOS keychain, instead of plaintext on disk in settings.xml. Project is > here: https://github.com/exabrial/locksmith > > If you're in a regulated environment, this makes your Maven settings.xml > FIPS-140 compliant. > > This is useful to avoid your credentials (passwords, tokens, etc) getting > read silently, or sucked up into a misconfigured LLM. The extension is > written in a way where no project changes should be required from you, as > it's a tool-only change. > > It can also read secrets into Maven properties which may be useful for > different scenario. > > Also it can read secrets from a socket, allowing you to use a custom > password manager, or forward a socket over ssh for remote builds (to keep > credentials off remote machines). > > Example for your settings.xml: > > <servers> > <server> > <id>my-nexus</id> > <username>your-nexus-username</username> > <password>{[type=locksmith] > nexus.superbiz.example.com/your-nexus-username}</password> > </server> > </servers> > > I hope you find it useful. Feedback and other ideas welcome! > > -- > Jonathan | [email protected] > Pessimists, see a jar as half empty. Optimists, in contrast, see it as half > full. > Engineers, of course, understand the glass is twice as big as it needs to > be. --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
