Skip to content

Conversation

prabhu
Copy link
Collaborator

@prabhu prabhu commented Jul 31, 2025

The safest thing to do for now is not to log any arguments. This is because the arguments could be constructed using values from environment variables, which might include plaintext credentials.

Fixes #2121

Signed-off-by: Prabhu Subramanian <prabhu@appthreat.com>
@prabhu prabhu mentioned this pull request Jul 31, 2025
@prabhu prabhu merged commit dcf1f79 into master Jul 31, 2025
80 checks passed
@prabhu prabhu deleted the fix/sensitive-args-logging branch July 31, 2025 15:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

[bug] mvn dependency:tree command is logging MVN_ARGS in the clear
1 participant