Skip to content

Commit 3c91805

Browse files
authored
House keeping (#64)
* Remove fingerprint of signing from POM * prevent leakage of NVD API key in logs
1 parent 6878189 commit 3c91805

File tree

3 files changed

+3
-2
lines changed

3 files changed

+3
-2
lines changed

.github/workflows/publish-central.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -32,3 +32,4 @@ jobs:
3232
MAVEN_PASSWORD: ${{ secrets.OSSRH_PASSWORD }}
3333
MAVEN_GPG_PASSPHRASE: ${{ secrets.RELEASES_GPG_PASSPHRASE }}
3434
MAVEN_GPG_KEY: ${{ secrets.RELEASES_GPG_PRIVATE_KEY }}
35+
MAVEN_GPG_KEY_FINGERPRINT: ${{ vars.RELEASES_GPG_KEY_FINGERPRINT }}

.github/workflows/publish-github.yml

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -23,6 +23,7 @@ jobs:
2323
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
2424
MAVEN_GPG_PASSPHRASE: ${{ secrets.RELEASES_GPG_PASSPHRASE }}
2525
MAVEN_GPG_KEY: ${{ secrets.RELEASES_GPG_PRIVATE_KEY }}
26+
MAVEN_GPG_KEY_FINGERPRINT: ${{ vars.RELEASES_GPG_KEY_FINGERPRINT }}
2627
- name: Slack Notification
2728
uses: rtCamp/action-slack-notify@v2
2829
env:

pom.xml

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -263,7 +263,7 @@
263263
<skipTestScope>true</skipTestScope>
264264
<detail>true</detail>
265265
<suppressionFile>suppression.xml</suppressionFile>
266-
<nvdApiKey>${env.NVD_API_KEY}</nvdApiKey>
266+
<nvdApiKeyEnvironmentVariable>NVD_API_KEY</nvdApiKeyEnvironmentVariable>
267267
</configuration>
268268
<executions>
269269
<execution>
@@ -321,7 +321,6 @@
321321
</goals>
322322
<configuration>
323323
<signer>bc</signer>
324-
<keyFingerprint>58117AFA1F85B3EEC154677D615D449FE6E6A235</keyFingerprint>
325324
</configuration>
326325
</execution>
327326
</executions>

0 commit comments

Comments
 (0)