This message was deleted.
# community-support
s
This message was deleted.
m
Copy code
maven {
        name = "ossStaging"
        uri("...")
        credentials {
          username = System.getenv("SONATYPE_NEXUS_USERNAME")
          password = System.getenv("SONATYPE_NEXUS_PASSWORD")
        }
      }
c
never ever store secure information in the environment
m
How is a gradle property better?
e
I prefer
Copy code
repositories {
    maven {
        credentials(PasswordCredentials::class)
    }
}
over
System.getenv
. it pulls from Gradle properties, although you can still specify those via environment if needed
m
You can always do:
Copy code
credentials {
      username = findProperty("SONATYPE_NEXUS_USERNAME").toString()
      password = findProperty("SONATYPE_NEXUS_PASSWORD").toString()
    }
c
@Martin see article on why not store secrets in the environment
e
I don't think most of that applies to Gradle
using the built-in credentials helps Gradle track it better than findProperty anyway though
c
it does, in fact github flagged configuration cache storage as a vulnerability because it puts secure credentials in the environment and gradle sticks all environment variables in the cache
e
(since unfortunately it isn't a provider api)
c
@ephemient yes, but what's the default property, and can I change it?
also there is a providers.getCredentials()
e
yes, that works as documented, repositoryNameUsername/repositoryNamePassword properties
I mean you can't do
Copy code
username = providers.gradleProperty("...")
c
I mean you could, but you have to call get. Ah, so it's the name? I found the example to be a little unclear
e
if you call get then it's no better than findProperty
m
If the secret is readable in a
gradle.properties
file, how is that different from the secret being in
~.gradle/configuration-cache/something
? File permissions maybe?
c
@Martin please read that article, also you could stick the output of the gradle.properties in your home directory in the secure thing, but github is probably exposing that via env var only... github not being the only CI though
e
I've been using ejson-kotlin. There's no documentation and no security audit though 😅
It's a Kotlin implementation of https://github.com/Shopify/ejson
c
well, the gradle build action no longer stores the configuration cache at all, so if you're using that you're fine
ok, so if the credentials are based on repo name... what if 2 repos use the same credentials?
because they're really the same server
e
you have other problems if they use the same name
c
just segmented because nexus/artifactory
so my only option then is findProperty?
e
Copy code
repositories {
    maven { name = "foo" }
    maven { name = "bar" }
`fooUsername`/`fooPassword` and `barUsername`/`barPassword`
that is distinct from
url
. if you have conflicting names you have problems regardless of credentials
c
Copy code
maven("<https://org.jfrog.io/artifactory/org-dcp>") {
        credentials {
            username = findProperty("artifactoryUsername").toString()
            password = findProperty("artifactoryPassword").toString()
        }
    }
    maven("<https://org.jfrog.io/artifactory/plugins-release>") {
        credentials {
            username = findProperty("artifactoryUsername").toString()
            password = findProperty("artifactoryPassword").toString()
        }
    }
so is that the best I can do?
e
why do you think that
c
because I"m dumb? that's why I'm asking
I don't want to change ~/.gradle.properties current structure
which uses those keys
because then I would have to ask everyone to change their properties files
so given the credential name has to remain, e.g
artifactoryUsername
, is that the simplest and most secure thing that can work?
e
you could just copy the properties if they exist
c
copy?
e
e.g. setproperty(findproperty) somewhere early like in settings
c
doesn't feel particularly better 😢