Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SFI: Remove passwords from WebSdk/README.md #44860

Open
Rick-Anderson opened this issue Nov 14, 2024 · 0 comments
Open

SFI: Remove passwords from WebSdk/README.md #44860

Rick-Anderson opened this issue Nov 14, 2024 · 0 comments
Labels
Area-WebSDK untriaged Request triage from a team member

Comments

@Rick-Anderson
Copy link
Contributor

The WebSdk/README.md contains password 31 times. Per this comment by @baronfel:

I'd strongly consider changing the doc to some mechanism that does not ingest secrets of any kind into MSBuild via Properties - once something is an MSBuild property it is visible to all Task and MSBuild logic that runs in that same build, so unless you are strictly auditing the build logic you use (including build logic from NuGet packages, etc) you're exposing yourself.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Area-WebSDK untriaged Request triage from a team member
Projects
None yet
Development

No branches or pull requests

2 participants