You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
ferventcoder
changed the title
"source add -s [url]-u [user] -p [pass]" puts clear text password in chocolatey log file
Passwords in command line options are logged in clear text
Sep 18, 2016
Original Title: "source add -s [url]-u [user] -p [pass]" puts clear text password in chocolatey log file
It appears that the default chocolatey logging (debug?) captures the password for a source in the log.
I have worked hard to eliminate the password being recorded on the clients I build using packer and chocolatey, but I can't fix this one.
Even for debug logs I think that secrets should not be recordable in the log.
The text was updated successfully, but these errors were encountered: