BlueOcean is exposing SonarQube token

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

      Hi,

      when providing withSonarQubeEnv with access token from Jenkins credentials, default Jenkins logs hide it:

      However, the same stage reveals it in BlueOcean by displaying the full command being executed:

      This should be hidden with asterisks in the same manner as in Jenkins logs.

      And please ensure it is done not just for Sonar but any other similar statements as withcredentials or sshagent (not sure if it is revealed for those too).

            Assignee:
            Unassigned
            Reporter:
            Darko
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Archived: