-
Notifications
You must be signed in to change notification settings - Fork 406
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AWS WebIdentityToken exposure in log files #2719
Comments
Can you try a local |
Tried
|
Using |
I'm still unable to reproduce, with a new project and a
|
I've removed |
deltalake-core v0.18.1 depends on |
Aha, I see that. That's effectively an error in the datafusion dependency chain which we don't have a way to remedy other than upgrades. our |
0.18.2 has the fix here i believe |
https://rustsec.org/advisories/RUSTSEC-2024-0358
When using AWS WebIdentityTokens with the
object_store
crate, in the event ofa failure and automatic retry, the underlying
reqwest
error, including thefull URL with the credentials, potentially in the parameters, is written to the
logs.
The text was updated successfully, but these errors were encountered: