範例訊息
error XA4252: Insecure HTTP Maven repository URL 'http://repo.example.com/maven2/' is not allowed. Use an HTTPS URL, or set AllowInsecureHttp="true" metadata on the item to override this check.
Issue
<AndroidMavenLibrary> 項目使用 http:// 而非 https:// 來指定 Maven 儲存庫 URL。
透過純 HTTP 下載文件存在安全風險,因為連線未加密,容易受到中間人攻擊和供應鏈入侵。
此檢查與 Gradle (allowInsecureProtocol) 和 Maven (<blocked>http://*</blocked>) 的預設行為相符,用於防禦縱深及供應鏈強化。
解決方案
盡可能使用 HTTPS 網址作為 Maven 儲存庫:
<ItemGroup>
<AndroidMavenLibrary Include="com.example:mylib" Version="1.0.0" Repository="https://repo.example.com/maven2/" />
</ItemGroup>
如果該儲存庫不支援 HTTPS,且你了解其安全影響,請設定 AllowInsecureHttp="true" 為明確選擇不安全的 HTTP:
<ItemGroup>
<AndroidMavenLibrary Include="com.example:mylib" Version="1.0.0" Repository="http://repo.example.com/maven2/" AllowInsecureHttp="true" />
</ItemGroup>