適用於 Android 的 .NET 錯誤 XA4252

範例訊息

error XA4252: Insecure HTTP Maven repository URL 'http://repo.example.com/maven2/' is not allowed. Use an HTTPS URL, or set AllowInsecureHttp="true" metadata on the item to override this check.

Issue

<AndroidMavenLibrary> 項目使用 http:// 而非 https:// 來指定 Maven 儲存庫 URL。 透過純 HTTP 下載文件存在安全風險,因為連線未加密,容易受到中間人攻擊和供應鏈入侵。

此檢查與 Gradle (allowInsecureProtocol) 和 Maven (<blocked>http://*</blocked>) 的預設行為相符,用於防禦縱深及供應鏈強化。

解決方案

盡可能使用 HTTPS 網址作為 Maven 儲存庫:

<ItemGroup>
  <AndroidMavenLibrary Include="com.example:mylib" Version="1.0.0" Repository="https://repo.example.com/maven2/" />
</ItemGroup>

如果該儲存庫不支援 HTTPS,且你了解其安全影響,請設定 AllowInsecureHttp="true" 為明確選擇不安全的 HTTP:

<ItemGroup>
  <AndroidMavenLibrary Include="com.example:mylib" Version="1.0.0" Repository="http://repo.example.com/maven2/" AllowInsecureHttp="true" />
</ItemGroup>