Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

`dependency add` and `project build` do not support Git HTTPS authentication for private dependencies

Open
#370 0 comments 1 reaction 0 assignees View on GitHub

Maintainers usually reply within 2 days

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
68/100
Issue type
Feature
Clarity
Mostly clear
Activity status
Active
Tech stack
go
Domain
cli

Research direction

Start with the dependency add and project build command entry points, then compare their dependency access with dependency update-cache, which already exposes the Git HTTPS credential options. Verify both commands read CROSSPLANE_GIT_TOKEN and CROSSPLANE_GIT_USERNAME, support the documented workflow, and keep credentials out of project files, URLs, logs, and errors.

Written by the indexing model from the issue text.

Description

bug
What happened?

Our corporate network cannot access public source-code hosts such as GitHub. We mirror the CRD manifests we need in a private repository on our internal Git server and use that repository as a project dependency.

The CLI cannot authenticate to that repository when it is accessed by crossplane dependency add or crossplane project build.

This leaves us unable to:

  1. Add the Git dependency to a project in the first place.
  2. Build a project when its dependency schemas need to be generated or refreshed.

This is surprising because crossplane dependency update-cache already supports Git-over-HTTPS authentication with:

  • --git-token / CROSSPLANE_GIT_TOKEN
  • --git-username / CROSSPLANE_GIT_USERNAME

The equivalent options are not available to dependency add or project build.

How can we reproduce it?

dependency add rejects the authentication flag:

$ crossplane dependency add --git-token=not-a-real-token
crossplane: error: unknown flag --git-token

The same flag is available on dependency update-cache:

$ crossplane dependency update-cache --help
...
      --git-token=STRING    Token for git HTTPS authentication ($CROSSPLANE_GIT_TOKEN).
      --git-username="x-access-token"
                            Username for git HTTPS authentication ($CROSSPLANE_GIT_USERNAME).

I expect this workflow to work:

export CROSSPLANE_GIT_TOKEN=<read-only-token>

crossplane dependency add \
  https://<git-server>/<organization>/<repository>.git \
  --git-ref main \
  --git-path config/crd/bases

After the dependency has been added, a regular build should also be able to access it:

crossplane project build

Both commands should use credentials supplied through environment variables. Credentials must not be written to crossplane-project.yaml, included in the repository URL, or exposed in logs and error messages.

I would be happy to contribute a fix for this issue.

What environment did it happen in?
  • Crossplane CLI version: v2.5.0
  • Platform: linux/amd64
  • Crossplane version: not applicable
Dominant language
Go
Stars
19
Forks
33
Avg merge
2d 17h
Merged PRs (30d)
52

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from crossplane/cli

All issues in crossplane/cli

Similar issues

More Go issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.