If I have a username/password in my settings.xml
file for a (Nexus) remote repository with an HTTP (not HTTPS) URL, will this username/password be sent in plaintext to the remote server?
I'm wondering if there's a potential security issue with our public-facing HTTP-only password-authenticated Nexus server.