Edit

.NET for Android error XA4252

Example message

error XA4252: Insecure HTTP Maven repository URL 'http://repo.example.com/maven2/' is not allowed. Use an HTTPS URL, or set AllowInsecureHttp="true" metadata on the item to override this check.

Issue

An <AndroidMavenLibrary> item specifies a Maven repository URL using http:// instead of https://. Downloading artifacts over plain HTTP is a security risk because the connection is not encrypted and is vulnerable to man-in-the-middle attacks and supply-chain compromise.

This check aligns with default behavior in Gradle (allowInsecureProtocol) and Maven (<blocked>http://*</blocked>) for defense in depth and supply-chain hardening.

Solution

Use an HTTPS URL for the Maven repository whenever possible:

<ItemGroup>
  <AndroidMavenLibrary Include="com.example:mylib" Version="1.0.0" Repository="https://repo.example.com/maven2/" />
</ItemGroup>

If the repository does not support HTTPS and you understand the security implications, set AllowInsecureHttp="true" to explicitly opt in to insecure HTTP:

<ItemGroup>
  <AndroidMavenLibrary Include="com.example:mylib" Version="1.0.0" Repository="http://repo.example.com/maven2/" AllowInsecureHttp="true" />
</ItemGroup>