Build logs can become secret leaks

Pipelines print what they are doing, and what they are doing frequently includes a credential.

Debug output, environment dumps, a command echoed with its arguments, an error containing a connection string. Those logs are usually readable by more people than the secret store is, and retained longer. Masking helps and only catches what it recognises.

More on CI/CD security