Build logs can become secret leaks
Pipelines print what they are doing, and what they are doing frequently includes a credential.
Debug output, environment dumps, a command echoed with its arguments, an error containing a connection string. Those logs are usually readable by more people than the secret store is, and retained longer. Masking helps and only catches what it recognises.
More on CI/CD security
- A deployment pipeline is a privileged production pathIt goes straight over the gate
- Code review does not protect a compromised runnerNobody looked inside the machine
- Forked code should not automatically receive secretsThe belt does not ask who sent it
- Branch protection does not protect every release pathThe gate only guards its own road
- Deployment credentials should match deployment scopeOne bolt across all three
- Self-hosted runners inherit local trustYou gave the job a desk indoors
