Extend Well-Known secret masking
extend the well known secret masking to the password segment of URIs.
examples:
https://username:password@git.example.com/user/repo.git
ssh://user:password@host:port/path
postgres://username:password@host:port/database
- Workaround
- no
- Problem
Log in to comment and vote
Comments2
Black Breeze
Jun 10, 2025
Archiving due to inactivity.
Black Breeze
May 7, 2025
Thanks for flagging this—really helpful.
Quick question back: how are these URIs ending up in logs in the first place? We’re curious what surface is leaking them.
For example:
Is the password part showing up in Terraform plan output?
Or being echoed by a script or hook?
Or logged as part of a CLI command?
Our default posture is to avoid logging sensitive data altogether—so if these values are leaking, it’s likely happening via user-defined logic (e.g. shell scripts, Terraform output, or custom tools). Understanding that path would help us know whether masking is the right fix—or whether we need to tighten the input/output surfaces upstream.
If you can share where and how you’re seeing it, we can make sure it’s addressed the right way—not just band-aided.
Thanks again—this is exactly the kind of sharp edge we want to blunt.