Private key blocks are fully redacted and secret rules no longer fire inside longer identifiers.
What's wrong with this entry?
The redactor that masks secrets before they leave your machine now detects PEM private key blocks by scanning for matching BEGIN and END lines with at least 64 characters between them, replacing the whole block with [REDACTED], and loops so several keys in one text are all caught. High-confidence rules now require a non-word character on both sides, so they no longer trigger inside a longer identifier.
- The private key detector is added to the rule list as its own rule and reports as "Private Key".
- Candidates that look like a shell fragment or a path/URL are now left alone instead of being masked.
[REDACTED], { ruleId: "private-key", label: "Private Key" }
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.232
GitLab token detection grows from 2 patterns to 11
Both mention secret redaction
-
v2.1.232
GitLab tokens are now stripped from logs and error output
Both mention secret redaction
-
v2.1.232
Nine more GitLab token types are caught by the secret scanner
Both mention secret redaction