Slack workflow tokens and webhook URLs are now scrubbed from text before it leaves your machine.
What's wrong with this entry?
The credential scrubber applied to text before it leaves the client now catches Slack workflow tokens beginning xwfp- and Slack webhook URLs under hooks.slack.com/services, /workflows and /triggers, replacing them with a placeholder instead of letting them through.
- Tokens are replaced with
[REDACTED-PAT]; webhook URLs are replaced with their own placeholder. - Both patterns were added to every scrubber in the build, including the token table that already handled bearer and Basic headers,
sk-ant-keys, GitHub and GitLab tokens and Slackxoxb-tokens.
hooks.slack.com/<redacted>, [REDACTED-PAT]
Strings lifted out of the shipped bundle, so the claim above can be checked against them.
Related
Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.
-
v2.1.232
GitLab token detection grows from 2 patterns to 11
Both mention secret redaction
-
v2.1.232
GitLab tokens are now stripped from logs and error output
Both mention secret redaction
-
v2.1.232
Nine more GitLab token types are caught by the secret scanner
Both mention secret redaction