You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.280,
ImprovementsSection of the release
What
A new redaction routine scans text for patterns that look like credentials, such as AWS secret keys, bearer tokens, and session tokens, written as either key=value or key: value, including escaped or quoted forms. Any matching value is replaced with <token>.
Placeholder-like values, such as undefined, null, none, true, false, bearer, or basic, are left alone rather than redacted, since they aren't actual secrets.
Why
This reduces the chance that real credentials get shown or logged when they appear in tool output.