{"version":"2.1.290","anchor":"redaction-rules-skip-regex-when-prefilter-fails","canonical_anchor":"redaction-rules-skip-regex-when-prefilter-fails","heading":"Hiding secrets in output skips rules that cannot match","tier":"internal","area":"Secret Redaction","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/redaction-rules-skip-regex-when-prefilter-fails","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Hiding secrets in output skips rules that cannot match\n\nEach secret-hiding rule now runs a quick check first and skips its full pattern when it cannot match\n\n**Unclear.** It is not confirmed that the rebuilt escaped-assignment rule matches exactly the same text as before.\n\n**What**\n\nClaude Code hides things that look like secrets, such as keys and passwords, in output it displays. It does this by running a list of patterns over the text. Each high-confidence pattern can now have a cheap first check. If that check shows the pattern cannot match, Claude Code skips the full pattern. This is meant to leave what gets hidden unchanged.\n\nThe rule that catches escaped secret assignments was also rebuilt from different pieces.\n\n**Why**\n\nHiding secrets in large outputs should be faster.\n\n- Area: Secret Redaction\n- Tier: Under the hood\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}