/ super-linter Public
Stop logging token #3251
Add this suggestion to a batch that can be applied as a single commit. This suggestion is invalid because no changes were made to the code. Suggestions cannot be applied while the pull request is closed. Suggestions cannot be applied while viewing a subset of changes. Only one suggestion per line can be applied in a batch. Add this suggestion to a batch that can be applied as a single commit. Applying suggestions on deleted lines is not supported. You must change the existing code in this line in order to create a valid suggestion. Outdated suggestions cannot be applied. This suggestion has been applied or marked resolved. Suggestions cannot be applied from pending reviews. Suggestions cannot be applied on multi-line comments. Suggestions cannot be applied while the pull request is queued to merge.
Registering the token in the log has no value, if a user pulls the token from the secret store it is automatically redacted, moreover the python scripts that drive Super Linter exit if the token is not set.
The risk is in users registering tokens by other means, such as generating app tokens at runtime where they can't be registered as secrets. Since there is all risk and no reward, remove the logging of the token.