Evidence record EV-0038

Dry-run output printed secrets until a fix redacted them

An issue on Cloudflare's cf beta reported that --dry-run printed secret values in plain text, and Cloudflare merged a fix redacting sensitive values in dry-run output on 5 October 2026.

Evidence class: Independent measurement. Often a single report on one version. Software changes, so check again before you rely on it. Pattern tags: dry-run, secrets.

Effect, as the source reports it

  • Secret values in --dry-run output. Baseline: cf 1.0.0-beta.5: printed in plain text. With the change: After pull request #167: redacted. Direction: decrease. Size: Plain text to redacted. Sample: One reproduction.

Agent profile

  • Note on models: Not an agent run: CLI behaviour.

Conflicts of interest

None apparent. The issue was filed by a user; the fix was made by a Cloudflare maintainer.

Source

cloudflare/cf#103: `--dry-run` prints secret values in plain text, GitHub, joeblew999, 30 September 2026. Retrieved ; verification: verified-live.

The full primary source was fetched on 2026-10-08 and every number in this record was found in it. The issue was closed and pull request #167 was merged on 2026-10-05.

Corroborating sources:

Limitations

  • Fixed; recorded as an example of a failure mode, not current behaviour.

For designers

Dry-run output ends up in logs, pull requests and agent transcripts. Redact secrets in it by default.

Cite this record

Cite the original source for any number, and keep the evidence class and model set with the figure. To point at this record, use "AX evidence register, EV-0038" and this page's address, https://agentexperience.tech/evidence/ev-0038/. The record is also in /evidence.json. The register's licence will be confirmed before its source repository is published.