Evidence record EV-0038
Dry-run output printed secrets until a fix redacted them
An issue on Cloudflare's cf beta reported that --dry-run printed secret values in plain text, and Cloudflare merged a fix redacting sensitive values in dry-run output on 5 October 2026.
Independent measurement · Observation · Retrieved
Evidence class: Independent measurement. Often a single report on one version. Software changes, so check again before you rely on it. Pattern tags: dry-run, secrets.
Effect, as the source reports it
- Secret values in --dry-run output. Baseline: cf 1.0.0-beta.5: printed in plain text. With the change: After pull request #167: redacted. Direction: decrease. Size: Plain text to redacted. Sample: One reproduction.
Agent profile
- Note on models: Not an agent run: CLI behaviour.
Conflicts of interest
None apparent. The issue was filed by a user; the fix was made by a Cloudflare maintainer.
Source
cloudflare/cf#103: `--dry-run` prints secret values in plain text, GitHub, joeblew999, 30 September 2026. Retrieved ; verification: verified-live.
The full primary source was fetched on 2026-10-08 and every number in this record was found in it. The issue was closed and pull request #167 was merged on 2026-10-05.
Corroborating sources:
- cloudflare/cf#167: fix: redact sensitive values in dry-run output, GitHub, penalosa, 5 October 2026.
Limitations
- Fixed; recorded as an example of a failure mode, not current behaviour.
For designers
Dry-run output ends up in logs, pull requests and agent transcripts. Redact secrets in it by default.
Related checks
Cite this record
Cite the original source for any number, and keep the evidence class and model set with the figure. To point at this record, use "AX evidence register, EV-0038" and this page's address, https://agentexperience.tech/evidence/ev-0038/. The record is also in /evidence.json. The register's licence will be confirmed before its source repository is published.
