Skip to content
← All rules
ObservabilityData protection

observability/no-sensitive-logs

Detected log and telemetry calls must mask, allowlist, hash for disclosure control, or redact visibly sensitive emitted values.

loggingprivacyredaction
TypeScript
logger.info({ email, password }, "Login attempt");
Finding

Disallow sensitive values emitted without redaction.

Setup

Install the package, register its plugin factory, then enable the rule.

Install the package

pnpm add -D @scruple/observability

Register the plugin

In scruple.config.ts, register the factory under the observability namespace used by the rule ID.

import { observability } from "@scruple/observability";

plugins: {
  "observability": observability(),
},

Enable the rule

"observability/no-sensitive-logs": "warn"
Package
@scruple/observability
Default threshold
0.9
Minimum confidence
0.7

Released under the MIT License.