My only nitpick is the regex matching they do to mask protected environment variables from ci logs is not sufficient. It won't match + scrub aws secret keys in the logs, which seems like a pretty glaring problem in a cicd setup.
> masked so they are hidden in job logs, though they must match certain regexp requirements to do so
We've been able to work around it, but it did make that particular automation more difficult.