PII Entity Logging Leak
Detects PII-sensitive terms (email, SSN, password, etc.) appearing inside log calls in added lines.
Why this rule exists
Logs end up in third-party aggregators, support tickets, and analytics pipelines. PII in a log line is PII in every downstream system, often outside the compliance perimeter.
Code example
+ _logger.LogInformation("Login attempt: email={Email}, password={Password}", email, password);+ _logger.LogInformation("Login attempt: userId={UserId}", user.Id);Configuration
Disable or adjust the severity of this rule in .gauntletci.json:
{
"rules": {
"GCI0029": { "enabled": true, "severity": "Warn" }
}
}See Configuration for the full schema.
Related rules
Hardcoding and Configuration
Detects hardcoded IPs, URLs, connection strings, secrets, and environment names committed to source.
Security Risk
Detects SQL injection patterns, weak crypto algorithms (MD5, SHA1, DES), dangerous APIs (Assembly.Load, Process.Start), and credential exposure.
Error Handling Integrity
Detects swallowed exceptions (empty catch blocks) and exception handling patterns that hide failures from callers and operators.
Implemented in src/GauntletCI.Core/Rules/Implementations/GCI0029_*.cs.
Eric Cogen -- Founder, GauntletCI
Twenty years as a senior technical consultant building and modernizing enterprise platforms across .NET, AWS, serverless, microservices, and AI-driven systems.
