There are edge cases where secrets redaction via core.setSecret don't reliably work on multiline values when Actions debug mode is enable, which risk secret key leakage for things like GitHub App private keys.
This is a known issue to be documented in the README, and will discuss about this in the GitHub community forums for advice later.