When using Azure Pipes to deploy an Azure Web App while having the DEBUG flag to true, in one statement the logger logs the <publishData> response to the build log.
<publishData>...</publishData> not only contains the user password as cleartext but also the SQL Server connection string including the user and password.
This seems to be a security threat because anyone who can enable the Debug flag can get access to the deployment password and database login credentials.