Skip to content

FIPS 140-3 validated password hashing — ADR, packaging, and build pipeline - #8469

Draft
aaronlippold wants to merge 197 commits into
masterfrom
feature/fips-compliant-password-hashing
Draft

FIPS 140-3 validated password hashing — ADR, packaging, and build pipeline#8469
aaronlippold wants to merge 197 commits into
masterfrom
feature/fips-compliant-password-hashing

docs: add the distribution model to ADR-006

a8b1f1c
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis failed Jul 30, 2026 in 57s

Quality Gate failed

Failed conditions
9 New Vulnerabilities (required ≤ 0)
6 New Code Smells (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Annotations

Check warning on line 191 in packaging/rpm/heimdall-setup.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Make sure that using clear-text protocols is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bgExHV1Enipn-yT&open=AZ-z-bgExHV1Enipn-yT&pullRequest=8469

Check warning on line 310 in packaging/rpm/setup-rpm-build-env.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bazxHV1Enipn-yN&open=AZ-z-bazxHV1Enipn-yN&pullRequest=8469

Check warning on line 221 in packaging/rpm/scripts/setup-build-deps.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bgPxHV1Enipn-yY&open=AZ-z-bgPxHV1Enipn-yY&pullRequest=8469

Check warning on line 115 in packaging/rpm/setup-rpm-build-env.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Assign this positional parameter to a local variable.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bazxHV1Enipn-yQ&open=AZ-z-bazxHV1Enipn-yQ&pullRequest=8469

Check warning on line 133 in packaging/rpm/scripts/setup-build-deps.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bgPxHV1Enipn-yX&open=AZ-z-bgPxHV1Enipn-yX&pullRequest=8469

Check warning on line 31 in .github/workflows/build-rpm.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Move this read permission from workflow level to job level.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bg5xHV1Enipn-yZ&open=AZ-z-bg5xHV1Enipn-yZ&pullRequest=8469

Check warning on line 123 in packaging/rpm/heimdall-postgres-setup.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Merge this if statement with the enclosing one.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bf3xHV1Enipn-yS&open=AZ-z-bf3xHV1Enipn-yS&pullRequest=8469

Check warning on line 114 in packaging/rpm/setup-rpm-build-env.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Assign this positional parameter to a local variable.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bazxHV1Enipn-yP&open=AZ-z-bazxHV1Enipn-yP&pullRequest=8469

Check warning on line 312 in packaging/rpm/setup-rpm-build-env.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bazxHV1Enipn-yO&open=AZ-z-bazxHV1Enipn-yO&pullRequest=8469

Check warning on line 153 in packaging/rpm/setup-rpm-build-env.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bazxHV1Enipn-yM&open=AZ-z-bazxHV1Enipn-yM&pullRequest=8469

Check failure on line 130 in packaging/rpm/heimdall-setup.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Add a default case (*) to handle unexpected values.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bgExHV1Enipn-yV&open=AZ-z-bgExHV1Enipn-yV&pullRequest=8469

Check failure on line 201 in .github/workflows/build-rpm.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bg5xHV1Enipn-ya&open=AZ-z-bg5xHV1Enipn-ya&pullRequest=8469

Check warning on line 114 in packaging/rpm/heimdall-postgres-setup.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Merge this if statement with the enclosing one.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bf3xHV1Enipn-yR&open=AZ-z-bf3xHV1Enipn-yR&pullRequest=8469

Check warning on line 477 in packaging/rpm/heimdall-setup.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Make sure that using clear-text protocols is safe here.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bgExHV1Enipn-yU&open=AZ-z-bgExHV1Enipn-yU&pullRequest=8469

Check failure on line 200 in packaging/rpm/heimdall-setup.sh

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Add a default case (*) to handle unexpected values.

See more on https://sonarcloud.io/project/issues?id=mitre_heimdall2&issues=AZ-z-bgExHV1Enipn-yW&open=AZ-z-bgExHV1Enipn-yW&pullRequest=8469