FIPS 140-3 validated password hashing — ADR, packaging, and build pipeline - #8469
FIPS 140-3 validated password hashing — ADR, packaging, and build pipeline#8469aaronlippold wants to merge 197 commits into
9 new alerts including 1 high severity security vulnerability
New alerts in code changed by this pull request
Security Alerts:
- 1 high
- 5 medium
- 3 low
See annotations below for details.
Annotations
Check failure on line 201 in .github/workflows/build-rpm.yml
Code scanning / SonarCloud
External GitHub Actions and workflows should be pinned to a commit hash High
Check warning on line 133 in packaging/rpm/scripts/setup-build-deps.sh
Code scanning / SonarCloud
HTTPS should be enforced on HTTP clients following redirects Medium
Check warning on line 221 in packaging/rpm/scripts/setup-build-deps.sh
Code scanning / SonarCloud
HTTPS should be enforced on HTTP clients following redirects Medium
Check warning on line 153 in packaging/rpm/setup-rpm-build-env.sh
Code scanning / SonarCloud
HTTPS should be enforced on HTTP clients following redirects Medium
Check warning on line 310 in packaging/rpm/setup-rpm-build-env.sh
Code scanning / SonarCloud
HTTPS should be enforced on HTTP clients following redirects Medium
Check warning on line 312 in packaging/rpm/setup-rpm-build-env.sh
Code scanning / SonarCloud
HTTPS should be enforced on HTTP clients following redirects Medium
Check notice on line 31 in .github/workflows/build-rpm.yml
Code scanning / SonarCloud
Read permissions should be defined at the job level Low
Check notice on line 191 in packaging/rpm/heimdall-setup.sh
Code scanning / SonarCloud
Clear-text protocols should not be used Low
Check notice on line 477 in packaging/rpm/heimdall-setup.sh
Code scanning / SonarCloud
Clear-text protocols should not be used Low