Skip to content

FIPS 140-3 validated password hashing — ADR, packaging, and build pipeline - #8469

Draft
aaronlippold wants to merge 197 commits into
masterfrom
feature/fips-compliant-password-hashing
Draft

FIPS 140-3 validated password hashing — ADR, packaging, and build pipeline#8469
aaronlippold wants to merge 197 commits into
masterfrom
feature/fips-compliant-password-hashing

docs(authn): cite the tracking card for the LDAP prefer-at disable

6c69c3c
Select commit
Loading
Failed to load commit list.
GitGuardian / GitGuardian Security Checks failed Aug 16, 2026 in 51s

10 secrets uncovered!

10 secrets were uncovered from the scan of 197 commits in your pull request. ❌

Please have a look to GitGuardian findings and remediate in order to secure your code.

Details

🔎 Detected hardcoded secrets in your pull request

  • Pull request #8469: feature/fips-compliant-password-hashing 👉 master
GitGuardian id GitGuardian status Secret Commit Filename
35573710 Triggered Generic Database Assignment 35d47de packaging/rpm/INSTALL.md View secret
36202367 Triggered Generic Password 3dd3db9 libs/password-hash-vectors/src/vectors.ts View secret
36202368 Triggered Generic Password 3dd3db9 libs/password-hash-vectors/src/vectors.ts View secret
22339997 Triggered PostgreSQL Credentials 54dd1df apps/backend/test/constants/environment_test.constant.ts View secret
36202369 Triggered Generic Password 3a09a58 apps/backend/seeders/demo-seed-helpers.js View secret
36202370 Triggered Generic Password 3dd3db9 libs/password-hash-vectors/scripts/generate-vectors.ts View secret
36202371 Triggered Generic Password c7532b7 apps/backend/test/demo-users-seeder.spec.ts View secret
36202372 Triggered Generic Password 3dd3db9 libs/password-hash-vectors/scripts/generate-vectors.ts View secret
36202373 Triggered Generic Password ebc5a78 apps/backend/src/authn/rehash-lifecycle.spec.ts View secret
36202374 Triggered Generic Password 3dd3db9 libs/password-hash-vectors/scripts/generate-vectors.ts View secret

🛠 Guidelines to remediate hardcoded secrets

  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secrets safely. Learn here the best practices.
  3. Revoke and rotate these secrets.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider


🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.