Auditor
Passwords are hashed with argon2, scrypt or bcrypt with adequate cost; never MD5, SHA-1 or plain SHA-256.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
| { re: /createHash\s*\(\s*['"](md5|sha1|sha256|sha512)['"]\s*\)[^\n]{0,160}?\.update\s*\(\s*[^)\n]*PASSWORD/g }, // -> FAIL |
| { re: /hashlib\.(md5|sha1|sha256)\s*\(\s*[^)\n]*PASSWORD/g }, // -> FAIL |
| const SLOW_HASH = /\b(?:bcrypt|argon2|scrypt|pbkdf2|password_hash|Hash::make|make_password|passlib|crypto_pwhash)\b/; // required for PASS |
| // bcrypt cost < 10, PBKDF2 < 100000, argon2 memory < 15 MiB, scrypt N < 16384 -> MEDIUM |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.