The deployed origin refuses TLS 1.0 and TLS 1.1 handshakes and accepts TLS 1.2, and no configuration in the checkout allows the legacy protocols.
Inputs
Three TLS handshake probes (1.0, 1.1, 1.2) against the deployed origin through the execution context's TLS probe, when the repository declares an origin and the context provides the probe. Server, proxy, load-balancer, CDN and application configuration files of the checkout. Paths listed in excludes (test, spec and tmp files, __tests__, __mocks__, fixtures, test, tests and audit-scripts folders) are never analysed.
Decision rule
FAIL when a configuration file explicitly allows TLS 1.0 or 1.1 (nginx ssl_protocols, Apache SSLProtocol, Node minVersion/secureProtocol, Python ssl minimum_version, HAProxy ssl-min-ver, Caddy protocols, ALB ELBSecurityPolicy-2016-08 and older, CloudFront TLSv1/TLSv1_2016/TLSv1.1_2016, Cloudflare/Azure min TLS 1.0/1.1), regardless of the probe. With a probe: FAIL when a TLS 1.0 or 1.1 handshake completes or a TLS 1.2 handshake is refused; PASS when 1.0 and 1.1 are refused and 1.2 is accepted. Without a deployed origin or without a TLS probe, and without a HIGH finding, the check is not applicable; explicit TLS 1.2 minimum declarations are reported as informative.
Type
deterministic
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
for (const version of ['TLSv1', 'TLSv1.1', 'TLSv1.2']) results[version] = (await ctx.probeTls({ host, port, version })).accepted;