keycloak/keycloak
61a4555fe865
(9 days ago)
→
dd4ae31d1b67
(3 hours ago)
| Measure | Before | After | Change |
|---|---|---|---|
| Findings to address | 804 | 801 | -3 |
| Quantum-vulnerable locations | 746 | 739 | -7 |
| Quantum-safe locations | 134 | 130 | -4 |
| Key establishment | 109 | 109 | - |
| Files scanned | 10716 | 10897 | +181 |
Added
Present in the later scan and not in the earlier one.
| Finding | Assessment | Before | After |
|---|---|---|---|
SHA-256
Mask-generation digest named for RSA padding · java.mgf1
|
Reduced margin | 0 | 3 |
unknown
Mask-generation digest named for RSA padding · java.mgf1
|
Could not be determined | 0 | 1 |
Count changed
The same finding, in a different number of places.
| Finding | Assessment | Before | After |
|---|---|---|---|
ECDSA
Elliptic-curve cryptography through BouncyCastle · java.bouncycastle.ec
|
Quantum-vulnerable | 15 | 8 |
ECDSA
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 141 | 137 |
EC
Named elliptic curve requested · java.eccurve
|
Quantum-vulnerable | 10 | 12 |
EC
Classical key pair generated through the JCA · java.keypairgenerator
|
Quantum-vulnerable | 14 | 16 |
RSASSA-PKCS1v15
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-vulnerable | 133 | 132 |
unknown
Key store holding classical key material · java.keystore
|
Could not be determined | 5 | 6 |
HMAC
JOSE algorithm declared in configuration · jose.algorithm
|
Quantum-safe | 49 | 46 |
Argon2
Password hashing or key derivation · java.kdf
|
Quantum-safe | 4 | 2 |
CSPRNG
Random number generation · java.rng
|
Quantum-safe | 38 | 39 |
Unchanged
72 findings appear in both scans, in the same number of places. Each scan's own report lists them.