Skip to content

feat(parity): source reads of Bitwarden, Passbolt, Vault and Nextcloud Passwords, sources and 38 demand rows - #761

Merged
rubenvdlinde merged 10 commits into
developmentfrom
parity/w5-keepiq-source-reads
Sep 26, 2026
Merged

rubenvdlinde merged 10 commits into
developmentfrom
parity/w5-keepiq-source-reads

Conversation

@rubenvdlinde

Copy link
Copy Markdown
Contributor

What this does

Deepens the competitor columns of keepiq's capability matrix (wave 5). Four systems whose source is public are now rated from their code at a release tag, with path:line evidence. Every system gains a sources object, and 38 rows are added (23 mined from demand signals, 15 from the source reads). Data file only: openspec/parity/capabilities.json. No page is wired, and a JSON file under openspec/ cannot affect the app's suites, so they were not run.

Read on development at c88ff04. Branch head is the last commit of this PR.

Grades, before and after

system before after
Bitwarden docs-only (vendor docs) docs-only, source read at bitwarden/server@v2026.9.1 and bitwarden/clients@web-v2026.9.0, not driven
Passbolt docs-only docs-only, source read at passbolt_api, passbolt_browser_extension and passbolt_styleguide @v5.16.0, not driven
HashiCorp Vault docs-only docs-only, source read at hashicorp/vault@v2.1.1 (Community Edition tree), not driven
Nextcloud Passwords docs-only docs-only, source read at marius-wieschollek/passwords@2026.9.0 (81434de), not driven
1Password Business docs-only docs-only (closed source; more cells from vendor docs)
Keeper Enterprise docs-only docs-only (closed source; more cells from vendor docs)

The grade enum has no value for a source read, so the grade stays docs-only, readOn is 2026-09-26, and each system carries sourceRead plus a gradeNote. No labs were booted in this lane, so no system reached driven. No images were pulled.

Ratings per column (yes / partial / no / unknown)

system before (191 rows) y/p/n/u after, same 191 rows after, all 229 rows
keepiq 114 / 42 / 34 / 1 114 / 42 / 34 / 1 115 / 52 / 61 / 1
bitwarden 93 / 30 / 25 / 43 97 / 37 / 57 / 0 117 / 49 / 63 / 0
onepassword 89 / 34 / 21 / 47 89 / 36 / 21 / 45 99 / 45 / 23 / 62
passbolt 63 / 44 / 51 / 33 68 / 45 / 76 / 2 77 / 52 / 97 / 3
keeper 97 / 34 / 8 / 52 97 / 34 / 8 / 52 107 / 40 / 8 / 74
hashicorp-vault 47 / 39 / 17 / 88 49 / 52 / 89 / 1 57 / 58 / 113 / 1
nextcloud-passwords 38 / 47 / 68 / 38 39 / 49 / 98 / 5 49 / 56 / 115 / 9

Unknowns settled on the existing 191 rows: HashiCorp Vault 87 (88 unknown before, 1 left), Bitwarden 43 (all), Nextcloud Passwords 33, Passbolt 31, 1Password 2, Keeper 0. Most settle as no from a stated search of the source (terms and directories are in each cell).

Every rating change (evidence cut to 110 characters; the full string is in the file) on the existing 191 rows

bitwarden: 47 changes (unknown→no 33, unknown→partial 7, unknown→yes 3, partial→yes 2, yes→partial 1, no→partial 1)
row before after evidence
vault-08 unknown no searched 'nextcloud' (case-insensitive) in bitwarden/clients@web-v2026.9.0 and bitwarden/server@v2026.9.1 whol
vault-20 unknown no searched 'defaultCipherType', 'default.?view', 'VaultViewMode', 'listView' in bitwarden/clients@web-v2026.9.0
vault-21 unknown partial bitwarden/clients@web-v2026.9.0 libs/common/src/vault/services/cipher.service.ts:721 updateLastUsedDate, :554
crypto-13 yes partial bitwarden/server@v2026.9.1 src/Core/Enums/KdfType.cs:6 Argon2id (and PBKDF2); src/Api/Auth/Controllers/Account
crypto-14 unknown no searched 'X509', 'certificate' in bitwarden/server@v2026.9.1 src/Core/KeyManagement src/Api/KeyManagement and
crypto-15 unknown yes bitwarden/server@v2026.9.1 src/Api/Auth/Controllers/AccountsController.cs:571 POST accounts/keys, :580 throws
crypto-16 unknown partial bitwarden/server@v2026.9.1 src/Api/KeyManagement/Controllers/AccountsKeyManagementController.cs:119 rotate-use
sharing-11 unknown no searched 'TransferOwnership', 'transfer.?ownership' in bitwarden/server@v2026.9.1 src/ bitwarden_license/: no
sharing-13 unknown no bitwarden/clients@web-v2026.9.0 apps/web/src/locales/en/messages.json:8432 'requestAccess' is used only by app
sharing-19 unknown no bitwarden/server@v2026.9.1 src/Core/Vault/Commands/CreateManyTaskNotificationsCommand.cs is the only caller of
sharing-23 unknown no searched 'comment' in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault and '"[a-zA-Z]comment[a-zA-Z]"
requests-09 unknown no searched 'reverse.?send', 'SendRequest', 'FileRequest', 'SecretRequest', 'CredentialRequest' in bitwarden/serv
apps-02 unknown no bitwarden/server@v2026.9.1 src/Api/SecretsManager/Controllers/ServiceAccountsController.cs:123 creates the mac
apps-03 unknown no bitwarden/server@v2026.9.1 src/Api/SecretsManager/Controllers/ServiceAccountsController.cs:123 no pending regi
apps-04 unknown no bitwarden/server@v2026.9.1 src/Api/SecretsManager/Controllers/ServiceAccountsController.cs:244 POST {id}/acces
apps-08 partial yes bitwarden/server@v2026.9.1 src/Api/SecretsManager/Controllers/SecretsController.cs:308 GET organizations/{orga
apps-09 unknown no bitwarden/server@v2026.9.1 src/Api/Utilities/ServiceCollectionExtensions.cs:100 only the OIDC /.well-known/ope
apps-19 unknown no searched 'dynamic.?secret', 'DatabaseCredential', 'transit' in bitwarden/server@v2026.9.1 src/Api/SecretsManag
apps-20 unknown partial bitwarden/server@v2026.9.1 bitwarden_license/src/Services/Pam/AccessConnector/Rotation/Api/Endpoints/RotationC
apps-23 unknown no searched 'nextcloud', 'conduction' in bitwarden/server@v2026.9.1 and bitwarden/clients@web-v2026.9.0: no match
apps-24 unknown no searched 'transit', 'encrypt-as', 'EncryptionService' routes in bitwarden/server@v2026.9.1 src/Api/SecretsMana
pki-01 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-02 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-03 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-04 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-05 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-06 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-07 unknown no searched 'x509', 'certificate' (case-insensitive) in bitwarden/server@v2026.9.1 src/Core/Vault src/Api/Vault s
pki-09 unknown no bitwarden/server@v2026.9.1 src/Api/SecretsManager/Controllers/ServiceAccountsController.cs:244 POST access-tok
rotation-04 unknown partial bitwarden/server@v2026.9.1 src/Api/Vault/Controllers/SecurityTaskController.cs:65 PATCH tasks/{taskId}/complet
rotation-06 no partial bitwarden/server@v2026.9.1 src/Api/Vault/Controllers/SecurityTaskController.cs:52 GET tasks (pending), :90 met
rotation-07 unknown no bitwarden/server@v2026.9.1 src/Core/AdminConsole/Enums/PolicyType.cs:5-34 no expiry policy; bitwarden/clients@
admin-03 unknown no bitwarden/server@v2026.9.1 src/Api/SecretsManager/Controllers/ServiceAccountsController.cs:123 machine account
admin-07 unknown no bitwarden/clients@web-v2026.9.0 libs/common/src/vault/services/cipher.service.ts:1911 password history hard-ca
admin-16 unknown yes bitwarden/server@v2026.9.1 src/Admin/Views/Home/Index.cshtml:13 installed vs latest web and core versions (web
admin-17 unknown no bitwarden/server@v2026.9.1 src/Admin/Views/Home/Index.cshtml shows versions only; no application registration
audit-02 unknown partial bitwarden/server@v2026.9.1 src/Api/Dirt/Controllers/EventsController.cs:65-309 only GET routes, no edit or del
audit-04 unknown no bitwarden/server@v2026.9.1 src/Api/Dirt/Controllers/EventsController.cs:65 GET events (current user's own even
audit-09 unknown no searched 'snapshot', 'signature', 'hash chain' in bitwarden/server@v2026.9.1 src/Core/Dirt src/Api/Dirt: no ma
audit-10 unknown no searched 'honey', 'decoy', 'canary' in bitwarden/server@v2026.9.1 src/ bitwarden_license/src: only a public su
audit-12 partial yes bitwarden/server@v2026.9.1 src/Api/Auth/Controllers/AccountsController.cs:633 DELETE accounts with secret veri
audit-13 unknown partial bitwarden/server@v2026.9.1 src/Sql/dbo/Stored Procedures/User_DeleteById.sql deletes the user and vault rows b
portability-03 unknown no bitwarden/clients@web-v2026.9.0 libs/importer/src/services/import.service.ts:155 parses by fixed format and :2
clients-07 unknown no bitwarden/clients@web-v2026.9.0 apps/web/src/manifest.json has name, icons and colours but no start_url or dis
clients-14 unknown no searched 'nextcloud' in bitwarden/clients@web-v2026.9.0 and bitwarden/server@v2026.9.1: no match Note: No Next
clients-15 unknown partial bitwarden/server@v2026.9.1 src/Core/Dirt/Enums/IntegrationType.cs:8 Webhook, :7 Slack, :11 Teams; src/Core/Dir
clients-17 unknown yes bitwarden/clients@web-v2026.9.0 apps/web/src/app/vault/individual-vault/vault-onboarding/vault-onboarding.comp
onepassword: 2 changes (unknown→partial 2)
row before after evidence
admin-05 unknown partial https://support.1password.com/business-security-practices/ : 'if you want to make sure sensitive data isn't lo
portability-04 unknown partial https://support.1password.com/import-lastpass/ : 'Private folders will be converted to tags'; shared folders b
passbolt: 37 changes (unknown→no 25, unknown→partial 5, partial→yes 5, yes→partial 1, unknown→yes 1)
row before after evidence
vault-21 unknown no searched 'last_used', 'recently used', 'dashboard' in passbolt_api src/ plugins/ and passbolt_styleguide src/:
vault-22 unknown no searched 'clone', 'duplicate', 'copy as new' in passbolt_styleguide src/react-extension/components/Resource an
crypto-12 yes partial passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Authentication/DownloadRecoveryKit, src/re
crypto-14 unknown no searched 'x509', 'certificate authority', 'csr' in passbolt_api src/ plugins/ and passbolt_browser_extension s
crypto-16 unknown partial passbolt/passbolt_browser_extension@v5.16.0 src/all/background_page/service/metadata/rotateMetadata/rotateMeta
sharing-03 partial yes passbolt/passbolt_api@v5.16.0 config/routes.php:151 PUT /groups/{id}/dry-run (src/Controller/Groups/GroupsUpda
sharing-13 unknown no passbolt/passbolt_api@v5.16.0 searched 'request access', 'requestAccess', 'access request', 'share request' in
apps-02 unknown no passbolt/passbolt_api@v5.16.0 searched 'approve', 'pending' registration in src/ plugins/: only AccountRecover
apps-03 unknown no passbolt/passbolt_api@v5.16.0 src/Notification/Email/Redactor: admin emails cover account recovery requests an
apps-04 unknown no passbolt/passbolt_api@v5.16.0 searched 'csr', 'certificate signing', 'certificate' in src/ plugins/: only the
apps-08 unknown partial passbolt/passbolt_api@v5.16.0 src/Model/Table/ResourcesTable.php:593 resources expose a modified timestamp; pl
apps-09 unknown no passbolt/passbolt_api@v5.16.0 plugins/PassboltCe/JwtAuthentication/config/routes.php:21 only well-known route
pki-09 unknown partial passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Authentication/CreateGpgKey/CreateGpgKey.j
health-02 unknown no passbolt/passbolt_styleguide@v5.16.0 searched 'reuse', 'reused', 'duplicate password' in src/react-extension s
health-09 unknown no passbolt/passbolt_styleguide@v5.16.0 src/shared/lib/SecretGenerator/: generators are PasswordGenerator, Passph
health-10 unknown no passbolt/passbolt_styleguide@v5.16.0 src/locales/en-UK/common.json:1539 breach messages only concern a passphr
health-11 unknown no passbolt/passbolt_styleguide@v5.16.0 searched '2fa', 'two-factor', 'twofactorauth' site advisory in src/react-
health-12 unknown no passbolt/passbolt_browser_extension@v5.16.0 searched 'insecure', 'http:' warnings in src/all: only an OpenPGP
rotation-04 partial yes passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Resource/EditResource/EditResource.js:484
admin-03 unknown no passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Administration/: no application queue comp
admin-04 partial yes passbolt/passbolt_api@v5.16.0 src/Model/Table/UsersTable.php:458 softDelete: :522 GroupsUsers deleteAll for th
admin-16 partial yes passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Administration/DisplayHealthcheckAdministr
admin-17 unknown no passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Administration/: no application queue or c
audit-10 unknown no passbolt/passbolt_api@v5.16.0 searched 'decoy', 'honeypot', 'canary' in src/ plugins/: no match Note: No decoy
audit-13 unknown no passbolt/passbolt_api@v5.16.0 src/Model/Table/UsersTable.php:559 user is only marked deleted = true, profile a
audit-15 unknown partial passbolt/passbolt_api@v5.16.0 src/Notification/Email/Redactor/User/UserAdminRoleRevokedEmailRedactor.php:43 AD
portability-02 unknown no passbolt/passbolt_browser_extension@v5.16.0 src/all/background_page/model/import/resources/csvRowParser/: pars
portability-03 unknown no passbolt/passbolt_browser_extension@v5.16.0 src/all/background_page/model/import/resources/resourcesCsvImportP
portability-05 unknown no passbolt/passbolt_browser_extension@v5.16.0 searched 'duplicate' in src/all/background_page/service/resource/i
portability-06 unknown yes passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Resource/ImportResources/ImportResourcesRe
portability-07 unknown no passbolt/passbolt_browser_extension@v5.16.0 searched 'cxf', 'credential exchange' in src/: only binary image m
portability-08 unknown no passbolt/passbolt_browser_extension@v5.16.0 searched 'cxp', 'credential exchange' in src/: no code match; pass
clients-06 partial yes passbolt/passbolt_browser_extension@v5.16.0 src/all/background_page/service/auth/startLoopAuthSessionCheckServ
clients-07 unknown no passbolt/passbolt_api@v5.16.0 git ls-files: no web app manifest or service worker in webroot/ or templates/ (o
clients-15 unknown no passbolt/passbolt_api@v5.16.0 searched 'webhook', 'workflow' in src/ plugins/: no match; events only feed emai
clients-17 unknown partial passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/AuthenticationSetup/SetupAuthentication/Se
clients-18 unknown no passbolt/passbolt_styleguide@v5.16.0 src/react-extension/components/Administration/HomePage/AdministrationHome
hashicorp-vault: 89 changes (unknown→no 72, unknown→partial 13, unknown→yes 2, partial→yes 1, yes→partial 1)
row before after evidence
vault-07 unknown partial hashicorp/vault@v2.1.1 ui/lib/kv/addon/components/page/list.hbs:51 KvListFilter in the list toolbar; ui/lib/kv
vault-09 unknown no hashicorp/vault@v2.1.1 searched 'favorite', 'favourite', 'bookmark', 'star' in ui/app/templates ui/app/compone
vault-15 unknown no hashicorp/vault@v2.1.1 searched 'passkey', 'webauthn', 'fido' in all .go .hbs .ts files: no match Note: No pas
vault-17 unknown partial hashicorp/vault@v2.1.1 command/kv_put.go:49 'The data can also be consumed from a file on disk by prefixing wi
vault-19 unknown no hashicorp/vault@v2.1.1 ui/lib/kv/addon/components/page/list.hbs:94 each row is a LinkedBlock with a per-row Ma
vault-20 unknown no hashicorp/vault@v2.1.1 ui/lib/kv/addon/routes.js:8 no preferences route; ui/app/router.js settings routes are
vault-21 unknown no hashicorp/vault@v2.1.1 ui/app/components/dashboard/overview.hbs:23 SecretsEngines, :48 QuickActions, :50 Clien
vault-22 unknown no hashicorp/vault@v2.1.1 ui/lib/kv/addon/components/page/secret/metadata/version-history.hbs:132 'Create new ver
vault-23 unknown partial hashicorp/vault@v2.1.1 ui/lib/core/addon/components/linked-block.hbs:6 list row is a div role=link with a clic
crypto-03 unknown no hashicorp/vault@v2.1.1 searched 'password_policy', 'strength', 'min length' in builtin/credential/userpass/*.g
crypto-06 partial yes hashicorp/vault@v2.1.1 ui/lib/core/addon/components/sidebar/user-menu.hbs:63 Log out; ui/app/services/auth.js:
crypto-08 unknown no hashicorp/vault@v2.1.1 vault/login_mfa.go:50 MFA method types totp, duo, okta, pingid only; searched 'passkey'
crypto-09 unknown no hashicorp/vault@v2.1.1 searched 'webauthn', 'biometric', 'touchid', 'fingerprint' in .go .hbs .ts: no login pa
crypto-12 unknown no hashicorp/vault@v2.1.1 searched 'recovery code', 'backup code' in .go and .hbs: no match; recovery keys in vau
crypto-13 yes partial hashicorp/vault@v2.1.1 vault/logical_system.go:4674 handleKeyStatus returns term, install_time, encryptions on
crypto-15 unknown yes hashicorp/vault@v2.1.1 vault/keyring.go:43 single activeTerm field, :129 adding a key moves activeTerm to the
sharing-11 unknown no hashicorp/vault@v2.1.1 searched 'owner' in vault/identity_store*.go and ui/lib/kv/addon: no secret ownership f
sharing-12 unknown no hashicorp/vault@v2.1.1 searched 'owner' in vault/identity_store*.go and ui/lib/kv/addon: no ownership concept;
sharing-16 unknown partial hashicorp/vault@v2.1.1 ui/app/components/tools/lookup.ts wrapping lookup by token; vault/logical_system_paths.
sharing-17 unknown no hashicorp/vault@v2.1.1 searched 'federat', 'remote user', 'external share' in vault/ and ui/app: no cross-inst
sharing-19 unknown no hashicorp/vault@v2.1.1 searched 'notification' in ui/app/templates ui/app/components ui/lib/kv/addon ui/lib/co
sharing-20 unknown no hashicorp/vault@v2.1.1 searched 'emergency', 'grantee' in ui/app ui/lib and vault/*.go: only the init page roo
sharing-21 unknown no hashicorp/vault@v2.1.1 searched 'emergency', 'grantee' in ui/app ui/lib and vault/*.go: no emergency access fl
sharing-22 unknown no hashicorp/vault@v2.1.1 searched 'emergency', 'grantee', 'wait time' in ui/app ui/lib and vault/*.go: no emerge
sharing-23 unknown no hashicorp/vault@v2.1.1 searched 'comment' in ui/app/templates ui/app/components ui/lib/kv/addon ui/lib/core/ad
requests-01 unknown no hashicorp/vault@v2.1.1 searched 'secret request', 'request link' in ui templates: no match; ui/app/router.js h
requests-02 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-03 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-04 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-05 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-06 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-07 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-08 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-09 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-10 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
requests-11 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no secret-request route; searched 'secret request', 'request link'
apps-02 unknown no hashicorp/vault@v2.1.1 builtin/credential/approle/path_role.go:126 roles are created directly by a caller with
apps-03 unknown no hashicorp/vault@v2.1.1 builtin/credential/approle/path_role.go:126 roles created directly, no pending state; s
apps-09 unknown partial hashicorp/vault@v2.1.1 vault/logical_system_paths.go:2899 sys/internal/specs/openapi serves an OpenAPI documen
pki-05 unknown partial hashicorp/vault@v2.1.1 command/healthcheck/pki_ca_validity_period.go:27 ca_validity_period check warns about C
pki-06 unknown no hashicorp/vault@v2.1.1 ui/lib/pki/addon/routes.js no renewal route; searched 'renew' in ui/lib/pki/addon/compo
health-01 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned', 'password
health-02 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned', 'password
health-03 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned', 'password
health-04 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned', 'password
health-05 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned', 'password
health-06 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned' in ui/app u
health-10 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach', 'haveibeenpwned' in ui/app u
health-11 unknown no hashicorp/vault@v2.1.1 searched '2fa directory', 'twofactorauth', 'inactive two-factor' in ui/app ui/lib: no m
health-12 unknown no hashicorp/vault@v2.1.1 ui/lib/core/addon/components/kv-object-editor.hbs:25 untyped fields, no URL field to in
health-13 unknown no hashicorp/vault@v2.1.1 searched 'zxcvbn', 'strength', 'reuse', 'pwned', 'breach' in ui/app ui/lib and vault/*.
rotation-03 unknown no hashicorp/vault@v2.1.1 searched 'reminder', 'notification' in ui/lib/kv/addon and ui/app/components: none for
rotation-04 unknown partial hashicorp/vault@v2.1.1 ui/lib/kv/addon/components/page/secret/metadata/version-history.hbs:52 Version diff bet
rotation-05 unknown no hashicorp/vault@v2.1.1 searched 'breach', 'compromis', 'needs rotation' in ui/lib/kv/addon ui/app/components a
rotation-06 unknown no hashicorp/vault@v2.1.1 ui/app/components/dashboard/overview.hbs:23 SecretsEngines, :48 QuickActions, :50 Clien
rotation-07 unknown partial hashicorp/vault@v2.1.1 ui/lib/kv/addon/routes/configure.js:20 KV engine configure screen with delete_version_a
admin-02 unknown no hashicorp/vault@v2.1.1 searched 'password_policy', 'strength', 'min length' in builtin/credential/userpass/*.g
admin-03 unknown no hashicorp/vault@v2.1.1 searched 'pending', 'approve' in builtin/credential/approle: no match; ui/app/router.js
admin-05 unknown no hashicorp/vault@v2.1.1 command/agent/config/config.go Agent/Proxy cache is configured per agent process; no or
admin-06 unknown no hashicorp/vault@v2.1.1 searched 'breach', 'pwned', 'haveibeenpwned' in ui/app ui/lib and vault/*.go: no match
admin-12 unknown partial hashicorp/vault@v2.1.1 ui/app/router.js access.identity entities list; ui/app/routes/vault/cluster/clients/cou
admin-15 unknown no hashicorp/vault@v2.1.1 internalshared/configutil/listener.go:65 max_request_size is a listener-wide request ca
admin-17 unknown no hashicorp/vault@v2.1.1 ui/app/components/dashboard/overview.hbs:23-64 widgets SecretsEngines, Replication, Clu
audit-03 unknown no hashicorp/vault@v2.1.1 searched 'retention', 'purge', 'max_age' in audit/ and internal/observability/event/sin
audit-04 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no activity or audit route for users; audit output goes only to ex
audit-08 unknown no hashicorp/vault@v2.1.1 searched 'compliance report', 'pdf' in ui/app/components templates: no match; CSV expor
audit-09 unknown no hashicorp/vault@v2.1.1 searched 'compliance report', 'snapshot' in ui/app/components for compliance: only raft
audit-10 unknown no hashicorp/vault@v2.1.1 searched 'honey', 'decoy', 'canary' in vault/*.go builtin ui/app ui/lib: only plugin re
audit-11 unknown no hashicorp/vault@v2.1.1 ui/app/router.js has no personal data export route; searched 'gdpr', 'personal data' in
audit-12 unknown partial hashicorp/vault@v2.1.1 ui/app/router.js access.identity entity delete by an admin; ui/app/models/identity/enti
audit-13 unknown no hashicorp/vault@v2.1.1 audit/hashstructure.go:25 HMACs secret values at write time only; searched 'anonymi' in
audit-15 unknown partial hashicorp/vault@v2.1.1 http/handler.go:546 sys/events/subscribe websocket stream of events such as KV data-wri
portability-01 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'import', 'csv' in ui/lib/kv/
portability-02 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-03 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-04 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-05 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-06 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-07 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-08 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
portability-10 unknown no hashicorp/vault@v2.1.1 ui/lib/kv/addon/routes.js:8 no export route; searched 'csv' in ui/lib/kv/addon: no matc
portability-11 unknown no hashicorp/vault@v2.1.1 vault/logical_system_raft.go:142 snapshot is the whole store; ui/lib/kv/addon/routes.js
portability-12 unknown no hashicorp/vault@v2.1.1 searched 'keepass', 'lastpass', 'bitwarden', '1password', 'credential exchange', 'cxf'
clients-07 unknown no hashicorp/vault@v2.1.1 ui/public contains favicon, fonts, images, robots.txt, no web app manifest; ui/app/inde
clients-08 unknown partial hashicorp/vault@v2.1.1 ui/app/index.html:14 viewport meta; ui/lib/core/addon/components/sidebar/frame.hbs:53 H
clients-09 unknown no hashicorp/vault@v2.1.1 ui/public has no service worker for offline data (the only one is ui/lib/service-worker
clients-16 unknown no hashicorp/vault@v2.1.1 ui/lib/config-ui/addon/routes.js:8 custom messages and login-settings only; searched 'c
clients-17 unknown partial hashicorp/vault@v2.1.1 ui/app/utils/constants/wizard.ts:8 wizards for acl-policy, auth-methods, secret-engines
clients-18 unknown yes hashicorp/vault@v2.1.1 ui/app/router.js dashboard route; ui/app/components/dashboard/overview.hbs:23 SecretsEn
nextcloud-passwords: 37 changes (unknown→no 32, no→partial 2, yes→partial 1, partial→yes 1, unknown→yes 1)
row before after evidence
vault-08 no partial marius-wieschollek/passwords@2026.9.0 src/js/Manager/SearchManager.js:38 subscribe('nextcloud:unified-search.s
crypto-05 unknown no marius-wieschollek/passwords@2026.9.0 src/js/Manager/EncryptionManager.js:47-54 update() only re-wraps the key
crypto-14 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Encryption/Keychain/SseV2KeychainEncryption.php and src/lib/Encr
crypto-17 unknown no marius-wieschollek/passwords@2026.9.0 searched 'revoke', 'suspend', 'reinstate' in src/lib/Encryption src/lib/
sharing-02 no partial marius-wieschollek/passwords@2026.9.0 src/appinfo/routes.php:71 POST /api/1.0/share/recipients/resolve-group;
sharing-12 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/EventListener/User/UserDeletedListener.php:44 on user deletion d
sharing-13 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Controller/Api/ShareApiController.php:164 shareable flag lets a
sharing-20 unknown no marius-wieschollek/passwords@2026.9.0 searched 'emergency', 'grantee', 'trusted contact' in src/lib src/js src
sharing-21 unknown no marius-wieschollek/passwords@2026.9.0 searched 'emergency', 'grantee' in src/lib src/js src/vue: no emergency
sharing-22 unknown no marius-wieschollek/passwords@2026.9.0 searched 'emergency', 'grantee', 'waiting period' in src/lib src/js src/
sharing-23 unknown no marius-wieschollek/passwords@2026.9.0 searched 'comment' in src/lib src/js src/vue: only src/vue/Components/Si
apps-02 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Controller/Link/ConnectController.php:221 confirm() is called by
apps-04 unknown no marius-wieschollek/passwords@2026.9.0 searched 'csr', 'certificate', 'x509', 'openssl' in src/lib: no certific
apps-09 unknown no marius-wieschollek/passwords@2026.9.0 searched 'ICapability', 'registerCapability', 'well-known' in src/lib: o
apps-14 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Db/Registration.php is a client pairing, not an owner of secrets
apps-17 unknown no marius-wieschollek/passwords@2026.9.0 searched 'kubernetes', 'k8s', 'operator' in src and scripts: no match No
apps-18 unknown no marius-wieschollek/passwords@2026.9.0 searched 'github action', 'gitlab', 'ci' integration in src and scripts:
apps-22 unknown no marius-wieschollek/passwords@2026.9.0 searched 'terraform' in src and scripts: no match Note: No Terraform pro
pki-09 unknown no marius-wieschollek/passwords@2026.9.0 searched "certificate", "x509", "openssl_csr", "pki" in src/lib src/js s
health-07 yes partial marius-wieschollek/passwords@2026.9.0 src/appinfo/routes.php:81 GET /api/1.0/service/password; src/lib/Control
health-09 unknown no marius-wieschollek/passwords@2026.9.0 searched 'alias', 'generateUsername', 'username generat' in src/lib src/
health-10 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Provider/SecurityCheck/*.php check password hashes only; searche
health-11 unknown no marius-wieschollek/passwords@2026.9.0 searched '2fa', 'twofactor', '2factor' in src/js src/vue: only src/vue/S
health-12 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Services/PasswordSecurityCheckService.php:28-32 statuses BREACHE
rotation-03 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Cron/CheckPasswordsJob.php:95-107 notifies only when a revision
admin-03 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Settings/AdminSettings.php:99-122 admin page parameters have no
admin-11 unknown no marius-wieschollek/passwords@2026.9.0 searched 'AuthorizedAdminSetting', 'IDelegatedSettings' in src/lib: no m
admin-12 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Command/SystemReportCommand.php:43 and src/lib/Helper/Survey/Ser
admin-17 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Dashboard/PasswordsWidget.php:27 the only dashboard widget is th
audit-10 unknown no marius-wieschollek/passwords@2026.9.0 searched 'decoy', 'honeypot', 'canary' in src/lib src/js src/vue: no mat
audit-13 unknown no marius-wieschollek/passwords@2026.9.0 src/lib/Helper/User/DeleteUserDataHelper.php:136-145 deletes the user's
portability-01 partial yes marius-wieschollek/passwords@2026.9.0 src/vue/Components/Import.vue:9-26 formats: backup JSON, Passwords/Folde
portability-07 unknown no marius-wieschollek/passwords@2026.9.0 searched 'cxf', 'credential exchange' in src: no match; src/vue/Componen
portability-08 unknown no marius-wieschollek/passwords@2026.9.0 searched 'cxp', 'credential exchange' in src: no match Note: No Credenti
clients-07 unknown no marius-wieschollek/passwords@2026.9.0 searched 'manifest', 'webmanifest', 'serviceWorker' in src: no match Not
clients-15 unknown no marius-wieschollek/passwords@2026.9.0 searched 'workflowengine', 'IOperation', 'flow' in src/lib: no match; ev
clients-17 unknown yes marius-wieschollek/passwords@2026.9.0 src/js/Manager/SetupManager.js:16 runs unless client.setup.initialized;

New rows (38)

row name origin keepiq bitwarden onepassword passbolt keeper hashicorp-vault nextcloud-passwords
vault-24 Sort items by date added, date changed or date last used. featureRequest partial partial partial partial partial no partial
vault-25 Find duplicate items already in the vault and merge them. featureRequest no no partial no partial no partial
vault-26 Preview an attached file without downloading it. featureRequest no no partial no unknown no partial
vault-27 Archive an item so it leaves search and autofill without being deleted. featureRequest no yes yes no unknown no partial
vault-28 Link several website addresses to one login. featureRequest no yes yes yes yes no partial
crypto-20 Ask for the master password again before a sensitive item is shown or filled. featureRequest no yes no yes unknown no no
crypto-21 See where you are signed in and end a session on another device. featureRequest partial partial yes no yes partial no
admin-18 An administrator defines new item types and the fields they carry. featureRequest no no no no yes no no
admin-19 Suspend a user's access and reactivate it later without deleting the account. featureRequest partial yes yes yes yes yes no
admin-20 Stop ordinary users from browsing the full list of people in the organisation. featureRequest partial partial unknown yes unknown yes yes
clients-19 Edit items while offline and have the changes sync when you are back online. featureRequest no no yes no unknown no unknown
clients-20 Type a login into a desktop application with a keyboard shortcut. featureRequest no partial yes unknown yes no unknown
clients-21 Switch between several accounts or servers in the same app or extension. featureRequest no yes yes no yes partial unknown
admin-26 Administrators see each user's two-factor status and last sign-in in the user list. featureRequest partial partial unknown yes unknown no no
clients-23 Use the vault in your own language, chosen per user from many translations. featureRequest yes yes unknown yes unknown no yes
sharing-27 Group managers who are not administrators can add and remove members of their own group. featureRequest partial partial unknown yes unknown partial partial
rotation-08 Open the website's own change-password page straight from a login, found through its well-known address. featureRequest no yes unknown no unknown no yes
admin-27 Administrators schedule automatic encrypted backups of every vault on the server and restore them from the command line. featureRequest no partial unknown no unknown partial yes
vault-30 Print a login, or show its password as a QR code to type it on another device. featureRequest no no unknown no unknown no yes
admin-21 Show every user an announcement, for example about planned maintenance. roadmap no yes unknown no unknown yes no
crypto-22 Item names, website addresses and usernames are encrypted too, so the server sees no item metadata. changelog no yes yes yes yes no partial
sharing-25 Share an item with a colleague for a set period, after which their access ends by itself. changelog no partial partial no yes partial yes
health-14 Ask the members who hold an at-risk password to change it, and track whether they did. changelog no yes partial no partial no no
health-15 See which of your logins are for websites that accept a passkey you have not set up. changelog no yes yes no unknown no no
clients-22 The browser extension warns you before you open a known phishing site. changelog no yes unknown no unknown no unknown
crypto-24 Approve a sign-in on a new device from a device where you are already signed in, or have an administrator approve it. changelog no yes unknown yes unknown no yes
admin-23 Claim the company's email domain so accounts on it are managed by the organisation. changelog no yes unknown partial unknown no no
admin-24 An administrator sets the maximum vault timeout that members may choose. changelog no yes unknown partial unknown partial no
admin-25 New members are confirmed automatically, without an administrator handing over access by hand. changelog no yes unknown partial unknown yes yes
sharing-26 Require an approved access request before someone may use a privileged login, limited by time window and IP address. changelog partial partial unknown no unknown yes no
health-16 Mark business-critical applications and see which members hold their at-risk passwords. changelog no yes unknown no unknown no no
audit-16 See a report of which members can reach which collections and items. changelog no yes unknown no unknown no no
vault-31 See each login with the website's icon and a screenshot preview of the site. changelog partial partial unknown no unknown no yes
sharing-24 Let a colleague sign in with a shared login without being able to see or copy the password. tender no yes yes partial partial no no
admin-22 Require that work logins are kept in the organisation's vault rather than in personal vaults. tender no yes partial no partial no no
vault-29 Compare two versions of a secret side by side to see what changed. source read (Vault reader) partial no partial partial partial yes no
crypto-23 Lock a user out after repeated failed sign-in attempts. source read (Vault reader) partial partial partial partial yes yes yes
apps-25 Push secrets out to cloud secret stores such as AWS Secrets Manager, Azure Key Vault or GitHub and keep them in sync. source read (Vault reader) no partial partial no yes yes no

By origin: {'featureRequest': 19, 'changelog': 13, 'tender': 2, 'roadmap': 1, 'source read': 3}. The first pass added 23 rows: 20 mined, of which featureRequest 13 (Bitwarden and Passbolt community boards), roadmap 1 (Passbolt), changelog 4 (Bitwarden clients PRs, Passbolt v5.0.0), tender 2 (TenderNed 295007 Gemeente Eindhoven, CanadaBuys); the other 3 came from the Vault source read. Fifteen more came from the reader proposals: 8 from Bitwarden, 3 kept of 6 from Passbolt, and 4 kept of 6 from Nextcloud Passwords. Each has a changelog or feature-request URL.

Sources per system

Every system has a sources object. An absent field is null, with its reason under sources.nullReasons (hydra#706).

bitwarden
onepassword
passbolt
keeper
hashicorp-vault
nextcloud-passwords

Verifier

hydra development parity_verify.py --strict, fetched fresh today; the schema is the one after hydra#707. Before, on development c88ff04:

parity-verify: /dev/fd/63
  191 rated rows, 0 pending, 7 systems

unknown-cells  (1)
    302 cells rate unknown. That is legitimate, and it is listed so it cannot hide: capabilities[vault-07] hashicorp-vault, capabilities[vault-08] bitwarden, capabilities[vault-08] onepassword, capabilities[vault-09] hashicorp-vault, capabilities[vault-10] keeper, capabilities[vault-15] hashicorp-vault, capabilities[vault-17] hashicorp-vault, capabilities[vault-19] hashicorp-vault

1 finding(s) in 1 check(s)

After:

parity-verify: openspec/parity/capabilities.json
  229 rated rows, 0 pending, 7 systems

unknown-cells  (1)
    150 cells rate unknown. That is legitimate, and it is listed so it cannot hide: capabilities[vault-08] onepassword, capabilities[vault-10] keeper, capabilities[vault-20] onepassword, capabilities[vault-26] keeper, capabilities[vault-27] keeper, capabilities[vault-30] onepassword, capabilities[vault-30] keeper, capabilities[vault-31] onepassword

1 finding(s) in 1 check(s)

The after run shows only the unknown census. Most of the 150 unknown cells are 1Password and Keeper on the new rows: closed source, rated from vendor docs where the docs speak. JSON Schema validation against capabilities.schema.json (hydra development): 0 errors.

Where the method was harder

  • Bitwarden: several features sit behind feature flags (for example FeatureFlag.Pam on the PAM access rules); the source shows the flag, not its default per tenant, so a yes behind a flag means "shipped in the code", not "on for every customer".

  • The eight rows from the Bitwarden source read carry origin changelog with the release that mentions the feature in the last twelve months; for three (critical applications web-v2026.6.2, member access report web-v2025.11.1, device approval server v2026.4.0) the release entry is a fix to an existing feature, so it proves the feature is live rather than new. Vault cells for these eight were rated by the lane from the Vault source.

  • Tenders: SURF (TenderNed 260154, 269319, 270057, 307164, 311305, 314176, 316729, 334533; 334533 awarded to Bitwarden, EUR 9.5M) and Gemeente Eindhoven (295007, 306724, 345771) are in the intelligence database with eisen_count 0 and no tender_documents, tagged not-relevant or iam rather than to this category. Only the Eindhoven 295007 description yielded a row (admin-22, business use enforced). The method's "tender requirements tagged to the category" found nothing under the category and no requirement lists anywhere.

  • Passbolt proposals: six, deduped against the rows; three kept with a feature-request URL (admin-26 from Bitwarden community 93955, clients-23 from 157, sharing-27 from 82556), three dropped because no feature request or changelog entry could be found for them: the personal security colour and code on every dialog, admin choice of email notification content, and a dry run of directory synchronisation. All three are real Passbolt capabilities read from v5.16.0.

  • Passbolt: nine cells keep their docs rating because the CLI, Ansible, Terraform, SDK and mobile and desktop apps live in repositories not cloned; each cell says so.

  • Source reads leave products in other repos unread. Passbolt's Go CLI, Ansible, Terraform, SDK and mobile and desktop apps, and the Nextcloud Passwords browser extension and mobile apps, sit in repos that were not cloned. Those cells keep their docs rating, and each one starts with "not in the cloned repos, docs rating kept:". A few stay unknown with the reason.

  • Vault's commercial features (control groups, secrets sync, automated snapshots) show in the public UI tree and changelog, but their server code is not public. They are rated from the UI routes and changelog, and each cell says so.

  • Nextcloud Passwords: sharing an end-to-end encrypted item downgrades it to server-side encryption (CreateShareAction.js:45,90; CreatePasswordShareHelper.php:187). This is noted on crypto-01 and crypto-22.

  • One keepiq cell was fixed for the schema: admin-18 built.state was partial, which is outside the enum. It is now building, because the API and store exist and no page reaches them.

  • A killed lane was resumed from its partial packs. The fold is idempotent, so the packs were folded as they grew.

  • Pre-existing: one em-dash in the file is a verbatim quote of keepiq UI copy ('There is no trash ... cannot be undone').

🤖 Generated with Claude Code

@rubenvdlinde
rubenvdlinde merged commit 48cea4b into development Sep 26, 2026
36 checks passed
@github-actions

Copy link
Copy Markdown
Contributor

Quality Report — ConductionNL/keepiq @ b7e301d

Check PHP Vue Security License Tests
lint ✅
phpcs ✅
phpmd ✅
psalm ✅
phpstan ✅
phpmetrics ✅
eslint ✅
stylelint ✅
build ✅
check-manifest ✅
test-l10n ✅
format ✅
check-l10n-js ✅
check-schema-l10n ✅
composer ✅ ✅ 114/114
npm ✅ ✅ 660/660
app:check-code ⏭️
info.xml ✅
REUSE ✅
lockfile sync ✅
PHPUnit ⏭️ not run for this diff — no file in this diff matches the code globs, and none carries a source extension — the heavy tier has nothing to decide about it.
Newman ✅
Playwright ⏭️ deferred: E2E runs locally and on the promotion path only. This pull request targets development, so the suite is asked once per promotion into beta and main rather than once per push per open pull request. Run it on any branch from the Actions tab, or locally with npx playwright test.
Hydra gates ✅

Quality workflow — 2026-09-26 14:26 UTC

Download the full PDF report from the workflow artifacts.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant