Closed meuzgebre closed 1 year ago
I think this is better covered by using a nosec
as in general not setting a password is an insecure setting.
Maybe this should be a different error though? Without greater context, it's possible you're providing a default password that disables authn/authz on a service and that's a problem we should alert on with low confidence
Don't give a warning when a password variable is assigned an empty value.
The above should not be reported as a warning.
Resolve: #714