Skip to content
Benchmarks

redact-secret · Report

Connection-string password

Password embedded in a URI's userinfo component per RFC 3986.

  • Not provider-specific
  • Detectors: connection-string
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14
  • Dossier verdictReady
  • Dossier evidence levelT3 · Project policy
  • Dossier researched2026-09-26

Research record

From credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0. It describes the research on the format, not what any scanner or the product does, and not a support status.
  • Review stateDraft, not reviewed
  • Format revision1 · current
  • ResearchResearched
  • Researched2026-09-26

3 events in the review history: 2 observed, 1 reviewed. Latest: observed on 2026-10-03 by automation, project maintainer. Project-maintained review is not independent validation. The family record at this release.

Format

Provider format research from credential-evidence snapshot-2026.10.06.4 · records at 77ce761 · schema 1.8.0.

What it looks like

Shape not recorded.

Format facts

  • Provider documented · mutable-property-source · current · observed 2026-09-20

    Documentation for the one property varied in legacy twin fixtures (RFC 3986 userinfo): userinfo is delimited from the host by "@" and the deprecated user:password form places the password after the first ":". The password value has no grammar, so twins mutate the context, not the value

    • www.rfc-editor.org/rfc/rfc3986provider-documentation · last read 2026-10-03 · latest outcome read · supports userinfo is delimited from the host by "@" and the deprecated user:password form places the password after the first ":". The password value has no grammar, so twins mutate the context, not the value · #section-3.2.1
  • Unresolved · listed-references · current · observed 2026-09-20

    The legacy contract lists 1 reference without stating which property each supports.

    • www.rfc-editor.org/rfc/rfc3986provider-documentation · last read 2026-10-03 · latest outcome read · supports Listed as a reference by the legacy contract · #section-3.2.1
  • Project policy · legacy-contract-tier · current · observed 2026-09-20

    The legacy contract records this grammar as project masking policy (tier T3), not as a provider format.

    Source not recorded.

  • Project policy · dossier-research · current · observed 2026-09-26

    Legacy dossier research (verdict ready, tier T3) cited 2 sources; the dossier does not attribute sources to individual properties.

Open questions

No open question is recorded for this revision.

Benchmark dossier notes

From the provider dossier, as written. The evidence level above says how well the format is backed; a fact the dossier does not record is not shown.
Shape
RFC 3986 §3.2.1 userinfo: the password sits after the first : and before @. No RFC or vendor states a length or identifying element; §7.5 deprecates passwords in URIs. Vendors disagree on which characters need percent-encoding (MongoDB requires $ encoded, MySQL Connector/J requires ( ) & =, RabbitMQ forbids a raw :).
Basis
RFC 3986, RFC 1738, RabbitMQ URI spec, MongoDB and PostgreSQL docs: delimiter and alphabet only. The #651 hunt found no provider or RFC identifying element (2026-09-23); the boundary is project policy (T3, decision 2026-09-26-qualify-bounded-t3-credential-policy, benchmarks#365, core #857), so the verdict is ready at T3, consistent with bearer and OTP seed.
Issuance
not applicable.
Contract in core
detector-families.md; #651 record. Password surfaces outside userinfo (password= parameters, Azure Storage AccountKey=) fall outside the family definition.

In this benchmark

Fixture rows on the current run. Counts are for redact-secret in published · redact-secret 0.1.0-beta.14 mode.
Fixtures
104
Left readable
0
Redacted too much
0
False alarms
0

104 fixtures: 4 expect a redaction, 59 must stay quiet, 41 record project policy. See every row

redact-secret fixture counts by evidence level
Evidence levelFixturesLeft readableToo muchFalse alarms
T1Provider-documented26000
T3Project policy78000

Every scanner on the same fixtures

In run order. Counts are what each scanner recorded on this family's fixtures, whichever rules it has; a scanner with no rule for the family has nothing to report on it.

Counts per scanner on this family's fixtures
ScannerFixturesLeft readableToo muchFalse alarms
flare-redactRuntime library · 1.6.1 · Published npm package · secrets-only (pii, generic_assignment disabled) · JavaScript engine1 rule targets it1046918
gitleaksRepository scanner · 8.30.1 · Directory scan · default rulesNo rule maps to it1044300
redact-secretProduct measured here · 0.1.0-beta.14 · Published npm package · default detectors1 detector mapped104000
trufflehogRepository scanner · 3.97.4 · Filesystem scan · verification disabled4 rules target it10423612

Looks like it, but isn't

Values the dossier records as resembling this credential without being one.
Collisions
providers that issue passwords with a fixed prefix (PlanetScale pscale_pw_, Neon npg_, Aiven and DigitalOcean AVNS_) are separate families.

Scanner rules for this family

Mapped by hand (reviewed 2026-09-30) from each scanner's pinned rule file, never from what a scanner found on the fixtures.
Peer scanner rules that target this family
ScannerRuleWhat the rule matches
flare-redact · rules 1.6.1url_credentialsscheme:// user:password@ URL
openredaction · rules 1.1.5DATABASE_CONNECTIONpostgres, mysql, mongodb, redis or sqlite URI with a password
openredaction · rules 1.1.5URL_WITH_AUTHhttp(s) or ftp URL with user:password@
trufflehog · rules 3.97.4mongodbmongodb:// or mongodb+srv:// URI with a password
trufflehog · rules 3.97.4postgrespostgres:// or postgresql:// URI with a password
trufflehog · rules 3.97.4redisredis:// URI with a password
trufflehog · rules 3.97.4urihttp(s) URL with a userinfo password

No rule maps to this family in gitleaks.

104 of 104 rows

Fixtures in this family

104 rows, redact-secret's outcome on each. Rows that need a look come first (0), then the rest in corpus order. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Connection-string password
FixtureKind and evidenceredact-secret
go-sum-excerpt-with-goproxy-passworddeveloper-artifact-lookalikes-authored · package-integrity-hashes-beside-a-literal-registry-passwordMust redactT1 · Provider-documentedRedacted
pip-requirements-hashes-with-index-url-passworddeveloper-artifact-lookalikes-authored · package-integrity-hashes-beside-a-literal-registry-passwordMust redactT1 · Provider-documentedRedacted
connection-string-celery-amqpsgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-database-url-querygeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-docs-uppercase-placeholdergeneric · documentation-placeholderMust not flagT3 · Project policyQuiet
connection-string-interpolated-password-referencegeneric · templated-referenceMust not flagT3 · Project policyQuiet
connection-string-jdbc-user-param-public-idgeneric · public-identifierMust not flagT1 · Provider-documentedQuiet
connection-string-mariadb-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mariadb-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mariadb-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mongodb-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mongodb-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mongodb-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mysql-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mysql-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-mysql-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-orm-connection-errorgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-percent-template-encoded-valuegeneric · benign-encoded-valueMust not flagT3 · Project policyQuiet
connection-string-postgres-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-postgres-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-postgres-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-postgres-userinfogeneric · password-inside-connection-stringsProject policyT3 · Project policyRedacted
connection-string-psql-historygeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-rails-database-ymlgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-redis-baregeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-redis-quotedgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-redis-unicode-crlfgeneric · documented-format-literalProject policyT3 · Project policyRedacted
connection-string-rediss-password-onlygeneric · password-inside-connection-stringsProject policyT3 · Project policyRedacted
connection-string-referencegeneric · variable-reference-in-credential-positionMust not flagT3 · Project policyQuiet
connection-string-sqlalchemy-ipv6generic · documented-format-literalProject policyT3 · Project policyRedacted
embedded-wordgeneric · connection-uri-placeholder-lookalike-passwordsProject policyT3 · Project policyRedacted
filler-near-missgeneric · connection-uri-placeholder-lookalike-passwordsProject policyT3 · Project policyRedacted
mariadb-defaultgeneric · tutorial-default-url-passwordsMust not flagT3 · Project policyQuiet
mariadb-literalgeneric · literal-url-passwordsProject policyT3 · Project policyRedacted
mongodb-defaultgeneric · tutorial-default-url-passwordsMust not flagT3 · Project policyQuiet
mongodb-literalgeneric · literal-url-passwordsProject policyT3 · Project policyRedacted
mysql-defaultgeneric · tutorial-default-url-passwordsMust not flagT3 · Project policyQuiet
mysql-literalgeneric · literal-url-passwordsProject policyT3 · Project policyRedacted
placeholder-1generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
placeholder-2generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
placeholder-3generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
placeholder-4generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
placeholder-5generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
placeholder-6generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
placeholder-7generic · connection-uri-placeholder-passwordsMust not flagT3 · Project policyQuiet
postgres-defaultgeneric · tutorial-default-url-passwordsMust not flagT3 · Project policyQuiet
postgres-literalgeneric · literal-url-passwordsProject policyT3 · Project policyRedacted
redis-defaultgeneric · tutorial-default-url-passwordsMust not flagT3 · Project policyQuiet
redis-literalgeneric · literal-url-passwordsProject policyT3 · Project policyRedacted
unrelated-suffixgeneric · connection-uri-placeholder-lookalike-passwordsProject policyT3 · Project policyRedacted

Sources

Researched 2026-09-26.

Documentation and code

Research log