Loading
refactor(df): rename JVM truststore password from changeit
Changes the static JVM truststore password from Java's default changeit to df-truststore-not-secret.
The value changeit reads like a placeholder that ought to be rotated. In this case the password protects a temporary PKCS#12 truststore that holds only public certificates (no private keys) and is removed after the run, so it is not a secret — the JVM simply requires one. The new value is self-documenting and signals that the fixed value is intentional.
Testing
go build ./internal/dependencyfirewall/pm/go test ./internal/dependencyfirewall/pm/ -run TrustStore