By default, Tuleap requires passwords to be at least 8 characters long. You can set your own rules for validating user passwords.
Here is an example of rules:
The password must be at least 8 characters long.
The password must contain at least 2 uppercase letters.
The password must contain at least 3 non-numeric characters.
Compromised password
Tuleap attempts to block passwords that frequently appear in data breaches. To do this, it communicates with the Have I Been Pwned service. However, password confidentiality is always maintained, and no one can see your users’ passwords.
This feature can be enabled via the site administration panel (see below).
.png?sv=2026-02-06&spr=https&st=2026-08-25T01%3A33%3A19Z&se=2026-08-25T01%3A44%3A19Z&sr=c&sp=r&sig=RAflXbvcQxiVUxEk2kohCk79cJaF34q9yr1%2F3OwoKlQ%3D)