Password hashing algorithm?

Which hashing algorithm does mastodon use for passwords? And where in the source code would I go to change it? For instance if I wanted to use PBKDF2 or SHA256

I think we are using Devise and it’s devise-two-factor module:

which uses, among others, Devise’s standard database authentication:

That component has a useful comment:

which seems to lead to the code that uses bcrypt