False positive: Python `hashlib.sha1(..., usedforsecurity=False)`
- Vorherrschende Sprache
- CodeQL
- Sterne
- 10.1k
- Forks
- 2.1k
- Ø Merge
- 2 T. 15 Std.
- Gemergte PRs (30 T.)
- 141
Beschreibung
**Description of the false positive**
The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`
In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.
CodeQL should respect that argument and not alert when used.
**Code samples or links to source code**
```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```
https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210
**URL to the alert on GitHub code scanning (optional)**
https://github.com/pypi/warehouse/security/code-scanning/9
Beitragsleitfaden
Bewertung
Dieses Issue wurde noch nicht bewertet.