github / github/codeql

False positive: Python `hashlib.sha1(..., usedforsecurity=False)`

Offen
#13,637 0 Kommentare 1 Reaktion 0 zugewiesene Personen Auf GitHub ansehen
false-positive
Vorherrschende Sprache
CodeQL
Sterne
10.1k
Forks
2.1k
Ø Merge
2 T. 15 Std.
Gemergte PRs (30 T.)
141

Beschreibung

**Description of the false positive**

The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`

In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.

CodeQL should respect that argument and not alert when used.

**Code samples or links to source code**

```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```

https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210

**URL to the alert on GitHub code scanning (optional)**

https://github.com/pypi/warehouse/security/code-scanning/9

Beitragsleitfaden

Beitragsleitfaden öffnen

Bewertung

Dieses Issue wurde noch nicht bewertet.

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.