False positive: Python `hashlib.sha1(..., usedforsecurity=False)`
- Dominant language
- CodeQL
- Stars
- 10.1k
- Forks
- 2.1k
- Avg merge
- 2d 15h
- Merged PRs (30d)
- 141
Description
**Description of the false positive**
The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`
In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.
CodeQL should respect that argument and not alert when used.
**Code samples or links to source code**
```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```
https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210
**URL to the alert on GitHub code scanning (optional)**
https://github.com/pypi/warehouse/security/code-scanning/9
Contributor guide
Assessment
This issue has not been assessed yet.