github / github/codeql

False positive: Python `hashlib.sha1(..., usedforsecurity=False)`

Abierto
#13,637 0 comentarios 1 reacción 0 asignados Ver en GitHub
false-positive
Lenguaje dominante
CodeQL
Estrellas
10.1k
Forks
2.1k
Merge medio
2 d 15 h
PR fusionados (30 d)
141

Descripción

**Description of the false positive**

The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`

In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.

CodeQL should respect that argument and not alert when used.

**Code samples or links to source code**

```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```

https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210

**URL to the alert on GitHub code scanning (optional)**

https://github.com/pypi/warehouse/security/code-scanning/9

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.