False positive: Python `hashlib.sha1(..., usedforsecurity=False)`
- Lenguaje dominante
- CodeQL
- Estrellas
- 10.1k
- Forks
- 2.1k
- Merge medio
- 2 d 15 h
- PR fusionados (30 d)
- 141
Descripción
**Description of the false positive**
The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`
In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.
CodeQL should respect that argument and not alert when used.
**Code samples or links to source code**
```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```
https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210
**URL to the alert on GitHub code scanning (optional)**
https://github.com/pypi/warehouse/security/code-scanning/9
Guía de contribución
Evaluación
Este issue todavía no se ha evaluado.