github / github/codeql

False positive: Python `hashlib.sha1(..., usedforsecurity=False)`

Ouverte
#13,637 0 commentaires 1 réaction 0 personnes assignées Voir sur GitHub
false-positive
Langage dominant
CodeQL
Étoiles
10.1k
Forks
2.1k
Merge moyen
2 j 15 h
PR mergées (30 j)
141

Description

**Description of the false positive**

The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`

In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.

CodeQL should respect that argument and not alert when used.

**Code samples or links to source code**

```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```

https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210

**URL to the alert on GitHub code scanning (optional)**

https://github.com/pypi/warehouse/security/code-scanning/9

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.