False positive: Python `hashlib.sha1(..., usedforsecurity=False)`
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
**Description of the false positive**
The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`
In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.
CodeQL should respect that argument and not alert when used.
**Code samples or links to source code**
```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```
https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210
**URL to the alert on GitHub code scanning (optional)**
https://github.com/pypi/warehouse/security/code-scanning/9
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.