github / github/codeql

False positive: Python `hashlib.sha1(..., usedforsecurity=False)`

Đang mở
#13,637 0 bình luận 1 reaction 0 người được giao Xem trên GitHub
false-positive
Ngôn ngữ chính
CodeQL
Star
10.1k
Fork
2.1k
Merge trung bình
2 ngày 15 giờ
Pull request đã merge (30 ngày)
141

Mô tả

**Description of the false positive**

The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`

In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.

CodeQL should respect that argument and not alert when used.

**Code samples or links to source code**

```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```

https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210

**URL to the alert on GitHub code scanning (optional)**

https://github.com/pypi/warehouse/security/code-scanning/9

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.