False positive: Python `hashlib.sha1(..., usedforsecurity=False)`
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`
In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.
CodeQL should respect that argument and not alert when used.
**Code samples or links to source code**
```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```
https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210
**URL to the alert on GitHub code scanning (optional)**
https://github.com/pypi/warehouse/security/code-scanning/9
貢獻指南
評估
這個 Issue 還沒有評估資料。