github / github/codeql

False positive: Python `hashlib.sha1(..., usedforsecurity=False)`

未關閉
#13,637 0 則留言 1 個 reaction 已指派 0 人 在 GitHub 檢視
false-positive
主要語言
CodeQL
星號
10.1k
分支
2.1k
平均合併
2 天 15 小時
30 天內合併 PR
141

描述

**Description of the false positive**

The current Python scanner reports that using `hashlib.sha1()` function violates rule ID `py/weak-sensitive-data-hashing`

In Python 3.9 and up, the `hashlib` constructors accept a `usedforsecurity=False` keyword argument that signals that this is acceptable and has been intentionally used for this purpose.

CodeQL should respect that argument and not alert when used.

**Code samples or links to source code**

```python
hashed_password = hashlib.sha1(password.encode("utf8"), usedforsecurity=False).hexdigest()
```

https://github.com/pypi/warehouse/pull/14045#pullrequestreview-1507543210

**URL to the alert on GitHub code scanning (optional)**

https://github.com/pypi/warehouse/security/code-scanning/9

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。