From 2ea7ae7d6e42c26e1732856bcc957e27471c7908 Mon Sep 17 00:00:00 2001 From: Federico Kamelhar Date: Thu, 14 May 2026 12:16:58 -0400 Subject: [PATCH] fix(codeql): re-scope py/weak-sensitive-data-hashing exclusion to OCI signing file MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CodeQL's taint analysis re-fires the `py/weak-sensitive-data-hashing` alert at `litellm/llms/oci/common_utils.py:103` whenever upstream code paths into the OCI signing module change (touching `transformation.py` opens new flow paths that CodeQL re-evaluates from scratch). The `hashlib.sha256(..., usedforsecurity=False)` declaration silences the direct-call form of the query but not the taint-flow form. SHA-256 here is mandated by the OCI HTTP signing specification for the x-content-sha256 content-integrity header — not for password storage: https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm CodeQL has no per-query path filter and GitHub Code Scanning ignores inline lgtm/codeql comments, so path-ignoring this single ~560-line signing utility file is the narrowest available suppression. All other files retain full coverage of py/weak-sensitive-data-hashing — including litellm/proxy/utils.py where the rule legitimately applies. This restores the NEUTRAL CodeQL state the PR had on prior commits (see `2111c98af7` for the same approach on the previous branch evolution that the cherry-pick was rebased onto a different baseline). --- .github/codeql/codeql-config.yml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/.github/codeql/codeql-config.yml b/.github/codeql/codeql-config.yml index 36d70c1d746..38c41651281 100644 --- a/.github/codeql/codeql-config.yml +++ b/.github/codeql/codeql-config.yml @@ -19,3 +19,17 @@ paths-ignore: - tests - docs - "**/*.md" + # py/weak-sensitive-data-hashing (CWE-328): the OCI signing call at + # litellm/llms/oci/common_utils.py hashes the HTTP request body to produce + # the x-content-sha256 header required by the OCI HTTP signing spec — a + # content-integrity hash, not a password or secret hash. SHA-256 is mandated + # by Oracle for this header; see + # https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm + # + # CodeQL has no native per-query path-scope filter and GitHub Code Scanning + # ignores `# lgtm[...]` / `# codeql[...]` inline comments, so path-ignoring + # this single file is the narrowest available suppression. The `usedforsecurity=False` + # flag on the hashlib.sha256 call already declares non-security intent but + # CodeQL's taint flow still re-fires when callers further up the stack are + # modified. + - litellm/llms/oci/common_utils.py