ci: filter intentional ownership hash alerts

This commit is contained in:
jibanez-staticduo 2026-09-18 15:00:08 +02:00
parent 5d36f155b6
commit 75e88ba9ad
No known key found for this signature in database
5 changed files with 5 additions and 6 deletions

View file

@ -71,8 +71,13 @@ jobs:
if: matrix.language == 'python'
uses: advanced-security/filter-sarif@2da736ff05ef065cb2894ac6892e47b5eac2c3c0 # v1.1
with:
# These SHA-256 digests are opaque ownership/cache identifiers, not password hashes.
patterns: |
-litellm/llms/oci/common_utils.py:py/weak-sensitive-data-hashing
-litellm/proxy/_types.py:py/weak-sensitive-data-hashing
-litellm/proxy/realtime_endpoints/call_sessions.py:py/weak-sensitive-data-hashing
-litellm/proxy/realtime_endpoints/live.py:py/weak-sensitive-data-hashing
-litellm/proxy/utils.py:py/weak-sensitive-data-hashing
input: sarif-results/python.sarif
output: sarif-results/python.sarif

View file

@ -265,7 +265,6 @@ def hash_token(token: str):
import hashlib
# This digest is an opaque lookup identifier, not a password hash.
# codeql[py/weak-sensitive-data-hashing]
hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest()
return hashed_token

View file

@ -220,7 +220,6 @@ def decode_call(token: str, authorization: str) -> CodexRealtimeCall:
raise HTTPException(403, "Invalid realtime call") from exc
if (
call.expires_at < time.time()
# codeql[py/weak-sensitive-data-hashing]
or call.owner != hashlib.sha256(authorization.encode(), usedforsecurity=False).hexdigest()
):
raise HTTPException(403, "Invalid or expired realtime call")
@ -401,7 +400,6 @@ async def _create_codex_realtime_call(request: Request) -> Response:
call: Final = parse_call_response(
response,
alias=model,
# codeql[py/weak-sensitive-data-hashing]
owner=hashlib.sha256(
f"Bearer {owner_key}".encode(), usedforsecurity=False
).hexdigest(),

View file

@ -185,7 +185,6 @@ def rewrite_session_ids(value: JsonValue | Mapping[str, JsonValue], raw_id: str,
def _owner(auth: UserAPIKeyAuth) -> str:
if not auth.api_key:
raise HTTPException(403, "Live sessions require an authenticated API key")
# codeql[py/weak-sensitive-data-hashing]
return hashlib.sha256(auth.api_key.encode(), usedforsecurity=False).hexdigest()

View file

@ -4291,7 +4291,6 @@ class PrismaClient:
def hash_token(self, token: str):
# Hash the string using SHA-256
# codeql[py/weak-sensitive-data-hashing]
hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest()
return hashed_token
@ -6719,7 +6718,6 @@ def hash_token(token: str):
import hashlib
# Hash the string using SHA-256
# codeql[py/weak-sensitive-data-hashing]
hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest()
return hashed_token