From 75e88ba9ada857e7b5b59842a5dca24d74b909ac Mon Sep 17 00:00:00 2001 From: jibanez-staticduo Date: Fri, 18 Sep 2026 15:00:08 +0200 Subject: [PATCH] ci: filter intentional ownership hash alerts --- .github/workflows/codeql.yml | 5 +++++ litellm/proxy/_types.py | 1 - litellm/proxy/realtime_endpoints/call_sessions.py | 2 -- litellm/proxy/realtime_endpoints/live.py | 1 - litellm/proxy/utils.py | 2 -- 5 files changed, 5 insertions(+), 6 deletions(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index d3a165a11da..83a7dbeb9bb 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -71,8 +71,13 @@ jobs: if: matrix.language == 'python' uses: advanced-security/filter-sarif@2da736ff05ef065cb2894ac6892e47b5eac2c3c0 # v1.1 with: + # These SHA-256 digests are opaque ownership/cache identifiers, not password hashes. patterns: | -litellm/llms/oci/common_utils.py:py/weak-sensitive-data-hashing + -litellm/proxy/_types.py:py/weak-sensitive-data-hashing + -litellm/proxy/realtime_endpoints/call_sessions.py:py/weak-sensitive-data-hashing + -litellm/proxy/realtime_endpoints/live.py:py/weak-sensitive-data-hashing + -litellm/proxy/utils.py:py/weak-sensitive-data-hashing input: sarif-results/python.sarif output: sarif-results/python.sarif diff --git a/litellm/proxy/_types.py b/litellm/proxy/_types.py index f9045d20765..741128b2769 100644 --- a/litellm/proxy/_types.py +++ b/litellm/proxy/_types.py @@ -265,7 +265,6 @@ def hash_token(token: str): import hashlib # This digest is an opaque lookup identifier, not a password hash. - # codeql[py/weak-sensitive-data-hashing] hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest() return hashed_token diff --git a/litellm/proxy/realtime_endpoints/call_sessions.py b/litellm/proxy/realtime_endpoints/call_sessions.py index 803c0998e5e..cf4937f3252 100644 --- a/litellm/proxy/realtime_endpoints/call_sessions.py +++ b/litellm/proxy/realtime_endpoints/call_sessions.py @@ -220,7 +220,6 @@ def decode_call(token: str, authorization: str) -> CodexRealtimeCall: raise HTTPException(403, "Invalid realtime call") from exc if ( call.expires_at < time.time() - # codeql[py/weak-sensitive-data-hashing] or call.owner != hashlib.sha256(authorization.encode(), usedforsecurity=False).hexdigest() ): raise HTTPException(403, "Invalid or expired realtime call") @@ -401,7 +400,6 @@ async def _create_codex_realtime_call(request: Request) -> Response: call: Final = parse_call_response( response, alias=model, - # codeql[py/weak-sensitive-data-hashing] owner=hashlib.sha256( f"Bearer {owner_key}".encode(), usedforsecurity=False ).hexdigest(), diff --git a/litellm/proxy/realtime_endpoints/live.py b/litellm/proxy/realtime_endpoints/live.py index 634425c029c..8f68e870497 100644 --- a/litellm/proxy/realtime_endpoints/live.py +++ b/litellm/proxy/realtime_endpoints/live.py @@ -185,7 +185,6 @@ def rewrite_session_ids(value: JsonValue | Mapping[str, JsonValue], raw_id: str, def _owner(auth: UserAPIKeyAuth) -> str: if not auth.api_key: raise HTTPException(403, "Live sessions require an authenticated API key") - # codeql[py/weak-sensitive-data-hashing] return hashlib.sha256(auth.api_key.encode(), usedforsecurity=False).hexdigest() diff --git a/litellm/proxy/utils.py b/litellm/proxy/utils.py index 6f4ef72f3cf..dc0ba6bfbd1 100644 --- a/litellm/proxy/utils.py +++ b/litellm/proxy/utils.py @@ -4291,7 +4291,6 @@ class PrismaClient: def hash_token(self, token: str): # Hash the string using SHA-256 - # codeql[py/weak-sensitive-data-hashing] hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest() return hashed_token @@ -6719,7 +6718,6 @@ def hash_token(token: str): import hashlib # Hash the string using SHA-256 - # codeql[py/weak-sensitive-data-hashing] hashed_token: Final = hashlib.sha256(token.encode(), usedforsecurity=False).hexdigest() return hashed_token