mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-28 01:32:17 +00:00
fix(oci): silence CodeQL py/weak-sensitive-data-hashing on sha256_base64
CodeQL's taint analysis traces request bodies back to environment-loaded secrets and flags `hashlib.sha256(body).digest()` as `py/weak-sensitive-data-hashing` — even though SHA-256 is the algorithm mandated by the OCI HTTP request signing spec for the `x-content-sha256` header (not a password/secret hash). The previous suppression used legacy `# lgtm[...]` syntax which the modern CodeQL action ignores. Switch to Python's standard `hashlib.sha256(..., usedforsecurity=False)` (Python 3.9+) which CodeQL honours as a non-security declaration. Behaviour unchanged.
This commit is contained in:
parent
742635d2ca
commit
a09f629a5c
1 changed files with 5 additions and 3 deletions
|
|
@ -96,9 +96,11 @@ def sha256_base64(data: bytes) -> str:
|
|||
# OCI HTTP signing specification (RSA-SHA256 request signing), not for password
|
||||
# or secret hashing. This is the correct and mandated algorithm for this purpose.
|
||||
# See: https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm
|
||||
digest = hashlib.sha256(
|
||||
data
|
||||
).digest() # lgtm[py/weak-sensitive-data-hashing] # noqa: S324
|
||||
#
|
||||
# ``usedforsecurity=False`` declares non-security intent to static analyzers
|
||||
# (CodeQL ``py/weak-sensitive-data-hashing``) — without it the request body
|
||||
# gets flagged as "password-like data" via taint tracking.
|
||||
digest = hashlib.sha256(data, usedforsecurity=False).digest() # noqa: S324
|
||||
return base64.b64encode(digest).decode()
|
||||
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue