From a09f629a5c80c2dfbee6580db5b4d9e3a366e541 Mon Sep 17 00:00:00 2001 From: Federico Kamelhar Date: Wed, 6 May 2026 00:31:19 -0400 Subject: [PATCH] fix(oci): silence CodeQL py/weak-sensitive-data-hashing on sha256_base64 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit CodeQL's taint analysis traces request bodies back to environment-loaded secrets and flags `hashlib.sha256(body).digest()` as `py/weak-sensitive-data-hashing` — even though SHA-256 is the algorithm mandated by the OCI HTTP request signing spec for the `x-content-sha256` header (not a password/secret hash). The previous suppression used legacy `# lgtm[...]` syntax which the modern CodeQL action ignores. Switch to Python's standard `hashlib.sha256(..., usedforsecurity=False)` (Python 3.9+) which CodeQL honours as a non-security declaration. Behaviour unchanged. --- litellm/llms/oci/common_utils.py | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/litellm/llms/oci/common_utils.py b/litellm/llms/oci/common_utils.py index 5c450e8334c..9e60c24c32a 100644 --- a/litellm/llms/oci/common_utils.py +++ b/litellm/llms/oci/common_utils.py @@ -96,9 +96,11 @@ def sha256_base64(data: bytes) -> str: # OCI HTTP signing specification (RSA-SHA256 request signing), not for password # or secret hashing. This is the correct and mandated algorithm for this purpose. # See: https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm - digest = hashlib.sha256( - data - ).digest() # lgtm[py/weak-sensitive-data-hashing] # noqa: S324 + # + # ``usedforsecurity=False`` declares non-security intent to static analyzers + # (CodeQL ``py/weak-sensitive-data-hashing``) — without it the request body + # gets flagged as "password-like data" via taint tracking. + digest = hashlib.sha256(data, usedforsecurity=False).digest() # noqa: S324 return base64.b64encode(digest).decode()