mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-11 03:38:38 +00:00
ci(codeql): filter the legacy sha256 password-row verifier alert
Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com>
This commit is contained in:
parent
6e7247071c
commit
a5bf805d4d
1 changed files with 7 additions and 1 deletions
8
.github/workflows/codeql.yml
vendored
8
.github/workflows/codeql.yml
vendored
|
|
@ -72,13 +72,19 @@ jobs:
|
|||
# a lookup key into the haveibeenpwned range API (the protocol mandates
|
||||
# SHA-1) and the digest itself never leaves the proxy beyond its first 5
|
||||
# characters.
|
||||
- name: Filter SARIF (OCI sha256, HIBP sha1)
|
||||
# The same query fires on the legacy-row verifier in
|
||||
# litellm/proxy/utils.py, where a stored 64-hex SHA256 row is matched by
|
||||
# hashing the submitted password to compare. No new SHA256 rows are
|
||||
# written (new passwords are PBKDF2-HMAC-SHA256); the call exists only so
|
||||
# pre-migration rows can still sign in and be rehashed.
|
||||
- name: Filter SARIF (OCI sha256, HIBP sha1, legacy password row verify)
|
||||
if: matrix.language == 'python'
|
||||
uses: advanced-security/filter-sarif@2da736ff05ef065cb2894ac6892e47b5eac2c3c0 # v1.1
|
||||
with:
|
||||
patterns: |
|
||||
-litellm/llms/oci/common_utils.py:py/weak-sensitive-data-hashing
|
||||
-litellm/proxy/auth/password_policy.py:py/weak-sensitive-data-hashing
|
||||
-litellm/proxy/utils.py:py/weak-sensitive-data-hashing
|
||||
input: sarif-results/python.sarif
|
||||
output: sarif-results/python.sarif
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue