From a5bf805d4d72df87e6858ca470aa2dba9e7de821 Mon Sep 17 00:00:00 2001 From: yucheng Date: Thu, 24 Sep 2026 08:42:06 +0000 Subject: [PATCH] ci(codeql): filter the legacy sha256 password-row verifier alert Co-Authored-By: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> --- .github/workflows/codeql.yml | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 9a85ced57f6..d767c6a8951 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -72,13 +72,19 @@ jobs: # a lookup key into the haveibeenpwned range API (the protocol mandates # SHA-1) and the digest itself never leaves the proxy beyond its first 5 # characters. - - name: Filter SARIF (OCI sha256, HIBP sha1) + # The same query fires on the legacy-row verifier in + # litellm/proxy/utils.py, where a stored 64-hex SHA256 row is matched by + # hashing the submitted password to compare. No new SHA256 rows are + # written (new passwords are PBKDF2-HMAC-SHA256); the call exists only so + # pre-migration rows can still sign in and be rehashed. + - name: Filter SARIF (OCI sha256, HIBP sha1, legacy password row verify) if: matrix.language == 'python' uses: advanced-security/filter-sarif@2da736ff05ef065cb2894ac6892e47b5eac2c3c0 # v1.1 with: patterns: | -litellm/llms/oci/common_utils.py:py/weak-sensitive-data-hashing -litellm/proxy/auth/password_policy.py:py/weak-sensitive-data-hashing + -litellm/proxy/utils.py:py/weak-sensitive-data-hashing input: sarif-results/python.sarif output: sarif-results/python.sarif