fix(oci): suppress CodeQL false positive on sha256_base64 (OCI HTTP signing, not password hashing)

This commit is contained in:
Federico Kamelhar 2026-04-07 01:35:59 -04:00
parent 7a4e8ecd43
commit e34de1e7d1

View file

@ -96,7 +96,7 @@ def sha256_base64(data: bytes) -> str:
# OCI HTTP signing specification (RSA-SHA256 request signing), not for password
# or secret hashing. This is the correct and mandated algorithm for this purpose.
# See: https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm
digest = hashlib.sha256(data).digest()
digest = hashlib.sha256(data).digest() # lgtm[py/weak-sensitive-data-hashing] # noqa: S324
return base64.b64encode(digest).decode()