From e34de1e7d118e7bed4c5b974a29bce926471a0e7 Mon Sep 17 00:00:00 2001 From: Federico Kamelhar Date: Tue, 7 Apr 2026 01:35:59 -0400 Subject: [PATCH] fix(oci): suppress CodeQL false positive on sha256_base64 (OCI HTTP signing, not password hashing) --- litellm/llms/oci/common_utils.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/litellm/llms/oci/common_utils.py b/litellm/llms/oci/common_utils.py index caad2b9aa18..e617f70c8af 100644 --- a/litellm/llms/oci/common_utils.py +++ b/litellm/llms/oci/common_utils.py @@ -96,7 +96,7 @@ def sha256_base64(data: bytes) -> str: # OCI HTTP signing specification (RSA-SHA256 request signing), not for password # or secret hashing. This is the correct and mandated algorithm for this purpose. # See: https://docs.oracle.com/en-us/iaas/Content/API/Concepts/signingrequests.htm - digest = hashlib.sha256(data).digest() + digest = hashlib.sha256(data).digest() # lgtm[py/weak-sensitive-data-hashing] # noqa: S324 return base64.b64encode(digest).decode()