Check MD5 & SHA1 usage#8542
Open
sfayer wants to merge 1 commit into
Open
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi,
I've looked through all of the usage of MD5 & SHA1 in the codebase... The majority of these are just protection for accidental corruption and caching (where the input parameters aren't user controlled). I've marked these as usedforsecurity=False. (This flag doesn't do anything on non-FIPS systems, but is picked up by security scanners as a hint).
There is one place in the proxy cache where I swapped md5 out for truncated sha256: This doesn't make an enormous amount of difference and is more an "abundance of caution" style change.
Regards,
Simon
BEGINRELEASENOTES
*All
FIX: Mark md5/sha1 usage as not used for security where appropriate.
*Core
FIX: Use truncated sha256 for proxy hash (caching) rather than md5.
ENDRELEASENOTES