mirror of
https://github.com/actions/actions-runner-controller.git
synced 2026-01-16 08:44:03 +08:00
Potential fix for code scanning alert no. 7: Use of a broken or weak cryptographic hashing algorithm on sensitive data (#4353)
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
This commit is contained in:
@@ -2,7 +2,7 @@ package actionssummerwindnet
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"crypto/sha1"
|
"crypto/sha256"
|
||||||
"encoding/hex"
|
"encoding/hex"
|
||||||
"fmt"
|
"fmt"
|
||||||
"sort"
|
"sort"
|
||||||
@@ -176,7 +176,7 @@ func (c *MultiGitHubClient) initClientForSecret(secret *corev1.Secret, dependent
|
|||||||
|
|
||||||
sort.SliceStable(ks, func(i, j int) bool { return ks[i] < ks[j] })
|
sort.SliceStable(ks, func(i, j int) bool { return ks[i] < ks[j] })
|
||||||
|
|
||||||
hash := sha1.New()
|
hash := sha256.New()
|
||||||
for _, k := range ks {
|
for _, k := range ks {
|
||||||
hash.Write(secret.Data[k])
|
hash.Write(secret.Data[k])
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user