fix(agent-team): clear 3 non-blocking SAST mediums on main

clarifier_llm: sha1 -> sha256 for the non-security cache-discriminator (CWE-327 false positive). github_adapter + github_intake: inline nosemgrep on the urlopen lines (dynamic-urllib-use-detected) — the URL is built from a fixed https GitHub API base, dynamic part is the path only, no SSRF/file:// surface (extends the existing noqa:S310 trusted-host judgment to semgrep). Scanner now reports 0 mediums on the agent-team scope.
This commit is contained in:
Adam Moussa 2026-06-18 14:16:31 -04:00
parent 516cf18111
commit 035c6e57e5
3 changed files with 9 additions and 3 deletions

View file

@ -94,7 +94,9 @@ def _turn_cache_key(
digest_src = json.dumps(list(qa_history), sort_keys=True, default=repr)
except (TypeError, ValueError):
digest_src = repr(list(qa_history))
content_hash = hashlib.sha1(digest_src.encode("utf-8")).hexdigest()
# sha256 (not sha1): this is a non-security cache-discriminator, but using a
# modern digest keeps the SAST scanners quiet (CWE-327) with no downside.
content_hash = hashlib.sha256(digest_src.encode("utf-8")).hexdigest()
return (thread_id, len(qa_history), content_hash)

View file

@ -173,7 +173,9 @@ def _default_http_post(
for key, value in headers.items():
request.add_header(key, value)
try:
with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host)
# url is built from a fixed https GitHub API base; the dynamic part is the
# path, never the scheme, so there is no SSRF/file:// surface.
with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host); nosemgrep
status = response.getcode()
raw = response.read().decode("utf-8")
except _urlerror.HTTPError as exc: # pragma: no cover - network path

View file

@ -283,7 +283,9 @@ def build_default_issue_client(
request.add_header("Authorization", f"Bearer {token}")
request.add_header("Accept", "application/vnd.github+json")
request.add_header("X-GitHub-Api-Version", "2022-11-28")
with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host)
# url is built from a fixed https GitHub API base; the dynamic part is
# the path, never the scheme, so there is no SSRF/file:// surface.
with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host); nosemgrep
raw = response.read().decode("utf-8")
data = json.loads(raw) if raw else []
# The issues endpoint can include pull requests (they share the