diff --git a/agent-team/agent_team/nodes/clarifier_llm.py b/agent-team/agent_team/nodes/clarifier_llm.py index cd6604d..32459cd 100644 --- a/agent-team/agent_team/nodes/clarifier_llm.py +++ b/agent-team/agent_team/nodes/clarifier_llm.py @@ -94,7 +94,9 @@ def _turn_cache_key( digest_src = json.dumps(list(qa_history), sort_keys=True, default=repr) except (TypeError, ValueError): digest_src = repr(list(qa_history)) - content_hash = hashlib.sha1(digest_src.encode("utf-8")).hexdigest() + # sha256 (not sha1): this is a non-security cache-discriminator, but using a + # modern digest keeps the SAST scanners quiet (CWE-327) with no downside. + content_hash = hashlib.sha256(digest_src.encode("utf-8")).hexdigest() return (thread_id, len(qa_history), content_hash) diff --git a/agent-team/agent_team/transport/github_adapter.py b/agent-team/agent_team/transport/github_adapter.py index 9254a49..669d698 100644 --- a/agent-team/agent_team/transport/github_adapter.py +++ b/agent-team/agent_team/transport/github_adapter.py @@ -173,7 +173,9 @@ def _default_http_post( for key, value in headers.items(): request.add_header(key, value) try: - with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host) + # url is built from a fixed https GitHub API base; the dynamic part is the + # path, never the scheme, so there is no SSRF/file:// surface. + with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host); nosemgrep status = response.getcode() raw = response.read().decode("utf-8") except _urlerror.HTTPError as exc: # pragma: no cover - network path diff --git a/agent-team/agent_team/transport/github_intake.py b/agent-team/agent_team/transport/github_intake.py index a3db56f..14e0598 100644 --- a/agent-team/agent_team/transport/github_intake.py +++ b/agent-team/agent_team/transport/github_intake.py @@ -283,7 +283,9 @@ def build_default_issue_client( request.add_header("Authorization", f"Bearer {token}") request.add_header("Accept", "application/vnd.github+json") request.add_header("X-GitHub-Api-Version", "2022-11-28") - with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host) + # url is built from a fixed https GitHub API base; the dynamic part is + # the path, never the scheme, so there is no SSRF/file:// surface. + with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host); nosemgrep raw = response.read().decode("utf-8") data = json.loads(raw) if raw else [] # The issues endpoint can include pull requests (they share the