From 035c6e57e5b86c82bf4f56e10526d888ad2d57f9 Mon Sep 17 00:00:00 2001 From: Adam Moussa Date: Thu, 18 Jun 2026 14:16:31 -0400 Subject: [PATCH] fix(agent-team): clear 3 non-blocking SAST mediums on main MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit clarifier_llm: sha1 -> sha256 for the non-security cache-discriminator (CWE-327 false positive). github_adapter + github_intake: inline nosemgrep on the urlopen lines (dynamic-urllib-use-detected) — the URL is built from a fixed https GitHub API base, dynamic part is the path only, no SSRF/file:// surface (extends the existing noqa:S310 trusted-host judgment to semgrep). Scanner now reports 0 mediums on the agent-team scope. --- agent-team/agent_team/nodes/clarifier_llm.py | 4 +++- agent-team/agent_team/transport/github_adapter.py | 4 +++- agent-team/agent_team/transport/github_intake.py | 4 +++- 3 files changed, 9 insertions(+), 3 deletions(-) diff --git a/agent-team/agent_team/nodes/clarifier_llm.py b/agent-team/agent_team/nodes/clarifier_llm.py index cd6604d..32459cd 100644 --- a/agent-team/agent_team/nodes/clarifier_llm.py +++ b/agent-team/agent_team/nodes/clarifier_llm.py @@ -94,7 +94,9 @@ def _turn_cache_key( digest_src = json.dumps(list(qa_history), sort_keys=True, default=repr) except (TypeError, ValueError): digest_src = repr(list(qa_history)) - content_hash = hashlib.sha1(digest_src.encode("utf-8")).hexdigest() + # sha256 (not sha1): this is a non-security cache-discriminator, but using a + # modern digest keeps the SAST scanners quiet (CWE-327) with no downside. + content_hash = hashlib.sha256(digest_src.encode("utf-8")).hexdigest() return (thread_id, len(qa_history), content_hash) diff --git a/agent-team/agent_team/transport/github_adapter.py b/agent-team/agent_team/transport/github_adapter.py index 9254a49..669d698 100644 --- a/agent-team/agent_team/transport/github_adapter.py +++ b/agent-team/agent_team/transport/github_adapter.py @@ -173,7 +173,9 @@ def _default_http_post( for key, value in headers.items(): request.add_header(key, value) try: - with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host) + # url is built from a fixed https GitHub API base; the dynamic part is the + # path, never the scheme, so there is no SSRF/file:// surface. + with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host); nosemgrep status = response.getcode() raw = response.read().decode("utf-8") except _urlerror.HTTPError as exc: # pragma: no cover - network path diff --git a/agent-team/agent_team/transport/github_intake.py b/agent-team/agent_team/transport/github_intake.py index a3db56f..14e0598 100644 --- a/agent-team/agent_team/transport/github_intake.py +++ b/agent-team/agent_team/transport/github_intake.py @@ -283,7 +283,9 @@ def build_default_issue_client( request.add_header("Authorization", f"Bearer {token}") request.add_header("Accept", "application/vnd.github+json") request.add_header("X-GitHub-Api-Version", "2022-11-28") - with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host) + # url is built from a fixed https GitHub API base; the dynamic part is + # the path, never the scheme, so there is no SSRF/file:// surface. + with _urlrequest.urlopen(request) as response: # noqa: S310 (trusted api host); nosemgrep raw = response.read().decode("utf-8") data = json.loads(raw) if raw else [] # The issues endpoint can include pull requests (they share the