Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FIX: [CodeQL: SM02196] Weak cryptography in TrackingConfigHashAlgorithm.cs #5065

Open
wants to merge 4 commits into
base: master
Choose a base branch
from

Conversation

MantavyaDh
Copy link
Contributor

@MantavyaDh MantavyaDh commented Dec 18, 2024

Context

In TrackingConfigHashAlgorithm.cs, SHA1 was being used to compute the hashKey, which is used to identify the tracking config file in the agent system and hence the workspace identifier.

Change Description

The PR addresses the CodeQL warning of using a weak hash algortihm by replacing it with SHA256 based on the recommendations - SM02196

Also it updates the existing Unit Tests with the updated hash values from the new algorithm.

Validations

  • Locally debugged the agent and checked that the new hashes are being generated from the SHA256 algorithm.
  • Verified that the tracking config file has the new hash in azure-pipelines-agent_layout\win-x64_work\SourceRootMapping\collectionID\definitionID
  • Ran the unit and functional tests.

@MantavyaDh
Copy link
Contributor Author

@MantavyaDh please read the following Contributor License Agreement(CLA). If you agree with the CLA, please reply with the following information.

@microsoft-github-policy-service agree [company="{your company}"]

Options:

  • (default - no company specified) I have sole ownership of intellectual property rights to my Submissions and I am not making Submissions in the course of work for my employer.
@microsoft-github-policy-service agree
  • (when company given) I am making Submissions in the course of work for my employer (or my employer has intellectual property rights in my Submissions by contract or applicable law). I have permission from my employer to make Submissions and enter into this Agreement on behalf of my employer. By signing below, the defined term “You” includes me and my employer.
@microsoft-github-policy-service agree company="Microsoft"

Contributor License Agreement

@microsoft-github-policy-service agree company="Microsoft"

@MantavyaDh MantavyaDh added the bug label Dec 18, 2024
@MantavyaDh MantavyaDh marked this pull request as ready for review December 20, 2024 12:09
@MantavyaDh MantavyaDh requested review from a team as code owners December 20, 2024 12:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant