Skip to content

Commit 946a68d

Browse files
authored
Merge pull request #969 from AzureAD/avdunn/codeql-suppress
Suppressed SHA-1 CodeQL flag
2 parents 15e26ca + eea7ab0 commit 946a68d

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

msal4j-sdk/src/main/java/com/microsoft/aad/msal4j/DefaultHttpClientManagedIdentity.java

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -136,7 +136,7 @@ public void checkServerTrusted(X509Certificate[] certificates, String authentica
136136
private static String extractCertificateThumbprint(Certificate certificate) {
137137
try {
138138
StringBuilder thumbprint = new StringBuilder();
139-
MessageDigest messageDigest = MessageDigest.getInstance("SHA-1");
139+
MessageDigest messageDigest = MessageDigest.getInstance("SHA-1"); // CodeQL [SM05136] We cannot control what the server uses, and must continue to use SHA-1
140140

141141
byte[] encodedCertificate;
142142

0 commit comments

Comments
 (0)