Skip to content

please upgrade pip to use something else instead of sha224 #158611

Description

@xnox

Feature or enhancement

  File "/tmp/tmpk8m6peir/pip-26.2.1-py3-none-any.whl/pip/_internal/cache.py", line 144, in get
    for wheel_name, wheel_dir in self._get_candidates(link, canonical_package_name):
  File "/tmp/tmpk8m6peir/pip-26.2.1-py3-none-any.whl/pip/_internal/cache.py", line 82, in _get_candidates
    path = self.get_path_for_link(link)
  File "/tmp/tmpk8m6peir/pip-26.2.1-py3-none-any.whl/pip/_internal/cache.py", line 124, in get_path_for_link
    parts = self._get_cache_path_parts(link)
  File "/tmp/tmpk8m6peir/pip-26.2.1-py3-none-any.whl/pip/_internal/cache.py", line 68, in _get_cache_path_parts
    hashed = _hash_dict(key_parts)
  File "/tmp/tmpk8m6peir/pip-26.2.1-py3-none-any.whl/pip/_internal/cache.py", line 30, in _hash_dict
    return hashlib.sha224(s.encode("ascii")).hexdigest()
AttributeError: module 'hashlib' has no attribute 'sha224'

Many FIPS modules and minimal systems are removing unused algorithms. For example SHA-224 is not needed to implement TLS, nor does it provide sufficient security at post quantum security levels.

Please consider upgrading to SHA256, SHA384, or SHA512 - or like xxhash if this is not meant to be used in security relevant context.

Has this already been discussed elsewhere?

This is a minor feature, which does not need previous discussion elsewhere

Links to previous discussion of this feature:

No response

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    type-featureA feature request or enhancement

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions