# HG changeset patch # User Franz Glasner # Date 1645972954 -3600 # Node ID a31de3c65877d2cc20a861ce32b16e5b2c68d451 # Parent 6cec638c995cec835f7dece034ce27f6b8537773 Remove the use of "hmac.compare_digest()": there are no secrets to protect here diff -r 6cec638c995c -r a31de3c65877 cutils/shasum.py --- a/cutils/shasum.py Sat Feb 26 19:35:41 2022 +0100 +++ b/cutils/shasum.py Sun Feb 27 15:42:34 2022 +0100 @@ -20,10 +20,6 @@ import binascii import errno import hashlib -try: - from hmac import compare_digest -except ImportError: - compare_digest = None import io try: import mmap @@ -211,10 +207,7 @@ return False else: return False - if compare_digest: - return compare_digest(given_digest, exd) - else: - return given_digest == exd + return given_digest == exd def verify_digests_with_checklist(opts):