Replace deprecated CC_MD5 with CC_SHA256 for cache key generation - #658
Open
PullaguraSatish wants to merge 1 commit into
Open
Replace deprecated CC_MD5 with CC_SHA256 for cache key generation#658PullaguraSatish wants to merge 1 commit into
PullaguraSatish wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
This PR replaces the deprecated
CC_MD5APIs withCC_SHA256inPINRemoteImageManagerwhen generating hashed cache keys.Motivation
Apple has deprecated the
CC_MD5APIs, and many security scanning tools (such as NowSecure) flag MD5 usage even when it is used for non-cryptographic purposes. Replacing it with SHA-256 removes the dependency on the deprecated hashing algorithm while continuing to generate deterministic cache keys.Changes
CC_MD5_CTXwithCC_SHA256_CTXCC_MD5_InitwithCC_SHA256_InitCC_MD5_UpdatewithCC_SHA256_UpdateCC_MD5_FinalwithCC_SHA256_FinalCC_MD5_DIGEST_LENGTHtoCC_SHA256_DIGEST_LENGTHNotes
This change only affects the hashing algorithm used when generating cache keys for long cache key strings. The overall cache key generation logic remains unchanged, although the resulting hash values will differ from those generated using MD5.