File tree
2,423 files changed
+119543
-43345
lines changed- .github/workflows
- config
- cpp
- autobuilder/Semmle.Autobuild.Cpp.Tests
- downgrades/625f706f2a44ae8dc3fc168bfe2637e65c30b012
- ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- ir/dataflow
- internal
- ssa0
- tainttracking1
- tainttracking2
- tainttracking3
- rangeanalysis
- semantic
- analysis
- semmle/code/cpp
- commons
- dataflow/internal
- tainttracking1
- tainttracking2
- exprs
- ir
- dataflow/internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa/internal
- internal
- raw/internal
- unaliased_ssa/internal
- models
- implementations
- interfaces
- pointsto
- upgrades/f96ad9b2da43bbc9e55a72a165febd270ae07981
- src
- Architecture
- General Class-Level Information
- General Top-Level Information
- Refactoring Opportunities
- Critical
- Likely Bugs/Memory Management
- Metrics/Namespaces
- PointsTo
- Security/CWE
- CWE-311
- CWE-313
- change-notes
- released
- experimental
- Likely Bugs
- Security/CWE/CWE-193
- test
- experimental
- library-tests/rangeanalysis/rangeanalysis
- query-tests/Security/CWE
- CWE-119
- CWE-193
- array-access
- pointer-deref
- library-tests
- builtins/type_traits
- ir/ir
- syntax-zoo
- query-tests
- Critical/MissingCheckScanf
- Likely Bugs/Memory Management/UsingExpiredStackAddress
- Security/CWE/CWE-311/semmle/tests
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- extractor/Semmle.Extraction.CSharp.Driver
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- dotnet_build
- dotnet_pack
- dotnet_publish
- dotnet_run
- posix-only/dotnet_test
- lib
- change-notes
- released
- semmle/code
- cil
- internal
- csharp
- controlflow/internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- frameworks
- microsoft
- system
- collections
- data
- net
- runtime
- src
- Stubs
- change-notes
- released
- experimental
- Security Features/JsonWebTokenHandler
- ir/implementation
- internal
- unaliased_ssa/internal
- utils/model-generator
- internal
- test
- experimental/Security Features/JsonWebTokenHandler
- library-tests/dataflow
- external-models
- library
- utils/model-generator
- dataflow
- typebasedflow
- tools
- linux64
- osx64
- win64
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- writing-codeql-queries
- ql-libraries/dataflow
- go
- codeql-tools
- linux64
- osx64
- win64
- ql
- lib
- change-notes
- released
- semmle/go
- concepts
- dataflow/internal
- frameworks
- stdlib
- security
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-020
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-117
- CWE-190
- CWE-209
- CWE-312
- CWE-322
- CWE-601
- CWE-643
- CWE-918
- change-notes
- released
- experimental
- CWE-090
- CWE-840
- CWE-918
- CWE-942
- frameworks
- test
- experimental
- CWE-090
- CWE-840
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- concepts/HTTP
- frameworks
- BeegoOrm
- Beego
- Echo
- ElazarlGoproxy
- Macaron
- Revel
- query-tests
- InconsistentCode
- ConstantLengthComparison
- MissingErrorCheck
- RedundantCode
- CompareIdenticalValues
- DuplicateCondition
- DuplicateSwitchCase
- SelfAssignment
- Security
- CWE-020
- IncompleteHostnameRegexp
- SuspiciousCharacterInRegexp
- CWE-022
- CWE-078
- CWE-089
- CWE-190
- CWE-209
- CWE-312
- CWE-601/OpenUrlRedirect
- CWE-643
- CWE-918
- javascript
- documentation
- extractor
- src/com/semmle
- jcorn
- flow
- js
- extractor
- parser
- tests/mozilla/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- src
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- frameworks
- AngularJS
- data/internal
- heuristics
- internal
- security
- dataflow
- regexp
- src
- AngularJS
- Expressions
- RegExp
- Security
- CWE-022
- CWE-073
- CWE-078
- CWE-079
- CWE-094
- CWE-117
- CWE-134
- CWE-200
- CWE-201
- CWE-209
- CWE-312
- CWE-327
- CWE-338
- CWE-352
- CWE-367
- CWE-377
- CWE-400
- CWE-451
- CWE-502
- CWE-506
- CWE-598
- CWE-601
- CWE-611
- CWE-640
- CWE-643
- CWE-730
- CWE-776
- CWE-834
- CWE-912
- change-notes
- released
- experimental
- Summaries
- poi
- meta
- analysis-quality
- extraction-metrics
- test
- ApiGraphs
- custom-entry-point
- typed
- experimental/PoI
- library-tests
- SensitiveActions
- TypeScript/HasUnderlyingType
- frameworks
- AngularJS
- dependency-dataflow
- dependency-resolution
- scopes
- Express
- Firebase
- HTTP-heuristics
- HTTP
- Micro
- Nest
- NodeJSLib
- Redux
- SQL
- Templating
- connect
- fastify
- hapi
- koa
- restify
- query-tests
- LanguageFeatures/SyntaxError
- RegExp/RegExpAlwaysMatches
- Security
- CWE-020/SuspiciousRegexpRange
- CWE-022
- TaintedPath
- ZipSlip
- CWE-073
- CWE-078
- CWE-079
- DomBasedXss
- UnsafeHtmlConstruction
- lib2
- src
- lib
- src
- CWE-094
- CodeInjection
- UnsafeDynamicMethodAccess
- CWE-117
- CWE-134
- CWE-200
- CWE-201
- CWE-209
- CWE-312
- CWE-327
- CWE-338
- CWE-367
- CWE-400
- DeepObjectResourceExhaustion
- RemovePropertyInjection
- CWE-502
- CWE-506
- CWE-601
- ClientSideUrlRedirect
- ServerSideUrlRedirect
- CWE-611
- CWE-640
- CWE-643
- CWE-730
- CWE-776
- CWE-834
- CWE-843
- CWE-912
- CWE-915/PrototypePollutingAssignment
- Summaries
- tutorials/Introducing the JavaScript libraries
- java
- documentation/library-coverage
- kotlin-extractor
- src/main
- java/com/semmle/extractor/java
- kotlin
- comments
- utils
- ql
- integration-tests/posix-only/kotlin
- compiler_arguments
- app
- src/main/kotlin/testProject
- kotlin_kfunction
- app
- src/main/kotlin/testProject
- lib
- change-notes
- released
- semmle/code
- java
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- dispatch
- frameworks
- android
- javaee
- kotlin
- spring
- struts
- security
- regexp
- xml
- src
- Advisory/Deprecated Code
- Architecture/Refactoring Opportunities
- Frameworks/JavaEE/EJB
- Likely Bugs
- Collections
- Reflection
- Performance
- Security/CWE
- CWE-022
- CWE-079
- CWE-094
- CWE-312
- CWE-327
- Violations of Best Practice
- Implementation Hiding
- Naming Conventions
- change-notes
- released
- experimental
- Security/CWE
- CWE-094
- CWE-352
- CWE-625
- semmle/code/java/frameworks
- utils/model-generator
- internal
- test
- experimental/query-tests/security/CWE-094
- kotlin/library-tests
- classes
- comments
- data-classes
- dataflow
- func
- summaries
- declaration-stack
- exprs
- CONSISTENCY
- generics-location
- java_and_kotlin_internal
- java_and_kotlin
- methods-mixed-java-and-kotlin
- methods
- multiple_files
- operator-overloads
- reflection
- special-method-getters
- vararg
- library-tests
- MemberRefExpr
- annotation-arrays
- annotations
- dataflow
- callctx
- state
- dispatch
- frameworks
- android
- content-provider-summaries
- notification
- play
- thymeleaf
- implicit-this-type
- typeflow
- query-tests
- AmbiguousOuterSuper
- ExposeRepresentation
- IteratorRemoveMayFail
- security
- CWE-022/semmle/tests
- CWE-094
- CWE-312
- android
- CleartextStorage
- backup
- TestEmptyManifest
- TestExplicitlyDisabled
- TestExplicitlyEnabled
- TestLibrary
- TestMissing
- Testbuild
- CWE-927
- stubs
- apache-freemarker-2.3.31/freemarker
- cache
- core
- template
- utility
- apache-velocity-2.3/org
- apache/velocity
- app
- event
- context
- runtime
- directive
- parser
- node
- resource
- loader
- util
- util
- introspection
- slf4j
- event
- spi
- google-android-9.0.0
- androidx
- core/app
- remotecallback
- slice
- builders/impl
- compat
- versionedparcelable
- android
- app
- service/notification
- jinjava-2.6.0
- com
- fasterxml/jackson
- annotation
- core
- filter
- format
- io
- sym
- type
- util
- databind
- annotation
- cfg
- deser
- impl
- introspect
- jsonFormatVisitors
- jsonschema
- jsontype
- node
- ser
- impl
- std
- type
- util
- google/common/collect
- hubspot/jinjava
- doc
- el/ext
- interpret
- errorcategory
- lib
- expression
- exptest
- filter
- fn
- tag
- eager
- loader
- mode
- objects
- serialization
- random
- tree
- output
- parse
- util
- jinjava/javax/el
- pebble-3.1.5/com/mitchellbosecke/pebble
- mitchellbosecke/pebble
- attributes
- methodaccess
- cache
- extension
- escaper
- lexer
- loader
- node
- expression
- operator
- parser
- template
- tokenParser
- utils
- template
- thymeleaf-3.0.14/org/thymeleaf
- cache
- context
- dialect
- engine
- expression
- inline
- linkbuilder
- messageresolver
- model
- postprocessor
- preprocessor
- processor
- cdatasection
- comment
- doctype
- element
- processinginstruction
- templateboundaries
- text
- xmldeclaration
- templatemode
- templateparser/markup/decoupled
- templateresolver
- templateresource
- misc
- bazel
- scripts/models-as-data
- suite-helpers
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- essa
- frameworks
- Stdlib
- data/internal
- internal
- objects
- pointsto
- security
- dataflow
- regexp
- src
- Exceptions
- Functions
- Security
- CWE-020-ExternalAPIs
- CWE-022
- CWE-078
- CWE-090
- CWE-094
- CWE-117
- CWE-209
- CWE-295
- CWE-352
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-730
- CWE-776
- CWE-918
- change-notes
- released
- experimental/semmle/python
- frameworks
- meta/alerts
- test
- 2/query-tests/Exceptions
- generators
- raising
- experimental
- dataflow
- TestUtil
- basic
- calls
- coverage
- summaries
- typetracking_imports
- pkg
- typetracking
- meta
- library-tests
- ApiGraphs/py3
- PointsTo/new
- frameworks/data
- variables/scopes
- query-tests
- Functions
- ModificationOfParameterWithDefault
- general
- Security
- CWE-022-PathInjection
- CWE-022-TarSlip
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- ql/ql
- src
- codeql_ql
- ast
- style
- codeql
- queries
- bugs
- style
- test/queries/style/Misspelling
- ruby
- downgrades/3595c826de6db850f16b9da265a54dbf24dd3126
- extractor
- generator
- ql
- consistency-queries
- examples/snippets
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttrackingforlibraries
- experimental
- filters
- frameworks
- core/internal
- data
- internal
- http_clients
- internal
- regexp
- internal
- security
- internal
- regexp
- typetracking
- upgrades/4ba51641799d2aaa315c7323931e2dd2a94c9f9d
- src
- change-notes
- released
- experimental
- cwe-807
- decompression-api
- improper-memoization
- manually-check-http-verb
- performance
- weak-params
- filters
- queries
- analysis
- diagnostics
- metrics
- security
- cwe-022
- cwe-078
- cwe-079
- cwe-089
- cwe-094
- cwe-116
- cwe-117
- cwe-1333
- cwe-134
- cwe-295
- cwe-300
- cwe-312
- cwe-327
- cwe-352
- cwe-502
- cwe-506
- cwe-601
- cwe-611
- cwe-732
- cwe-798
- cwe-829
- cwe-912
- cwe-918
- summary
- variables
- test
- TestUtilities
- library-tests
- ast
- calls
- constants
- control
- erb
- escape_sequences
- gems
- literals
- misc
- modules
- operations
- params
- concepts
- dataflow
- api-graphs
- array-flow
- call-sensitivity
- global
- hash-flow
- local
- params
- pathname-flow
- string-flow
- summaries
- type-tracker
- experimental
- frameworks
- action_view
- active_resource
- active_support
- archive
- arel
- files
- http_clients
- pathname
- railties
- modules
- security
- query-tests
- experimental/improper-memoization
- security
- cwe-022
- cwe-078
- cwe-079
- cwe-089
- cwe-094
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-117
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-134
- cwe-295
- cwe-300
- cwe-312
- cwe-502
- oj-global-options
- unsafe-deserialization
- cwe-506
- cwe-601
- cwe-611
- cwe-807-user-controlled-bypass
- cwe-829
- cwe-912
- cwe-918
- swift
- codegen
- generators
- lib
- schema
- test
- extractor
- infra
- remapping
- trap
- visitors
- ql
- lib
- codeql/swift
- controlflow/internal
- dataflow
- internal
- tainttracking1
- elements
- decl
- expr
- type
- generated
- decl
- expr
- stmt
- type
- printast
- security
- src
- queries/Security
- CWE-135
- CWE-311
- CWE-328
- CWE-757
- test
- extractor-tests
- declarations
- generated
- decl
- IfConfigClause
- IfConfigDecl
- ImportDecl
- expr
- PackExpr
- ReifyPackExpr
- UnresolvedDeclRefExpr
- UnresolvedPatternExpr
- type
- NestedArchetypeType
- PackExpansionType
- PackType
- ParameterizedProtocolType
- library-tests
- ast
- controlflow/graph
- query-tests/Security
- CWE-135
- CWE-311
- CWE-328
- CWE-757
- tools
- fishhook
- prebuilt
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,423 files changed
+119543
-43345
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
2 | 2 |
| |
3 | 3 |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
| 31 | + | |
31 | 32 |
| |
32 | 33 |
| |
33 | 34 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
56 | 56 |
| |
57 | 57 |
| |
58 | 58 |
| |
59 |
| - | |
| 59 | + | |
60 | 60 |
| |
61 | 61 |
| |
62 | 62 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
55 | 55 |
| |
56 | 56 |
| |
57 | 57 |
| |
58 |
| - | |
| 58 | + | |
59 | 59 |
| |
60 | 60 |
| |
61 | 61 |
| |
|
Lines changed: 14 additions & 7 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
8 | 15 |
| |
9 | 16 |
| |
10 | 17 |
| |
| |||
54 | 61 |
| |
55 | 62 |
| |
56 | 63 |
| |
57 |
| - | |
| 64 | + | |
58 | 65 |
| |
59 | 66 |
| |
60 | 67 |
| |
| |||
108 | 115 |
| |
109 | 116 |
| |
110 | 117 |
| |
111 |
| - | |
| 118 | + | |
112 | 119 |
| |
113 | 120 |
| |
114 | 121 |
| |
115 | 122 |
| |
116 | 123 |
| |
117 | 124 |
| |
118 | 125 |
| |
119 |
| - | |
120 |
| - | |
| 126 | + | |
| 127 | + | |
121 | 128 |
| |
122 | 129 |
| |
123 | 130 |
| |
124 | 131 |
| |
125 | 132 |
| |
126 |
| - | |
| 133 | + | |
127 | 134 |
| |
128 | 135 |
| |
129 | 136 |
| |
| |||
139 | 146 |
| |
140 | 147 |
| |
141 | 148 |
| |
142 |
| - | |
| 149 | + | |
143 | 150 |
| |
144 | 151 |
| |
145 | 152 |
| |
146 | 153 |
| |
147 | 154 |
| |
148 |
| - | |
| 155 | + | |
149 | 156 |
| |
150 | 157 |
| |
151 | 158 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
95 | 95 |
| |
96 | 96 |
| |
97 | 97 |
| |
| 98 | + | |
98 | 99 |
| |
99 | 100 |
| |
100 | 101 |
| |
| |||
196 | 197 |
| |
197 | 198 |
| |
198 | 199 |
| |
199 |
| - | |
| 200 | + | |
200 | 201 |
| |
201 | 202 |
| |
202 | 203 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + | |
| 8 | + | |
7 | 9 |
| |
8 | 10 |
| |
9 | 11 |
| |
|
Lines changed: 10 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + | |
| 8 | + | |
7 | 9 |
| |
8 | 10 |
| |
9 | 11 |
| |
| |||
30 | 32 |
| |
31 | 33 |
| |
32 | 34 |
| |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
33 | 43 |
| |
34 | 44 |
| |
35 | 45 |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + | |
| 8 | + | |
7 | 9 |
| |
8 | 10 |
| |
9 | 11 |
| |
|
0 commit comments