File tree
1,125 files changed
+66944
-36501
lines changed- .github/workflows
- config
- cpp/ql
- examples
- lib
- change-notes
- released
- semmle/code/cpp
- dataflow/internal
- ir
- dataflow/internal
- implementation
- internal
- raw/internal
- internal
- rangeanalysis/new
- internal/semantic/analysis
- security
- src
- Critical
- Likely Bugs
- change-notes
- released
- experimental/Security/CWE/CWE-415
- test
- experimental/query-tests/Security/CWE
- CWE-119
- CWE-193/pointer-deref
- library-tests
- attributes/type_attributes
- constants/constants
- dataflow/dataflow-tests
- ir
- ir
- modulus-analysis
- range-analysis
- sign-analysis
- structs/compatible_c
- syntax-zoo
- query-tests
- Critical
- MemoryFreed
- MissingCheckScanf
- Likely Bugs
- Format/NonConstantFormat
- RedundantNullCheckSimple
- Security/CWE/CWE-416/semmle/tests
- csharp
- documentation/library-coverage
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- examples
- integration-tests
- all-platforms
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- dotnet_run
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- lib
- change-notes
- released
- ext
- semmle/code/csharp
- dataflow
- internal
- frameworks
- system
- security
- dataflow
- flowsinks
- xml
- src
- API Abuse
- Language Abuse
- Likely Bugs
- LeapYear
- Security Features
- CWE-022
- CWE-079
- CWE-091
- CWE-114
- CWE-134
- CWE-201
- CWE-209
- CWE-327
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-838
- change-notes
- released
- experimental
- CWE-099
- CWE-918
- Security Features
- CWE-1004
- CWE-614
- CWE-759
- JsonWebTokenHandler
- Serialization
- backdoor
- dataflow/flowsources
- ir/implementation/internal
- utils/modelgenerator/internal
- test
- library-tests
- csharp7
- dataflow
- async
- call-sensitivity
- collections
- content
- external-models
- fields
- global
- tuples
- types
- frameworks/EntityFramework
- query-tests/Security Features
- CWE-079/StoredXSS
- CWE-312
- CWE-338
- CWE-359
- docs/codeql
- query-help
- reusables
- go
- extractor
- cli/go-autobuilder
- util
- ql
- examples
- lib
- change-notes
- released
- semmle/go
- dataflow/internal
- security
- src
- change-notes/released
- experimental/CWE-79
- test
- experimental/CWE-79
- library-tests/semmle/go
- dataflow/FlowSteps
- frameworks/TaintSteps
- query-tests/Security/CWE-079
- javascript
- extractor
- lib/typescript/src
- src/com/semmle/js
- extractor
- parser
- tests/json/output/trap
- ql
- examples
- experimental/adaptivethreatmodeling/src
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- frameworks
- linters
- security
- dataflow
- regexp
- src
- Security/CWE-916
- examples
- change-notes
- released
- experimental/Security/CWE-444
- examples
- test
- library-tests
- DOM
- JSON
- TypeScript/RegressionTests/GenericTypeAlias
- frameworks
- Angular2
- Express
- src
- typed_src
- HTTP-heuristics
- Nest
- query-tests/Security
- CWE-020/UntrustedDataToExternalAPI
- CWE-079
- DomBasedXss
- UnsafeJQueryPlugin
- CWE-502
- CWE-915/PrototypePollutingAssignment
- java
- documentation/library-coverage
- ql
- examples
- integration-tests/all-platforms/kotlin
- default-parameter-mad-flow
- kotlin-interface-inherited-default
- kotlin_java_static_fields
- lib
- change-notes
- released
- ext
- semmle/code/java
- dataflow/internal
- security
- src
- Metrics/Summaries
- Security/CWE
- CWE-798
- CWE-927
- Telemetry
- change-notes/released
- utils/modelgenerator/internal
- test
- TestUtilities
- experimental/query-tests/security
- CWE-020
- CWE-089/src/main
- CWE-200
- CWE-299
- CWE-327
- CWE-400
- CWE-601
- ext/TestModels
- kotlin/library-tests
- dataflow
- extensionMethod
- foreach
- func
- notnullexpr
- stmtexpr
- taint
- whenexpr
- field-initializer-flow
- jvmoverloads_flow
- parameter-defaults
- super-method-calls
- vararg
- library-tests
- dataflow
- call-sensitivity
- callback-dispatch
- capture
- collections
- entrypoint-types
- fields
- lambda
- local-flow
- null
- partial
- records
- switchexpr
- taint-ioutils
- taintgettersetter
- taintreturn
- taintsources
- taint
- this-flow
- typepruning
- frameworks
- JaxWs
- android
- content-provider
- external-storage
- slice
- sources
- taint-database
- apache-http
- guava/handwritten
- guice
- jms
- netty
- generated
- manual
- okhttp
- rabbitmq
- ratpack
- retrofit
- spring
- controller
- util
- pathsanitizer
- query-tests
- Metrics/GeneratedVsManualCoverage/TopJdkApisTest
- TopJdkApis/java/lang
- security
- CWE-022/semmle/tests
- mad
- CWE-078
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- CWE-117
- CWE-190/semmle/tests
- CWE-643
- CWE-798/semmle/tests
- CWE-918
- CWE-927
- stubs/apache-http-5/org/apache/hc
- client5/http
- async/methods
- classic
- methods
- config
- fluent
- impl/classic
- core5
- concurrent
- function
- http
- impl
- bootstrap
- io
- nio
- io
- support
- message
- nio
- ssl
- protocol
- support
- io
- net
- pool
- reactor
- ssl
- util
- misc
- bazel
- codegen/templates
- suite-helpers
- change-notes/released
- python
- downgrades/0355ecf0ac589e66467a378e0e9d60f41ee4a757
- ql
- examples
- lib
- change-notes
- released
- semmle/python
- dataflow/new/internal
- frameworks
- upgrades/47e552c4357a04c5735355fad818630daee4a5ac
- src
- Security/CWE-295
- change-notes/released
- experimental/Security
- CWE-074/paramiko
- CWE-611
- test
- experimental
- dataflow
- TestUtil
- basic
- fieldflow
- tainttracking/basic
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-074/paramiko
- library-tests/Yaml
- query-tests/Security/CWE-295-MissingHostKeyValidation
- ql
- buramu
- extractor
- src
- ql/src/codeql_ql/ast
- scripts
- tools
- ruby
- extractor
- src
- bin
- ql
- examples
- lib
- change-notes
- released
- codeql/ruby
- ast/internal
- dataflow/internal
- frameworks
- data/internal
- src
- change-notes/released
- queries
- meta/internal
- security/cwe-078
- test
- library-tests
- dataflow
- array-flow
- call-sensitivity
- flow-summaries
- global
- hash-flow
- helpers
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- sinatra
- query-tests
- experimental
- TemplateInjection
- cwe-022-ZipSlip
- manually-check-http-verb
- weak-params
- security
- cwe-020/MissingFullAnchor
- cwe-022
- cwe-078
- CommandInjection
- KernelOpen
- NonConstantKernelOpen
- UnsafeShellCommandConstruction
- cwe-079
- cwe-089
- cwe-094
- CodeInjection
- UnsafeCodeConstruction
- cwe-117
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-134
- cwe-209
- cwe-312
- cwe-502
- oj-global-options
- unsafe-deserialization
- cwe-506
- cwe-601
- cwe-611
- libxml-backend
- xxe
- cwe-732
- cwe-798
- cwe-807-user-controlled-bypass
- cwe-829
- cwe-912
- cwe-918
- decompression-api
- scripts
- tools
- swift
- downgrades/ba4171b90d0665b40e9e203bac9e3d4a0b2d03ec
- extractor
- infra
- file
- log
- invocation
- mangler
- translators
- trap
- integration-tests/posix-only
- cross-references
- deduplication
- hello-world
- linkage-awareness
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- frameworks
- StandardLibrary
- generated
- decl
- expr
- printast
- security
- upgrades/f937d9e63094280b7ec0ef26c70310daad5c1f79
- src
- queries/Security
- CWE-079
- CWE-094
- CWE-135
- CWE-311
- CWE-312
- CWE-943
- test
- extractor-tests
- declarations
- expressions
- generated
- decl
- Accessor
- CapturedDecl
- ConcreteVarDecl
- Deinitializer
- ExtensionDecl
- Initializer
- NamedFunction
- ParamDecl
- expr
- ExplicitClosureExpr
- InitializerRefCallExpr
- LazyInitializationExpr
- OtherInitializerRefExpr
- RebindSelfInInitializerExpr
- type/TupleType
- types
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- taint/core
- elements
- decl
- abstractfunctiondecl
- extensiondecl
- function
- expr/methodlookup
- query-tests/Security
- CWE-022
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-135
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-327
- CWE-328
- CWE-757
- CWE-760
- CWE-916
- third_party
- binlog
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,125 files changed
+66944
-36501
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| |||
50 | 50 |
| |
51 | 51 |
| |
52 | 52 |
| |
53 |
| - | |
| 53 | + | |
54 | 54 |
| |
55 | 55 |
| |
56 | 56 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
23 | 23 |
| |
24 | 24 |
| |
25 | 25 |
| |
26 |
| - | |
| 26 | + | |
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
|
Lines changed: 10 additions & 19 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
58 | 58 |
| |
59 | 59 |
| |
60 | 60 |
| |
61 |
| - | |
62 |
| - | |
63 |
| - | |
64 |
| - | |
| 61 | + | |
| 62 | + | |
65 | 63 |
| |
66 | 64 |
| |
67 | 65 |
| |
| |||
88 | 86 |
| |
89 | 87 |
| |
90 | 88 |
| |
91 |
| - | |
92 |
| - | |
93 |
| - | |
| 89 | + | |
94 | 90 |
| |
95 | 91 |
| |
96 | 92 |
| |
97 | 93 |
| |
98 | 94 |
| |
99 |
| - | |
| 95 | + | |
100 | 96 |
| |
101 | 97 |
| |
102 | 98 |
| |
| |||
111 | 107 |
| |
112 | 108 |
| |
113 | 109 |
| |
114 |
| - | |
115 |
| - | |
116 |
| - | |
117 |
| - | |
| 110 | + | |
| 111 | + | |
118 | 112 |
| |
119 | 113 |
| |
120 | 114 |
| |
| |||
172 | 166 |
| |
173 | 167 |
| |
174 | 168 |
| |
175 |
| - | |
176 |
| - | |
177 |
| - | |
178 |
| - | |
179 |
| - | |
180 |
| - | |
181 |
| - | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
182 | 173 |
| |
183 | 174 |
| |
184 | 175 |
| |
|
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
43 |
| - | |
44 | 43 |
| |
45 | 44 |
| |
46 | 45 |
| |
|
Lines changed: 0 additions & 1 deletion
This file was deleted.
Lines changed: 26 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
1 | 27 |
| |
2 | 28 |
| |
3 | 29 |
| |
|
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 4 deletions
This file was deleted.
0 commit comments