File tree
1,341 files changed
+261160
-22399
lines changed- .github
- actions
- fetch-codeql
- os-version
- workflows
- config
- cpp
- downgrades/a5bb28ed29f73855d64cc5f939cef977fa8fd19a
- ql
- lib
- change-notes/released
- experimental/semmle/code/cpp
- ir/dataflow/internal
- rangeanalysis
- semantic/analysis
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- dispatch
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- metrics
- models
- implementations
- interfaces
- rangeanalysis
- security
- stmts
- valuenumbering
- upgrades/ba86bebea4c7a8235c2fa0e220391fbd4446a087
- src
- Best Practices/Magic Constants
- Critical
- Documentation
- Likely Bugs
- Format
- Protocols
- Metrics
- Dependencies
- Files
- Security/CWE
- CWE-121
- CWE-290
- CWE-311
- CWE-367
- CWE-428
- CWE-468
- CWE-732
- change-notes/released
- codeql-suites
- experimental
- Likely Bugs
- Security/CWE
- CWE-020
- CWE-078
- CWE-1041
- CWE-1126
- CWE-120
- CWE-125
- CWE-190
- CWE-193
- CWE-200
- CWE-243
- CWE-266
- CWE-273
- CWE-285
- CWE-359
- CWE-362
- CWE-377
- CWE-401
- CWE-415
- CWE-476
- CWE-561
- CWE-670
- CWE-675
- CWE-691
- CWE-703
- CWE-754
- CWE-758
- CWE-783
- CWE-787
- CWE-788
- jsf/4.09 Style
- test
- library-tests
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- globals
- dataflow-tests
- taint-tests
- exprs/value_categories
- ir
- ir
- modulus-analysis
- sign-analysis
- syntax-zoo
- templates/type_instantiations
- type_sizes
- types/integral_types
- unspecified_type/types
- variables/variables
- query-tests/Security/CWE
- CWE-134/semmle/argv
- CWE-290/semmle/AuthenticationBypass
- csharp
- downgrades
- 1136957c0b3c73a7798ae42645c361e813295393
- 81a394bedda3d4747e36496c7be4d958424636d6
- d0fba103f7dee477dd7d9f6c038518b3f683b2c7
- extractor
- Semmle.Extraction.CIL/Entities
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Kinds
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- semmle/code
- cil
- csharp
- commons
- controlflow/internal
- dataflow
- internal
- rangeanalysis
- exprs
- metrics
- security/dataflow
- upgrades
- 1136957c0b3c73a7798ae42645c361e813295393
- 83aca6b3e4fa38dd2b97b9b51dfc199a2ba9c7f2
- d0fba103f7dee477dd7d9f6c038518b3f683b2c7
- src
- Documentation
- Likely Bugs/Dynamic
- Metrics
- Summaries
- internal
- Security Features/CWE-502
- Telemetry
- change-notes/released
- codeql-suites
- experimental
- CWE-099
- CWE-918
- Security Features
- CWE-1004
- CWE-327/Azure
- CWE-614
- CWE-759
- JsonWebTokenHandler
- Serialization
- backdoor
- dataflow/flowsources
- ir
- implementation
- raw
- internal
- unaliased_ssa
- internal
- internal
- rangeanalysis
- meta/frameworks
- utils
- model-generator
- modelconverter
- modelgenerator
- test
- experimental/ir/ir
- library-tests
- arguments
- attributes
- cil
- attributes
- typeAnnotations
- comments
- csharp11
- cil
- csharp6
- csharp7.1
- csharp7.3
- csharp7
- csharp8
- csharp9
- definitions
- delegates
- dynamic
- enums
- exceptions
- expressions
- fields
- generics
- goto
- indexers
- methods
- nestedtypes
- properties
- statements
- utils
- model-generator
- dataflow
- typebasedflow
- modelgenerator
- dataflow
- typebasedflow
- tools
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- ql-language-reference
- reusables
- vs-code-basic-instructions
- writing-codeql-queries
- go
- extractor/util
- ql
- lib
- change-notes/released
- ext
- semmle/go
- controlflow
- dataflow
- internal
- frameworks/stdlib
- security
- src
- Security
- CWE-327
- CWE-352
- change-notes/released
- codeql-suites
- experimental
- CWE-090
- CWE-1004
- CWE-285
- CWE-321
- CWE-327
- CWE-369
- CWE-400
- CWE-79
- CWE-807
- CWE-840
- CWE-918
- CWE-942
- IntegerOverflow
- Unsafe
- frameworks
- test
- TestUtilities
- library-tests/semmle/go
- dataflow
- ExternalFlowVarArgs
- ExternalFlow
- PromotedFields
- VarArgsWithFunctionModels
- frameworks
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- SQL
- query-tests/Security
- CWE-089
- CWE-117
- javascript/ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- extraction
- src
- test
- endpoint_large_scale
- autogenerated/ShellCommandInjectionFromEnvironment
- CommandInjection
- IndirectCommandInjection
- SecondOrderCommandInjection
- ShellCommandInjectionFromEnvironment
- UnsafeShellCommandConstruction/lib
- subLib2
- subLib3
- subLib4
- subLib
- UselessUseOfCat
- endpoint_unit_tests
- query_mappings
- lib
- change-notes/released
- semmle/javascript
- dataflow
- internal
- frameworks
- data
- security
- dataflow
- regexp
- src
- Declarations
- Security
- CWE-116
- CWE-770/examples
- change-notes/released
- codeql-suites
- experimental/Security
- CWE-094
- CWE-340
- CWE-918
- meta/analysis-quality
- test
- library-tests
- AST/Decorators
- DataFlow
- TypeScript
- TypeAnnotations
- Types
- query-tests/Security
- CWE-078/UnsafeShellCommandConstruction
- lib
- CWE-116/BadTagFilter
- CWE-400/ReDoS
- lib
- CWE-601/ClientSideUrlRedirect
- CWE-770/MissingRateLimit
- CWE-915/PrototypePollutingAssignment
- otherlib
- src
- tutorials/Introducing the JavaScript libraries
- java
- documentation/library-coverage
- kotlin-extractor
- src/main/kotlin
- utils
- versions
- v_1_4_32
- v_1_8_0
- ql
- integration-tests
- all-platforms
- java
- android-sample-kotlin-build-script-no-wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample-kotlin-build-script
- gradle/wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample-no-wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample-old-style-kotlin-build-script-no-wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample-old-style-kotlin-build-script
- gradle/wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample-old-style-no-wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample-old-style
- gradle/wrapper
- project
- src/main
- java/com/github/androidsample
- android-sample
- gradle/wrapper
- project
- src/main
- java/com/github/androidsample
- gradle-sample-kotlin-script
- app
- src
- main/java/test
- test/java/test
- gradle/wrapper
- gradle-sample
- partial-gradle-sample
- kotlin
- annotation-id-consistency
- default-parameter-mad-flow
- logs
- linux-only/kotlin/custom_plugin/plugin
- lib
- change-notes
- released
- ext
- semmle/code/java
- dataflow
- internal
- rangeanalysis
- frameworks
- android
- spring
- metrics
- regex
- security
- src
- Advisory
- Declarations
- Documentation
- Likely Bugs
- Arithmetic
- Comparison
- Metrics/Summaries
- Performance
- Security/CWE
- CWE-023
- CWE-190
- CWE-200
- CWE-327
- CWE-502
- CWE-681
- Telemetry
- Violations of Best Practice/Comments
- change-notes/released
- codeql-suites
- experimental/Security/CWE
- CWE-016
- CWE-020
- CWE-036
- CWE-073
- CWE-078
- CWE-089
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- CWE-295
- CWE-297
- CWE-299
- CWE-321
- CWE-327
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-489
- CWE-502
- CWE-522
- CWE-548
- CWE-552
- CWE-555
- CWE-598
- CWE-600
- CWE-601
- CWE-611
- CWE-625
- CWE-652
- CWE-665
- CWE-755
- CWE-759
- CWE-939
- utils/modelgenerator
- test
- experimental/query-tests/security
- CWE-400
- CWE-755
- ext
- TestModels
- TopJdkApis
- kotlin/library-tests
- annotation_classes
- enum
- exprs
- java-lang-number-conversions
- reflection
- library-tests
- constants
- dataflow
- entrypoint-types
- taintsources
- taint
- frameworks
- android/taint-database
- guava/handwritten
- jms
- ratpack
- query-tests
- Telemetry/UnsupportedExternalAPIs
- security
- CWE-074
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- CWE-094
- CWE-1204
- CWE-129/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests
- CWE-326
- CWE-347
- CWE-522
- CWE-643
- CWE-730
- CWE-749
- CWE-807/semmle/tests
- CWE-917
- CWE-927
- CWE-940
- stubs/google-android-9.0.0/android/webkit
- utils
- model-generator/dataflow
- modelgenerator
- dataflow
- p
- typebasedflow
- p
- misc
- bazel
- scripts
- models-as-data
- suite-helpers
- change-notes/released
- python/ql
- lib
- analysis
- change-notes/released
- semmle/python
- dataflow
- new/internal
- old
- essa
- objects
- pointsto
- types
- web/turbogears
- src
- Expressions
- Security/CWE-020-ExternalAPIs
- Statements
- analysis
- change-notes/released
- codeql-suites
- experimental/Security
- CWE-022bis
- CWE-022
- CWE-074
- CWE-079
- CWE-091
- CWE-113
- CWE-1236
- CWE-287
- CWE-327/Azure
- CWE-338
- CWE-340
- CWE-347
- CWE-348
- CWE-522
- CWE-611
- CWE-614
- CWE-943
- external
- test
- experimental
- dataflow
- TestUtil
- variable-capture
- query-tests/Security/CWE-022
- library-tests/ApiGraphs/py2
- query-tests/Security
- CWE-022-PathInjection
- CWE-078-CommandInjection
- ql
- ql
- src
- codeql_ql/style
- queries/style
- test/queries/style/OmittableExists
- tools
- ruby
- actions/create-extractor-pack
- downgrades/307ebf14d59930ba903d71d377f6f4129d0a6d22
- extractor
- generator
- ql
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- dataflow
- internal
- frameworks
- regexp
- internal
- security
- upgrades/3595c826de6db850f16b9da265a54dbf24dd3126
- src
- change-notes
- released
- codeql-suites
- experimental
- cwe-807
- decompression-api
- improper-memoization
- manually-check-http-verb
- weak-params
- queries/security
- cwe-079
- examples
- cwe-094
- examples
- cwe-1333
- cwe-798
- test
- library-tests
- ast
- calls
- params
- controlflow/graph
- dataflow/api-graphs
- frameworks/rack
- query-tests
- diagnostics
- security
- cwe-078/UnsafeShellCommandConstruction
- impl
- cwe-079
- app/views/foo
- bars
- stores
- lib
- cwe-094
- CodeInjection
- UnsafeCodeConstruction
- impl
- cwe-116/IncompleteMultiCharacterSanitization
- scripts
- tools
- swift
- codegen
- generators
- lib
- schema
- templates
- test
- downgrades/98a78b66651ad4eb35a8edf1642767c794909ea4
- extractor
- config
- infra
- file
- invocation
- remapping
- translators
- trap
- integration-tests/posix-only
- cross-references
- frontend-invocations
- linkage-awareness
- Foo1
- Sources/foo
- Foo2
- Sources/foo
- partial-modules
- ql
- lib
- codeql/swift
- controlflow
- dataflow
- internal
- elements/type
- generated
- decl
- expr
- security
- upgrades/5559b5a367524777b3f6ef3fc285ae81031ca1da
- src
- codeql-suites
- queries/Security
- CWE-089
- CWE-1204
- CWE-134
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-760
- test
- extractor-tests/generated/decl/ExtensionDecl
- library-tests
- dataflow
- dataflow
- taint
- elements/type/numerictype
- query-tests/Security
- CWE-022
- CWE-089
- CWE-1204
- CWE-134
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-760
- third_party
- fishhook
- swift-llvm-support
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,341 files changed
+261160
-22399
lines changedLines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| 22 | + | |
| 23 | + | |
22 | 24 |
|
Lines changed: 32 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + |
Lines changed: 1 addition & 13 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 | 3 |
| |
4 |
| - | |
5 |
| - | |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 |
| - | |
| 4 | + | |
17 | 5 |
| |
18 | 6 |
| |
19 | 7 |
| |
|
Lines changed: 6 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
| 14 | + | |
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
| 43 | + | |
43 | 44 |
| |
44 | 45 |
| |
45 | 46 |
| |
46 | 47 |
| |
47 |
| - | |
48 |
| - | |
| 48 | + | |
49 | 49 |
| |
50 | 50 |
| |
51 | 51 |
| |
| |||
61 | 61 |
| |
62 | 62 |
| |
63 | 63 |
| |
64 |
| - | |
| 64 | + | |
65 | 65 |
| |
66 | 66 |
| |
67 | 67 |
| |
| |||
100 | 100 |
| |
101 | 101 |
| |
102 | 102 |
| |
| 103 | + | |
| 104 | + | |
103 | 105 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
50 | 50 |
| |
51 | 51 |
| |
52 | 52 |
| |
53 |
| - | |
| 53 | + | |
54 | 54 |
| |
55 | 55 |
| |
56 | 56 |
| |
|
Lines changed: 11 additions & 9 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
| |||
38 | 38 |
| |
39 | 39 |
| |
40 | 40 |
| |
| 41 | + | |
| 42 | + | |
41 | 43 |
| |
42 | 44 |
| |
43 | 45 |
| |
44 | 46 |
| |
45 | 47 |
| |
46 |
| - | |
| 48 | + | |
47 | 49 |
| |
48 | 50 |
| |
49 | 51 |
| |
| |||
77 | 79 |
| |
78 | 80 |
| |
79 | 81 |
| |
80 |
| - | |
| 82 | + | |
81 | 83 |
| |
82 | 84 |
| |
83 | 85 |
| |
| |||
86 | 88 |
| |
87 | 89 |
| |
88 | 90 |
| |
89 |
| - | |
| 91 | + | |
90 | 92 |
| |
91 | 93 |
| |
92 | 94 |
| |
| |||
137 | 139 |
| |
138 | 140 |
| |
139 | 141 |
| |
140 |
| - | |
| 142 | + | |
141 | 143 |
| |
142 | 144 |
| |
143 | 145 |
| |
144 | 146 |
| |
145 | 147 |
| |
146 |
| - | |
| 148 | + | |
147 | 149 |
| |
148 |
| - | |
| 150 | + | |
149 | 151 |
| |
150 | 152 |
| |
151 | 153 |
| |
152 | 154 |
| |
153 |
| - | |
| 155 | + | |
154 | 156 |
| |
155 | 157 |
| |
156 | 158 |
| |
| |||
172 | 174 |
| |
173 | 175 |
| |
174 | 176 |
| |
175 |
| - | |
| 177 | + |
Lines changed: 4 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
28 |
| - | |
| 28 | + | |
29 | 29 |
| |
30 | 30 |
| |
| 31 | + | |
| 32 | + | |
31 | 33 |
| |
32 | 34 |
| |
33 | 35 |
| |
34 | 36 |
| |
35 | 37 |
| |
36 | 38 |
| |
37 |
| - | |
| 39 | + | |
38 | 40 |
| |
39 | 41 |
| |
40 | 42 |
| |
|
Lines changed: 61 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 |
| - | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
| 28 | + | |
| 29 | + | |
28 | 30 |
| |
29 | 31 |
| |
30 | 32 |
| |
31 | 33 |
| |
32 | 34 |
| |
33 | 35 |
| |
34 |
| - | |
| 36 | + | |
35 | 37 |
| |
36 | 38 |
| |
37 | 39 |
| |
38 | 40 |
| |
39 | 41 |
| |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
40 | 47 |
| |
41 | 48 |
| |
42 |
| - | |
| 49 | + | |
43 | 50 |
| |
44 | 51 |
| |
45 |
| - | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
46 | 89 |
| |
47 |
| - | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
48 | 97 |
| |
49 | 98 |
| |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + |
Lines changed: 7 additions & 21 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
48 | 48 |
| |
49 | 49 |
| |
50 | 50 |
| |
| 51 | + | |
| 52 | + | |
51 | 53 |
| |
52 | 54 |
| |
53 | 55 |
| |
| |||
58 | 60 |
| |
59 | 61 |
| |
60 | 62 |
| |
61 |
| - | |
| 63 | + | |
62 | 64 |
| |
63 | 65 |
| |
64 | 66 |
| |
65 | 67 |
| |
66 | 68 |
| |
67 | 69 |
| |
68 | 70 |
| |
69 |
| - | |
| 71 | + | |
70 | 72 |
| |
71 | 73 |
| |
72 | 74 |
| |
| |||
203 | 205 |
| |
204 | 206 |
| |
205 | 207 |
| |
206 |
| - | |
207 |
| - | |
208 |
| - | |
209 |
| - | |
210 |
| - | |
211 | 208 |
| |
212 | 209 |
| |
213 | 210 |
| |
| |||
216 | 213 |
| |
217 | 214 |
| |
218 | 215 |
| |
219 |
| - | |
220 |
| - | |
221 |
| - | |
222 |
| - | |
223 |
| - | |
224 |
| - | |
225 |
| - | |
226 |
| - | |
227 |
| - | |
228 |
| - | |
229 |
| - | |
230 |
| - | |
| 216 | + | |
231 | 217 |
| |
232 | 218 |
| |
233 | 219 |
| |
234 |
| - | |
| 220 | + | |
235 | 221 |
| |
236 | 222 |
| |
237 | 223 |
| |
238 |
| - | |
| 224 | + | |
239 | 225 |
| |
240 | 226 |
| |
241 | 227 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
| 28 | + | |
28 | 29 |
| |
29 | 30 |
| |
30 | 31 |
| |
|
0 commit comments