File tree
3,747 files changed
+278371
-216931
lines changed- .github
- actions
- cache-query-compilation
- find-latest-bundle
- workflows
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- ir/dataflow
- internal
- tainttracking1
- semantic/analysis
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- tainttracking1
- exprs
- ir
- dataflow
- internal
- tainttracking1
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- models
- implementations
- interfaces
- rangeanalysis
- security
- src
- Security/CWE
- CWE-078
- CWE-732
- change-notes/released
- experimental/Security/CWE
- CWE-369
- CWE-415
- CWE-805
- test
- experimental/query-tests/Security/CWE
- CWE-369/semmle/tests
- CWE-805/semmle/tests
- library-tests
- CPP-205
- allocators
- declarationEntry/more
- ir/range-analysis
- noexcept/copy_from_prototype
- templates/isfromtemplateinstantiation
- query-tests
- Critical/MissingCheckScanf
- Security/CWE/CWE-078/semmle/ExecTainted
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- downgrades/cd877b8cc2fb8327499f96fbefd01bb988b2ed63
- extractor
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Kinds
- Semmle.Extraction
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- dotnet_build
- dotnet_pack
- dotnet_publish
- dotnet_run
- msbuild
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- scripts
- dotnet_test
- inherit-env-vars
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- scripts
- lib
- change-notes
- released
- semmle/code
- cil
- csharp
- commons
- dataflow
- internal
- tainttracking1
- dispatch
- exprs
- frameworks
- system
- collections
- runtime
- security/cryptography
- security/dataflow
- flowsources
- dotnet
- upgrades/97da4e8c5750e07c4f7c8a366b21060e05ecd5ed
- src
- Likely Bugs
- Stubs
- Telemetry
- change-notes/released
- experimental
- Security Features
- JsonWebTokenHandler
- backdoor
- ir/implementation
- raw
- internal
- desugar
- internal
- unaliased_ssa
- internal
- meta/frameworks
- test
- library-tests
- csharp11
- dataflow/library
- dispatch
- frameworks/EntityFramework
- query-tests
- Likely Bugs/StaticFieldWrittenByInstance
- Stubs
- All
- Minimal
- resources/stubs/_frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- scripts
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- writing-codeql-queries
- go
- extractor
- cli
- go-autobuilder
- go-extractor
- diagnostics
- util
- ql
- integration-tests
- all-platforms/go
- diagnostics
- build-constraints-exclude-all-go-files
- work
- go-files-found-not-processed
- work
- subdir
- newer-go-version-needed
- work
- no-go-files-found
- work
- package-not-found-with-go-mod
- work
- package-not-found-without-go-mod
- work
- unsupported-relative-path
- work/main
- subpkg
- go-get-without-modules-sample
- go-mod-sample
- make-sample
- ninja-sample
- linux-only/go
- dep-sample
- work
- vendor/golang.org/x/time
- rate
- glide-sample
- work
- vendor/golang.org/x/time
- rate
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- tainttracking1
- frameworks
- stdlib
- security
- src
- Diagnostics
- InconsistentCode
- Security
- CWE-117
- CWE-209
- CWE-295
- CWE-327
- CWE-681
- change-notes/released
- experimental
- CWE-285
- CWE-321
- CWE-942
- test
- example-tests/snippets
- extractor-tests
- diagnostics
- CONSISTENCY
- go1.14
- library-tests/semmle/go
- Function
- IR
- Types
- CONSISTENCY
- concepts/HTTP
- dataflow
- ArrayConversion
- VarArgsWithFunctionModels
- frameworks
- StdlibTaintFlow
- Twirp
- client
- rpc/notes
- server
- vendor
- github.com/twitchtv/twirp
- ctxsetters
- internal/contextkeys
- google.golang.org/protobuf
- encoding
- protojson
- prototext
- protowire
- internal
- descfmt
- descopts
- detrand
- encoding
- defval
- json
- messageset
- tag
- text
- errors
- filedesc
- filetype
- flags
- genid
- impl
- order
- pragma
- set
- strs
- version
- proto
- reflect
- protoreflect
- protoregistry
- runtime
- protoiface
- protoimpl
- query-tests
- Diagnostics
- CONSISTENCY
- InconsistentCode/UnhandledCloseWritableHandle
- RedundantCode
- DeadStoreOfLocal/CONSISTENCY
- ImpossibleInterfaceNilCheck/CONSISTENCY
- Security
- CWE-681
- CWE-918
- vendor
- golang.org/x
- mod
- modfile
- module
- sys/execabs
- tools
- go
- gcexportdata
- internal/gcimporter
- packages
- internal
- gcimporter
- gocommand
- pkgbits
- tokeninternal
- typesinternal
- javascript
- extractor
- src/com/semmle
- js
- extractor
- parser
- ts/extractor
- tests/vue/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- extraction
- src
- test
- integration-tests/all-platforms
- diagnostics/syntax-error
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- AngularJS
- heuristics
- internal
- security
- dataflow
- internal
- src
- Security
- CWE-020
- CWE-078
- CWE-730
- change-notes
- released
- test
- experimental/Security/CWE-918
- library-tests/CryptoLibraries
- query-tests/Security
- CWE-078/UnsafeShellCommandConstruction
- lib
- CWE-079
- UnsafeHtmlConstruction
- lib2
- src
- XssThroughDom
- CWE-089/untyped
- CWE-094/CodeInjection
- CWE-400/ReDoS
- lib
- subLib5
- subLib6
- CWE-730
- CWE-918
- java
- documentation/library-coverage
- downgrades/934bf10b4bd34cf648893efcd1d0d7be9471d39f
- kotlin-extractor
- src/main/kotlin
- ql
- integration-tests/all-platforms
- java/diagnostics
- android-gradle-incompatibility
- gradle/wrapper
- project
- src/main
- java/com/github/androidsample
- compilation-error
- src
- main
- java/com/example
- resources
- test/java/com/example
- dependency-error
- src
- main
- java/com/example
- resources
- test/java/com/example
- java-version-too-old
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- maven-http-repository
- src
- main
- java/com/example
- resources
- test/java/com/example
- multiple-candidate-builds
- maven-project-1
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-project-2
- src
- main
- java/com/example
- resources
- test/java/com/example
- no-build-system
- no-gradle-test-classes
- no-gradle-wrapper
- src
- main/java/com/example
- test/java/com/example
- kotlin
- compiler_arguments
- gradle/wrapper
- diagnostics/kotlin-version-too-new
- fake-kotlinc-source
- com/intellij
- mock
- openapi
- driver
- kotlin
- org/jetbrains/kotlin
- cli
- common
- arguments
- jvm
- config
- utils
- gradle_groovy_app
- gradle/wrapper
- gradle_kotlinx_serialization
- gradle/wrapper
- kotlin_kfunction
- gradle/wrapper
- lib
- change-notes
- released
- config
- ext
- semmle/code
- java
- dataflow
- internal
- tainttracking1
- deadcode
- dispatch
- internal
- frameworks
- android
- google
- jackson
- javaee/ejb
- os
- security
- xml
- upgrades/44d61b266bebf261cb027872646262e645efa059
- src
- Likely Bugs/Collections
- Metrics/Summaries
- Security/CWE
- CWE-022
- CWE-079
- CWE-113
- CWE-209
- CWE-327
- CWE-532
- CWE-611
- CWE-681
- CWE-918
- Telemetry
- change-notes/released
- experimental/Security/CWE
- CWE-321
- CWE-348
- utils
- flowtestcasegenerator
- modelconverter
- modelgenerator/internal
- stub-generator
- test
- TestUtilities
- experimental/query-tests/security/CWE-321
- library-tests
- dataflow
- collections
- fluent-methods
- inoutbarriers
- partial
- state
- taint-format
- frameworks
- JaxWs
- android
- content-provider
- external-storage
- slice
- sources
- apache-commons-compress
- apache-commons-lang3
- apache-http
- jdk/java.net
- okhttp
- rabbitmq
- retrofit
- spring/controller
- pathsanitizer
- qlengine
- query-tests
- RangeAnalysis
- security
- CWE-022/semmle/tests
- mad
- CWE-023/semmle/tests
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- mad
- CWE-117
- CWE-266
- CWE-295/InsecureTrustManager
- CWE-441
- CWE-470
- CWE-489
- debuggable-attribute
- Testbuild
- webview-debugging
- CWE-524/res/layout
- CWE-532
- CWE-780
- CWE-798/semmle/tests
- CWE-918
- mad
- CWE-926
- incomplete_provider_permissions
- CWE-927
- stubs
- apache-commons-compress/org/apache/commons/compress/archivers
- tar
- zip
- apache-hive
- com/google/protobuf
- javax
- crypto
- jdo
- annotations
- datastore
- listener
- metadata
- query
- net
- security
- auth
- callback
- sasl
- transaction
- ws/rs/core
- org
- apache
- commons/logging
- hadoop
- conf
- fs
- permission
- hive
- metastore
- api
- columnstats/aggr
- model
- partition/spec
- security
- utils
- ql/io/sarg
- io
- retry
- ipc
- metrics
- protobuf
- metrics2
- lib
- util
- security
- authorize
- proto
- token
- delegation
- util
- concurrent
- hive/hcatalog/templeton
- tool
- htrace
- core
- shaded/fasterxml/jackson
- annotation
- core
- format
- io
- sym
- type
- util
- databind
- annotation
- cfg
- deser
- impl
- introspect
- jsonFormatVisitors
- jsonschema
- jsontype
- node
- ser
- impl
- std
- type
- util
- thrift
- meta_data
- protocol
- scheme
- transport
- datanucleus/enhancement
- slf4j
- event
- spi
- apache-http-4.4.13/org/apache/http
- client/utils
- util
- cargo/org/codehaus/cargo
- container/installer
- util
- log
- javafx-web
- com
- sun/javafx/tk
- zaxxer/hikari
- metrics
- io/micrometer/observation
- jakarta/ws/rs
- client
- core
- javafx
- animation
- beans
- binding
- property
- value
- collections
- transformation
- concurrent
- css
- event
- geometry
- print
- scene
- effect
- image
- input
- paint
- text
- transform
- web
- stage
- util
- javax
- net
- ssl
- security/cert
- servlet
- annotation
- descriptor
- http
- sql
- ws/rs
- client
- core
- org
- apache
- commons/logging
- http
- client
- config
- methods
- concurrent
- conn
- routing
- message
- params
- protocol
- codehaus/cargo
- container/installer
- util
- log
- jdbi/v3/core
- argument
- internal
- array
- codec
- collector
- config
- extension
- generic
- mapper
- qualifier
- result
- spi
- statement
- internal
- transaction
- postgresql
- util
- reactivestreams
- springframework
- boot/jdbc
- core
- codec
- io
- buffer
- support
- http
- client
- reactive
- support
- codec
- converter
- server
- reactive
- jdbc/datasource
- util
- web
- client
- reactive/function
- client
- util
- w3c/dom
- reactor
- core
- observability
- publisher
- scheduler
- util
- context
- function
- retry
- mssql-jdbc-12.2.0
- com/microsoft/sqlserver/jdbc
- javax
- crypto
- spec
- naming
- security/auth
- sql
- org/ietf/jgss
- springframework-5.3.8/org/springframework/boot/jdbc
- utils/modelgenerator/dataflow
- misc
- bazel
- codegen
- generators
- lib
- loaders
- templates
- test
- scripts
- suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- concepts
- internal
- dataflow/new
- internal
- tainttracking1
- frameworks
- internal
- objects
- pointsto
- security/dataflow
- types
- xml
- src
- Security
- CWE-020-ExternalAPIs
- CWE-022/examples
- CWE-327
- change-notes/released
- experimental
- Security
- CWE-022bis
- examples
- CWE-348
- semmle/python/security
- meta/analysis-quality
- test
- 2
- library-tests/six
- query-tests/Imports/syntax_error
- experimental
- dataflow
- TestUtil
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage
- enclosing-callable
- exceptions
- fieldflow
- global-flow
- match
- pep_328
- regression
- strange-essaflow
- strange-pointsto-interaction-investigation
- src
- test-1-normal
- test-2-without-splitting
- test-3-max-import-depth-0
- test-4-max-import-depth-100
- test-5-max-import-depth-3
- test-6-max-import-depth-2
- summaries
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking
- variable-capture
- import-resolution
- package/subpackage2
- library-tests
- CallGraph-implicit-init
- CallGraph-imports
- pkg
- CallGraph
- code
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
3,747 files changed
+278371
-216931
lines changedLines changed: 21 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + |
Lines changed: 103 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 |
| - | |
| 12 | + | |
13 | 13 |
| |
14 | 14 |
| |
15 | 15 |
| |
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
31 | 33 |
| |
32 | 34 |
| |
33 | 35 |
| |
| |||
37 | 39 |
| |
38 | 40 |
| |
39 | 41 |
| |
40 |
| - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
41 | 45 |
| |
42 | 46 |
| |
43 | 47 |
| |
44 | 48 |
| |
45 |
| - | |
46 |
| - | |
| 49 | + | |
| 50 | + | |
47 | 51 |
| |
48 | 52 |
| |
49 |
| - | |
50 |
| - | |
51 |
| - | |
52 | 53 |
| |
53 | 54 |
| |
54 | 55 |
| |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + |
Lines changed: 0 additions & 75 deletions
This file was deleted.
Lines changed: 0 additions & 26 deletions
This file was deleted.
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
30 | 29 |
| |
31 |
| - | |
| 30 | + | |
32 | 31 |
| |
33 | 32 |
| |
34 | 33 |
| |
|
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
27 |
| - | |
| 27 | + | |
28 | 28 |
| |
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
| |
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
37 |
| - | |
| 37 | + |
Lines changed: 4 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| |||
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
50 |
| - | |
| 50 | + | |
51 | 51 |
| |
52 | 52 |
| |
53 |
| - | |
| 53 | + | |
54 | 54 |
| |
55 | 55 |
| |
56 | 56 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
24 | 24 |
| |
25 | 25 |
| |
26 |
| - | |
| 26 | + | |
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
|
0 commit comments