File tree
404 files changed
+9222
-4692
lines changed- .github/workflows
- cpp/ql
- lib
- experimental/semmle/code/cpp/dataflow
- semmle/code/cpp/models
- implementations
- interfaces
- src/experimental
- Likely Bugs
- Security/CWE/CWE-193
- test
- experimental/query-tests/Security/CWE/CWE-119
- library-tests/ir/range-analysis
- csharp/ql
- campaigns/Solorigate
- src
- test/Solorigate
- consistency-queries
- lib/semmle/code/csharp/dataflow/internal
- src
- API Abuse
- CSI
- Concurrency
- Dead Code
- Language Abuse
- Linq
- Security Features
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-091
- CWE-094
- CWE-099
- CWE-112
- CWE-114
- CWE-117
- CWE-134
- CWE-201
- CWE-209
- CWE-312
- CWE-321
- CWE-327
- CWE-384
- CWE-611
- CWE-643
- CWE-730
- CWE-807
- change-notes
- experimental
- CWE-918
- Security Features/backdoor
- test
- experimental
- CWE-918
- Security Features/backdoor
- library-tests/dataflow
- global
- local
- query-tests
- API Abuse
- ClassDoesNotImplementEquals
- NoDisposeCallOnLocalIDisposable
- Concurrency/SynchSetUnsynchGet
- Dead Code
- NonAssignedFields
- Tests
- Language Abuse
- ForeachCapture
- UselessIsBeforeAs
- Nullness
- Security Features
- CWE-022/TaintedPath
- CWE-078
- CWE-079/StoredXSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-312
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsecureSQLConnection
- CWE-338
- CWE-384
- CWE-611
- CWE-643
- CWE-730/ReDoS
- CWE-807
- docs
- codeql
- codeql-overview
- support/reusables
- javascript/ql
- experimental/adaptivethreatmodeling/test/endpoint_large_scale
- lib/semmle/javascript
- frameworks/data/internal
- security
- dataflow
- src/Security
- CWE-079
- CWE-094
- test/query-tests/Security
- CWE-116
- BadTagFilter
- IncompleteSanitization
- CWE-798
- java
- kotlin-extractor/src/main
- java/com/semmle/extractor/java
- kotlin
- ql
- integration-tests/posix-only/kotlin/gradle_kotlinx_serialization
- src
- Advisory/Documentation
- Frameworks/Spring
- Architecture/Refactoring Opportunities
- Violations of Best Practice
- Language Abuse
- Likely Bugs
- Collections
- Comparison
- Concurrency
- Likely Typos
- Nullness
- Serialization
- Statements
- Performance
- Security/CWE
- CWE-022
- CWE-023
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-094
- CWE-113
- CWE-117
- CWE-129
- CWE-134
- CWE-190
- CWE-266
- CWE-295
- CWE-297
- CWE-312
- CWE-319
- CWE-347
- CWE-367
- CWE-470
- CWE-502
- CWE-522
- CWE-601
- CWE-611
- CWE-643
- CWE-681
- CWE-730
- CWE-732
- CWE-780
- CWE-807
- CWE-917
- CWE-918
- CWE-925
- CWE-927
- CWE-940
- Violations of Best Practice
- Dead Code
- Undesirable Calls
- change-notes
- experimental/Security/CWE
- CWE-020
- CWE-036
- CWE-078
- CWE-094
- CWE-1004
- CWE-297
- CWE-299
- CWE-327
- CWE-489
- CWE-502
- CWE-548
- CWE-600
- CWE-939
- utils/stub-generator
- test
- experimental/query-tests/security
- CWE-020
- CWE-078
- CWE-297
- CWE-299
- CWE-327
- CWE-502
- CWE-548
- CWE-600
- kotlin/library-tests
- data-classes
- exprs
- java-map-methods
- methods
- library-tests/frameworks/JaxWs
- query-tests
- ContradictoryTypeChecks
- InefficientOutputStream
- IteratorRemoveMayFail
- MissingInstanceofInEquals
- Nullness
- PartiallyMaskedCatch
- SelfAssignment
- Stubs
- Minimal
- testlib
- org/test
- UselessNullCheck
- WrongNanComparison
- security
- CWE-022/semmle/tests
- CWE-023/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-297
- CWE-311/CWE-319
- CWE-367/semmle/tests
- CWE-601/semmle/tests
- CWE-611
- CWE-681/semmle/tests
- CWE-732/semmle/tests
- CWE-807/semmle/tests
- python/ql
- lib
- change-notes
- semmle/python
- dataflow/new
- internal
- frameworks
- data/internal
- security
- src/experimental/semmle/python/frameworks
- test/query-tests/Security
- CWE-078-CommandInjection
- CWE-079-Jinja2WithoutEscaping
- CWE-116-BadTagFilter
- CWE-209-StackTraceExposure
- CWE-215-FlaskDebug
- CWE-327-InsecureProtocol
- CWE-601-UrlRedirect
- CWE-732-WeakFilePermissions
- ruby/ql
- lib
- change-notes
- codeql/ruby
- ast
- internal
- dataflow
- internal
- frameworks
- core
- data/internal
- security
- typetracking
- src/queries/analysis
- test
- library-tests
- dataflow
- api-graphs
- array-flow
- global
- summaries
- type-tracker
- frameworks
- action_view
- active_support
- app/controllers
- modules
- query-tests/security
- cwe-022
- cwe-079
- app/views/foo/bars
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-502/unsafe-deserialization
- swift/ql
- lib/codeql/swift
- dataflow
- frameworks/StandardLibrary
- src/queries/Security/ECB-Encryption
- test
- library-tests/dataflow/flowsources
- query-tests/Security/ECB-Encryption
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
404 files changed
+9222
-4692
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
|
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
7 |
| - | |
8 |
| - | |
| 7 | + | |
9 | 8 |
| |
10 | 9 |
| |
11 | 10 |
| |
|
Lines changed: 94 additions & 14 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
| 24 | + | |
24 | 25 |
| |
25 | 26 |
| |
26 | 27 |
| |
| |||
89 | 90 |
| |
90 | 91 |
| |
91 | 92 |
| |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
92 | 148 |
| |
93 | 149 |
| |
94 | 150 |
| |
| |||
103 | 159 |
| |
104 | 160 |
| |
105 | 161 |
| |
106 |
| - | |
| 162 | + | |
107 | 163 |
| |
108 | 164 |
| |
109 | 165 |
| |
110 |
| - | |
| 166 | + | |
111 | 167 |
| |
112 | 168 |
| |
113 | 169 |
| |
114 |
| - | |
| 170 | + | |
115 | 171 |
| |
116 | 172 |
| |
117 | 173 |
| |
118 | 174 |
| |
119 | 175 |
| |
120 | 176 |
| |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
121 | 188 |
| |
122 | 189 |
| |
123 | 190 |
| |
124 | 191 |
| |
125 | 192 |
| |
126 |
| - | |
127 |
| - | |
128 |
| - | |
129 |
| - | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
130 | 197 |
| |
131 | 198 |
| |
132 | 199 |
| |
133 |
| - | |
134 |
| - | |
135 |
| - | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
136 | 204 |
| |
137 | 205 |
| |
138 | 206 |
| |
139 |
| - | |
| 207 | + | |
140 | 208 |
| |
141 | 209 |
| |
142 | 210 |
| |
143 | 211 |
| |
144 | 212 |
| |
145 | 213 |
| |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
146 | 225 |
| |
147 | 226 |
| |
148 | 227 |
| |
| 228 | + | |
149 | 229 |
| |
150 | 230 |
| |
151 | 231 |
| |
152 | 232 |
| |
153 |
| - | |
| 233 | + | |
154 | 234 |
| |
155 | 235 |
| |
156 | 236 |
| |
| |||
213 | 293 |
| |
214 | 294 |
| |
215 | 295 |
| |
216 |
| - | |
| 296 | + | |
217 | 297 |
| |
218 | 298 |
| |
219 | 299 |
| |
|
0 commit comments