File tree
3,650 files changed
+438202
-143428
lines changed- .github/workflows
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- downgrades
- 298438feb146335af824002589cd6d4e96e5dbf9
- 4f9fabab5124d49108782c081579f45a70571d74
- 7f34caf73ca98314885030cc5a22b6e328fe687c
- cf72c8898d19eb1b3374432cf79d8276cb07ad43
- d8149ca90e695fe26f9a0c5a7fa0edd6d4ea3f5d
- ql
- lib
- change-notes
- released
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- exprs
- headers
- internal
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- models
- implementations
- interfaces
- rangeanalysis
- new/internal/semantic/analysis
- security/flowafterfree
- stmts
- upgrades
- 098850d25c4e9d417eb74c1bef9deb2f9d2dc417
- 4f9fabab5124d49108782c081579f45a70571d74
- 7f34caf73ca98314885030cc5a22b6e328fe687c
- d8149ca90e695fe26f9a0c5a7fa0edd6d4ea3f5d
- fc81eb5a3a7cdde8d9ad813da1e8f1e90dadbb91
- src
- Critical
- Diagnostics
- Likely Bugs
- Format
- Memory Management
- Microsoft
- Security/CWE
- CWE-120
- CWE-416
- CWE-497
- CWE-704
- change-notes
- released
- experimental/Security/CWE/CWE-1240
- jsf
- 4.06 Pre-Processing Directives
- 4.10 Classes
- 4.16 Initialization
- test
- experimental/query-tests/Security/CWE
- CWE-078
- CWE-1240
- library
- CWE-190/AllocMultiplicationOverflow
- CWE-193
- array-access
- constant-size
- CWE-359/semmle/tests
- header-variant-tests/clang-pch
- library-tests
- arguments
- builtins/functions_file
- c++_exceptions
- dataflow
- asExpr
- dataflow-tests
- fields
- destructors
- headers/preprocBlock
- ir/ir
- literals/uuidof
- special_members/generated_copy
- string_concat
- syntax-zoo
- query-tests
- Critical
- MemoryFreed
- MissingCheckScanf
- Diagnostics
- Likely Bugs
- Conversion/CastArrayPointerArithmetic
- Format/NonConstantFormat
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-119
- SAMATE
- semmle/tests
- CWE-120/semmle/tests
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- consts
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- TaintedAllocationSize
- tainted
- CWE-193
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests
- UseAfterFree
- UseOfStringAfterLifetimeEnds
- UseOfUniquePtrAfterLifetimeEnds
- CWE-457/semmle/tests
- CWE-497
- SAMATE
- semmle/tests
- CWE-611
- CWE-704
- CWE-807/semmle/TaintedCondition
- jsf/4.06 Pre-Processing Directives/AV Rule 32
- successor-tests
- forstmt/rangebasedforstmt
- stackvariables/stackvariables
- staticlocals/no_dynamic_init
- csharp
- actions/create-extractor-pack
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- downgrades
- c9ee11bd1ee96e925a35cedff000be924634447f
- f145a9a7275c8f457b392b2ebc9f8e07960a0ed2
- f595d31422d7d462d2bee8c69b44341df8bdadb6
- fc9c7ab844ab055b97222a97e895b4bf2e1f8f4e
- extractor
- Semmle.Extraction.CIL.Driver
- Semmle.Extraction.CIL
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.DependencyStubGenerator
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp.Util
- Semmle.Extraction.CSharp
- Entities
- Compilations
- Expressions
- Collections
- PreprocessorDirectives
- Statements
- Types
- Extractor
- Kinds
- Semmle.Extraction.Tests
- Semmle.Extraction
- Extractor
- Semmle.Util.Tests
- Semmle.Util
- Logging
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms
- autobuild
- cshtml_standalone_disabled
- Views/Home
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- Views/Home
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- standalone_dependencies_net48
- standalone
- linux-only
- compiler_args
- standalone_dependencies_non_utf8_filename
- posix-only
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget_config_error
- proj
- standalone_dependencies_nuget_no_sources
- proj
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows-only/standalone_dependencies
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- generated
- semmle/code
- asp
- cil
- internal
- csharp
- commons
- controlflow
- internal
- dataflow
- internal
- exprs
- frameworks
- microsoft
- system/runtime
- security
- cryptography
- dataflow
- flowsources
- dotnet
- upgrades
- 1f291d4f424b498e7500c0359ca1fe030628a448
- 6b8962d52bd5ed58edb163f78467074fd7e1a127
- 90fdbc8f87761f223ef7723e4b421c5b26ecc15e
- f145a9a7275c8f457b392b2ebc9f8e07960a0ed2
- f595d31422d7d462d2bee8c69b44341df8bdadb6
- f93793ee5f6b7bec615eaa1af0a1a4dea19472bb
- fc9c7ab844ab055b97222a97e895b4bf2e1f8f4e
- src
- Diagnostics
- Security Features
- CWE-022
- examples
- CWE-079
- CWE-601
- examples
- Telemetry
- change-notes
- released
- experimental
- Security Features/backdoor
- ir/implementation
- internal
- raw
- internal
- unaliased_ssa
- internal
- utils
- modeleditor
- modelgenerator
- internal
- test
- experimental
- CWE-918
- Security Features
- CWE-1004
- CookieHttpOnlyFalseSystemWeb
- CookieWithoutHttpOnlySystemWeb
- ConfigEmpty
- ConfigFalse
- HttpCookiesTrue
- CWE-614
- RequireSSLFalseSystemWeb
- RequireSSLSystemWeb
- ConfigEmpty
- ConfigFalse
- FormsTrue
- HttpCookiesTrue
- CWE-759
- backdoor
- library-tests
- arguments
- asp/basic
- assemblies
- cil
- attributes
- consistency
- dataflow
- enums
- functionPointers
- init-only-prop
- typeAnnotations
- collections
- constructors
- controlflow/guards
- conversion
- boxing
- operator
- csharp7
- csharp9
- dataflow
- async
- call-sensitivity
- collections
- constructors
- delegates
- external-models
- fields
- flowsources/remote
- global
- library
- operators
- ssa
- threat-models
- tuples
- typeflow-dispatch
- types
- delegates
- diagnostics
- expressions
- frameworks
- Aws
- EntityFramework
- NHibernate
- ServiceStack
- sql
- system/data/entity
- parameters
- security/dataflow/flowsources
- standalone/errorrecovery
- typealias
- types
- query-tests
- API Abuse
- DisposeNotCalledOnException
- FormatInvalid
- Likely Bugs/UnsafeYearConstruction
- Nullness
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSSRazorPages
- Generated
- XSS
- XssPageModels
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsecureSQLConnection
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- CWE-838
- Telemetry
- LibraryUsage
- SupportedExternalApis
- SupportedExternalSinks
- SupportedExternalSources
- resources/stubs
- Amazon.Lambda.APIGatewayEvents/2.7.0
- Amazon.Lambda.Core/2.2.0
- Antlr3.Runtime/3.5.1
- Dapper/2.1.24
- EntityFramework/6.4.4
- Iesi.Collections/4.0.4
- Microsoft.CSharp/4.7.0
- Microsoft.Extensions.DependencyInjection.Abstractions/6.0.0
- Microsoft.Extensions.DependencyInjection/6.0.0
- Microsoft.Extensions.Http/6.0.0
- Microsoft.Extensions.Logging.Abstractions/6.0.0
- Microsoft.Extensions.Logging/6.0.0
- Microsoft.Extensions.Options/6.0.0
- Microsoft.Extensions.Primitives/6.0.0
- Microsoft.NETCore.Platforms
- 1.1.0
- 3.1.0
- 5.0.0
- Microsoft.NETCore.Targets/1.1.0
- Microsoft.Win32.Primitives/4.3.0
- Microsoft.Win32.Registry/4.7.0
- Microsoft.Win32.SystemEvents
- 5.0.0
- 6.0.0
- NETStandard.Library/1.6.1
- NHibernate/5.4.7
- Newtonsoft.Json/13.0.3
- Remotion.Linq.EagerFetching/2.2.0
- Remotion.Linq/2.2.0
- ServiceStack.Client
- 6.2.0
- 8.0.0
- ServiceStack.Common
- 6.2.0
- 8.0.0
- ServiceStack.Interfaces
- 6.2.0
- 8.0.0
- ServiceStack.OrmLite.SqlServer
- 6.2.0
- 8.0.0
- ServiceStack.OrmLite
- 6.2.0
- 8.0.0
- ServiceStack.Text
- 6.2.0
- 8.0.0
- ServiceStack
- 6.2.0
- 8.0.0
- Stub.System.Data.SQLite.Core.NetStandard
- 1.0.116
- 1.0.118
- System.AppContext/4.3.0
- System.Buffers/4.3.0
- System.CodeDom/4.7.0
- System.Collections.Concurrent/4.3.0
- System.Collections.NonGeneric/4.3.0
- System.Collections/4.3.0
- System.ComponentModel.Annotations/5.0.0
- System.ComponentModel.Primitives/4.3.0
- System.ComponentModel/4.3.0
- System.Configuration.ConfigurationManager
- 6.0.0
- 8.0.0
- System.Console/4.3.0
- System.Data.OleDb/8.0.0
- System.Data.SQLite.Core/1.0.118
- System.Data.SQLite.EF6
- 1.0.116
- 1.0.118
- System.Data.SQLite/1.0.118
- System.Data.SqlClient
- 4.8.3
- 4.8.5
- System.Diagnostics.Debug/4.3.0
- System.Diagnostics.DiagnosticSource/6.0.0
- System.Diagnostics.EventLog/8.0.0
- System.Diagnostics.PerformanceCounter/8.0.0
- System.Diagnostics.Tools/4.3.0
- System.Diagnostics.Tracing/4.3.0
- System.Drawing.Common
- 5.0.2
- 6.0.0
- System.Dynamic.Runtime/4.3.0
- System.Globalization.Calendars/4.3.0
- System.Globalization.Extensions/4.3.0
- System.Globalization/4.3.0
- System.IO.Compression.ZipFile/4.3.0
- System.IO.Compression/4.3.0
- System.IO.FileSystem.Primitives/4.3.0
- System.IO.FileSystem/4.3.0
- System.IO/4.3.0
- System.Linq.Expressions/4.3.0
- System.Linq.Queryable/4.0.1
- System.Linq/4.3.0
- System.Memory/4.5.5
- System.Net.Http/4.3.0
- System.Net.Primitives/4.3.0
- System.Net.Sockets/4.3.0
- System.ObjectModel/4.3.0
- System.Reflection.Emit.ILGeneration/4.3.0
- System.Reflection.Emit.Lightweight/4.7.0
- System.Reflection.Emit/4.7.0
- System.Reflection.Extensions/4.3.0
- System.Reflection.Primitives/4.3.0
- System.Reflection.TypeExtensions/4.7.0
- System.Reflection/4.3.0
- System.Resources.ResourceManager/4.3.0
- System.Runtime.CompilerServices.Unsafe/6.0.0
- System.Runtime.Extensions/4.3.0
- System.Runtime.Handles/4.3.0
- System.Runtime.InteropServices.RuntimeInformation/4.3.0
- System.Runtime.InteropServices/4.3.0
- System.Runtime.Numerics/4.3.0
- System.Runtime.Serialization.Formatters/4.3.0
- System.Runtime.Serialization.Primitives/4.3.0
- System.Runtime/4.3.0
- System.Security.AccessControl
- 4.7.0
- 6.0.0
- System.Security.Cryptography.Algorithms/4.3.0
- System.Security.Cryptography.Cng/4.3.0
- System.Security.Cryptography.Csp/4.3.0
- System.Security.Cryptography.Encoding/4.3.0
- System.Security.Cryptography.OpenSsl/4.3.0
- System.Security.Cryptography.Primitives/4.3.0
- System.Security.Cryptography.ProtectedData
- 6.0.0
- 8.0.0
- System.Security.Cryptography.X509Certificates/4.3.0
- System.Security.Permissions/6.0.0
- System.Security.Principal.Windows/4.7.0
- System.Text.Encoding.Extensions/4.3.0
- System.Text.Encoding/4.3.0
- System.Text.RegularExpressions/4.3.0
- System.Threading.Tasks.Extensions/4.3.0
- System.Threading.Tasks/4.3.0
- System.Threading.Timer/4.3.0
- System.Threading/4.3.0
- System.Windows.Extensions/6.0.0
- System.Xml.ReaderWriter/4.3.0
- System.Xml.XDocument/4.3.0
- System.Xml.XmlDocument/4.3.0
- _frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- runtime.debian.8-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.fedora.23-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.fedora.24-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.native.System.Data.SqlClient.sni/4.7.0
- runtime.native.System.IO.Compression/4.3.0
- runtime.native.System.Net.Http/4.3.0
- runtime.native.System.Security.Cryptography.Apple/4.3.0
- runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.native.System/4.3.0
- runtime.opensuse.13.2-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.Apple/4.3.0
- runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.14.04-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.16.04-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.16.10-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.win-arm64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x86.runtime.native.System.Data.SqlClient.sni/4.4.0
- utils
- modeleditor
- modelgenerator
- dataflow
- typebasedflow
- scripts
- stubs
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-overview
- codeql-changelog
- ql-language-reference
- reusables
- writing-codeql-queries
- ql-libraries/dataflow
- go
- documentation/library-coverage
- extractor
- autobuilder
- cli/go-autobuilder
- diagnostics
- project
- toolchain
- vendor
- golang.org/x/tools
- go
- packages
- types/objectpath
- internal
- event/keys
- gcimporter
- typeparams
- versions
- ql
- consistency-queries
- change-notes/released
- integration-tests/all-platforms/go
- bazel-sample-1
- src
- bazel-sample-2
- src
- diagnostics
- build-constraints-exclude-all-go-files
- go-files-found-not-processed
- newer-go-version-needed
- no-go-files-found
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- unsupported-relative-path
- go-get-without-modules-sample
- src
- go-mod-sample
- src
- make-sample
- src
- ninja-sample
- src
- single-go-mod-and-go-files-not-under-it
- src
- subdir
- subsubdir
- single-go-mod-in-root
- src
- subdir
- single-go-mod-not-in-root
- src/subdir
- subsubdir
- single-go-work-not-in-root
- src/modules
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-nested-none-in-root
- src/subdir0
- subdir1
- subsubdir1
- subdir2
- two-go-mods-nested-one-in-root
- src
- subdir1
- subsubdir1
- subdir2
- two-go-mods-not-nested
- src
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- lib
- change-notes
- released
- ext
- semmle/go
- concepts
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- Diagnostics
- Security
- CWE-347
- CWE-352
- CWE-798
- change-notes/released
- experimental
- CWE-321
- CWE-347
- test
- experimental
- CWE-090
- CWE-1004
- CWE-203
- CWE-287
- CWE-321-V2
- CWE-321
- CWE-347
- CWE-369
- CWE-74
- CWE-79
- CWE-918
- Unsafe
- library-tests/semmle/go
- Function
- dataflow
- ChannelField
- DefaultTaintSanitizer
- FlowSteps
- HiddenNodes
- frameworks
- AwsLambda
- vendor
- github.com/aws/aws-lambda-go/lambda
- BeegoOrm
- Beego
- Chi
- Echo
- Encoding
- Fasthttp
- vendor
- github.com/valyala/fasthttp
- Gin
- GoMicro
- Gorestful
- Revel
- TaintSteps
- Twirp
- XNetHtml
- query-tests
- Diagnostics
- InconsistentCode/UnhandledCloseWritableHandle
- Security
- CWE-020/IncompleteHostnameRegexp
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- CWE-209
- CWE-312
- CWE-322
- CWE-326
- CWE-327
- CWE-338/InsecureRandomness
- CWE-347
- vendor
- github.com
- go-jose/go-jose/v3/jwt
- golang-jwt/jwt/v5
- CWE-352
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- vendor
- github.com/lestrrat-go/libxml2/parser
- CWE-681
- CWE-798
- vendor
- github.com
- appleboy/gin-jwt/v2
- cristalhq/jwt/v3
- gin-gonic/gin
- go-kit/kit/auth/jwt
- gogf/gf-jwt/v2
- golang-jwt/jwt/v4
- iris-contrib/middleware/jwt
- kataras
- iris/v12/middleware/jwt
- jwt
- lestrrat/go-jwx/jwk
- square/go-jose/v3
- gopkg.in/square/go-jose.v2
- CWE-918
- javascript
- extractor
- lib/typescript/src
- src/com/semmle/js/extractor
- test/com/semmle/js/extractor/test
- ql
- integration-tests/all-platforms/no-types
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- endpoints
- frameworks
- data/internal
- security
- dataflow
- internal
- regexp
- src
- Diagnostics
- Expressions
- LanguageFeatures
- change-notes
- released
- test
- library-tests
- DataFlow
- EndpointNaming
- pack10
- pack1
- pack2
- pack3
- pack4
- pack5
- src
- pack6
- pack7
- pack8
- pack9
- TaintTracking
- frameworks
- Templating
- views
- data
- query-tests
- Diagnostics
- LanguageFeatures/SpuriousArguments
- Security
- CWE-020/SuspiciousRegexpRange
- CWE-079/DomBasedXss
- Statements/UselessConditional
- testUtilities
- internal
- java
- documentation/library-coverage
- integration-tests-lib
- kotlin-extractor
- src/main/kotlin
- comments
- utils
- versions
- v_1_5_0
- v_1_5_20
- v_1_6_0
- v_1_6_20
- v_1_7_0
- v_1_7_20
- v_1_8_0
- v_1_9_0-Beta
- v_2_0_0-Beta3
- v_2_0_255-SNAPSHOT
- ql
- automodel
- src
- change-notes/released
- test
- AutomodelApplicationModeExtraction
- AutomodelFrameworkModeExtraction
- com/github/codeql/test
- java
- io
- nio/file
- integration-tests/all-platforms
- java
- buildless-dependency-different-repository
- repo2/releases/com/github/hosted/in/other/repo/test/inotherrepo/1.0
- repo/releases/com/github/my/other/repo/test/otherreleasetest/1.0
- src/main/java
- buildless-gradle
- gradle/wrapper
- src/main/java/com/fractestexample
- buildless-maven-multimodule
- submod1
- src
- main
- java/com/example
- resources
- test/java/com/example
- submod2
- src
- main
- java/com/example
- resources
- test/java/com/example
- buildless-maven
- buildless-sibling-projects
- gradle-sample2
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- gradle-sample
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- maven-project-1
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-project-2
- src
- main
- java/com/example
- resources
- test/java/com/example
- buildless-snapshot-repository
- buildless
- maven-sample
- kotlin
- kotlin_java_static_fields
- path_transformer
- lib
- change-notes
- released
- ext
- semmle/code
- java
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- camel
- gwt
- j2objc
- javaee/ejb
- regex
- security
- regexp
- xml
- src
- Metrics/Summaries
- Security/CWE
- CWE-022
- examples
- CWE-074
- CWE-078
- CWE-113
- CWE-200
- CWE-287
- CWE-327
- CWE-330
- examples
- Telemetry
- change-notes/released
- experimental/Security/CWE
- CWE-020
- CWE-073
- CWE-078
- CWE-089
- CWE-1004
- CWE-348
- CWE-470
- CWE-552
- utils
- modeleditor
- modelgenerator/internal
- test-kotlin2
- library-tests
- arrays
- comments
- controlflow
- basic
- dominance
- data-classes
- dataflow
- foreach
- func
- exprs
- java-kotlin-collection-type-generic-methods
- methods
- operator-overloads
- parameter-defaults
- stmts
- query-tests/UnderscoreIdentifier
- test
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- NotConstantTimeCheckOnSignature
- TimingAttackAgainstSignagure
- CWE-299
- CWE-327
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-502
- CWE-552
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- ext/TopJdkApis
- library-tests
- dataflow
- call-sensitivity
- external-models
- flowfeature
- inoutbarriers
- threat-models
- frameworks
- JaxWs
- android/notification
- neutrals/neutralsinks
- pathcreation
- pathsanitizer
- regex/parser
- query-tests
- Telemetry/SupportedExternalSinks
- security
- CWE-022/semmle/tests
- mad
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests
- SensitiveNotification
- SensitiveTextView
- res/layout
- TempDirLocalInformationDisclosure
- WebViewAccess
- CWE-287
- CWE-295/AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- Test5
- CWE-297
- CWE-311/CWE-319
- CWE-327/semmle/tests
- CWE-330
- CWE-601/semmle/tests
- CWE-681/semmle/tests
- CWE-807/semmle/tests
- stubs
- esapi-2.0.1/org/owasp/esapi
- reference
- google-android-9.0.0
- androidx
- biometric
- core
- app
- content
- pm
- android
- app
- content/pm
- hardware
- biometrics
- fingerprint
- os
- security/identity
- util
- widget
- netty-4.1.x/io/netty/handler/codec/http
- utils
- modeleditor
- modelgenerator/dataflow
- p
- misc
- bazel
- cmake
- scripts/models-as-data
- suite-helpers
- change-notes/released
- python
- downgrades
- 503c0516fba2e5da9570f00eb34ef43025ecb8fb
- ql
- consistency-queries
- lib
- change-notes
- released
- experimental/cryptography/utils
- semmle/python
- dataflow/new
- internal
- essa
- frameworks
- Stdlib
- data/internal
- subclass-capture
- internal
- internal
- objects
- pointsto
- regexp/internal
- security
- dataflow
- internal
- regexp
- xml
- src
- Diagnostics
- Security/CWE-601
- examples
- change-notes/released
- experimental
- Security
- CWE-176
- CWE-409
- semmle/python
- frameworks
- security
- meta
- ClassHierarchy
- alerts
- analysis-quality
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
3,650 files changed
+438202
-143428
lines changedLines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
71 | 71 |
| |
72 | 72 |
| |
73 | 73 |
| |
| 74 | + | |
| 75 | + | |
| 76 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
3 | 6 |
| |
4 | 7 |
| |
5 | 8 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
| 12 | + | |
| 13 | + | |
| 14 | + | |
12 | 15 |
| |
13 | 16 |
| |
14 | 17 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| 13 | + | |
| 14 | + | |
| 15 | + | |
13 | 16 |
| |
14 | 17 |
| |
15 | 18 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
| 14 | + | |
| 15 | + | |
| 16 | + | |
14 | 17 |
| |
15 | 18 |
| |
16 | 19 |
| |
|
Lines changed: 4 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
| 9 | + | |
| 10 | + | |
8 | 11 |
| |
9 | 12 |
| |
10 | 13 |
| |
11 | 14 |
| |
12 | 15 |
| |
13 | 16 |
| |
14 | 17 |
| |
15 |
| - | |
| 18 | + | |
16 | 19 |
| |
17 | 20 |
| |
18 | 21 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
33 |
| - | |
| 33 | + | |
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
| 11 | + | |
| 12 | + | |
| 13 | + | |
11 | 14 |
| |
12 | 15 |
| |
| 16 | + | |
13 | 17 |
| |
14 | 18 |
| |
15 | 19 |
| |
|
Lines changed: 9 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
| 28 | + | |
| 29 | + | |
| 30 | + | |
28 | 31 |
| |
29 | 32 |
| |
30 | 33 |
| |
| |||
46 | 49 |
| |
47 | 50 |
| |
48 | 51 |
| |
| 52 | + | |
49 | 53 |
| |
50 | 54 |
| |
51 | 55 |
| |
| |||
74 | 78 |
| |
75 | 79 |
| |
76 | 80 |
| |
77 |
| - | |
| 81 | + | |
78 | 82 |
| |
79 | 83 |
| |
80 |
| - | |
81 |
| - | |
82 |
| - | |
83 |
| - | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
84 | 88 |
| |
85 | 89 |
| |
86 | 90 |
| |
|
0 commit comments