File tree
1,309 files changed
+75504
-6493
lines changed- .github
- workflows
- config
- cpp
- autobuilder/Semmle.Autobuild.Cpp
- change-notes
- old-change-notes
- ql
- lib
- change-notes/released
- experimental/semmle/code/cpp
- models/interfaces
- rangeanalysis
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa/internal
- unaliased_ssa/internal
- security
- src
- Likely Bugs
- Arithmetic
- Format
- Security/CWE
- CWE-120
- CWE-311
- CWE-319
- change-notes
- released
- experimental/Security/CWE/CWE-266
- test
- experimental/query-tests/Security/CWE/CWE-266/semmle/tests
- query-tests
- Likely Bugs/Arithmetic/BadAdditionOverflowCheck
- Security/CWE
- CWE-190/semmle/tainted
- CWE-311/semmle/tests
- upgrades
- change-notes/released
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CIL
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Types
- Extractor
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util.Tests
- old-change-notes
- ql
- consistency-queries
- lib
- change-notes/released
- semmle/code
- cil
- csharp
- commons
- controlflow
- internal
- dataflow
- internal
- dispatch
- exprs
- frameworks
- microsoft
- system
- collections
- componentmodel
- data
- io
- net
- runtime
- security
- cryptography
- text
- threading
- web/ui
- xml
- internal
- security/dataflow
- dotnet
- src
- Language Abuse
- change-notes/released
- experimental/ir
- implementation/unaliased_ssa/internal
- internal
- test
- library-tests
- assemblies
- cil/consistency
- controlflow/graph
- csharp8
- csharp9
- global
- dataflow
- global
- library
- tuples
- expressions
- frameworks
- EntityFramework
- JsonNET
- test
- nestedtypes
- overrides
- standalone
- controlflow
- errorrecovery
- query-tests/Stubs/References
- resources/stubs
- upgrades
- change-notes/released
- docs/codeql
- codeql-cli
- support/reusables
- javascript
- change-notes
- extractor
- lib/typescript
- src/com/semmle
- jcorn
- js
- ast
- extractor
- ts/extractor
- tests
- generatedcode/output/trap
- shebang/output/trap
- old-change-notes
- ql
- examples/snippets
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- src
- lib
- change-notes/released
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- meta
- security
- dataflow
- internal
- src
- Security
- CWE-116
- CWE-352
- CWE-770
- change-notes
- released
- experimental
- Security/CWE-020
- semmle/javascript
- test
- library-tests
- Classes
- Routing
- routes
- TaintTracking
- TypeInference
- CallWithAnalyzedReturnFlow
- LocalFunction
- TypeScript
- HasUnderlyingType
- ImportOwnPackage
- bar
- foo
- QualifiedNameResolution
- RegressionTests/ImportSelf
- Types
- frameworks
- Express
- src
- Templating
- projectA
- src
- views
- projectB
- src
- views
- views
- query-tests
- Expressions/SuspiciousInvocation
- LanguageFeatures/SyntaxError
- Security
- CWE-022/TaintedPath
- CWE-073
- CWE-079/DomBasedXss
- CWE-089/untyped
- CWE-352
- CWE-770
- upgrades
- 8320e9d13aad4f77a4348e744b55024e785bfcdf
- change-notes/released
- java
- change-notes
- documentation/library-coverage
- old-change-notes
- ql
- lib
- change-notes
- released
- semmle/code/java
- dataflow
- internal
- frameworks
- android
- src
- change-notes/released
- experimental/Security/CWE
- CWE-020
- CWE-089
- semmle/code/xml
- utils/flowtestcasegenerator
- test
- experimental/query-tests/security
- CWE-020
- CWE-089/src/main
- library-tests
- dataflow/entrypoint-types
- frameworks/android/notification
- stubs
- apache-log4j-2.14.1
- javax/servlet
- annotation
- descriptor
- http
- org/apache/logging/log4j
- message
- spi
- util
- google-android-9.0.0/android
- app
- content/pm
- graphics
- drawable
- media
- org.mybatis-3.5.4/org/apache/ibatis/annotations
- springframework-5.3.8/org/springframework
- stereotype
- web/bind/annotation
- upgrades
- change-notes/released
- misc/suite-helpers
- python
- change-notes
- old-change-notes
- ql
- lib
- change-notes/released
- semmle/python
- concepts
- internal
- dataflow/new/internal
- essa
- frameworks
- objects
- pointsto
- security
- dataflow
- src
- Security
- CWE-116
- CWE-327
- CWE-918
- examples
- change-notes
- released
- test
- experimental
- dataflow
- global-flow
- import-star
- meta
- library-tests
- PointsTo/new
- frameworks
- requests
- stdlib
- query-tests/Security/CWE-918-ServerSideRequestForgery
- upgrades
- change-notes/released
- ql
- .vscode
- autobuilder
- src
- extractor
- src
- generator
- src
- node-types
- src
- ql
- consistency-queries
- docs
- examples
- src
- codeql-suites
- codeql_ql
- ast
- internal
- performance
- style
- docs
- codeql
- files
- experimental
- ide-contextual-queries
- queries
- diagnostics
- metrics
- performance
- style
- docs
- summary
- test
- callgraph
- packs
- lib
- LibThing
- src
- printAst
- queries
- performance/VarUnusedInDisjunct
- style
- ImplicitThis
- MissingOverride
- SwappedParameterNames
- UseSetLiteral
- type
- scripts
- tools
- ruby
- change-notes
- extractor
- generator
- old-change-notes
- ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- frameworks
- security
- internal
- typetracking
- src
- change-notes/released
- experimental/cwe-807
- examples
- queries
- analysis
- security/cwe-116
- test
- library-tests
- ast
- CONSISTENCY
- constants
- control
- CONSISTENCY
- params
- controlflow/graph
- dataflow
- array-flow
- local
- params
- summaries
- frameworks
- app/controllers/foo
- modules
- security
- variables
- query-tests/security
- cwe-022
- cwe-078
- cwe-079
- cwe-089
- cwe-094
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-502
- oj-global-options
- unsafe-deserialization
- cwe-601
- cwe-611
- cwe-798
- cwe-807-user-controlled-bypass
- cwe-918
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,309 files changed
+75504
-6493
lines changedLines changed: 12 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| 13 | + | |
13 | 14 |
| |
14 |
| - | |
15 |
| - | |
16 |
| - | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
| 29 | + | |
| 30 | + | |
| 31 | + |
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
| 10 | + | |
10 | 11 |
| |
11 | 12 |
| |
12 | 13 |
| |
|
Lines changed: 192 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + |
Lines changed: 84 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + |
Lines changed: 52 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
| 28 | + | |
| 29 | + | |
| 30 | + |
Lines changed: 8 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
452 | 452 |
| |
453 | 453 |
| |
454 | 454 |
| |
455 |
| - | |
| 455 | + | |
456 | 456 |
| |
457 |
| - | |
| 457 | + | |
| 458 | + | |
| 459 | + | |
| 460 | + | |
| 461 | + | |
| 462 | + | |
| 463 | + | |
458 | 464 |
| |
459 | 465 |
| |
460 | 466 |
| |
|
0 commit comments