File tree
649 files changed
+26485
-6278
lines changed- .github
- actions/fetch-codeql
- workflows
- config
- cpp
- change-notes
- ql
- lib/semmle/code/cpp
- commons
- dataflow/internal
- ir
- dataflow
- internal
- implementation
- aliased_ssa
- raw
- unaliased_ssa
- models/implementations
- src
- Security/CWE
- CWE-313
- CWE-319
- experimental/Security/CWE
- CWE-243
- CWE-377
- test
- experimental/query-tests/Security/CWE
- CWE-243/semmle/tests
- CWE-377/semmle/tests
- CWE-675/semmle/tests
- library-tests
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- dataflow-tests
- fields
- security-taint
- smart-pointers-taint
- taint-tests
- ir/ir
- syntax-zoo
- types
- __wchar_t
- wchar_t_typedef
- variables/variables
- query-tests
- Likely Bugs/Conversion/CastArrayPointerArithmetic
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078/SAMATE/ExecTainted
- CWE-120/semmle/tests
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190/semmle
- ArithmeticUncontrolled
- TaintedAllocationSize
- tainted
- CWE-242/semmle/tests
- CWE-319/UseOfHttp
- CWE-807/semmle/TaintedCondition
- csharp
- ql
- consistency-queries
- lib
- Linq
- semmle/code
- cil/internal
- csharp
- controlflow
- internal
- pressa
- dataflow/internal
- basessa
- frameworks
- dotnet
- src
- Bad Practices/Implementation Hiding
- Linq
- Security Features/CWE-020
- experimental/ir
- implementation
- raw
- unaliased_ssa
- internal
- test
- experimental/ir/ir
- library-tests
- arguments
- assignments
- attributes
- comments
- constructors
- controlflow
- graph
- splits/CONSISTENCY
- conversion/operator
- csharp6
- csharp7.1
- csharp7.2
- csharp7.3
- csharp7
- csharp8
- csharp9
- dataflow
- async
- external-models
- global
- local
- tuples
- definitions
- delegates
- dynamic
- enums
- events
- exceptions
- expressions
- fields
- frameworks/EntityFramework
- generics
- goto
- indexers
- initializers
- linq
- members
- methods
- namespaces
- nestedtypes
- operators
- partial
- properties
- statements
- types
- unsafe
- tools/osx64
- docs
- codeql
- codeql-cli
- support/reusables
- writing-codeql-queries
- javascript
- change-notes
- extractor
- src/com/semmle/js/extractor
- tests
- es2015/output/trap
- exprs/output/trap
- jsx/output/trap
- regexp
- input
- output/trap
- ts/output/trap
- ql
- experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling
- lib
- semmle/javascript
- dataflow
- internal
- filters
- frameworks
- AngularJS
- internal
- security
- dataflow
- performance
- src
- Expressions
- Security
- CWE-116
- examples
- CWE-295
- CWE-312
- CWE-326
- CWE-346
- CWE-384
- examples
- CWE-598
- examples
- CWE-915
- experimental/Security/CWE-918
- test
- ApiGraphs/async-await
- experimental/Security/CWE-918
- library-tests
- RangeAnalysis
- StringConcatenation
- query-tests
- Performance/ReDoS
- lib
- Security
- CWE-020
- CWE-022/TaintedPath
- CWE-079
- DomBasedXss
- UnsafeJQueryPlugin
- CWE-116/BadTagFilter
- CWE-326
- CWE-384
- CWE-598
- CWE-915/PrototypePollutingAssignment
- upgrades/e54b35a8a129ebcf246cd4e834935f929b54aa04
- java
- change-notes
- documentation/library-coverage
- ql
- lib/semmle/code/java
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- apache
- javaee/ejb
- security
- src
- Likely Bugs
- Concurrency
- Inheritance
- Security/CWE/CWE-940
- Telemetry
- experimental/Security/CWE/CWE-598
- utils/model-generator
- test
- experimental/query-tests/security/CWE-200
- library-tests
- dataflow
- callback-dispatch
- taintsources
- taint
- frameworks
- android
- asynctask
- intent
- stream
- overrides
- query-tests
- Telemetry/ExternalLibraryUsage
- security
- CWE-297
- CWE-798/semmle/tests
- CWE-940
- stubs/google-android-9.0.0/android
- annotation
- app
- content
- os
- webkit
- utils/model-generator
- p
- python
- change-notes
- ql
- lib/semmle/python
- concepts
- dataflow/new/internal
- essa
- frameworks
- internal
- pointsto
- security
- performance
- src
- Security
- CWE-116
- examples
- CWE-295
- Statements
- experimental
- Security/CWE-347
- semmle/python
- frameworks
- libraries
- meta/alerts
- test
- experimental
- dataflow/tainttracking/defaultAdditionalTaintStep
- meta
- debug
- query-tests/Security/CWE-347
- library-tests/frameworks
- aiomysql
- aiopg
- flask_admin
- rest_framework
- testapp
- migrations
- testproj
- stdlib
- query-tests/Security
- CWE-022-PathInjection
- CWE-116-BadTagFilter
- CWE-295-RequestWithoutValidation
- CWE-730-ReDoS
- ruby
- change-notes
- generator/src
- ql
- consistency-queries
- lib/codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- frameworks
- http_clients
- security
- performance
- typetracking
- src
- ide-contextual-queries
- queries
- analysis
- security
- cwe-078
- cwe-116
- examples
- cwe-1333
- cwe-798
- cwe-918
- test
- library-tests
- controlflow/graph
- dataflow/type-tracker
- frameworks/http_clients
- regexp
- query-tests/security
- cwe-116
- cwe-601
- cwe-918
- scripts
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
649 files changed
+26485
-6278
lines changedLines changed: 16 additions & 11 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
4 |
| - | |
5 |
| - | |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
11 |
| - | |
12 |
| - | |
| 11 | + | |
| 12 | + | |
13 | 13 |
| |
14 | 14 |
|
Lines changed: 31 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + |
Lines changed: 38 additions & 14 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
3 | 6 |
| |
4 | 7 |
| |
5 | 8 |
| |
6 | 9 |
| |
7 |
| - | |
| 10 | + | |
8 | 11 |
| |
9 | 12 |
| |
10 | 13 |
| |
11 | 14 |
| |
12 | 15 |
| |
13 | 16 |
| |
14 | 17 |
| |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
15 | 24 |
| |
16 | 25 |
| |
17 | 26 |
| |
| 27 | + | |
| 28 | + | |
18 | 29 |
| |
19 | 30 |
| |
20 | 31 |
| |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
26 |
| - | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
27 | 35 |
| |
28 | 36 |
| |
29 |
| - | |
30 | 37 |
| |
31 |
| - | |
32 |
| - | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
33 | 44 |
| |
34 | 45 |
| |
35 |
| - | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
36 | 54 |
| |
37 |
| - | |
38 |
| - | |
39 |
| - | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + |
Lines changed: 6 additions & 14 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
6 |
| - | |
| 6 | + | |
| 7 | + | |
7 | 8 |
| |
8 | 9 |
| |
9 |
| - | |
| 10 | + | |
10 | 11 |
| |
11 | 12 |
| |
12 |
| - | |
| 13 | + | |
| 14 | + | |
13 | 15 |
| |
14 | 16 |
| |
15 |
| - | |
| 17 | + | |
16 | 18 |
| |
17 | 19 |
| |
18 | 20 |
| |
| |||
100 | 102 |
| |
101 | 103 |
| |
102 | 104 |
| |
103 |
| - | |
104 |
| - | |
105 |
| - | |
106 |
| - | |
107 |
| - | |
108 |
| - | |
109 |
| - | |
110 |
| - | |
111 |
| - | |
112 |
| - | |
113 | 105 |
| |
114 | 106 |
| |
115 | 107 |
| |
|
Lines changed: 4 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
7 |
| - | |
| 7 | + | |
8 | 8 |
| |
9 | 9 |
| |
| 10 | + | |
10 | 11 |
| |
11 | 12 |
| |
12 | 13 |
| |
13 |
| - | |
| 14 | + | |
14 | 15 |
| |
15 | 16 |
| |
| 17 | + | |
16 | 18 |
| |
17 | 19 |
| |
18 | 20 |
| |
|
Lines changed: 8 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
6 |
| - | |
| 6 | + | |
| 7 | + | |
7 | 8 |
| |
8 | 9 |
| |
9 |
| - | |
| 10 | + | |
10 | 11 |
| |
11 | 12 |
| |
12 |
| - | |
| 13 | + | |
| 14 | + | |
13 | 15 |
| |
14 | 16 |
| |
15 |
| - | |
| 17 | + | |
16 | 18 |
| |
17 | 19 |
| |
18 | 20 |
| |
| |||
30 | 32 |
| |
31 | 33 |
| |
32 | 34 |
| |
33 |
| - | |
| 35 | + | |
34 | 36 |
| |
35 | 37 |
| |
36 | 38 |
| |
| |||
44 | 46 |
| |
45 | 47 |
| |
46 | 48 |
| |
47 |
| - | |
| 49 | + | |
48 | 50 |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
| 30 | + | |
| 31 | + | |
| 32 | + |
Lines changed: 8 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
449 | 449 |
| |
450 | 450 |
| |
451 | 451 |
| |
452 |
| - | |
| 452 | + | |
| 453 | + | |
453 | 454 |
| |
454 | 455 |
| |
455 | 456 |
| |
| |||
470 | 471 |
| |
471 | 472 |
| |
472 | 473 |
| |
473 |
| - | |
| 474 | + | |
| 475 | + | |
| 476 | + | |
| 477 | + | |
| 478 | + | |
| 479 | + | |
474 | 480 |
| |
475 | 481 |
| |
476 | 482 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
0 commit comments