File tree
1,487 files changed
+21680
-58004
lines changed- .github/workflows
- config
- cpp/ql
- lib
- experimental/semmle/code/cpp
- ir/dataflow/internal
- ssa0
- semantic/analysis
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- metrics
- rangeanalysis
- security
- valuenumbering
- src
- Best Practices
- Likely Errors
- Unused Entities
- Critical
- Documentation
- Likely Bugs
- Arithmetic
- Likely Typos
- Memory Management
- Underspecified Functions
- Metrics
- Classes
- Namespaces
- Security/CWE
- CWE-120
- CWE-190
- CWE-732
- change-notes
- released
- experimental
- Best Practices
- Security/CWE
- CWE-078
- CWE-273
- CWE-362
- CWE-561
- CWE-703
- CWE-754
- external
- jsf
- 4.07 Header Files
- 4.13 Functions
- 4.21 Operators
- test
- experimental/query-tests/Security/CWE
- CWE-078
- CWE-703/semmle/tests
- query-tests/Best Practices
- Likely Errors/CommaBeforeMisleadingIndentation
- Unused Entities/UnusedStaticFunctions
- csharp
- extractor
- Semmle.Extraction.CIL
- Entities
- Base
- Semmle.Extraction.CSharp
- Entities
- Semmle.Extraction/Entities/Base
- Semmle.Util
- old-change-notes
- ql
- campaigns/Solorigate/lib
- lib
- experimental/code/csharp/Cryptography
- semmle/code
- cil
- internal
- csharp
- commons
- controlflow
- internal
- dataflow
- internal
- exprs
- frameworks
- microsoft
- system/security
- security/xml
- src
- API Abuse
- Bad Practices
- Implementation Hiding
- Magic Constants
- Likely Bugs
- Security Features
- Telemetry
- Useless code
- experimental
- Security Features
- CWE-327/Azure
- JsonWebTokenHandler
- backdoor
- ir/implementation
- raw
- internal
- unaliased_ssa
- internal
- meta/frameworks
- utils/model-generator/internal
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- ql-language-reference
- support/reusables
- writing-codeql-queries
- go/ql
- src
- Security/CWE-322
- experimental
- CWE-321
- CWE-369
- CWE-918
- test
- experimental/CWE-942
- query-tests/Security/CWE-918
- javascript/ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- counting
- evaluation
- extraction
- src
- test
- endpoint_large_scale
- endpoint_unit_tests
- lib/semmle/javascript
- frameworks
- security
- dataflow
- regexp
- src
- LanguageFeatures
- Security
- CWE-079
- CWE-094
- CWE-367
- CWE-829
- Statements
- change-notes
- released
- test
- library-tests/frameworks/Express
- src
- query-tests/Security/CWE-367
- java
- downgrades/709f1d1fd04ffd9bbcf242f17b120f8a389949bd
- kotlin-extractor/src/main
- java/com/semmle
- extractor/java
- util
- expansion
- files
- kotlin
- comments
- utils
- ql
- integration-tests
- linux-only/kotlin/custom_plugin
- posix-only/kotlin/java_modifiers
- libsrc/extlib
- lib
- change-notes
- config
- semmle/code
- java
- dataflow
- internal
- deadcode
- frameworks
- security
- regexp
- xml
- upgrades/ecb42310286011ada450ff65b9b417509863549f
- src
- Advisory/Declarations
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Likely Bugs/Concurrency
- Security/CWE
- CWE-200
- CWE-441
- CWE-925
- CWE-926
- Telemetry
- Violations of Best Practice/Naming Conventions
- change-notes
- experimental/Security/CWE
- CWE-094
- CWE-299
- CWE-327
- CWE-470
- CWE-502
- CWE-665
- utils/model-generator/internal
- test
- kotlin
- library-tests
- classes
- collection-literals
- exprs
- CONSISTENCY
- generic-instance-methods
- inherited-callee
- lateinit
- methods
- ministdlib
- modifiers
- numlines
- parameter-defaults
- private-anonymous-types
- properties
- reflection
- query-tests
- ConfusingMethodSignature
- UselessNullCheck
- UselessParameter
- library-tests/dataflow
- stream-collect
- synth-global
- query-tests/security
- CWE-297
- CWE-441
- CWE-926/incomplete_provider_permissions
- Testbuild
- misc/bazel/cmake
- python
- PoCs/XmlParsing
- ql
- examples/snippets
- lib
- change-notes
- released
- semmle/python
- dataflow
- new
- internal
- old
- frameworks
- Stdlib
- internal
- objects
- pointsto
- security
- dataflow
- regexp
- types
- src
- Classes
- Exceptions
- Expressions/Comparisons
- Functions
- Imports
- Numerics
- Security
- CWE-020
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-094
- CWE-117
- CWE-295
- CWE-312
- CWE-327
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-730
- CWE-776
- CWE-798
- CWE-918
- Statements
- Variables
- analysis
- change-notes
- experimental
- Security
- CWE-022
- CWE-091
- CWE-113
- CWE-1236
- CWE-287
- CWE-522
- CWE-611
- CWE-943
- semmle/python
- frameworks
- libraries
- templates
- semmle/python/functions
- test
- 2/query-tests
- Classes/new-style
- Exceptions
- generators
- raising
- 3/query-tests/Statements/iter
- experimental
- library-tests/CallGraph/code
- query-tests/Security
- CWE-022
- CWE-113
- CWE-287
- CWE-522
- CWE-611-SimpleXmlRpcServer
- CWE-943
- library-tests
- ApiGraphs/py3
- frameworks
- cx_Oracle
- django-orm
- modeling-example
- oracledb
- phoenixdb
- pymssql
- pymysql
- pyodbc
- query-tests
- Classes
- subclass-shadowing
- undefined-attribute
- Expressions/comparisons
- Functions
- ModificationOfParameterWithDefault
- general
- return_values
- Imports
- PyCheckerTests
- general
- Numerics
- Security
- CWE-020-IncompleteUrlSubstringSanitization
- CWE-022-PathInjection
- CWE-022-TarSlip
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-089-SqlInjection
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-295-RequestWithoutValidation
- CWE-312-CleartextLogging
- CWE-312-CleartextStorage-py3
- CWE-312-CleartextStorage
- CWE-327-InsecureProtocol
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-798-HardcodedCredentials
- CWE-918-ServerSideRequestForgery
- Statements
- DocStrings
- asserts
- general
- no_effect
- Variables
- capture
- general
- multiple
- unused_local_nonlocal
- unused
- tools/recorded-call-graph-metrics/src/cg_trace
- ql
- extractor/src
- node-types/src
- ql
- src
- codeql_ql
- ast
- internal
- dataflow
- style
- queries
- bugs
- diagnostics
- performance
- style
- test/queries/style
- AcronymsShouldBeCamelCase
- DeadCode
- RedundantCast
- RedundantOverride
- ruby
- actions/create-extractor-pack
- extractor/src
- node-types/src
- ql
- lib
- change-notes
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- tainttrackingforregexp
- experimental
- filters
- frameworks
- core
- http_clients
- internal
- regexp/internal
- security
- regexp
- typetracking
- src
- change-notes
- released
- experimental/manually-check-http-verb
- queries/security
- cwe-078
- cwe-502
- cwe-598
- examples
- cwe-829
- test
- library-tests
- controlflow/graph
- dataflow
- array-flow
- barrier-guards
- type-tracker
- frameworks
- action_controller
- action_mailer
- active_support
- app/controllers
- modules
- query-tests
- experimental/manually-check-http-verb
- security
- cwe-078
- KernelOpen
- NonConstantKernelOpen
- cwe-079
- app
- controllers/foo
- views/foo/stores
- cwe-094
- cwe-1333-polynomial-redos
- cwe-327
- cwe-502/unsafe-deserialization
- cwe-598
- app/controllers
- config
- cwe-601
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- visitors
- integration-tests
- ql
- lib/codeql/swift
- controlflow/internal
- dataflow
- internal
- elements
- decl
- expr
- pattern
- stmt
- type
- frameworks/StandardLibrary
- generated
- decl
- expr
- pattern
- stmt
- type
- src/queries/Security
- CWE-312
- CWE-321
- test
- extractor-tests/generated
- File
- expr
- AnyHashableErasureExpr
- ArchetypeToSuperExpr
- ArrayToPointerExpr
- ClassMetatypeToObjectExpr
- CollectionUpcastConversionExpr
- CovariantFunctionConversionExpr
- CovariantReturnConversionExpr
- DerivedToBaseExpr
- DestructureTupleExpr
- DifferentiableFunctionExpr
- DifferentiableFunctionExtractOriginalExpr
- ErasureExpr
- ExistentialMetatypeToObjectExpr
- ForeignObjectConversionExpr
- FunctionConversionExpr
- ImplicitConversionExpr
- InOutToPointerExpr
- InjectIntoOptionalExpr
- LinearFunctionExpr
- LinearFunctionExtractOriginalExpr
- LinearToDifferentiableFunctionExpr
- LoadExpr
- MetatypeConversionExpr
- PointerToPointerExpr
- ProtocolMetatypeToObjectExpr
- ReifyPackExpr
- StringToPointerExpr
- UnderlyingToOpaqueExpr
- UnevaluatedInstanceExpr
- type/BuiltinType
- library-tests
- controlflow/graph
- dataflow
- flowsources
- taint
- elements/location
- query-tests/Security
- CWE-312
- CWE-321
- tools
- xcode-autobuilder
- tests
- hello-autobuilder
- hello-autobuilder.xcodeproj
- project.xcworkspace
- hello-workspace
- Hello.xcworkspace
- hello-workspace.xcodeproj
- project.xcworkspace
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,487 files changed
+21680
-58004
lines changedLines changed: 27 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + |
Lines changed: 6 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| 13 | + | |
| 14 | + | |
| 15 | + | |
13 | 16 |
| |
14 | 17 |
| |
15 | 18 |
| |
| |||
18 | 21 |
| |
19 | 22 |
| |
20 | 23 |
| |
21 |
| - | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
22 | 27 |
| |
23 | 28 |
| |
24 | 29 |
| |
|
Lines changed: 3 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
28 | 28 |
| |
29 | 29 |
| |
30 | 30 |
| |
31 |
| - | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
32 | 34 |
| |
33 | 35 |
| |
34 | 36 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
33 | 33 |
| |
34 | 34 |
| |
35 | 35 |
| |
| 36 | + | |
| 37 | + | |
| 38 | + | |
36 | 39 |
| |
37 | 40 |
| |
38 | 41 |
| |
|
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
24 |
| - | |
25 |
| - | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
|
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
70 | 70 |
| |
71 | 71 |
| |
72 | 72 |
| |
73 |
| - | |
74 | 73 |
| |
75 | 74 |
| |
76 | 75 |
| |
|
Lines changed: 14 additions & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
838 | 838 |
| |
839 | 839 |
| |
840 | 840 |
| |
841 |
| - | |
| 841 | + | |
842 | 842 |
| |
843 | 843 |
| |
844 | 844 |
| |
845 | 845 |
| |
846 | 846 |
| |
847 |
| - | |
| 847 | + | |
848 | 848 |
| |
849 | 849 |
| |
850 | 850 |
| |
| |||
860 | 860 |
| |
861 | 861 |
| |
862 | 862 |
| |
863 |
| - | |
| 863 | + | |
864 | 864 |
| |
865 | 865 |
| |
866 | 866 |
| |
| |||
907 | 907 |
| |
908 | 908 |
| |
909 | 909 |
| |
910 |
| - | |
| 910 | + | |
911 | 911 |
| |
912 | 912 |
| |
913 | 913 |
| |
| |||
999 | 999 |
| |
1000 | 1000 |
| |
1001 | 1001 |
| |
1002 |
| - | |
| 1002 | + | |
1003 | 1003 |
| |
1004 | 1004 |
| |
1005 | 1005 |
| |
| |||
1260 | 1260 |
| |
1261 | 1261 |
| |
1262 | 1262 |
| |
1263 |
| - | |
| 1263 | + | |
1264 | 1264 |
| |
1265 | 1265 |
| |
1266 | 1266 |
| |
| |||
1484 | 1484 |
| |
1485 | 1485 |
| |
1486 | 1486 |
| |
1487 |
| - | |
| 1487 | + | |
1488 | 1488 |
| |
1489 | 1489 |
| |
1490 | 1490 |
| |
| |||
1662 | 1662 |
| |
1663 | 1663 |
| |
1664 | 1664 |
| |
1665 |
| - | |
| 1665 | + | |
1666 | 1666 |
| |
1667 | 1667 |
| |
1668 | 1668 |
| |
| |||
1675 | 1675 |
| |
1676 | 1676 |
| |
1677 | 1677 |
| |
1678 |
| - | |
| 1678 | + | |
| 1679 | + | |
| 1680 | + | |
1679 | 1681 |
| |
1680 | 1682 |
| |
1681 | 1683 |
| |
1682 |
| - | |
| 1684 | + | |
1683 | 1685 |
| |
1684 | 1686 |
| |
1685 | 1687 |
| |
| |||
1700 | 1702 |
| |
1701 | 1703 |
| |
1702 | 1704 |
| |
1703 |
| - | |
| 1705 | + | |
1704 | 1706 |
| |
1705 | 1707 |
| |
1706 | 1708 |
| |
| |||
1742 | 1744 |
| |
1743 | 1745 |
| |
1744 | 1746 |
| |
1745 |
| - | |
| 1747 | + | |
1746 | 1748 |
| |
1747 | 1749 |
| |
1748 | 1750 |
| |
|
Lines changed: 14 additions & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
838 | 838 |
| |
839 | 839 |
| |
840 | 840 |
| |
841 |
| - | |
| 841 | + | |
842 | 842 |
| |
843 | 843 |
| |
844 | 844 |
| |
845 | 845 |
| |
846 | 846 |
| |
847 |
| - | |
| 847 | + | |
848 | 848 |
| |
849 | 849 |
| |
850 | 850 |
| |
| |||
860 | 860 |
| |
861 | 861 |
| |
862 | 862 |
| |
863 |
| - | |
| 863 | + | |
864 | 864 |
| |
865 | 865 |
| |
866 | 866 |
| |
| |||
907 | 907 |
| |
908 | 908 |
| |
909 | 909 |
| |
910 |
| - | |
| 910 | + | |
911 | 911 |
| |
912 | 912 |
| |
913 | 913 |
| |
| |||
999 | 999 |
| |
1000 | 1000 |
| |
1001 | 1001 |
| |
1002 |
| - | |
| 1002 | + | |
1003 | 1003 |
| |
1004 | 1004 |
| |
1005 | 1005 |
| |
| |||
1260 | 1260 |
| |
1261 | 1261 |
| |
1262 | 1262 |
| |
1263 |
| - | |
| 1263 | + | |
1264 | 1264 |
| |
1265 | 1265 |
| |
1266 | 1266 |
| |
| |||
1484 | 1484 |
| |
1485 | 1485 |
| |
1486 | 1486 |
| |
1487 |
| - | |
| 1487 | + | |
1488 | 1488 |
| |
1489 | 1489 |
| |
1490 | 1490 |
| |
| |||
1662 | 1662 |
| |
1663 | 1663 |
| |
1664 | 1664 |
| |
1665 |
| - | |
| 1665 | + | |
1666 | 1666 |
| |
1667 | 1667 |
| |
1668 | 1668 |
| |
| |||
1675 | 1675 |
| |
1676 | 1676 |
| |
1677 | 1677 |
| |
1678 |
| - | |
| 1678 | + | |
| 1679 | + | |
| 1680 | + | |
1679 | 1681 |
| |
1680 | 1682 |
| |
1681 | 1683 |
| |
1682 |
| - | |
| 1684 | + | |
1683 | 1685 |
| |
1684 | 1686 |
| |
1685 | 1687 |
| |
| |||
1700 | 1702 |
| |
1701 | 1703 |
| |
1702 | 1704 |
| |
1703 |
| - | |
| 1705 | + | |
1704 | 1706 |
| |
1705 | 1707 |
| |
1706 | 1708 |
| |
| |||
1742 | 1744 |
| |
1743 | 1745 |
| |
1744 | 1746 |
| |
1745 |
| - | |
| 1747 | + | |
1746 | 1748 |
| |
1747 | 1749 |
| |
1748 | 1750 |
| |
|
0 commit comments