File tree
4,795 files changed
+431198
-191876
lines changed- .github
- workflows
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- downgrades
- 298438feb146335af824002589cd6d4e96e5dbf9
- 4f9fabab5124d49108782c081579f45a70571d74
- aa7ff0ab32cd4674f6ab731d32fea64116997b05
- abfce5c170f93e281948f7689ece373464fdaf87
- ql
- lib
- change-notes/released
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- new
- exprs
- headers
- internal
- ir
- dataflow
- internal
- ssa0
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- constant
- internal
- internal
- raw
- constant
- internal
- unaliased_ssa
- constant
- internal
- internal
- models
- implementations
- interfaces
- security/flowafterfree
- stmts
- upgrades
- 298438feb146335af824002589cd6d4e96e5dbf9
- 4f9fabab5124d49108782c081579f45a70571d74
- 7f34caf73ca98314885030cc5a22b6e328fe687c
- aa7ff0ab32cd4674f6ab731d32fea64116997b05
- src
- Critical
- Diagnostics
- Likely Bugs
- Format
- Memory Management
- Protocols
- Microsoft
- Security/CWE
- CWE-497
- CWE-611
- CWE-704
- CWE-843
- Summary
- change-notes
- released
- experimental/Security/CWE/CWE-416
- test
- examples/expressions
- experimental/query-tests/Security/CWE
- CWE-078
- CWE-190/AllocMultiplicationOverflow
- CWE-193
- array-access
- constant-size
- CWE-359/semmle/tests
- CWE-416
- include
- library-tests
- CPP-205
- arguments
- compiler_generated
- controlflow
- guards-ir
- guards
- dataflow
- asExpr
- dataflow-tests
- fields
- taint-tests
- destructors
- headers/preprocBlock
- ir
- ir
- points_to
- special_members/generated_copy
- specifiers2
- string_concat
- syntax-zoo
- query-tests
- Critical
- MemoryFreed
- MissingCheckScanf
- Diagnostics
- Likely Bugs
- Conversion/CastArrayPointerArithmetic
- Format/NonConstantFormat
- Protocols
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-119
- SAMATE
- semmle/tests
- CWE-120/semmle/tests
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- consts
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- TaintedAllocationSize
- tainted
- CWE-193
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests/UseAfterFree
- CWE-457/semmle/tests
- CWE-497
- SAMATE
- semmle/tests
- CWE-611
- CWE-704
- CWE-807/semmle/TaintedCondition
- CWE-843
- jsf/4.13 Functions/AV Rule 114
- successor-tests
- conditional_destructors
- forstmt/rangebasedforstmt
- staticlocals/no_dynamic_init
- csharp
- actions/create-extractor-pack
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- downgrades
- 21ede72308c41493f19b37720d8259d5eb307f12
- c9ee11bd1ee96e925a35cedff000be924634447f
- f145a9a7275c8f457b392b2ebc9f8e07960a0ed2
- f595d31422d7d462d2bee8c69b44341df8bdadb6
- fc9c7ab844ab055b97222a97e895b4bf2e1f8f4e
- fd04e45710e1988076801608abffdfa013b680fc
- extractor
- Semmle.Extraction.CIL.Driver
- Properties
- Semmle.Extraction.CIL
- Entities
- Base
- PDB
- Properties
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.DependencyStubGenerator
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp
- Entities
- Compilations
- Expressions
- Collections
- ObjectCreation
- Patterns
- PreprocessorDirectives
- Statements
- Types
- Extractor
- Kinds
- Populators
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities
- Extractor
- Semmle.Util.Tests
- Semmle.Util
- Logging
- ToolStatusPage
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms
- autobuild
- cshtml_standalone_disabled
- Views/Home
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- Views/Home
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- standalone_dependencies_net48
- standalone_failed
- standalone
- linux-only
- compiler_args
- standalone_dependencies_non_utf8_filename
- posix-only
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- standalone_dependencies_executing_runtime
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget_config_error_timeout
- proj
- standalone_dependencies_nuget_config_error
- proj
- standalone_dependencies_nuget_no_sources
- proj
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows-only/standalone_dependencies
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- semmle/code
- asp
- cil
- internal
- csharp
- commons
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- dispatch
- exprs
- frameworks
- microsoft
- system
- diagnostics
- runtime
- security
- auth
- cryptography
- dataflow
- flowsources
- dotnet
- upgrades
- 1f291d4f424b498e7500c0359ca1fe030628a448
- 21ede72308c41493f19b37720d8259d5eb307f12
- c9ee11bd1ee96e925a35cedff000be924634447f
- f145a9a7275c8f457b392b2ebc9f8e07960a0ed2
- f595d31422d7d462d2bee8c69b44341df8bdadb6
- fc9c7ab844ab055b97222a97e895b4bf2e1f8f4e
- src
- API Abuse
- Dead Code
- Diagnostics
- Metrics/Summaries
- Security Features
- CWE-022
- examples
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-091
- CWE-114
- CWE-134
- CWE-502
- CWE-601
- examples
- CWE-643
- Telemetry
- change-notes/released
- experimental
- CWE-099
- CWE-918
- Security Features/backdoor
- ir
- implementation
- internal
- raw
- constant
- internal
- gvn
- internal
- internal
- common
- desugar
- internal
- reachability
- unaliased_ssa
- constant
- internal
- gvn
- internal
- internal
- reachability
- internal
- rangeanalysis
- utils
- modelconverter
- modeleditor
- modelgenerator/internal
- test
- TestUtilities
- experimental
- CWE-918
- Security Features
- CWE-759
- backdoor
- ir
- ir
- offbyone
- rangeanalysis
- library-tests
- attributes
- cil
- attributes
- consistency
- dataflow
- enums
- functionPointers
- init-only-prop
- pdbs
- regressions
- typeAnnotations
- collections
- comments
- commons/Disposal
- constructors
- controlflow
- graph
- guards
- splits
- csharp11
- cil
- csharp6
- csharp7.2
- csharp7
- csharp8
- csharp9
- dataflow
- async
- call-sensitivity
- collections
- constructors
- defuse
- delegates
- external-models
- fields
- flowsources
- local
- commandargs
- environment
- registry
- stored
- database/dapper
- file
- global
- library
- local
- operators
- ssa
- threat-models
- tuples
- typeflow-dispatch
- types
- definitions
- delegates
- diagnostics
- dispatch
- dynamic
- enums
- events
- expressions
- exprorstmtparent
- fields
- frameworks
- EntityFramework
- system
- Dispose
- Equals
- generics
- goto
- indexers
- members
- nullable
- overrides
- parameters
- standalone
- controlflow
- errorrecovery
- statements
- structuralcomparison
- types
- unification
- query-tests
- API Abuse
- FormatInvalid
- IncorrectCompareToSignature
- NoDisposeCallOnLocalIDisposable
- Likely Bugs/UnsafeYearConstruction
- Nullness
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSSRazorPages
- Generated
- XSS
- XssPageModels
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsecureSQLConnection
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- CWE-838
- scripts
- stubs
- tools
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview/codeql-changelog
- images/codeql-for-visual-studio-code
- reusables
- go
- documentation/library-coverage
- extractor
- autobuilder
- cli/go-autobuilder
- diagnostics
- project
- toolchain
- util
- vendor
- golang.org/x/tools
- go/packages
- internal/gcimporter
- integration-tests-lib
- ql
- consistency-queries
- change-notes/released
- integration-tests/all-platforms/go
- bazel-sample-1
- src
- bazel-sample-2
- src
- diagnostics
- build-constraints-exclude-all-go-files
- go-files-found-not-processed
- invalid-toolchain-version
- src
- newer-go-version-needed
- no-go-files-found
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- unsupported-relative-path
- go-get-without-modules-sample
- src
- go-mod-sample
- src
- go-mod-without-version
- src
- subdir
- go-version-bump
- src
- make-sample
- src
- mixed-layout
- src
- module
- stray-files
- workspace
- subdir
- ninja-sample
- src
- single-go-mod-and-go-files-not-under-it
- src
- subdir
- subsubdir
- single-go-mod-in-root
- src
- subdir
- single-go-mod-not-in-root
- src/subdir
- subsubdir
- single-go-work-not-in-root
- src/modules
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-nested-none-in-root
- src/subdir0
- subdir1
- subsubdir1
- subdir2
- two-go-mods-nested-one-in-root
- src
- subdir1
- subsubdir1
- subdir2
- two-go-mods-not-nested
- src
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-one-failure
- src
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- lib
- change-notes
- released
- ext
- semmle/go
- concepts
- controlflow
- dataflow
- internal
- tainttracking1
- tainttracking2
- frameworks
- stdlib
- internal
- security
- src
- Security
- CWE-020
- CWE-022
- CWE-089
- CWE-338
- CWE-347
- CWE-601
- CWE-770
- CWE-798
- Summary
- change-notes
- released
- experimental
- CWE-321
- CWE-347
- CWE-522-DecompressionBombs
- CWE-525
- examples
- frameworks
- test
- TestUtilities
- internal
- experimental
- CWE-090
- CWE-1004
- CWE-203
- CWE-287
- CWE-321-V2
- CWE-321
- CWE-347
- CWE-369
- CWE-522-DecompressionBombs
- vendor
- github.com
- DataDog/zstd
- dsnet/compress
- bzip2
- flate
- golang/snappy
- klauspost
- compress
- flate
- gzip
- s2
- snappy
- zip
- zlib
- zstd
- pgzip
- ulikunitz/xz
- CWE-525
- vendor
- github.com
- go-chi/chi/v5
- middleware
- gofiber/fiber/v2
- julienschmidt/httprouter
- CWE-74
- CWE-79
- CWE-918
- Unsafe
- extractor-tests
- diagnostics
- no-intermediate-strings
- library-tests/semmle/go
- Function
- controlflow/ControlFlowGraph
- dataflow
- ChannelField
- DefaultTaintSanitizer
- HiddenNodes
- MapReadsAndStores
- Switch
- frameworks
- AwsLambda
- vendor
- github.com/aws/aws-lambda-go/lambda
- BeegoOrm
- Beego
- Chi
- Echo
- Encoding
- Gin
- GoMicro
- Gorestful
- Macaron
- vendor/gopkg.in/macaron.v1
- Revel
- SQL
- vendor
- github.com/Masterminds/squirrel
- Twirp
- XNetHtml
- query-tests
- InconsistentCode/UnhandledCloseWritableHandle
- Security
- CWE-020/IncompleteHostnameRegexp
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- CWE-209
- CWE-312
- CWE-322
- CWE-326
- CWE-327
- CWE-338/InsecureRandomness
- CWE-347
- vendor
- github.com
- go-jose/go-jose/v3/jwt
- golang-jwt/jwt/v5
- CWE-352
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- CWE-770
- CWE-798
- vendor
- github.com
- appleboy/gin-jwt/v2
- cristalhq/jwt/v3
- gin-gonic/gin
- go-kit/kit/auth/jwt
- gogf/gf-jwt/v2
- golang-jwt/jwt/v4
- iris-contrib/middleware/jwt
- kataras
- iris/v12/middleware/jwt
- jwt
- lestrrat/go-jwx/jwk
- square/go-jose/v3
- gopkg.in/square/go-jose.v2
- CWE-918
- java
- documentation/library-coverage
- integration-tests-lib
- kotlin-extractor
- src/main
- java/com/semmle/util/process
- kotlin
- comments
- utils/versions
- v_1_5_0
- v_1_9_0-Beta
- v_2_0_0-RC1
- ql
- automodel
- src
- change-notes/released
- test
- AutomodelApplicationModeExtraction
- AutomodelFrameworkModeExtraction
- com/github/codeql/test
- java
- io
- nio/file
- consistency-queries
- integration-tests/all-platforms
- java
- buildless-erroneous
- buildless-gradle
- buildless-maven-multimodule
- buildless-maven
- buildless-sibling-projects
- gradle-sample2
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- gradle-sample
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- maven-project-1
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-project-2
- src
- main
- java/com/example
- resources
- test/java/com/example
- buildless
- maven-wrapper-script-only
- .mvn/wrapper
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-wrapper-source-only
- .mvn/wrapper
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-wrapper
- .mvn/wrapper
- src
- main
- java/com/example
- resources
- test/java/com/example
- multi-release-jar-java11
- mod1
- mod1pkg
- mod2
- mod2pkg
- multi-release-jar-java17
- mod1
- mod1pkg
- mod2
- mod2pkg
- partial-gradle-sample-without-gradle
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- kotlin
- default-parameter-mad-flow
- diagnostics/kotlin-version-too-new
- extractor_information_kotlin1
- extractor_information_kotlin2
- kotlin_java_static_fields
- path_transformer
- lib
- change-notes
- released
- ext
- experimental
- generated
- semmle/code
- java
- controlflow
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- deadcode
- dispatch
- frameworks
- android
- camel
- gwt
- j2objc
- javaee/ejb
- spring
- regex
- security
- regexp
- xml
- src
- Advisory/Documentation
- Likely Bugs
- Arithmetic
- Likely Typos
- Statements
- Metrics/Summaries
- Security/CWE
- CWE-022
- examples
- CWE-074
- CWE-078
- CWE-113
- CWE-200
- CWE-287
- CWE-552
- CWE-601
- examples
- Telemetry
- change-notes
- released
- experimental/Security/CWE
- CWE-020
- CWE-073
- CWE-078
- CWE-089
- CWE-348
- CWE-552
- utils
- flowtestcasegenerator
- modelconverter
- modeleditor
- modelgenerator/internal
- test-kotlin1
- TestUtilities
- library-tests
- compilation-units
- enum
- java-kotlin-collection-type-generic-methods
- reflection
- test-kotlin2/library-tests
- arrays
- comments
- controlflow
- basic
- dominance
- data-classes
- dataflow/func
- exprs
- java-kotlin-collection-type-generic-methods
- methods
- ministdlib
- multiple_files
- operator-overloads
- parameter-defaults
- reflection
- stmts
- test
- TestUtilities
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- NotConstantTimeCheckOnSignature
- TimingAttackAgainstSignagure
- CWE-299
- CWE-327
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-502
- CWE-552
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- ext
- TestModels
- TopJdkApis
- library-tests/dataflow
- call-sensitivity
- flowfeature
- inoutbarriers
- local-additional-taint
- threat-models
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
4,795 files changed
+431198
-191876
lines changedLines changed: 8 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
2 | 10 |
| |
3 | 11 |
| |
4 | 12 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
74 | 74 |
| |
75 | 75 |
| |
76 | 76 |
| |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
3 | 6 |
| |
4 | 7 |
| |
5 | 8 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
| 12 | + | |
| 13 | + | |
| 14 | + | |
12 | 15 |
| |
13 | 16 |
| |
14 | 17 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| 13 | + | |
| 14 | + | |
| 15 | + | |
13 | 16 |
| |
14 | 17 |
| |
15 | 18 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
| 14 | + | |
| 15 | + | |
| 16 | + | |
14 | 17 |
| |
15 | 18 |
| |
16 | 19 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
| 9 | + | |
| 10 | + | |
8 | 11 |
| |
9 | 12 |
| |
10 | 13 |
| |
|
0 commit comments