File tree
2,090 files changed
+231631
-37004
lines changed- .devcontainer
- .github
- actions/fetch-codeql
- workflows
- config
- cpp
- change-notes
- ql
- lib
- experimental/semmle/code/cpp/security
- external
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- exprs
- internal
- ir
- dataflow
- internal
- implementation
- aliased_ssa
- raw
- internal
- unaliased_ssa
- metrics
- models
- implementations
- interfaces
- padding
- rangeanalysis
- security
- boostorg/asio
- stmts
- valuenumbering
- src
- Architecture
- General Class-Level Information
- Refactoring Opportunities
- Best Practices
- Likely Errors
- Magic Constants
- Unused Entities
- JPL_C/LOC-2/Rule 09
- Likely Bugs
- Conversion
- Format
- Leap Year
- Likely Typos
- Memory Management
- Protocols
- Metrics
- Files
- History
- Power of 10/Rule 1
- Security/CWE
- CWE-022
- CWE-170
- CWE-295
- CWE-311
- CWE-313
- CWE-319
- CWE-497
- experimental/Security/CWE
- CWE-243
- CWE-273
- CWE-377
- CWE-783
- external
- jsf
- 4.09 Style
- 4.10 Classes
- 4.15 Declarations and Definitions
- 4.22 Pointers and References
- 4.28 Portable Code
- test
- experimental/query-tests/Security/CWE
- CWE-243/semmle/tests
- CWE-377/semmle/tests
- CWE-675/semmle/tests
- library-tests
- access/noPublic
- controlflow/controlflow
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- dataflow-tests
- fields
- security-taint
- smart-pointers-taint
- taint-tests
- ir
- ir
- points_to
- rangeanalysis/RangeSSA
- syntax-zoo
- types
- __wchar_t
- wchar_t_typedef
- variables/variables
- query-tests
- Likely Bugs
- Conversion/CastArrayPointerArithmetic
- Memory Management/ImproperNullTermination
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078/SAMATE/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-120/semmle/tests
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190/semmle
- ArithmeticUncontrolled
- TaintedAllocationSize
- tainted
- CWE-242/semmle/tests
- CWE-295
- CWE-319/UseOfHttp
- CWE-807/semmle/TaintedCondition
- csharp
- extractor
- Semmle.Extraction.CSharp/Entities
- Expressions
- Semmle.Extraction
- ql
- consistency-queries
- lib
- Linq
- semmle/code
- cil/internal
- csharp
- commons
- controlflow
- internal
- pressa
- dataflow
- internal
- basessa
- frameworks
- security
- dataflow
- flowsinks
- flowsources
- xml
- dotnet
- src
- Bad Practices
- Implementation Hiding
- Magic Constants
- Naming Conventions
- Dead Code
- Linq
- Security Features
- CWE-020
- CWE-730
- Stubs
- experimental
- CWE-918
- ir
- implementation
- raw
- internal
- unaliased_ssa
- internal
- internal
- test
- experimental
- CWE-918
- ir/ir
- library-tests
- arguments
- assemblies
- assignments
- attributes
- comments
- constructors
- controlflow
- graph
- splits/CONSISTENCY
- conversion/operator
- csharp6
- csharp7.1
- csharp7.2
- csharp7.3
- csharp7
- csharp8
- csharp9
- dataflow
- async
- external-models
- global
- library
- local
- tuples
- definitions
- delegates
- dynamic
- enums
- events
- exceptions
- expressions
- fields
- frameworks/EntityFramework
- generics
- goto
- indexers
- initializers
- linq
- members
- methods
- namespaces
- nestedtypes
- operators
- partial
- properties
- statements
- types
- unsafe
- query-tests/Security Features
- CWE-601/UrlRedirect
- CWE-838
- resources/stubs
- Microsoft.NETCore.Platforms/3.1.0
- Microsoft.Win32.Registry/4.7.0
- System.Data.SqlClient/4.8.3
- System.Security.AccessControl/4.7.0
- System.Security.Principal.Windows/4.7.0
- _frameworks/Microsoft.NETCore.App
- runtime.native.System.Data.SqlClient.sni/4.7.0
- runtime.win-arm64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x86.runtime.native.System.Data.SqlClient.sni/4.4.0
- tools/osx64
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- ql-language-reference
- query-help
- reusables
- support/reusables
- writing-codeql-queries
- ql-libraries/dataflow
- javascript
- change-notes
- extractor
- src/com/semmle/js/extractor
- tests
- es2015/output/trap
- exprs/output/trap
- generatedcode
- input
- output/trap
- jsx/output/trap
- regexp
- input
- output/trap
- ts/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- src
- codeql-suites
- lib
- semmle/javascript
- dataflow
- internal
- dependencies
- filters
- frameworks
- AngularJS
- internal
- linters
- security
- dataflow
- internal
- performance
- src
- AngularJS
- Declarations
- Expressions
- LanguageFeatures
- React
- Security
- CWE-020
- CWE-089
- CWE-1004
- examples
- CWE-116
- examples
- CWE-209
- CWE-295
- CWE-312
- CWE-326
- CWE-346
- CWE-384
- examples
- CWE-598
- examples
- CWE-614
- examples
- CWE-915
- Statements
- experimental
- Security
- CWE-090
- examples
- CWE-1004
- CWE-614
- CWE-918
- Summaries
- semmle/javascript/security
- external
- meta
- ApiGraphs
- test
- ApiGraphs
- async-await
- experimental/Security/CWE-918
- library-tests
- CFG
- RangeAnalysis
- SensitiveActions
- StringConcatenation
- TypeInference/FunctionWithAnalyzedParameters
- TypeScript
- Ambients
- Namespaces
- TypeAnnotations
- query-tests
- Declarations/MixedStaticInstanceThisAccess
- Performance/ReDoS
- lib
- Security
- CWE-020
- CWE-022/TaintedPath
- CWE-079
- DomBasedXss
- UnsafeJQueryPlugin
- CWE-089/untyped
- CWE-1004
- CWE-116/BadTagFilter
- CWE-326
- CWE-384
- CWE-598
- CWE-614
- CWE-915/PrototypePollutingAssignment
- tutorials/Analyzing data flow in JavaScript/Global data flow
- upgrades/e54b35a8a129ebcf246cd4e834935f929b54aa04
- java
- change-notes
- documentation/library-coverage
- ql
- lib
- config
- external
- semmle/code
- java
- arithmetic
- controlflow
- unreachableblocks
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- apache
- google
- gwt
- j2objc
- jackson
- javaee
- ejb
- jsf
- javase
- play
- ratpack
- spring
- struts
- metrics
- security
- xml
- src
- Compatibility/JDK9
- Diagnostics
- Language Abuse
- Likely Bugs
- Arithmetic
- Concurrency
- Inheritance
- Resource Leaks
- Performance
- Security/CWE
- CWE-190
- CWE-327
- CWE-611
- CWE-681
- CWE-798
- CWE-833
- CWE-927
- CWE-940
- Telemetry
- Violations of Best Practice
- Dead Code
- Magic Constants
- experimental/Security/CWE
- CWE-016
- CWE-094
- CWE-200
- CWE-326
- CWE-400
- CWE-502
- CWE-522
- CWE-552
- CWE-598
- CWE-927
- CWE-939
- external
- utils/model-generator
- test
- experimental/query-tests/security
- CWE-200
- CWE-400
- CWE-552
- CWE-927
- library-tests
- Encryption
- MemberRefExpr
- constants
- constants
- controlflow/basic
- dataflow
- callback-dispatch
- collections
- taintsources
- taint
- frameworks
- android
- asynctask
- intent
- ratpack
- resources
- stream
- literals
- charLiterals
- stringLiterals
- optional
- overrides
- query-tests
- Telemetry/ExternalLibraryUsage
- UselessComparisonTest
- security
- CWE-297
- CWE-611
- CWE-798/semmle/tests
- CWE-927
- CWE-940
- stubs
- apache-commons-fileupload-1.4/org/apache/commons/fileupload2
- google-android-9.0.0/android
- annotation
- app
- content
- os
- webkit
- guava-30.0/com/google/common/reflect
- jackson-core-2.12/com/fasterxml/jackson/core
- jackson-databind-2.12/com/fasterxml/jackson/databind
- node
- netty-4.1.x
- io/netty
- buffer
- handler/codec/http/cookie
- ratpack-1.9.x
- ratpack
- core
- form
- handling
- http
- parse
- render
- exec
- api
- registry
- stream
- func
- jackson
- utils/model-generator
- p
- upgrades/017ac1ed2df1eaa5d8c4ae1849261c82392209d4
- misc/scripts
- library-coverage
- python
- change-notes
- ql
- lib/semmle/python
- concepts
- dataflow
- new/internal
- old
- dependencies
- essa
- frameworks
- internal
- internal
- objects
- pointsto
- security
- dataflow
- injection
- internal
- performance
- types
- values
- web
- django
- falcon
- flask
- src
- Classes
- Diagnostics
- Expressions
- Functions
- Lexical
- Security
- CWE-020-ExternalAPIs
- CWE-022
- CWE-078
- CWE-089
- CWE-094
- CWE-116
- examples
- CWE-295
- CWE-312
- CWE-730
- Statements
- analysis
- experimental
- Security
- CWE-113
- CWE-347
- semmle/python
- frameworks
- libraries
- security/injection
- meta/alerts
- test
- experimental
- dataflow
- ApiGraphs
- tainttracking
- commonSanitizer
- defaultAdditionalTaintStep
- meta
- debug
- query-tests/Security
- CWE-113
- CWE-347
- library-tests
- PointsTo/api
- frameworks
- aiomysql
- aiopg
- asyncpg
- django-v2-v3
- fastapi
- flask_admin
- flask_sqlalchemy
- flask
- internal-ql-helpers
- rest_framework
- testapp
- migrations
- testproj
- ruamel.yaml
- sqlalchemy
- stdlib
- toml
- yaml
- objects
- regex
- query-tests
- Diagnostics
- Security
- CWE-022-PathInjection
- CWE-116-BadTagFilter
- CWE-295-RequestWithoutValidation
- CWE-730-PolynomialReDoS
- CWE-730-ReDoS
- ruby
- .vscode
- actions/create-extractor-pack
- autobuilder
- src
- change-notes
- doc
- extractor
- src
- generator
- src
- node-types
- src
- ql
- consistency-queries
- docs
- examples
- snippets
- lib
- codeql
- files
- ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- filters
- frameworks
- http_clients
- security
- performance
- typetracking
- upgrades
- 09a494ce67d8141f28d6411f89b9ff7bdad440f3
- 30e1075bbdc9ce935dbe28dc7175489fe8e69a4c
- 31a238d080f3dd563d7225fc0458254617d1e5ba
- 40be81bc2086eb0368f33c770e0a84817bb340c3
- 8725deeb2fa6627c45235f18b7c121c35498dac7
- b5aef9c93ae64f848017d2dcb760eed916ab0cdd
- f36dd8a35ce55a3b93a178e38a79b8e8cbea7463
- initial
- src
- codeql-suites
- experimental
- performance
- filters
- ide-contextual-queries
- queries
- analysis
- diagnostics
- metrics
- security
- cwe-022
- examples
- cwe-078
- examples
- cwe-079
- examples
- cwe-089
- examples
- cwe-094
- examples
- cwe-116
- examples
- cwe-1333
- examples
- cwe-295
- examples
- cwe-352
- examples
- cwe-502
- examples
- cwe-601
- examples
- cwe-611
- examples
- cwe-732
- cwe-798
- cwe-918
- summary
- variables
- test
- TestUtilities
- library-tests
- ast
- CONSISTENCY
- calls
- constants
- control
- CONSISTENCY
- erb
- gems
- lib
- literals
- misc
- modules
- operations
- params
- controlflow/graph
- dataflow
- api-graphs
- barrier-guards
- call-sensitivity
- local
- summaries
- type-tracker
- frameworks
- app
- components
- controllers/foo
- views/foo/bars
- files
- http_clients
- modules
- regexp
- variables
- query-tests
- AlertSuppression
- analysis
- diagnostics
- src
- vendor/cache
- metrics/FLines
- performance/UseDetect
- security
- cwe-022
- cwe-078
- cwe-079
- app
- controllers/foo
- models
- views/foo
- bars
- stores
- cwe-089
- cwe-094
- cwe-116
- cwe-1333-exponential-redos
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-295
- cwe-352
- railsapp
- app/controllers
- config
- environments
- test/controllers
- cwe-502
- oj-global-options
- unsafe-deserialization
- cwe-601
- cwe-611
- cwe-732
- cwe-798
- cwe-918
- summary
- src
- vendor/cache
- scripts
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,090 files changed
+231631
-37004
lines changedLines changed: 16 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
4 |
| - | |
5 |
| - | |
6 |
| - | |
7 |
| - | |
8 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + |
Lines changed: 5 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
3 | 5 |
| |
4 | 6 |
| |
5 | 7 |
| |
6 | 8 |
| |
| 9 | + | |
| 10 | + | |
| 11 | + | |
7 | 12 |
| |
8 | 13 |
| |
9 | 14 |
|
Lines changed: 14 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + |
Lines changed: 18 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
18 | 18 |
| |
19 | 19 |
| |
20 | 20 |
| |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
21 | 25 |
| |
22 | 26 |
| |
23 | 27 |
| |
|
Lines changed: 31 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + |
Lines changed: 63 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + |
0 commit comments