File tree
1,369 files changed
+93130
-15149
lines changed- .github
- workflows
- config
- cpp
- downgrades/5b388693c66db1e7dc2e76a90aa67a2b6eb74f0f
- ql
- lib
- change-notes
- released
- experimental/cryptography
- modules
- utils/OpenSSL
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- tainttracking1
- tainttracking2
- ir
- dataflow/internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- raw
- internal
- unaliased_ssa
- rangeanalysis
- security/InvalidPointerDereference
- upgrades/dbe9c8eb5fc6f54b7ae08c7317d0795b24961564
- src
- Critical
- Likely Bugs
- Microsoft
- Security/CWE
- CWE-079
- CWE-119
- change-notes
- released
- experimental/cryptography
- example_alerts
- inventory
- new_models
- old_models
- test
- examples/expressions
- experimental
- library-tests/rangeanalysis/signanalysis
- query-tests/Security/CWE/CWE-193/constant-size
- library-tests
- attributes/deprecated_with_msg
- dataflow
- DefaultTaintTracking/annotate_sinks_only
- dataflow-tests
- fields
- taint-tests
- ir
- ir
- range-analysis
- syntax-zoo
- templates/type_instantiations
- type_sizes
- unspecified_type/types
- valuenumbering/GlobalValueNumbering
- variables/variables
- query-tests
- Critical/MemoryFreed
- Security/CWE
- CWE-078/semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-119/semmle/tests
- CWE-134/semmle/argv
- CWE-190/semmle/TaintedAllocationSize
- CWE-193
- csharp
- downgrades
- 1f291d4f424b498e7500c0359ca1fe030628a448
- cc2eccd6026e5405594b75eb9d2d3f4646747ccd
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- PreprocessorDirectives
- Types
- Extractor
- Populators
- Semmle.Extraction.Tests
- Semmle.Extraction/Extractor
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- autobuild
- standalone_dependencies_net48
- posix-only/standalone_dependencies
- windows-only/standalone_dependencies
- lib
- change-notes/released
- semmle/code/csharp
- dataflow/internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- exprs
- frameworks
- security
- auth
- dataflow
- upgrades
- 585d6402ff8ba3d15114a869d205bdf6d4e0aa3f
- cc2eccd6026e5405594b75eb9d2d3f4646747ccd
- src
- Stubs
- change-notes/released
- experimental/ir/implementation
- raw
- unaliased_ssa
- meta/frameworks
- test
- library-tests/standalone/errorrecovery
- query-tests/Security Features
- CWE-285/MissingAccessControl/MVCTests
- CWE-639/MVCTests
- docs
- codeql
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- go
- documentation/library-coverage
- extractor
- cli/go-autobuilder
- vendor
- golang.org/x
- mod
- internal/lazyregexp
- modfile
- module
- semver
- sys
- execabs
- tools
- go
- gcexportdata
- internal/packagesdriver
- packages
- types/objectpath
- internal
- event
- core
- keys
- label
- tag
- gcimporter
- gocommand
- packagesinternal
- pkgbits
- tokeninternal
- typeparams
- typesinternal
- ql
- integration-tests/all-platforms/go/diagnostics/newer-go-version-needed
- work
- lib
- change-notes
- released
- semmle/go
- dataflow
- barrierguardutil
- internal
- tainttracking1
- tainttracking2
- frameworks
- stdlib
- security
- src
- Security/CWE-681
- change-notes/released
- experimental
- CWE-203
- CWE-321-V2
- CWE-347
- CWE-74
- frameworks
- meta/frameworks
- test
- experimental
- CWE-321-V2
- vendor
- github.com
- go-jose/go-jose/v3/jwt
- golang-jwt/jwt/v5
- CWE-347
- vendor
- github.com
- go-jose/go-jose/v3/jwt
- golang-jwt/jwt/v5
- library-tests/semmle/go/frameworks
- Afero
- vendor
- github.com/spf13/afero
- Beego
- vendor
- github.com/beego/beego/v2/server/web
- context
- Echo
- vendor/github.com/labstack/echo/v4
- Fiber
- vendor
- github.com/gofiber/fiber/v2
- Gin
- vendor/github.com/gin-gonic/gin
- binding
- GoKit
- Iris
- vendor
- github.com/kataras/iris/v12/context
- query-tests
- Diagnostics
- Security/CWE-681
- Summary/vendor/github.com/github/codeql-go/extractor/util
- javascript
- extractor
- lib/typescript/src
- src/com/semmle
- jcorn
- flow
- js
- ast
- extractor
- tests
- esnext
- input
- output/trap
- vue
- input
- output/trap
- ql
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- filters
- frameworks
- AngularJS
- internal
- security
- dataflow
- performance
- src
- Security/CWE-400
- change-notes
- released
- experimental/semmle/javascript
- test
- ApiGraphs/tagged-template
- library-tests
- AMD
- CallGraphs/FullTest
- TaintTracking
- TypeScript/ImportAssertions
- java
- documentation/library-coverage
- kotlin-extractor
- src/main
- java/com/semmle/extractor/java
- kotlin
- utils/versions
- v_1_5_0
- v_1_8_0
- ql
- automodel
- src
- change-notes/released
- test/AutomodelApplicationModeExtraction
- integration-tests/all-platforms
- java
- buildless-maven
- buildless
- kotlin/trap_compression
- lib
- change-notes
- released
- config
- ext
- threatmodels
- semmle/code/java
- controlflow/internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- deadcode
- frameworks
- camel
- hudson
- javaee
- struts
- security
- performance
- regexp
- src
- Likely Bugs/Comparison
- Security/CWE/CWE-352
- Telemetry
- change-notes
- released
- experimental/Security/CWE
- CWE-020
- CWE-036
- CWE-073
- CWE-078
- CWE-089
- CWE-094
- CWE-200
- CWE-208
- CWE-346
- CWE-352
- CWE-400
- CWE-470
- CWE-552
- CWE-600
- CWE-601
- CWE-652
- CWE-755
- meta/frameworks
- test
- experimental/query-tests/security/CWE-400
- kotlin/library-tests/java-kotlin-collection-type-generic-methods
- library-tests
- MemberRefExpr
- dataflow
- entrypoint-types
- threat-models
- frameworks
- JaxWs
- android
- content-provider
- external-storage
- slice
- sources
- apache-collections
- apache-http
- guice
- jms
- netty/manual
- rabbitmq
- ratpack
- spring/controller
- sensitive-actions
- types/record-classes
- query-tests/security/CWE-352
- CONSISTENCY
- stubs
- apache-mina-sshd-2.8.0/org/apache/sshd/common/util/threads
- springframework-5.3.8/org/springframework/security/config/annotation/web
- builders
- configurers
- misc
- scripts/library-coverage
- suite-helpers
- change-notes/released
- python
- ql
- lib
- change-notes
- released
- experimental/cryptography
- modules
- stdlib
- utils
- semmle/python
- dataflow/new
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- frameworks
- internal
- security
- dataflow
- performance
- strings
- web
- bottle
- cherrypy
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- webob
- src
- change-notes
- released
- experimental
- cryptography
- example_alerts
- inventory
- new_models
- old_models
- semmle/python/security
- test
- experimental
- dataflow
- coverage
- typetracking
- query-tests/Security/CWE-022-TarSlip
- library-tests
- ApiGraphs/py3
- frameworks
- joblib
- numpy
- pandas
- query-tests/Security
- CWE-020-SuspiciousRegexpRange
- CWE-502-UnsafeDeserialization
- ql
- buramu
- extractor
- ql/src
- ruby/ql
- lib
- change-notes
- released
- codeql/ruby
- ast
- dataflow
- internal
- tainttracking1
- frameworks
- core/internal
- security
- performance
- regexp
- src
- change-notes/released
- experimental/cwe-347
- examples
- queries/security
- cwe-134
- cwe-912
- test
- library-tests
- dataflow/barrier-guards
- frameworks/graphql
- app/graphql/types
- query-tests
- experimental/cwe-347
- security/cwe-078/CommandInjection
- swift
- downgrades
- c0db61944f46ba5507f207ec2b1cff77ad0529a1
- dd1bfe298d87cd82cb0d26e3349ada7244778785
- extractor
- translators
- ql
- lib
- change-notes
- released
- codeql/swift
- controlflow/internal
- dataflow/internal
- tainttracking1
- elements
- expr
- stmt
- frameworks
- SQL
- StandardLibrary
- generated
- stmt
- security
- upgrades
- dd1bfe298d87cd82cb0d26e3349ada7244778785
- f5a22f5168adfd7f308b5941c11852c925edd638
- src
- change-notes
- released
- queries/Summary
- test
- extractor-tests
- generated/decl
- ClassDecl
- ConcreteVarDecl
- EnumDecl
- updates
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- taint
- core
- libraries
- elements/expr/methodlookup
- query-tests/Security
- CWE-078
- CWE-1204
- CWE-135
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-760
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,369 files changed
+93130
-15149
lines changedLines changed: 23 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + |
Lines changed: 22 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
18 | 22 |
| |
19 | 23 |
| |
| 24 | + | |
20 | 25 |
| |
21 | 26 |
| |
22 | 27 |
| |
23 | 28 |
| |
24 |
| - | |
25 |
| - | |
26 | 29 |
| |
27 |
| - | |
28 |
| - | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
29 | 40 |
| |
30 |
| - | |
31 |
| - | |
32 | 41 |
| |
33 |
| - | |
34 |
| - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
| |
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
37 |
| - | |
| 37 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
91 | 91 |
| |
92 | 92 |
| |
93 | 93 |
| |
94 |
| - | |
| 94 | + | |
95 | 95 |
| |
96 | 96 |
| |
97 | 97 |
| |
|
Lines changed: 0 additions & 16 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
498 | 498 |
| |
499 | 499 |
| |
500 | 500 |
| |
501 |
| - | |
502 |
| - | |
503 |
| - | |
504 |
| - | |
505 |
| - | |
506 |
| - | |
507 |
| - | |
508 |
| - | |
509 |
| - | |
510 |
| - | |
511 |
| - | |
512 |
| - | |
513 |
| - | |
514 |
| - | |
515 |
| - | |
516 |
| - | |
517 | 501 |
| |
518 | 502 |
| |
519 | 503 |
| |
|
Lines changed: 7 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 | 1 |
| |
4 | 2 |
| |
| 3 | + | |
| 4 | + | |
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
10 | 15 |
| |
11 | 16 |
| |
12 | 17 |
| |
|
Lines changed: 19 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + |
0 commit comments