File tree
9,452 files changed
+806837
-181983
lines changed- .devcontainer
- .github
- codeql
- workflows
- .vscode
- change-notes
- 1.25
- 1.26
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- change-notes
- config/suites/cpp
- ql
- examples/snippets
- src
- Architecture
- General Class-Level Information
- General Namespace-Level Information
- Refactoring Opportunities
- Best Practices
- Exceptions
- Hiding
- Likely Errors
- Magic Constants
- Unused Entities
- Critical
- Diagnostics
- Documentation
- JPL_C
- LOC-2
- Rule 05
- Rule 07
- Rule 09
- Rule 11
- LOC-3/Rule 17
- LOC-4/Rule 21
- Likely Bugs
- Arithmetic
- Conversion
- Format
- Leap Year
- Likely Typos
- Memory Management
- Padding
- OO
- Underspecified Functions
- Metrics
- Dependencies
- Files
- Microsoft
- Power of 10
- Rule 4
- Rule 5
- Security/CWE
- CWE-014
- CWE-020
- ir
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-114
- CWE-119
- CWE-120
- CWE-121
- CWE-129
- CWE-131
- CWE-134
- CWE-170
- CWE-190
- CWE-191
- CWE-253
- CWE-290
- CWE-311
- CWE-313
- CWE-327
- CWE-367
- CWE-428
- CWE-457
- CWE-468
- CWE-497
- CWE-570
- CWE-676
- CWE-704
- CWE-732
- CWE-764
- CWE-807
- CWE-835
- Summary
- codeql-suites
- experimental
- Likely Bugs
- Security/CWE
- CWE-020
- CWE-089
- CWE-1126
- CWE-120
- CWE-190
- CWE-359
- CWE-401
- CWE-415
- CWE-691
- CWE-783
- CWE-788
- semmle/code/cpp
- models/interfaces
- rangeanalysis
- extensions
- security
- external
- tests
- filters
- jsf
- 4.05 Libraries
- 4.06 Pre-Processing Directives
- 4.07 Header Files
- 4.09 Style
- 4.10 Classes
- 4.12 Templates
- 4.13 Functions
- 4.15 Declarations and Definitions
- 4.16 Initialization
- 4.17 Types
- 4.18 Constants
- 4.20 Unions and Bit Fields
- 4.21 Operators
- 4.24 Control Flow Structures
- semmle
- code/cpp
- commons
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- exprs
- headers
- internal
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- metrics
- models
- implementations
- interfaces
- rangeanalysis
- security
- stmts
- uml
- test
- TestUtilities
- dataflow
- duplication-tests
- constants
- duplicate_functions
- tokenising
- examples/expressions
- experimental
- library-tests/rangeanalysis
- bitwiseand
- extended
- extensibility
- query-tests/Security/CWE
- CWE-020/semmle/tests
- CWE-1126/semmle/tests
- CWE-190/AllocMultiplicationOverflow
- CWE-359/semmle/tests
- CWE-401/semmle/tests
- CWE-415/semmle/tests
- CWE-691/semmle/tests
- CWE-788/semmle/tests
- semmle/tests
- header-variant-tests
- deduplication
- functions-in-headers
- include
- library-tests
- CPP-205
- access/canAccessMember
- arguments
- atomic
- blocks/cpp
- c++_exceptions
- clang_c99_default
- clang_ms
- classes/variadic
- conditions
- conversions
- cpp_builtin_types
- bool
- wchar_t
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- globals
- dataflow-tests
- fields
- security-taint
- smart-pointers-taint
- taint-tests
- declarationEntry/more
- declaration
- default_parameters
- defuse
- depends_initializers
- exprs/unevaluated
- fun_decl
- functions/functions
- identifiers/qualified_names
- instantiations
- ir
- ir
- points_to
- ssa
- lambdas
- calling_conv
- captures
- cfg
- locations/charloc
- macros
- inmacroexpansion
- macros
- members/getters
- multiple_declarations/functions
- namespaces
- namespaces
- same_name
- noexcept/copy_from_prototype
- parameters
- catch
- parameters
- pointsto/basic
- ptr_to_member/segfault
- question_mark_colon
- rangeanalysis/SimpleRangeAnalysis
- scopes
- parents
- scopes
- sideEffects/functions
- special_members
- detect
- generated_copy
- specifiers2
- structs
- compatible_cpp
- incomplete_definition
- switch
- syntax-zoo
- templates
- CPP-202
- CPP-203
- CPP-204
- CPP-223
- decls
- extern
- friends
- instantiations_functions
- isfromtemplateinstantiation
- variables
- typedefs
- types
- cstd_types
- types
- unspecified
- udl
- unions
- unnamed
- unspecified_type/unspecified_type
- valuenumbering/GlobalValueNumbering
- variables
- constexpr
- getanassignedvalue
- global
- thread_local
- variables
- vector_types
- virtual_functions/cfg
- vla
- query-tests
- Best Practices
- Hiding/DeclarationHidesParameter
- Unused Entities/UnusedLocals
- Critical
- MemoryFreed
- MissingNullTest
- NewFree
- SizeCheck
- UnsafeUseOfThis
- Likely Bugs
- Arithmetic
- IntMultToLong
- PointlessComparison
- Format
- NonConstantFormat
- WrongNumberOfFormatArguments
- WrongTypeFormatArguments
- Linux_signed_chars
- Linux_two_byte_wprintf
- Likely Typos/AssignWhereCompareMeant
- Memory Management
- ReturnStackAllocatedMemory
- SuspiciousCallToStrncat
- Underspecified Functions
- Security/CWE
- CWE-014
- CWE-022/semmle/tests
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114/semmle/UncontrolledProcessOperation
- CWE-119/semmle/tests
- CWE-120/semmle/tests
- CWE-131/semmle
- SizeCheck2
- SizeCheck
- CWE-134/semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190/semmle
- ComparisonWithWiderType
- TaintedAllocationSize
- extreme
- tainted
- uncontrolled
- CWE-191/UnsignedDifferenceExpressionComparedZero
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-327
- CWE-570
- CWE-764/semmle/tests
- CWE-807/semmle/TaintedCondition
- Summary
- definitions
- jsf/4.10 Classes/AV Rule 79
- successor-tests
- block/emptyblock
- conditional_destructors
- dostmt
- forstmt/shortforstmt
- ifstmt
- ifelsestmt
- ifstmt
- stackvariables/stackvariables
- whilestmt
- upgrades
- 098850d25c4e9d417eb74c1bef9deb2f9d2dc417
- 75da61c94e19ae80a142f03a877ab9d0728752bc
- b5fa4fb0283c4accf2d85d559aeb2bba914c102b
- c82db4c596b8979eba9a8958e24353a5756d7a02
- ef73d8cf906d356a00a10d0e8dc0e1c1e66d210c
- csharp
- .vscode
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- change-notes
- config
- suites/lgtm
- tracer/linux
- documentation/library-coverage
- extractor
- Semmle.Extraction.CIL.Driver
- Semmle.Extraction.CIL
- Entities
- Base
- PDB
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Comments
- Entities
- Compilations
- Expressions
- ObjectCreation
- Patterns
- PreprocessorDirectives
- Statements
- Types
- Extractor
- Kinds
- Populators
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities
- Base
- Extractor
- Semmle.Util.Tests
- Semmle.Util
- ql
- examples/snippets
- src
- API Abuse
- Architecture/Refactoring Opportunities
- Bad Practices
- Comments
- Control-Flow
- Implementation Hiding
- Concurrency
- Configuration
- Dead Code
- Diagnostics
- Documentation
- Input Validation
- Language Abuse
- Likely Bugs
- Collections
- Linq
- Metrics
- Dependencies
- Files
- RefTypes
- Summaries
- Security Features
- CWE-011
- CWE-016
- CWE-020
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-091
- CWE-094
- CWE-099
- CWE-112
- CWE-114
- CWE-117
- CWE-119
- CWE-134
- CWE-201
- CWE-209
- CWE-248
- CWE-312
- CWE-321
- CWE-327
- CWE-352
- CWE-359
- CWE-384
- CWE-451
- CWE-502
- CWE-548
- CWE-601
- CWE-611
- CWE-614
- CWE-643
- CWE-730
- CWE-798
- CWE-807
- CWE-838
- CWE-937
- Stubs
- Useless code
- codeql-suites
- experimental
- CWE-099
- Security Features
- Serialization
- backdoor
- campaign
- Solorigate
- code/csharp/Cryptography
- ir
- implementation
- internal
- raw
- internal
- desugar
- unaliased_ssa
- internal
- internal
- external
- examples/filters
- tests
- filters
- meta/frameworks
- semmle/code
- cil
- internal
- csharp
- commons
- controlflow
- internal
- pressa
- dataflow
- internal
- basessa
- rangeanalysis
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- dispatch
- exprs
- frameworks
- microsoft
- system
- data
- linq
- runtime
- text
- threading
- xml
- test
- metrics
- security
- cryptography
- dataflow
- flowsinks
- flowsources
- xml
- serialization
- dotnet
- test
- experimental
- Security Features
- Serialization
- backdoor
- campaign/Solorigate
- ir/ir
- library-tests
- aliases
- arguments
- assemblies
- assignables
- assignments
- async
- attributes
- cil
- attributes
- consistency
- dataflow
- enums
- functionPointers
- init-only-prop
- pdbs
- regressions
- typeAnnotations
- comments
- commons
- Assertions
- Disposal
- GeneratedCode
- TargetFramework
- compilations
- constructors
- controlflow
- graph
- guards-large
- guards
- splits
- conversion
- boxing
- identity
- nullable
- operator
- pointer
- reftype
- csharp6
- csharp7.1
- csharp7.2
- csharp7.3
- csharp7
- csharp8
- csharp9
- dataflow
- async
- call-sensitivity
- collections
- defuse
- delegates
- external-models
- fields
- flowsources/remote
- functionpointers
- global
- library
- local
- modulusanalysis
- signanalysis
- ssa
- tuples
- types
- definitions
- delegates
- diagnostics
- dispatch
- dynamic
- encoding
- enums
- events
- exceptions
- expressions
- exprorstmtparent
- extension-method-call
- extractor/tagstack
- fields
- filters/ClassifyFiles
- frameworks
- EntityFramework
- JsonNET
- NHibernate
- system
- Dispose
- System
- data/entity
- test
- generics
- goto
- indexers
- initializers
- linq
- members
- methods
- modifiers
- namespaces
- nestedtypes
- nullable
- operators
- overrides
- parameters
- partial
- properties
- regressions
- security/dataflow/flowsources
- standalone
- controlflow
- errorrecovery
- regressions
- standalonemode
- statements
- tostringwithtypes
- tuples
- typeMentions
- types
- unification
- unsafe
- query-tests
- API Abuse
- DisposeNotCalledOnException
- FormatInvalid
- FormatMissingArgument
- FormatUnusedArgument
- InconsistentEqualsGetHashCode
- MissingDisposeCall
- MissingDisposeMethod
- NoDisposeCallOnLocalIDisposable
- NonOverridingMethod
- Architecture/Dependencies/MutualDependency
- Bad Practices
- Control-Flow/ConstantCondition
- Declarations/LocalScopeVariableShadowsMember
- Naming Conventions/VariableNameTooShort
- CSI/CompareIdenticalValues
- Concurrency
- LockOrder
- SynchSetUnsynchGet
- UnsafeLazyInitialization
- UnsynchronizedStaticAccess
- Dead Code
- DeadStoreOfLocal
- Tests
- Language Abuse
- DubiousTypeTestOfThis
- ForeachCapture
- UselessCastToSelf
- UselessUpcast
- Likely Bugs
- BadCheckOdd
- Collections/ContainerSizeCmpZero
- ConstantComparison
- HashedButNoHash
- SelfAssignment
- ThreadUnsafeICryptoTransformLambda
- ThreadUnsafeICryptoTransform
- MagicConstants
- Metrics
- Dependencies/ExternalDependencies
- Files/FLinesOfDuplicatedCode
- Summaries
- Nullness
- ReadOnlyContainer
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-248/MissingASPNETGlobalErrorHandler
- WebConfigOffButGlobal
- WebConfigOff
- CWE-312
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsufficientKeySize
- CWE-338
- CWE-352
- global
- missing
- CWE-359
- CWE-384
- CWE-451/MissingXFrameOptions
- CodeAddedHeader
- NoHeader
- WebConfigAddedHeader
- CWE-502
- DeserializedDelegate
- UnsafeDeserializationUntrustedInput
- UnsafeDeserialization
- CWE-539/PersistentCookie
- CWE-601/UrlRedirect
- CWE-611
- CWE-614/RequireSSL/AddedInCode
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- CWE-838
- CWE-937
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
9,452 files changed
+806837
-181983
lines changedLines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
3 | 4 |
| |
4 | 5 |
| |
5 | 6 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
7 |
| - | |
| 7 | + | |
8 | 8 |
| |
9 | 9 |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
| 10 | + | |
| 11 | + |
Lines changed: 23 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + |
Lines changed: 30 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + |
Lines changed: 17 additions & 13 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2 | 2 |
| |
3 | 3 |
| |
4 | 4 |
| |
| 5 | + | |
| 6 | + | |
| 7 | + | |
5 | 8 |
| |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
6 | 14 |
| |
7 | 15 |
| |
8 | 16 |
| |
| |||
11 | 19 |
| |
12 | 20 |
| |
13 | 21 |
| |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
14 | 27 |
| |
15 | 28 |
| |
16 | 29 |
| |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
26 |
| - | |
| 30 | + | |
27 | 31 |
| |
28 | 32 |
| |
29 |
| - | |
| 33 | + | |
30 | 34 |
| |
31 | 35 |
| |
32 | 36 |
| |
| |||
35 | 39 |
| |
36 | 40 |
| |
37 | 41 |
| |
38 |
| - | |
| 42 | + | |
39 | 43 |
| |
40 | 44 |
| |
41 | 45 |
| |
| |||
49 | 53 |
| |
50 | 54 |
| |
51 | 55 |
| |
52 |
| - | |
| 56 | + |
Lines changed: 97 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + |
Lines changed: 34 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + |
Lines changed: 42 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + |
Lines changed: 44 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + |
0 commit comments