File tree
2,520 files changed
+189041
-40588
lines changed- .devcontainer/swift
- config
- cpp
- downgrades
- 25e365d1e8147df0f759b604f96eb4bffea48271
- 3d35dd6b50edfc540c14c6757e0c7b3c5b7b04dd
- 68930f3b81bbe3fdbb91c850deca1fec8072d62a
- 9629fc87dab7dbed0771bf5ce22bce4d7f943b52
- e197626a6ebccd052d5c891975fccf8aebcc9803
- ql
- lib
- change-notes
- released
- ext
- allocation
- deallocation
- semmle/code/cpp
- controlflow
- dataflow
- internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- internal
- raw
- gvn/internal
- internal
- unaliased_ssa
- gvn/internal
- internal
- models
- implementations
- interfaces
- upgrades
- 25e365d1e8147df0f759b604f96eb4bffea48271
- 3d35dd6b50edfc540c14c6757e0c7b3c5b7b04dd
- 9629fc87dab7dbed0771bf5ce22bce4d7f943b52
- abfce5c170f93e281948f7689ece373464fdaf87
- e197626a6ebccd052d5c891975fccf8aebcc9803
- src
- Critical
- Likely Bugs
- Format
- Memory Management
- Security/CWE
- CWE-014
- CWE-191
- CWE-311
- CWE-313
- CWE-367
- CWE-416
- CWE-570
- CWE-732
- change-notes/released
- test
- experimental/query-tests/Security/CWE/CWE-409
- library-tests
- allocators
- arguments
- array_sizes
- atomic
- attributes
- routine_attributes
- type_attributes
- var_attributes
- builtins/type_traits
- dataflow
- calls-as-ssa-variables
- dataflow-tests
- external-models
- models-as-data
- taint-tests
- declarationEntry
- declarationEntry
- more
- declaration
- deduction_guides
- depends_initializers
- exprs/unevaluated
- functions/functions
- identifiers/qualified_names
- instantiations
- ir
- ir
- points_to
- ssa
- members
- getters
- templates
- noexcept
- copy_from_prototype
- noexcept
- scopes/scopes
- special_members/generated_copy
- specifiers2
- syntax-zoo
- templates
- CPP-203
- friends
- incomplete_instantiations
- isfromtemplateinstantiation
- types/refersTo
- valuenumbering/GlobalValueNumbering
- query-tests
- Critical
- MemoryFreed
- MissingCheckScanf
- SizeCheck
- Likely Bugs
- Format/WrongTypeFormatArguments
- Linux_mixed_byte_wprintf
- Linux_mixed_word_size
- Linux_signed_chars
- Linux_two_byte_wprintf
- Linux_unsigned_chars
- Microsoft_no_wchar
- Microsoft
- Memory Management/SuspiciousCallToStrncat
- Security/CWE
- CWE-191/UnsignedDifferenceExpressionComparedZero
- CWE-416/semmle/tests/IteratorToExpiredContainer
- CWE-457/semmle/tests
- CWE-497/semmle/tests
- CWE-570
- successor-tests/forstmt/rangebasedforstmt
- csharp
- autobuilder
- Semmle.Autobuild.CSharp
- Semmle.Autobuild.Cpp
- downgrades/15b989afd2bfc4743536fdb0958c1d8177a32600
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp.Util
- Semmle.Extraction.CSharp
- Comments
- Entities
- Compilations
- Expressions
- Patterns
- PreprocessorDirectives
- Types
- Extractor
- Populators
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities
- Extractor
- Semmle.Util
- Logging
- Testrunner
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- autobuild
- binlog
- a
- b
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- msbuild
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_failed
- standalone_resx
- standalone_winforms
- standalone
- linux-only
- compiler_args
- standalone_dependencies_non_utf8_filename
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- standalone_dependencies_executing_runtime
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- standalone_dependencies_nuget_no_sources
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- standalone_dependencies
- lib
- change-notes
- released
- semmle/code
- cil
- internal
- csharp
- controlflow/internal
- dataflow
- internal
- rangeanalysis
- dispatch
- internal
- security/xml
- upgrades/fd04e45710e1988076801608abffdfa013b680fc
- src
- Concurrency
- Dead Code
- Documentation
- Telemetry
- change-notes
- released
- utils
- modelconverter
- modelgenerator
- internal
- test
- library-tests
- assignables
- csharp7
- dataflow
- async
- collections
- defuse
- external-models
- global
- library
- ssa
- threat-models
- exprorstmtparent
- query-tests/Documentation
- utils/modelgenerator/dataflow
- docs
- codeql
- codeql-language-guides
- codeql-overview
- codeql-changelog
- query-help
- reusables
- ql-libraries/dataflow
- go
- documentation/library-coverage
- extractor
- dbscheme
- project
- toolchain
- trap
- util
- vendor
- golang.org/x
- mod
- internal/lazyregexp
- modfile
- module
- semver
- tools
- go
- gcexportdata
- internal/packagesdriver
- packages
- types/objectpath
- internal
- event
- core
- keys
- label
- tag
- gcimporter
- gocommand
- packagesinternal
- pkgbits
- tokeninternal
- typeparams
- typesinternal
- versions
- integration-tests-lib
- ql
- consistency-queries
- change-notes/released
- integration-tests
- all-platforms/go
- bazel-sample-1
- bazel-sample-2
- diagnostics
- build-constraints-exclude-all-go-files
- go-files-found-not-processed
- invalid-toolchain-version
- newer-go-version-needed
- no-go-files-found
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- unsupported-relative-path
- extract-vendor
- src
- vendor
- example.com/test
- go-get-without-modules-sample
- go-mod-sample
- go-mod-without-version
- go-version-bump
- make-sample
- mixed-layout
- ninja-sample
- resolve-build-environment/newer-go-needed
- single-go-mod-and-go-files-not-under-it
- single-go-mod-in-root
- single-go-mod-not-in-root
- single-go-work-not-in-root
- two-go-mods-nested-none-in-root
- two-go-mods-nested-one-in-root
- two-go-mods-not-nested
- two-go-mods-one-failure
- linux-only/go
- dep-sample
- glide-sample
- lib
- change-notes
- released
- ext
- semmle/go
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- Security/CWE-322
- change-notes/released
- experimental
- CWE-918
- frameworks
- test
- TestUtilities
- experimental
- CWE-090
- CWE-203
- CWE-287
- CWE-369
- CWE-522-DecompressionBombs
- CWE-74
- CWE-79
- CWE-918
- library-tests/semmle/go
- concepts/HTTP
- dataflow
- DefaultTaintSanitizer
- ExternalTaintFlow
- ExternalValueFlow
- HiddenNodes
- ThreatModels
- frameworks
- BeegoOrm
- Beego
- Chi
- Echo
- Encoding
- Fasthttp
- Gin
- Gorestful
- Revel
- Twirp
- WebSocket
- XNetHtml
- query-tests/Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-312
- CWE-327
- CWE-338/InsecureRandomness
- CWE-347
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- vendor/github.com/antchfx/xpath
- CWE-918
- javascript
- extractor
- lib/typescript
- src/com/semmle
- jcorn
- js/extractor
- tests/flow
- input
- output/trap
- ql
- integration-tests
- all-platforms
- diagnostics
- internal-error
- syntax-error
- no-types
- lib
- change-notes
- released
- semmle/javascript
- frameworks
- helmet
- security
- dataflow
- domains
- IntegrityCheckingRequired
- compromised
- untrusted
- src
- Security
- CWE-693
- examples
- CWE-830
- change-notes/released
- experimental/Security/CWE-942
- examples
- test
- experimental/Security/CWE-942
- library-tests
- Modules
- TypeScript/Types
- query-tests/Security
- CWE-693
- CWE-798
- __tests__
- CWE-830
- java
- documentation/library-coverage
- integration-tests-lib
- kotlin-extractor
- deps
- dev
- src/main
- java/com/semmle
- extractor/java
- util/process
- kotlin
- utils/versions/v_2_0_20-Beta2
- ql
- automodel/src
- change-notes/released
- integration-tests/all-platforms
- java
- buildless-dependency-different-repository
- buildless-erroneous
- buildless-gradle-classifiers
- gradle/wrapper
- src/main/java/com/fractestexample
- buildless-gradle-timeout
- buildless-inherit-trust-store
- buildless-maven-executable-war
- src
- main
- java/com/example
- resources
- test/java/com/example
- buildless-maven-multimodule
- buildless-maven-timeout
- buildless-maven
- buildless-proxy-gradle
- gradle/wrapper
- src/main/java/com/fractestexample
- buildless-proxy-maven
- src
- main
- java/com/example
- resources
- test/java/com/example
- buildless-snapshot-repository
- diagnostics
- dependency-error
- maven-http-repository
- ecj-tolerate-enum-annotations
- java-web-jsp
- maven-enforcer
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-sample-extract-properties
- maven-sample-large-xml-files
- maven-sample-small-xml-files
- maven-sample-xml-mode-all
- maven-sample-xml-mode-byname
- maven-sample-xml-mode-disabled
- maven-sample-xml-mode-smart
- maven-sample
- kotlin/diagnostics/kotlin-version-too-new
- lib
- change-notes
- released
- ext
- experimental
- semmle/code
- java
- dataflow
- internal
- frameworks
- android
- regex
- security
- internal
- xml
- src
- Metrics/Summaries
- Security/CWE
- CWE-209
- CWE-319
- Telemetry
- Violations of Best Practice/Dead Code
- change-notes
- released
- experimental
- Security/CWE/CWE-522-DecompressionBombs
- semmle/code/java/security
- utils/modelgenerator
- internal
- test
- TestUtilities
- experimental
- query-tests/security
- CWE-020
- CWE-022
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- NotConstantTimeCheckOnSignature
- TimingAttackAgainstSignagure
- CWE-299
- CWE-327
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-502
- CWE-522-DecompressionBombs
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- stubs
- apache-commons-compress-1.23.0/org
- apache/commons/compress
- archivers
- arj
- ar
- cpio
- jar
- zip
- compressors
- brotli
- bzip2
- deflate64
- deflate
- gzip
- lz4
- lz77support
- lzma
- lzw
- pack200
- snappy
- xz
- zstandard
- z
- utils
- xerial/snappy
- lingala-zip4j-2.11.5/net/lingala/zip4j
- headers
- io/inputstream
- model
- enums
- progress
- util
- reactivestreams-1.0.4/org/reactivestreams
- software-amazon-awssdk-crt-0.20.3/software/amazon/awssdk
- auth/credentials
- awscore
- client/builder
- defaultsmode
- eventstream
- core
- async
- client
- builder
- config
- document
- exception
- interceptor
- internal
- io
- waiters
- io
- protocol
- retry
- backoff
- conditions
- signer
- sync
- traits
- waiters
- endpoints
- http
- async
- metrics
- profiles
- regions
- services/s3
- endpoints
- model
- paginators
- waiters
- transfer/s3
- config
- model
- progress
- utils
- builder
- zstd-jni-1.5.5/com/github/luben/zstd
- library-tests
- dataflow
- call-sensitivity
- flowfeature
- local-additional-taint
- taintsources
- threat-models
- frameworks
- JaxWs
- jdk/java.net
- lastaflute
- query-tests
- DeadCode/DeadRefTypes
- Metrics/GeneratedVsManualCoverage/ApacheCommonsIoTest
- security
- CWE-022/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests/TempDirLocalInformationDisclosure
- CWE-209/semmle/tests
- CWE-295/AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- CWE-297
- CWE-311/CWE-319
- CWE-327/semmle/tests
- CWE-532
- CWE-601/semmle/tests
- CWE-681/semmle/tests
- CWE-807/semmle/tests
- stubs
- lastaflute/org/lastaflute/web
- ruts/multipart
- springframework-5.3.8/org/springframework/core/io
- utils/modelgenerator/dataflow
- p
- misc
- bazel
- internal
- registry/modules/rules_nodejs
- 6.2.0-codeql.1
- patches
- scripts/models-as-data
- suite-helpers
- change-notes/released
- python
- extractor/semmle
- ql
- lib
- change-notes/released
- modeling
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- internal
- security/dataflow
- src
- Security
- CWE-020
- examples
- CWE-614
- examples
- CWE-798
- change-notes
- released
- experimental
- Security
- CWE-094
- CWE-614
- semmle/python
- frameworks
- security/injection
- utils/modeleditor
- test
- experimental
- meta
- query-tests/Security
- CWE-022-TarSlip
- CWE-094
- CWE-614
- library-tests
- dataflow
- model-summaries
- tainttracking/isinstance
- frameworks
- aiohttp
- data
- django-v2-v3
- fabric
- fastapi
- flask
- gradio
- pyramid
- rest_framework
- testapp
- stdlib
- streamlit
- tornado
- twisted
- modelling
- MyPackage
- NotPackage
- not-valid-package
- query-tests/Security
- CWE-020-CookieInjection
- CWE-614-InsecureCookie
- ruby
- downgrades/40a6b0a5e81115bd870b3a12a1fe954b06362bb7
- extractor
- ql
- integration-tests
- all-platforms
- diagnostics
- syntax-error
- unknown-encoding
- lib
- change-notes
- released
- codeql/ruby
- ast/internal
- controlflow/internal
- dataflow
- internal
- frameworks/http_clients
- security
- upgrades/63af05c01bdd6a38f280e41ac0453db52f46989c
- src
- change-notes/released
- queries/security/cwe-327
- examples
- test
- library-tests
- dataflow
- global
- local
- summaries
- modules
- query-tests/security
- cwe-327
- cwe-506
- swift
- ql
- integration-tests
- autobuilder/unsupported-os
- linux-only
- RegexLiteralExpr
- autobuilder/unsupported-os
- osx-only
- autobuilder
- failure
- no-build-system
- no-swift-with-spm
- no-swift
- no-xcode-with-spm
- only-tests-with-spm
- only-tests
- xcode-fails-spm-works
- canonical-case
- hello-xcode
- posix-only
- cross-references
- deduplication
- frontend-invocations
- hello-world
- linkage-awareness
- partial-modules
- symlinks
- lib
- change-notes/released
- codeql/swift
- dataflow
- internal
- frameworks/StandardLibrary
- security
- src
- change-notes/released
- queries/Security
- CWE-089
- CWE-311
- CWE-312
- CWE-321
- CWE-327
- CWE-760
- test
- library-tests/dataflow
- flowsources
- taint
- core
- libraries
- query-tests/Security
- CWE-078
- CWE-311
- CWE-321
- CWE-327
- CWE-760
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,520 files changed
+189041
-40588
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
.devcontainer/swift/root.sh
100644
100755
Lines changed: 13 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
6 | 16 |
| |
7 | 17 |
| |
8 | 18 |
| |
9 | 19 |
| |
10 | 20 |
| |
11 | 21 |
| |
12 | 22 |
| |
13 |
| - | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
14 | 26 |
| |
15 | 27 |
| |
16 | 28 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
3 | 5 |
| |
4 | 6 |
| |
5 | 7 |
| |
|
Lines changed: 15 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
17 |
| - | |
| 17 | + | |
18 | 18 |
| |
19 |
| - | |
| 19 | + | |
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 | 25 |
| |
26 |
| - | |
| 26 | + | |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
| 29 | + | |
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
| |||
85 | 85 |
| |
86 | 86 |
| |
87 | 87 |
| |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
88 | 92 |
| |
89 | 93 |
| |
90 | 94 |
| |
| |||
108 | 112 |
| |
109 | 113 |
| |
110 | 114 |
| |
| 115 | + | |
111 | 116 |
| |
112 | 117 |
| |
113 | 118 |
| |
| |||
120 | 125 |
| |
121 | 126 |
| |
122 | 127 |
| |
| 128 | + | |
123 | 129 |
| |
124 | 130 |
| |
125 | 131 |
| |
| |||
132 | 138 |
| |
133 | 139 |
| |
134 | 140 |
| |
| 141 | + | |
135 | 142 |
| |
136 | 143 |
| |
137 | 144 |
| |
138 | 145 |
| |
139 | 146 |
| |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
140 | 151 |
| |
141 | 152 |
| |
142 | 153 |
| |
|
Lines changed: 0 additions & 9 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
61 | 61 |
| |
62 | 62 |
| |
63 | 63 |
| |
64 |
| - | |
65 |
| - | |
66 |
| - | |
67 |
| - | |
68 | 64 |
| |
69 | 65 |
| |
70 | 66 |
| |
| |||
185 | 181 |
| |
186 | 182 |
| |
187 | 183 |
| |
188 |
| - | |
189 |
| - | |
190 |
| - | |
191 |
| - | |
192 |
| - | |
193 | 184 |
| |
194 | 185 |
| |
195 | 186 |
| |
|
0 commit comments