File tree
5,684 files changed
+440419
-115551
lines changed- .github
- workflows
- actions/ql
- integration-tests/query-suite
- lib
- change-notes/released
- codeql/actions
- security
- ext/config
- src
- Models
- Security
- CWE-077
- CWE-094
- CWE-1395
- CWE-275
- CWE-285
- CWE-312
- CWE-349
- CWE-367
- CWE-571
- CWE-829
- Violations Of Best Practice/CodeQL
- change-notes/released
- codeql-suites
- experimental/Security
- CWE-088
- CWE-829
- test/query-tests/Security
- CWE-094/.github/workflows
- CWE-275
- .github/workflows
- config
- cpp
- downgrades
- 3c45f8b9e71ec723bf50c40581e1f18f4f25e290
- 5340d6d5f428557632b1a50113e406430f29ef7d
- 5491582ac8511726e12fae3e2399000f9201cd9a
- 59cb96ca699929b63941e81905f9b8de7eed59a6
- 7bc12b02a4363149f0727a4bce07952dbb9d98aa
- 801b2f03360d78c85f51fbad9b75956fa8d58b00
- 827dbc206ea55377e032a8a934c8903fedc50fa0
- 9baef67d1ffc1551429dbe1c1130815693e28218
- a8c2176e9a5cf9be8d17053a4c8e7e56b5aced6d
- af887e83a815a9cefe774ffa80e2493a1365b9e2
- e38346051783182ea75822e4adf8d4c6a949bc37
- e70d0b653187b93d9688f21c9db46bb1cd46ab78
- ql
- integration-tests
- header-variant-tests/clang-pch
- query-suite
- lib
- change-notes
- released
- experimental
- quantum
- OpenSSL
- AlgorithmInstances
- AlgorithmValueConsumers
- Operations
- semmle/code/cpp/security
- ext
- generated
- brotli
- curl
- glibc
- libidn2
- libssh2
- libuv
- nghttp2
- openssl
- sqlite
- zlib
- semmle/code/cpp
- dataflow
- internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn
- raw
- gvn
- internal
- unaliased_ssa
- gvn
- internal
- models/interfaces
- rangeanalysis/new
- internal/semantic
- analysis
- security
- stmts
- upgrades
- 3c45f8b9e71ec723bf50c40581e1f18f4f25e290
- 5491582ac8511726e12fae3e2399000f9201cd9a
- 7bc12b02a4363149f0727a4bce07952dbb9d98aa
- 801b2f03360d78c85f51fbad9b75956fa8d58b00
- 827dbc206ea55377e032a8a934c8903fedc50fa0
- 9a7c3c14c1076f64b871719117a558733d987b48
- 9baef67d1ffc1551429dbe1c1130815693e28218
- a8c2176e9a5cf9be8d17053a4c8e7e56b5aced6d
- af887e83a815a9cefe774ffa80e2493a1365b9e2
- e38346051783182ea75822e4adf8d4c6a949bc37
- e70d0b653187b93d9688f21c9db46bb1cd46ab78
- utils/test
- src
- Critical
- Likely Bugs
- Conversion
- Memory Management
- Metrics/Dependencies
- Security/CWE
- CWE-089
- CWE-114
- CWE-129
- CWE-134
- CWE-190
- CWE-497
- CWE-611
- change-notes
- released
- codeql-suites
- experimental/Security/CWE
- CWE-078
- CWE-190
- jsf
- 4.07 Header Files
- 4.10 Classes
- test
- examples/expressions
- experimental
- library-tests
- quantum
- rangeanalysis/rangeanalysis
- stubs
- openssl
- library-tests
- attributes/namespace
- comments/binding
- controlflow
- guards-ir
- guards
- dataflow
- asExpr
- dataflow-tests
- external-models
- models-as-data
- taint-tests
- exprs/min_max
- floats/float128
- funcdname
- includes/includes
- ir
- ir
- range-analysis
- lambdas/syntax
- macros/inmacroexpansion
- ptr_to_member/segfault
- resolve_typedefs
- stmt/leave
- syntax-zoo
- templates
- instantiation_directive
- isfromtemplateinstantiation
- nontype_instantiations/general
- switch
- type_instantiations
- type_sizes
- unspecified_type/types
- variables/variables
- query-tests
- Critical/GlobalUseBeforeInit
- Likely Bugs/Format/WrongTypeFormatArguments
- Microsoft_no_wchar
- Microsoft
- Security/CWE/CWE-089/SqlTainted
- csharp
- autobuilder/Semmle.Autobuild.CSharp
- documentation/library-coverage
- extractor/Semmle.Extraction.CSharp.DependencyFetching
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- binlog_multiple
- binlog
- blazor_build_mode_none
- BlazorTest
- standalone_buildless_option
- standalone_failed
- standalone_resx
- standalone_winforms
- standalone
- posix
- query-suite
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- lib
- change-notes/released
- ext
- generated
- semmle/code/csharp
- commons
- dataflow
- internal
- rangeanalysis
- frameworks
- system
- security
- cryptography
- dataflow
- src
- API Abuse
- ASP
- Architecture/Refactoring Opportunities
- Bad Practices
- Control-Flow
- Declarations
- Implementation Hiding
- Naming Conventions
- CSI
- Complexity
- Concurrency
- Configuration
- Dead Code
- Documentation
- Language Abuse
- Likely Bugs
- Collections
- LeapYear
- Statements
- Linq
- Performance
- Security Features
- CWE-091
- CWE-114
- CWE-134
- CWE-201
- CWE-209
- CWE-327
- CWE-798
- Useless code
- change-notes
- released
- codeql-suites
- test
- library-tests/dataflow/library
- query-tests
- Language Abuse/MissedReadonlyOpportunity
- Nullness
- Security Features
- CWE-089-2
- CWE-089
- CWE-285/MissingAccessControl/MVCTests
- resources/stubs
- Azure.Core/1.38.0
- Azure.Identity/1.11.4
- Microsoft.Bcl.AsyncInterfaces/1.1.1
- Microsoft.Bcl.Cryptography/9.0.4
- Microsoft.Data.SqlClient.SNI.runtime/6.0.2
- Microsoft.Data.SqlClient/6.0.2
- Microsoft.Extensions.Caching.Abstractions/9.0.4
- Microsoft.Extensions.Caching.Memory/9.0.4
- Microsoft.Extensions.DependencyInjection.Abstractions/9.0.4
- Microsoft.Extensions.Logging.Abstractions/9.0.4
- Microsoft.Extensions.Options/9.0.4
- Microsoft.Extensions.Primitives/9.0.4
- Microsoft.Identity.Client.Extensions.Msal/4.61.3
- Microsoft.Identity.Client/4.61.3
- Microsoft.IdentityModel.Abstractions/7.5.0
- Microsoft.IdentityModel.JsonWebTokens/7.5.0
- Microsoft.IdentityModel.Logging/7.5.0
- Microsoft.IdentityModel.Protocols.OpenIdConnect/7.5.0
- Microsoft.IdentityModel.Protocols/7.5.0
- Microsoft.IdentityModel.Tokens/7.5.0
- Microsoft.SqlServer.Server/1.0.0
- System.ClientModel/1.0.0
- System.Configuration.ConfigurationManager/9.0.4
- System.Diagnostics.DiagnosticSource/6.0.1
- System.Diagnostics.EventLog/9.0.4
- System.IdentityModel.Tokens.Jwt/7.5.0
- System.Memory.Data/1.0.2
- System.Memory/4.5.4
- System.Numerics.Vectors/4.5.0
- System.Runtime.CompilerServices.Unsafe/6.0.0
- System.Security.Cryptography.Pkcs/9.0.4
- System.Security.Cryptography.ProtectedData/9.0.4
- System.Text.Encodings.Web/4.7.2
- System.Text.Json/4.7.2
- System.Threading.Tasks.Extensions/4.5.4
- scripts/stubs
- docs
- codeql
- codeql-language-guides
- codeql-overview
- codeql-changelog
- query-help
- reusables
- writing-codeql-queries
- go
- actions/test
- documentation/library-coverage
- extractor
- util
- ql
- consistency-queries
- change-notes/released
- integration-tests/query-suite
- lib
- change-notes/released
- ext
- semmle/go
- security
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-020
- CWE-079
- CWE-209
- CWE-326
- CWE-352
- CWE-640
- CWE-798
- change-notes/released
- codeql-suites
- experimental
- CWE-090
- CWE-203
- CWE-285
- CWE-287
- CWE-321-V2
- CWE-327
- CWE-369
- CWE-74
- CWE-79
- frameworks
- test
- experimental/CWE-79
- library-tests/semmle/go
- Decl
- Function
- Types
- frameworks/SQL/bigquery
- vendor
- cloud.google.com/go/bigquery
- query-tests
- Security
- CWE-079
- CWE-681
- CWE-770
- definitions
- javascript
- extractor
- lib/typescript/src
- src/com/semmle
- js/extractor
- tsconfig
- ts/extractor
- tests/ts/output/trap
- test/com/semmle/js/extractor/test
- ql
- integration-tests
- no-types
- query-suite
- lib
- Expressions
- change-notes
- released
- ext
- semmle/javascript
- dataflow
- internal
- frameworks
- AngularJS
- data/internal
- internal
- security/dataflow
- src
- AngularJS
- DOM
- Declarations
- examples
- Expressions
- LanguageFeatures
- NodeJS
- Quality
- examples
- React
- RegExp
- Security
- CWE-094
- examples
- CWE-312
- examples
- CWE-313
- CWE-798
- Statements
- Vue
- change-notes/released
- codeql-suites
- experimental
- Security/CWE-094
- examples
- semmle/javascript
- meta
- alerts
- types
- test
- experimental
- Execa
- CommandInjection
- PathInjection
- Security/CWE-094
- .github/workflows
- TypeOrm
- library-tests
- CallGraphs/AnnotatedTest
- DataFlow
- JSDoc/NameResolution
- NPM
- TripleDot
- TypeAnnotations
- JSDoc
- TSUnresolvedQualifiedName
- TypeScript
- Ambients
- ArrayTypes
- BaseTypes
- BigInts
- CallResolution
- CallSignatureTypes
- DeclarationFiles
- EmbeddedInScript
- ExpansiveTypes
- ExternalBaseTypes
- node_modules/@types/mylib
- ExternalTypes
- node_modules/@types
- esmodule
- util
- legacy
- modern
- HasQualifiedNameFallback
- HasUnderlyingType
- ImportOwnPackage
- bar
- foo
- IndexTypes
- InfiniteTypes
- LexicalTypes
- LiteralTypes
- NestedLiteral
- Nullability
- PathMapping
- src/lib
- test
- PromiseType
- node_modules/@types/q
- QualifiedNameResolution
- RegressionTests
- AllowJs
- EmptyName
- ExportEqualsExpr
- GenericTypeAlias
- ImportSelf
- RecursiveTypeAlias
- SemicolonInName
- TraceResolution
- node_modules/@types/foo
- TypeRootFile
- TSConfigReferences
- src
- TypeAliases
- TypeVariableTypes
- Types
- UnderlyingTypes
- frameworks
- ClientRequests
- Electron
- Nest
- global
- local
- ReactJS
- query-tests
- Declarations
- SuspiciousMethodNameDeclaration
- UnreachableOverloads
- Expressions/ExprHasNoEffect
- LanguageFeatures/TemplateSyntaxInStringLiteral
- Quality/UnhandledErrorInStreamPipeline
- RegExp/DuplicateCharacterInCharacterClass
- Security
- CWE-020
- IncompleteHostnameRegExp
- MissingRegExpAnchor
- CWE-022/TaintedPath
- CWE-078/CommandInjection
- CWE-079
- DomBasedXss
- ReflectedXss
- UnsafeHtmlConstruction
- CWE-094
- CodeInjection
- ExpressionInjection
- .github/workflows
- action1
- action2
- CWE-312
- .github/workflows
- CWE-918
- Statements/LoopIterationSkippedDueToShifting
- definitions
- java
- downgrades/1b8f5f4c747e4249f4731796ccaa0661c7434d8a
- kotlin-extractor
- src/main/kotlin
- utils/versions
- v_1_5_0
- v_1_5_20
- v_1_6_0
- v_2_1_20-Beta1
- ql
- integration-tests/java
- maven-enforcer-multiple-versions
- maven-enforcer-single-version
- maven-enforcer
- query-suite
- lib
- change-notes/released
- config
- experimental/quantum
- external
- semmle
- code
- configfiles
- java
- arithmetic
- comparison
- controlflow
- internal
- unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- frameworks
- dispatch
- internal
- environment
- frameworks
- android
- apache
- camel
- gigaspaces
- google
- guava
- gwt
- hudson
- j2objc
- jackson
- javaee
- ejb
- jsf
- javase
- kotlin
- mdht
- owasp
- play
- ratpack
- rundeck
- spring
- metrics
- stapler
- struts
- metrics
- os
- regex
- security
- internal
- regexp
- xml
- files
- upgrades/38d02c063878000356a3e5db49d5a6a8f38efe24
- utils/test/internal
- src
- Advisory
- Declarations
- Deprecated Code
- Documentation
- Compatibility/JDK9
- DeadCode
- Language Abuse
- Likely Bugs
- Arithmetic
- Collections
- Comparison
- Concurrency
- Inheritance
- Likely Typos
- Nullness
- Resource Leaks
- Statements
- Termination
- Performance
- Security/CWE
- CWE-078
- CWE-113
- CWE-134
- CWE-798
- Violations of Best Practice
- Boxed Types
- Dead Code
- Declarations
- Exception Handling
- Implementation Hiding
- Naming Conventions
- Records
- SpecialCharactersInLiterals
- Undesirable Calls
- change-notes/released
- codeql-suites
- experimental
- Security/CWE
- CWE-020
- CWE-036
- CWE-073
- CWE-078
- CWE-200
- CWE-400
- CWE-625
- quantum
- Examples
- InventorySlices
- meta/ssa
- test-kotlin1/library-tests/controlflow
- basic
- dominance
- test-kotlin2/library-tests/controlflow
- basic
- dominance
- test
- library-tests
- controlflow
- basic
- dominance
- frameworks/spring/controller
- guards12
- guards
- query-tests
- CallsToRunnableRun
- IgnoredSerializationMembersOfRecordClass
- NonExplicitControlAndWhitespaceCharsInLiterals
- Nullness
- RangeAnalysis
- ScheduledThreadPoolExecutorZeroThread
- StringReplaceAllWithNonRegex
- security
- CWE-022/semmle/tests
- CWE-023/semmle/tests
- CWE-074
- JndiInjection
- XsltInjection
- CWE-079/semmle/tests
- CWE-094
- ApkInstallationTest
- GroovyInjection
- JexlInjection
- MvelInjection
- SpelInjection
- TemplateInjection
- CWE-117
- CWE-266
- CWE-295/InsecureTrustManager
- CWE-312/CleartextStorageCookie
- CWE-326
- CWE-330
- CWE-347
- CWE-441
- CWE-470
- CWE-489/webview-debugging
- CWE-502
- CWE-522
- InsecureBasicAuth
- InsecureLdapAuth
- CWE-552
- CWE-611
- CWE-643
- CWE-730
- ExpRedos
- PolyRedos
- RegexInjection
- CWE-780
- CWE-917
- CWE-918
- mad
- CWE-925
- CWE-927
- ImplicitPendingIntents
- misc
- bazel/3rdparty/tree_sitter_extractors_deps
- codegen
- generators
- lib
- loaders
- templates
- test
- ripunzip
- scripts
- models-as-data
- suite-helpers
- change-notes/released
- python
- extractor
- tests/parser
- tsg-python/tsp
- src
- tree_sitter
- ql
- integration-tests/query-suite
- lib
- change-notes
- released
- semmle/python
- frameworks
- security/internal
- src
- Classes
- InitCallsSubclass
- examples
- Exceptions
- Expressions
- Comparisons
- Formatting
- Regex
- Functions
- examples
- Imports
- Lexical
- Resources
- Security/CWE-798
- Statements
- Testing
- Variables
- LoopVariableCapture
- change-notes/released
- codeql-suites
- experimental
- Security
- CWE-327/Azure
- CWE-346
- semmle/python/security
- test
- library-tests/frameworks/pandas
- query-tests
- Classes/init-calls-subclass-method
- Functions
- general
- iterators
- Resources/FileNotAlwaysClosed
- ql/ql
- src
- codeql_ql/ast
- internal
- queries/overlay
- test/queries/overlay/InlineOverlayCaller
- ruby
- downgrades
- dc51d416301df12df5b70fbc4338de6cc1f82bfd
- eae6926f5000373d5eb1d82131e1ff6152b67b2c
- extractor
- src
- ql
- integration-tests
- compression
- query-suite
- lib
- change-notes
- released
- codeql/ruby
- ast/internal
- dataflow/internal
- upgrades
- 40a6b0a5e81115bd870b3a12a1fe954b06362bb7
- dc51d416301df12df5b70fbc4338de6cc1f82bfd
- utils/test
- src
- change-notes/released
- codeql-suites
- experimental
- ldap-improper-auth
- manually-check-http-verb
- weak-params
- queries
- meta
- performance
- security/cwe-798
- variables
- test/query-tests
- experimental/ImproperLdapAuth
- meta/TaintedNodes
- security
- cwe-078/CommandInjection
- cwe-829
- rust
- ast-generator
- src
- templates
- downgrades
- 319c933d9615ccf40f363548cafd51d08c74a534
- 8e9b0c516ae822286689672d1020707020128a19
- a1005655e9efc9f67d3aa2b7a3128f6b80d405a9
- aa9a0bda17c76b804ad9e108d43da15f6beaf2a7
- e019447231cd93c23ecd173ea5f82e7f9ff54ece
- e3b3765116ecb8d796979f0b4787926cb8d691b5
- f72a3d8d021c81c67ba046c6af15c61a79cb8163
- extractor
- macros
- src
- config
- generated
- nightly-toolchain
- translate
- ql
- consistency-queries
- integration-tests
- hello-project
- hello-workspace
- macro-expansion
- macros
- src
- src
- options/features
- query-suite
- workspace-with-glob
- lib
- change-notes
- released
- codeql/rust
- controlflow
- internal
- generated
- dataflow
- internal
- elements
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
5,684 files changed
+440419
-115551
lines changedLines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
9 |
| - | |
| 9 | + | |
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 |
| - | |
| 13 | + | |
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
20 |
| - | |
| 20 | + | |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
|
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
19 |
| - | |
20 | 19 |
| |
21 | 20 |
| |
22 | 21 |
| |
|
Lines changed: 23 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + |
Lines changed: 0 additions & 34 deletions
This file was deleted.
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
36 | 36 |
| |
37 | 37 |
| |
38 | 38 |
| |
39 |
| - | |
| 39 | + | |
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
| |||
66 | 66 |
| |
67 | 67 |
| |
68 | 68 |
| |
69 |
| - | |
| 69 | + | |
70 | 70 |
| |
71 | 71 |
|
Lines changed: 0 additions & 36 deletions
This file was deleted.
Lines changed: 0 additions & 22 deletions
This file was deleted.
Lines changed: 1 addition & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
4 |
| - | |
5 |
| - | |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 | 3 |
| |
15 | 4 |
| |
16 | 5 |
| |
17 |
| - | |
| 6 | + | |
18 | 7 |
| |
19 | 8 |
| |
20 | 9 |
| |
|
Lines changed: 35 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + |
0 commit comments