File tree
1,226 files changed
+78810
-39859
lines changed- .github/workflows
- config
- cpp
- autobuilder/Semmle.Autobuild.Cpp.Tests
- downgrades/625f706f2a44ae8dc3fc168bfe2637e65c30b012
- ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- rangeanalysis
- semantic
- analysis
- semmle/code/cpp
- commons
- dataflow/internal
- tainttracking1
- tainttracking2
- exprs
- ir
- dataflow/internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation/raw/internal
- pointsto
- valuenumbering
- upgrades/f96ad9b2da43bbc9e55a72a165febd270ae07981
- src
- Architecture/Refactoring Opportunities
- Best Practices
- Likely Errors
- Critical
- Documentation
- Likely Bugs
- Arithmetic
- Likely Typos
- Microsoft
- Security/CWE
- CWE-457
- CWE-611
- change-notes
- released
- experimental/Likely Bugs
- jsf/3.02 Code Size and Complexity
- test
- experimental
- library-tests/rangeanalysis/rangeanalysis
- query-tests/Security/CWE
- CWE-119
- CWE-193/array-access
- library-tests
- builtins/type_traits
- ir/ir
- pod
- sal
- syntax-zoo
- query-tests
- Best Practices/Likely Errors/EmptyBlock
- Critical/MissingCheckScanf
- Documentation/CommentedOutCode
- Likely Bugs/Arithmetic
- BitwiseSignCheck
- FloatComparison
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- downgrades/4ac7d8bcac6f664b1e83c858aa71f8dc761cc603
- extractor
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests/all-platforms
- dotnet_build
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- semmle/code
- cil
- internal
- csharp
- controlflow
- internal
- pressa
- dataflow
- internal
- basessa
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- frameworks
- generated/dotnet
- microsoft
- system
- collections
- data
- net
- runtime
- security/dataflow/flowsinks
- upgrades/a696c8bae067f69ab3208e98ce35f4fdf7efb68b
- src
- Bad Practices
- Comments
- Naming Conventions
- Likely Bugs
- Collections
- Statements
- Security Features
- CWE-730
- Stubs
- Useless code
- change-notes
- released
- experimental/ir/implementation/raw/internal
- utils/model-generator/internal
- test
- library-tests/dataflow
- external-models
- library
- ssa
- query-tests
- Bad Practices/Comments/TodoComments
- EmptyBlock
- Likely Bugs
- Collections/ContainerLengthCmpOffByOne
- UncheckedCastInEquals
- Security Features/CWE-730/RegexInjection
- Useless Code/RedundantToStringCall
- utils/model-generator
- tools
- linux64
- osx64
- win64
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-overview
- ql-language-reference
- reusables
- support/reusables
- writing-codeql-queries
- go
- codeql-tools
- linux64
- osx64
- win64
- ql
- lib
- change-notes
- released
- semmle/go
- dataflow
- src
- RedundantCode
- Security
- CWE-020
- CWE-022
- CWE-209
- CWE-322
- CWE-643
- change-notes
- released
- experimental/CWE-285
- test
- library-tests/semmle/go/frameworks
- Beego
- Revel
- query-tests/Security
- CWE-022
- CWE-209
- CWE-643
- javascript
- extractor
- lib/typescript
- src
- src/com/semmle
- js/extractor
- ts/extractor
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- extraction
- src
- test
- endpoint_large_scale
- modeled_apis
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- AngularJS
- data/internal
- heuristics
- internal
- linters
- security
- dataflow
- regexp
- src
- AngularJS
- Declarations
- Expressions
- Security
- CWE-022
- CWE-078
- CWE-134
- CWE-178
- CWE-200
- CWE-327
- CWE-338
- CWE-377
- CWE-598
- CWE-643
- CWE-830
- Statements
- change-notes
- released
- experimental
- Security/CWE-094
- poi
- meta/analysis-quality
- test
- ApiGraphs
- custom-entry-point
- typed
- experimental/PoI
- library-tests
- SensitiveActions
- TypeScript
- HasUnderlyingType
- Types
- YAML
- frameworks
- AngularJS
- dependency-dataflow
- dependency-resolution
- scopes
- Express
- GWT
- NodeJSLib
- Redux
- SQL
- connect
- data
- fastify
- hapi
- koa
- restify
- query-tests
- Declarations/UnusedParameter
- Expressions/BitwiseSignCheck
- Security
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- lib/subLib4
- CWE-079
- DomBasedXss
- UnsafeHtmlConstruction
- lib2
- src
- lib
- src
- CWE-094/CodeInjection
- CWE-134
- CWE-178
- CWE-338
- CWE-643
- CWE-843
- Statements/NestedLoopsSameVariable
- tutorials
- Introducing the JavaScript libraries
- Validating RAML-based APIs
- java
- documentation/library-coverage
- kotlin-extractor
- src/main/kotlin
- comments
- utils
- ql
- integration-tests/posix-only/kotlin/kotlin_kfunction
- app
- src/main/kotlin/testProject
- lib
- change-notes
- released
- semmle/code
- java
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- deadcode
- dispatch
- internal
- frameworks
- android
- apache
- camel
- kotlin
- spring
- security
- regexp
- xml
- src
- DeadCode
- Frameworks/JavaEE/EJB
- Likely Bugs/Comparison
- Security/CWE
- CWE-089
- CWE-113
- CWE-312
- CWE-611
- Telemetry
- Violations of Best Practice
- Comments
- Dead Code
- Exception Handling
- Implementation Hiding
- legacy
- change-notes
- released
- experimental
- Security/CWE
- CWE-326
- CWE-555
- CWE-601
- CWE-625
- CWE-730
- CWE-755
- semmle/code/java/security
- utils/model-generator/internal
- test
- experimental/query-tests/security
- CWE-555
- CWE-625
- CWE-730
- kotlin/library-tests
- arrays
- classes
- comments
- dataflow/summaries
- declaration-stack
- exprs
- CONSISTENCY
- java_and_kotlin_internal
- operator-overloads
- special-method-getters
- vararg
- library-tests
- dataflow
- external-models
- state
- taint
- frameworks
- android/content-provider-summaries
- spring/data
- query-tests
- MissingInstanceofInEquals
- StaticArray
- UnreadLocal
- dead-code/UselessParameter
- security
- CWE-089/semmle/examples
- CWE-113/semmle/tests
- CWE-312
- android
- CleartextStorage
- backup
- TestEmptyManifest
- TestExplicitlyDisabled
- TestExplicitlyEnabled
- TestLibrary
- TestMissing
- Testbuild
- CWE-601/semmle/tests
- CWE-611
- CWE-927
- stubs/google-android-9.0.0/android/app
- misc/scripts/models-as-data
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new/internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- essa
- frameworks
- data/internal
- internal
- objects
- pointsto
- security
- regexp
- src
- Exceptions
- Functions
- Lexical
- Security
- CWE-022
- CWE-078
- CWE-090
- CWE-094
- CWE-117
- CWE-209
- CWE-295
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-730
- CWE-776
- Statements
- Variables
- change-notes
- released
- experimental/semmle/python
- frameworks
- libraries
- test
- experimental/dataflow
- TestUtil
- coverage
- fieldflow
- match
- strange-pointsto-interaction-investigation
- test-1-normal
- test-2-without-splitting
- test-3-max-import-depth-0
- test-4-max-import-depth-100
- test-5-max-import-depth-3
- test-6-max-import-depth-2
- typetracking_imports
- pkg
- typetracking
- library-tests
- ApiGraphs/py3
- PointsTo/new
- frameworks/django-orm
- variables/scopes
- query-tests
- Functions
- ModificationOfParameterWithDefault
- general
- Lexical/commented_out_code
- Security
- CWE-022-TarSlip
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- Statements/unreachable
- Variables
- unused_local_nonlocal
- unused
- ql/ql
- src
- codeql_ql
- ast
- internal
- style
- queries/style
- test/queries/style/Misspelling
- ruby
- downgrades/3595c826de6db850f16b9da265a54dbf24dd3126
- extractor
- generator
- ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- ast/internal
- controlflow
- dataflow
- internal
- tainttracking1
- tainttrackingforlibraries
- frameworks
- data/internal
- http_clients
- internal
- security
- regexp
- upgrades/4ba51641799d2aaa315c7323931e2dd2a94c9f9d
- src
- change-notes
- released
- queries
- security
- cwe-022
- cwe-079
- cwe-094
- cwe-295
- cwe-506
- examples
- cwe-611
- variables
- test
- library-tests
- ast
- literals
- dataflow
- api-graphs
- call-sensitivity
- summaries
- frameworks/active_resource
- modules
- query-tests/security
- cwe-020/SuspiciousRegexpRange
- cwe-022
- cwe-079
- cwe-094
- cwe-295
- cwe-506
- cwe-611
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- visitors
- integration-tests
- osx-only/frontend-invocations
- posix-only
- cross-references
- frontend-invocations
- partial-modules
- ql
- lib
- codeql/swift
- controlflow/internal
- dataflow
- internal
- tainttracking1
- elements
- decl
- expr
- generated
- decl
- expr
- printast
- security
- src/queries
- Security
- CWE-135
- CWE-311
- CWE-757
- ide-contextual-queries
- test
- extractor-tests
- declarations
- expressions
- generated
- decl
- ClassDecl
- EnumDecl
- ModuleDecl
- expr
- ConstructorRefCallExpr
- DotSyntaxCallExpr
- EnumIsCaseExpr
- MethodRefExpr
- type
- BuiltinType
- ModuleType
- types
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- taint
- parent
- query-tests/Security
- CWE-079
- CWE-135
- CWE-311
- CWE-757
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,226 files changed
+78810
-39859
lines changedLines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
| 31 | + | |
31 | 32 |
| |
32 | 33 |
| |
33 | 34 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
56 | 56 |
| |
57 | 57 |
| |
58 | 58 |
| |
59 |
| - | |
| 59 | + | |
60 | 60 |
| |
61 | 61 |
| |
62 | 62 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
55 | 55 |
| |
56 | 56 |
| |
57 | 57 |
| |
58 |
| - | |
| 58 | + | |
59 | 59 |
| |
60 | 60 |
| |
61 | 61 |
| |
|
Lines changed: 14 additions & 7 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
8 | 15 |
| |
9 | 16 |
| |
10 | 17 |
| |
| |||
54 | 61 |
| |
55 | 62 |
| |
56 | 63 |
| |
57 |
| - | |
| 64 | + | |
58 | 65 |
| |
59 | 66 |
| |
60 | 67 |
| |
| |||
108 | 115 |
| |
109 | 116 |
| |
110 | 117 |
| |
111 |
| - | |
| 118 | + | |
112 | 119 |
| |
113 | 120 |
| |
114 | 121 |
| |
115 | 122 |
| |
116 | 123 |
| |
117 | 124 |
| |
118 | 125 |
| |
119 |
| - | |
120 |
| - | |
| 126 | + | |
| 127 | + | |
121 | 128 |
| |
122 | 129 |
| |
123 | 130 |
| |
124 | 131 |
| |
125 | 132 |
| |
126 |
| - | |
| 133 | + | |
127 | 134 |
| |
128 | 135 |
| |
129 | 136 |
| |
| |||
139 | 146 |
| |
140 | 147 |
| |
141 | 148 |
| |
142 |
| - | |
| 149 | + | |
143 | 150 |
| |
144 | 151 |
| |
145 | 152 |
| |
146 | 153 |
| |
147 | 154 |
| |
148 |
| - | |
| 155 | + | |
149 | 156 |
| |
150 | 157 |
| |
151 | 158 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
95 | 95 |
| |
96 | 96 |
| |
97 | 97 |
| |
| 98 | + | |
98 | 99 |
| |
99 | 100 |
| |
100 | 101 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + | |
7 | 8 |
| |
8 | 9 |
| |
9 | 10 |
| |
|
Lines changed: 6 additions & 14 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
| 33 | + | |
33 | 34 |
| |
34 | 35 |
| |
35 | 36 |
| |
| |||
461 | 462 |
| |
462 | 463 |
| |
463 | 464 |
| |
464 |
| - | |
465 |
| - | |
466 |
| - | |
467 |
| - | |
468 |
| - | |
469 |
| - | |
470 |
| - | |
471 |
| - | |
472 |
| - | |
473 | 465 |
| |
474 | 466 |
| |
475 | 467 |
| |
| |||
585 | 577 |
| |
586 | 578 |
| |
587 | 579 |
| |
588 |
| - | |
| 580 | + | |
589 | 581 |
| |
590 | 582 |
| |
591 | 583 |
| |
592 |
| - | |
| 584 | + | |
593 | 585 |
| |
594 | 586 |
| |
595 | 587 |
| |
596 |
| - | |
| 588 | + | |
597 | 589 |
| |
598 | 590 |
| |
599 | 591 |
| |
600 |
| - | |
| 592 | + | |
601 | 593 |
| |
602 | 594 |
| |
603 | 595 |
| |
604 | 596 |
| |
605 | 597 |
| |
606 |
| - | |
| 598 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
299 | 299 |
| |
300 | 300 |
| |
301 | 301 |
| |
302 |
| - | |
| 302 | + | |
303 | 303 |
| |
304 | 304 |
| |
305 | 305 |
| |
|
Lines changed: 17 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + |
0 commit comments