File tree
3,520 files changed
+128170
-107644
lines changed- .github
- actions/fetch-codeql
- workflows
- change-notes
- 1.20
- 1.23
- 1.24
- config
- atm/ml-powered-queries-repo
- models
- cpp/ql
- examples
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- ir/dataflow/internal
- ssa0
- semantic
- analysis
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- metrics
- models
- implementations
- interfaces
- rangeanalysis
- security
- valuenumbering
- src
- Architecture
- General Namespace-Level Information
- Refactoring Opportunities
- Best Practices
- Hiding
- Likely Errors
- Magic Constants
- Unused Entities
- Critical
- Diagnostics
- Documentation
- Likely Bugs
- Arithmetic
- Conversion
- Format
- Leap Year
- Likely Typos
- Memory Management
- OO
- Protocols
- Underspecified Functions
- Metrics
- Classes
- Namespaces
- Security/CWE
- CWE-022
- CWE-078
- CWE-089
- CWE-114
- CWE-120
- CWE-121
- CWE-129
- CWE-134
- CWE-170
- CWE-190
- CWE-253
- CWE-311
- CWE-313
- CWE-319
- CWE-457
- CWE-468
- CWE-676
- CWE-732
- CWE-807
- change-notes
- released
- experimental
- Best Practices
- Likely Bugs
- Security/CWE
- CWE-020
- CWE-078
- CWE-1041
- CWE-120
- CWE-193
- CWE-273
- CWE-359
- CWE-362
- CWE-401
- CWE-561
- CWE-670
- CWE-691
- CWE-703
- CWE-754
- CWE-783
- CWE-787
- CWE-788
- external
- jsf
- 4.06 Pre-Processing Directives
- 4.07 Header Files
- 4.09 Style
- 4.10 Classes
- 4.11 Namespaces
- 4.13 Functions
- 4.15 Declarations and Definitions
- 4.21 Operators
- 4.22 Pointers and References
- 4.23 Type Conversions
- 4.25 Expressions
- test
- TestUtilities
- examples/BadLocking
- experimental/query-tests/Security/CWE
- CWE-020
- NoCheckBeforeUnsafePutUser
- semmle/tests
- CWE-078
- CWE-1041/semmle/tests
- CWE-119
- CWE-193
- array-access
- constant-size
- pointer-deref
- CWE-359/semmle/tests
- CWE-401/semmle/tests
- CWE-670/semmle/tests
- CWE-691/semmle/tests
- CWE-703/semmle/tests
- CWE-754/semmle/tests
- CWE-783/semmle/tests
- CWE-788/semmle/tests
- semmle/tests
- library-tests
- dataflow
- dataflow-tests
- fields
- ir/range-analysis
- printf
- formatAttribute
- formatLiteral
- syntax-zoo
- templates/CPP-223
- query-tests
- Architecture/Refactoring Opportunities/ComplexFunctions
- Best Practices
- Hiding/LocalVariableHidesGlobalVariable
- Likely Errors
- CommaBeforeMisleadingIndentation
- Slicing
- Unused Entities
- UnusedLocals
- UnusedStaticFunctions
- UnusedStaticVariables
- Critical
- FileClosed
- MemoryFreed
- MissingCheckScanf
- NewFree
- UnsafeUseOfThis
- Likely Bugs
- Arithmetic/BadAdditionOverflowCheck
- Conversion
- CastArrayPointerArithmetic
- ImplicitDowncastFromBitfield
- LossyFunctionResultCast
- Format
- NonConstantFormat
- WrongTypeFormatArguments
- Linux_mixed_byte_wprintf
- Linux_mixed_word_size
- Linux_signed_chars
- Linux_two_byte_wprintf
- Linux_unsigned_chars
- Microsoft_no_wchar
- Microsoft
- Leap Year/Adding365DaysPerYear
- Memory Management
- ImproperNullTermination
- NtohlArrayNoBound
- UsingExpiredStackAddress
- Protocols
- RedundantNullCheckSimple
- ShortLoopVarName
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-120/semmle/tests
- CWE-121/semmle/tests
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- ArithmeticWithExtremeValues
- TaintedAllocationSize
- tainted
- CWE-197/SAMATE/IntegerOverflowTainted
- CWE-242/semmle/tests
- CWE-253
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests
- CWE-457/semmle/tests
- CWE-468/semmle/IncorrectPointerScaling
- CWE-676/semmle/PotentiallyDangerousFunction
- CWE-732
- CWE-772
- SAMATE
- semmle
- tests-file
- tests-memory
- CWE-807/semmle/TaintedCondition
- jsf
- 4.09 Style/AV Rule 53 54
- 4.10 Classes/AV Rule 76
- csharp
- extractor
- Semmle.Extraction.CIL
- Entities
- Base
- Semmle.Extraction.CSharp
- Entities
- Semmle.Extraction/Entities/Base
- Semmle.Util
- old-change-notes
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- test
- Solorigate
- consistency-queries
- examples
- integration-tests
- all-platforms/dotnet_run
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- semmle/code
- cil
- internal
- csharp
- commons
- controlflow
- internal
- dataflow
- internal
- exprs
- frameworks
- microsoft
- system/security
- security
- cryptography
- xml
- src
- API Abuse
- Bad Practices
- Implementation Hiding
- Magic Constants
- CSI
- Concurrency
- Dead Code
- Diagnostics
- Language Abuse
- Likely Bugs
- Linq
- Metrics/Summaries
- Security Features
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-091
- CWE-094
- CWE-099
- CWE-112
- CWE-114
- CWE-117
- CWE-134
- CWE-201
- CWE-209
- CWE-312
- CWE-321
- CWE-327
- CWE-384
- CWE-611
- CWE-643
- CWE-730
- CWE-807
- Telemetry
- Useless code
- change-notes
- released
- experimental
- CWE-099
- CWE-918
- Security Features
- CWE-327/Azure
- JsonWebTokenHandler
- backdoor
- ir/implementation
- raw
- internal
- unaliased_ssa
- internal
- meta/frameworks
- utils/model-generator/internal
- test
- TestUtilities
- experimental
- CWE-918
- Security Features
- JsonWebTokenHandler
- backdoor
- library-tests
- dataflow
- fields
- global
- local
- frameworks/microsoft
- query-tests
- API Abuse
- ClassDoesNotImplementEquals
- NoDisposeCallOnLocalIDisposable
- Concurrency/SynchSetUnsynchGet
- Dead Code
- NonAssignedFields
- Tests
- Language Abuse
- ForeachCapture
- UselessIsBeforeAs
- Nullness
- Security Features
- CWE-022/TaintedPath
- CWE-078
- CWE-079/StoredXSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-312
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsecureSQLConnection
- CWE-338
- CWE-384
- CWE-611
- CWE-643
- CWE-730/ReDoS
- CWE-807
- tools
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview
- ql-language-reference
- support/reusables
- writing-codeql-queries
- ql-libraries/dataflow
- go
- old-change-notes
- ql
- config/legacy-support
- examples
- lib
- change-notes
- released
- semmle/go
- frameworks
- security
- src
- Diagnostics
- InconsistentCode
- Metrics
- Security
- CWE-020
- CWE-117
- CWE-322
- CWE-338
- change-notes
- released
- experimental
- CWE-321
- CWE-369
- CWE-400
- CWE-918
- InconsistentCode
- IntegerOverflow
- test
- TestUtilities
- experimental
- CWE-369
- CWE-400
- CWE-918
- CWE-942
- library-tests/semmle/go/frameworks/Beego
- query-tests
- Diagnostics
- InconsistentCode/WrappedErrorAlwaysNil
- Security
- CWE-020/SuspiciousCharacterInRegexp
- CWE-312
- protos
- query
- vendor
- github.com/golang/protobuf
- proto
- google.golang.org/protobuf
- internal/impl
- proto
- reflect/protoreflect
- runtime
- protoiface
- protoimpl
- CWE-338/InsecureRandomness
- CWE-918
- javascript
- documentation
- old-change-notes
- ql
- examples
- queries/dataflow/DecodingAfterSanitization
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- counting
- evaluation
- extraction
- src
- test
- endpoint_large_scale
- endpoint_unit_tests
- generic_feature_testing
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- frameworks
- data/internal
- minimongo
- mongodb
- mssql
- mysql
- pg
- sequelize
- spanner
- sqlite3
- security
- dataflow
- regexp
- src
- AngularJS
- DOM
- Declarations
- Diagnostics
- Expressions
- LanguageFeatures
- NodeJS
- Performance
- RegExp
- Security
- CWE-022
- CWE-073
- CWE-078
- examples
- CWE-079
- CWE-089
- CWE-094
- CWE-117
- CWE-1275
- CWE-134
- CWE-178
- CWE-200
- CWE-209
- CWE-312
- CWE-313
- CWE-338
- CWE-346
- CWE-352
- CWE-367
- CWE-384
- CWE-400
- CWE-502
- CWE-601
- CWE-611
- CWE-614
- CWE-643
- CWE-730
- CWE-770
- CWE-776
- CWE-807
- CWE-829
- CWE-834
- CWE-912
- CWE-915
- CWE-918
- Statements
- change-notes
- released
- experimental
- Security
- CWE-094
- CWE-340
- CWE-918
- Summaries
- test
- ApiGraphs/typed
- experimental/Security
- CWE-094
- CWE-918
- library-tests
- Security/heuristics
- frameworks
- Express
- src
- SQL
- Templating
- query-tests
- AngularJS
- DuplicateDependency
- InsecureUrlWhitelist
- DOM/HTML
- Declarations
- ClobberingVarInit
- DuplicateVarDecl
- RedeclaredVariable
- Expressions
- DuplicateProperty
- StringInsteadOfRegex
- UnboundEventHandlerReceiver
- LanguageFeatures
- BadTypeof
- NonLinearPattern
- ThisBeforeSuper
- NodeJS/MissingExports
- Performance/ReassignParameterAndUseArguments
- RegExp
- BackrefIntoNegativeLookahead
- DuplicateCharacterInCharacterClass
- Security
- CWE-022
- TaintedPath
- ZipSlip
- CWE-073
- CWE-078
- CommandInjection
- IndirectCommandInjection
- SecondOrderCommandInjection
- ShellCommandInjectionFromEnvironment
- UnsafeShellCommandConstruction
- lib
- subLib2
- subLib3
- subLib4
- subLib
- UselessUseOfCat
- CWE-079
- DomBasedXss
- pages
- ReflectedXss
- UnsafeHtmlConstruction
- CWE-089
- typed
- untyped
- CWE-094
- CodeInjection
- UnsafeDynamicMethodAccess
- CWE-116
- BadTagFilter
- IncompleteSanitization
- CWE-117
- CWE-1275
- CWE-134
- CWE-178
- CWE-200
- CWE-209
- CWE-312
- CWE-313
- CWE-338
- CWE-346
- CWE-352
- CWE-367
- CWE-384
- CWE-400/RemovePropertyInjection
- CWE-502
- CWE-601
- ClientSideUrlRedirect
- ServerSideUrlRedirect
- CWE-611
- CWE-614
- CWE-643
- CWE-730
- CWE-770/ResourceExhaustion
- CWE-776
- CWE-798
- CWE-807
- CWE-834
- CWE-912
- CWE-915/PrototypePollutingMergeCall
- CWE-918
- Summaries
- java
- documentation/library-coverage
- downgrades/709f1d1fd04ffd9bbcf242f17b120f8a389949bd
- kotlin-extractor
- src/main
- java/com/semmle
- extractor/java
- util
- expansion
- files
- trap/pathtransformers
- kotlin
- comments
- utils
- versions
- v_1_4_32
- v_1_5_20
- v_1_6_0
- v_1_7_0
- old-change-notes
- ql
- consistency-queries
- examples
- integration-tests
- all-platforms/kotlin
- compiler_arguments
- app
- src/main/kotlin/testProject
- default-parameter-mad-flow
- enabling
- enhanced-nullability
- external-property-overloads
- extractor_crash
- code
- gradle_groovy_app
- app
- src/main/kotlin/testProject
- gradle_kotlinx_serialization
- app
- src/main/kotlin/testProject
- java_modifiers
- libsrc/extlib
- jvmoverloads-external-class
- kotlin-interface-inherited-default
- kotlin_compiler_java_source
- kotlin_file_import
- libsrc
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- kotlin_kfunction
- app
- src/main/kotlin/testProject
- kotlinc_multi
- logs
- nested_generic_types
- libsrc/extlib
- private_property_accessors
- raw_generic_types
- libsrc/extlib
- trap_compression
- linux-only/kotlin
- custom_plugin
- posix-only/kotlin
- compiler_arguments
- enabling
- extractor_crash/code
- generic-extension-property
- gradle_groovy_app
- gradle_kotlinx_serialization
- app/src/main/kotlin/testProject
- java-interface-redeclares-tostring
- kotlin_file_import
- kotlin_java_lowering_wildcards
- kotlin_kfunction
- kotlinc_multi
- logs
- needless-java-wildcards
- nested_generic_types
- trap_compression
- lib
- change-notes
- released
- config
- semmle/code
- java
- controlflow
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- jackson
- kotlin
- regex
- security
- regexp
- xml
- upgrades/ecb42310286011ada450ff65b9b417509863549f
- src
- Advisory
- Declarations
- Documentation
- Compatibility/JDK9
- Diagnostics
- Frameworks/Spring
- Architecture/Refactoring Opportunities
- Violations of Best Practice
- Language Abuse
- Likely Bugs
- Arithmetic
- Collections
- Comparison
- Concurrency
- Likely Typos
- Nullness
- Serialization
- Statements
- Metrics/Summaries
- Performance
- Security/CWE
- CWE-022
- CWE-023
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-094
- CWE-113
- CWE-117
- CWE-129
- CWE-134
- CWE-190
- CWE-200
- CWE-266
- CWE-295
- CWE-297
- CWE-312
- CWE-319
- CWE-347
- CWE-367
- CWE-441
- CWE-470
- CWE-489
- CWE-502
- CWE-522
- CWE-601
- CWE-611
- CWE-643
- CWE-681
- CWE-730
- CWE-732
- CWE-780
- CWE-807
- CWE-917
- CWE-918
- CWE-925
- CWE-926
- CWE-927
- CWE-940
- Telemetry
- Violations of Best Practice
- Dead Code
- Implementation Hiding
- Naming Conventions
- Undesirable Calls
- change-notes
- released
- experimental
- Security/CWE
- CWE-020
- CWE-036
- CWE-073
- CWE-078
- CWE-094
- CWE-1004
- CWE-200
- CWE-297
- CWE-299
- CWE-327
- CWE-470
- CWE-489
- CWE-502
- CWE-548
- CWE-552
- CWE-600
- CWE-665
- CWE-939
- semmle/code/java
- frameworks
- utils
- model-generator/internal
- stub-generator
- test
- TestUtilities
- experimental/query-tests/security
- CWE-020
- CWE-078
- CWE-200
- CWE-297
- CWE-299
- CWE-327
- CWE-502
- CWE-548
- CWE-552
- CWE-600
- kotlin
- library-tests
- GeneratedFiles
- annotation-accessor-result-type
- annotation_classes
- annotations/jvmName
- arrays-with-variances
- arrays
- call-int-to-char
- classes
- collection-literals
- comments
- controlflow
- basic
- dominance
- data-classes
- dataflow
- extensionMethod
- func
- notnullexpr
- summaries
- enum
- exprs_typeaccess
- exprs
- CONSISTENCY
- extensions
- fake_overrides
- all_kotlin
- kotlin_calling_java
- for-array-iterators
- generic-inner-classes
- generic-instance-methods
- generics-location
- generics
- inherited-callee
- inherited-collection-implementation
- inherited-default-value
- internal-constructor-called-from-java
- internal-public-alias
- java-kotlin-collection-type-generic-methods
- java-lang-number-conversions
- java-map-methods
- java_and_kotlin_internal
- java_and_kotlin
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmoverloads_generics
- jvmstatic-annotation
- lateinit
- maps-iterator-overloads
- methods
- ministdlib
- modifiers
- multiple_extensions
- multiple_files
- numlines
- parameter-defaults
- private-anonymous-types
- properties
- reflection
- special-method-getters
- static-method-calls
- stmts
- super-method-calls
- this
- trap
- vararg
- query-tests
- AbstractToConcreteCollection
- ConfusingMethodSignature
- ConstantLoopCondition
- ExposeRepresentation
- MissingInstanceofInEquals
- PartiallyMaskedCatch
- UnderscoreIdentifier
- UselessNullCheck
- UselessParameter
- WhitespaceContradictsPrecedence
- library-tests
- dataflow
- partial
- stream-collect
- synth-global
- taintsources
- frameworks
- JaxWs
- android
- intent
- taint-database
- widget
- pathsanitizer
- structure
- structure
- query-tests
- ContradictoryTypeChecks
- InefficientOutputStream
- IteratorRemoveMayFail
- MissingInstanceofInEquals
- Nullness
- PartiallyMaskedCatch
- SelfAssignment
- SpuriousJavadocParam
- Stubs
- Minimal
- testlib
- org/test
- UselessNullCheck
- WrongNanComparison
- lgtm-example-queries
- security
- CWE-022/semmle/tests
- CWE-023/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-297
- CWE-311/CWE-319
- CWE-367/semmle/tests
- CWE-441
- CWE-489
- debuggable-attribute
- TestFalse
- TestNotSet
- Testbuild
- webview-debugging
- CWE-601/semmle/tests
- CWE-611
- CWE-681/semmle/tests
- CWE-732/semmle/tests
- CWE-807/semmle/tests
- CWE-926/incomplete_provider_permissions
- Testbuild
- stubs
- android
- android
- accounts
- app
- content
- pm
- res
- loader
- database
- sqlite
- graphics
- drawable
- text
- hardware
- icu/util
- net
- os
- util
- view
- webkit
- com/android/internal
- org/xmlpull/v1
- google-android-9.0.0/android/app
- springframework-5.3.8/org/springframework/core/io
- misc
- bazel
- cmake
- legacy-support
- cpp
- csharp
- javascript
- java
- python
- suite-helpers
- change-notes/released
- python
- .vscode
- PoCs/XmlParsing
- ql
- consistency-queries
- examples
- snippets
- lib
- change-notes
- released
- semmle/python
- dataflow
- new
- internal
- old
- frameworks
- Stdlib
- data/internal
- internal
- objects
- pointsto
- security
- dataflow
- regexp
- types
- src
- Classes
- Diagnostics
- Exceptions
- Expressions/Comparisons
- Functions
- Imports
- Numerics
- Security
- CWE-020
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-094
- CWE-117
- CWE-215
- CWE-295
- CWE-312
- CWE-327
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-730
- CWE-776
- CWE-798
- CWE-918
- Statements
- Variables
- analysis
- change-notes
- released
- experimental
- Security
- CWE-022bis
- CWE-022
- CWE-091
- CWE-113
- CWE-1236
- CWE-287
- CWE-340
- CWE-348
- CWE-522
- CWE-611
- CWE-943
- semmle/python
- frameworks
- libraries
- templates
- meta/alerts
- semmle/python/functions
- test
- 2/query-tests
- Classes/new-style
- Exceptions
- generators
- raising
- 3/query-tests/Statements/iter
- TestUtilities
- experimental
- dataflow
- basic
- calls
- consistency
- coverage
- fieldflow
- global-flow
- match
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests/CallGraph/code
- query-tests/Security
- CWE-022
- CWE-079
- CWE-113
- CWE-1236
- CWE-287
- CWE-522
- CWE-611-SimpleXmlRpcServer
- CWE-614
- CWE-943
- library-tests
- ApiGraphs/py3
- InlineExpectationsTest/missing-relevant-tag
- essa/ssa-compute
- frameworks
- cx_Oracle
- django-orm
- flask
- modeling-example
- oracledb
- phoenixdb
- pymssql
- pymysql
- pyodbc
- query-tests
- Classes
- subclass-shadowing
- undefined-attribute
- Expressions/comparisons
- Functions
- ModificationOfParameterWithDefault
- general
- return_values
- Imports
- PyCheckerTests
- general
- Numerics
- Security
- CWE-020-ExternalAPIs
- CWE-020-IncompleteUrlSubstringSanitization
- CWE-022-PathInjection
- CWE-022-TarSlip
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-Jinja2WithoutEscaping
- CWE-079-ReflectedXss
- CWE-089-SqlInjection
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-116-BadTagFilter
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-215-FlaskDebug
- CWE-295-RequestWithoutValidation
- CWE-312-CleartextLogging
- CWE-312-CleartextStorage-py3
- CWE-312-CleartextStorage
- CWE-327-InsecureProtocol
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-ReDoS
- CWE-730-RegexInjection
- CWE-732-WeakFilePermissions
- CWE-776-XmlBomb
- CWE-798-HardcodedCredentials
- CWE-918-ServerSideRequestForgery
- Statements
- DocStrings
- asserts
- general
- no_effect
- Variables
- capture
- general
- multiple
- unused_local_nonlocal
- unused
- tools/recorded-call-graph-metrics
- ql
- src/cg_trace
- ql
- extractor/src
- node-types/src
- ql
- consistency-queries
- examples
- src
- codeql_ql
- ast
- internal
- dataflow
- dependency
- style
- codeql
- queries
- bugs
- diagnostics
- explore
- performance
- style
- summary
- test
- TestUtilities
- callgraph/packs
- other
- src
- queries/style
- AcronymsShouldBeCamelCase
- DeadCode
- RedundantCast
- RedundantOverride
- ruby
- actions/create-extractor-pack
- extractor/src
- node-types/src
- ql
- consistency-queries
- examples
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- tainttrackingforlibraries
- experimental
- filters
- frameworks
- core
- data
- internal
- http_clients
- internal
- stdlib
- regexp
- internal
- security
- regexp
- typetracking
- src
- change-notes
- released
- experimental/manually-check-http-verb
- queries
- analysis
- diagnostics
- meta
- internal
- security
- cwe-078
- cwe-094
- cwe-295
- cwe-312
- cwe-327
- cwe-502
- cwe-598
- examples
- cwe-732
- cwe-798
- cwe-829
- cwe-912
- summary
- test
- TestUtilities
- library-tests
- ast
- operations
- controlflow/graph
- dataflow
- api-graphs
- array-flow
- barrier-guards
- call-sensitivity
- global
- hash-flow
- local
- ssa-flow
- summaries
- type-tracker
- experimental
- frameworks
- action_controller
- action_mailer
- action_view
- active_record
- active_storage
- active_support
- app/controllers
- http_clients
- pathname
- modules
- query-tests
- experimental
- improper-memoization
- manually-check-http-verb
- security
- cwe-020/MissingRegExpAnchor
- cwe-022
- cwe-078
- CommandInjection
- KernelOpen
- NonConstantKernelOpen
- cwe-079
- app
- controllers/foo
- views/foo
- bars
- stores
- cwe-094
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-1333-polynomial-redos
- cwe-295
- cwe-300
- cwe-312
- cwe-327
- cwe-502/unsafe-deserialization
- cwe-598
- app/controllers
- config
- cwe-601
- cwe-611
- libxml-backend
- xxe
- cwe-732
- cwe-798
- cwe-912
- cwe-918
- swift
- actions
- create-extractor-pack
- run-integration-tests
- run-ql-tests
- run-quick-tests
- setup-env
- codegen
- generators
- lib
- schema
- templates
- test
- extractor
- infra
- file
- remapping
- trap
- visitors
- integration-tests
- posix-only/hello-world
- ql/lib/codeql/swift
- controlflow/internal
- dataflow
- internal
- elements
- decl
- expr
- pattern
- stmt
- type
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
3,520 files changed
+128170
-107644
lines changedLines changed: 11 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
3 | 10 |
| |
4 | 11 |
| |
5 | 12 |
| |
6 | 13 |
| |
7 | 14 |
| |
| 15 | + | |
| 16 | + | |
| 17 | + | |
8 | 18 |
| |
9 | 19 |
| |
10 |
| - | |
| 20 | + | |
11 | 21 |
| |
12 | 22 |
| |
13 |
| - | |
14 |
| - | |
|
Lines changed: 11 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + |
Lines changed: 93 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + |
Lines changed: 12 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + |
Lines changed: 57 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
46 |
| - | |
| 46 | + | |
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
| |||
52 | 52 |
| |
53 | 53 |
| |
54 | 54 |
| |
55 |
| - | |
| 55 | + | |
56 | 56 |
| |
57 | 57 |
| |
58 | 58 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
96 | 96 |
| |
97 | 97 |
| |
98 | 98 |
| |
| 99 | + | |
99 | 100 |
| |
100 |
| - | |
101 | 101 |
| |
102 | 102 |
| |
103 | 103 |
| |
| |||
202 | 202 |
| |
203 | 203 |
| |
204 | 204 |
| |
205 |
| - | |
| 205 | + | |
206 | 206 |
| |
207 | 207 |
| |
208 | 208 |
| |
|
Lines changed: 0 additions & 39 deletions
This file was deleted.
Lines changed: 0 additions & 45 deletions
This file was deleted.
0 commit comments