File tree
2,120 files changed
+45957
-67140
lines changed- .github
- actions/fetch-codeql
- workflows
- change-notes
- 1.20
- 1.23
- 1.24
- config
- atm/ml-powered-queries-repo
- models
- cpp/ql
- examples
- lib
- change-notes/released
- experimental/semmle/code/cpp
- ir/dataflow/internal
- semantic/analysis
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- internal
- metrics
- rangeanalysis
- security
- valuenumbering
- src
- Best Practices
- Likely Errors
- Unused Entities
- Critical
- Likely Bugs
- Likely Typos
- Memory Management
- Underspecified Functions
- Security/CWE
- CWE-120
- CWE-190
- change-notes
- released
- experimental
- Best Practices
- Security/CWE
- CWE-078
- CWE-273
- CWE-362
- CWE-561
- CWE-703
- campaigns/nccoe-pqc-migration/QuantumVulnerableDiscovery
- external
- jsf
- 4.10 Classes
- 4.13 Functions
- 4.21 Operators
- test
- TestUtilities
- experimental/query-tests/Security/CWE
- CWE-078
- CWE-193/pointer-deref
- CWE-703/semmle/tests
- library-tests
- dataflow/dataflow-tests
- printf
- formatAttribute
- formatLiteral
- templates/CPP-223
- query-tests
- Best Practices/Unused Entities/UnusedStaticFunctions
- Likely Bugs/Format/NonConstantFormat
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-120/semmle/tests
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle/tainted
- CWE-290/semmle/AuthenticationBypass
- CWE-807/semmle/TaintedCondition
- jsf/4.10 Classes/AV Rule 76
- csharp
- extractor
- Semmle.Extraction.CIL
- Entities
- Base
- Semmle.Extraction.CSharp
- Entities
- Semmle.Extraction/Entities/Base
- Semmle.Util
- old-change-notes
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- test
- consistency-queries
- examples
- integration-tests
- lib
- change-notes/released
- experimental/code/csharp/Cryptography
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- exprs
- frameworks
- microsoft
- system/security
- security/xml
- src
- Bad Practices/Magic Constants
- Metrics/Summaries
- change-notes/released
- experimental
- Security Features
- CWE-327/Azure
- JsonWebTokenHandler
- backdoor
- ir/implementation
- raw
- internal
- unaliased_ssa
- internal
- meta/frameworks
- utils/model-generator/internal
- test
- TestUtilities
- experimental/Security Features/backdoor
- library-tests/dataflow
- fields
- local
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- ql-language-reference
- support/reusables
- writing-codeql-queries
- ql-libraries/dataflow
- go
- old-change-notes
- ql
- config/legacy-support
- examples
- lib
- change-notes/released
- semmle/go
- frameworks
- security
- src
- Diagnostics
- Metrics
- change-notes
- released
- experimental
- CWE-400
- InconsistentCode
- test
- TestUtilities
- query-tests
- Diagnostics
- Security/CWE-312
- protos
- query
- vendor
- github.com/golang/protobuf
- proto
- google.golang.org/protobuf
- internal/impl
- proto
- reflect/protoreflect
- runtime
- protoiface
- protoimpl
- javascript
- old-change-notes
- ql
- examples
- queries/dataflow/DecodingAfterSanitization
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- counting
- evaluation
- extraction
- model
- src
- test
- endpoint_large_scale
- endpoint_unit_tests
- lib
- change-notes/released
- semmle/javascript
- dataflow
- frameworks
- security
- dataflow
- regexp
- src
- AngularJS
- DOM
- Declarations
- Expressions
- LanguageFeatures
- NodeJS
- Performance
- RegExp
- Security
- CWE-022
- CWE-073
- CWE-078
- examples
- CWE-079
- CWE-089
- CWE-094
- CWE-117
- CWE-1275
- CWE-134
- CWE-178
- CWE-200
- CWE-209
- CWE-312
- CWE-313
- CWE-338
- CWE-346
- CWE-352
- CWE-367
- CWE-384
- CWE-400
- CWE-502
- CWE-601
- CWE-611
- CWE-614
- CWE-643
- CWE-730
- CWE-770
- CWE-776
- CWE-807
- CWE-834
- CWE-912
- CWE-915
- CWE-918
- change-notes
- released
- experimental/Security
- CWE-094
- CWE-340
- CWE-918
- test
- experimental/Security
- CWE-094
- CWE-918
- library-tests/frameworks
- Express
- src
- Templating
- query-tests
- AngularJS
- DuplicateDependency
- InsecureUrlWhitelist
- DOM/HTML
- Declarations
- ClobberingVarInit
- DuplicateVarDecl
- RedeclaredVariable
- Expressions
- DuplicateProperty
- StringInsteadOfRegex
- UnboundEventHandlerReceiver
- LanguageFeatures
- BadTypeof
- NonLinearPattern
- ThisBeforeSuper
- NodeJS/MissingExports
- Performance/ReassignParameterAndUseArguments
- RegExp
- BackrefIntoNegativeLookahead
- DuplicateCharacterInCharacterClass
- Security
- CWE-022
- TaintedPath
- ZipSlip
- CWE-073
- CWE-078
- CommandInjection
- IndirectCommandInjection
- SecondOrderCommandInjection
- ShellCommandInjectionFromEnvironment
- UnsafeShellCommandConstruction
- lib
- subLib2
- subLib3
- subLib4
- subLib
- UselessUseOfCat
- CWE-079
- DomBasedXss
- pages
- ReflectedXss
- UnsafeHtmlConstruction
- CWE-089
- typed
- untyped
- CWE-094
- CodeInjection
- UnsafeDynamicMethodAccess
- CWE-116/IncompleteSanitization
- CWE-117
- CWE-1275
- CWE-134
- CWE-178
- CWE-200
- CWE-209
- CWE-312
- CWE-313
- CWE-338
- CWE-346
- CWE-352
- CWE-367
- CWE-384
- CWE-400/RemovePropertyInjection
- CWE-502
- CWE-601
- ClientSideUrlRedirect
- ServerSideUrlRedirect
- CWE-611
- CWE-614
- CWE-643
- CWE-730
- CWE-770/ResourceExhaustion
- CWE-776
- CWE-807
- CWE-834
- CWE-912
- CWE-915/PrototypePollutingMergeCall
- CWE-918
- java
- documentation/library-coverage
- downgrades/709f1d1fd04ffd9bbcf242f17b120f8a389949bd
- kotlin-extractor
- src/main
- java/com/semmle
- extractor/java
- util
- expansion
- files
- trap/pathtransformers
- kotlin
- comments
- utils
- versions
- v_1_4_32
- v_1_5_20
- v_1_7_0
- old-change-notes
- ql
- consistency-queries
- examples
- integration-tests
- all-platforms/kotlin
- compiler_arguments
- app
- src/main/kotlin/testProject
- default-parameter-mad-flow
- enabling
- enhanced-nullability
- external-property-overloads
- extractor_crash
- code
- gradle_groovy_app
- app
- src/main/kotlin/testProject
- gradle_kotlinx_serialization
- app
- src/main/kotlin/testProject
- java_modifiers
- libsrc/extlib
- jvmoverloads-external-class
- kotlin-interface-inherited-default
- kotlin_compiler_java_source
- kotlin_file_import
- libsrc
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- kotlin_kfunction
- app
- src/main/kotlin/testProject
- kotlinc_multi
- logs
- nested_generic_types
- libsrc/extlib
- private_property_accessors
- raw_generic_types
- libsrc/extlib
- trap_compression
- linux-only/kotlin
- custom_plugin
- posix-only/kotlin
- generic-extension-property
- gradle_kotlinx_serialization
- app/src/main/kotlin/testProject
- java-interface-redeclares-tostring
- kotlin_java_lowering_wildcards
- needless-java-wildcards
- lib
- change-notes
- released
- config
- semmle/code/java
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- jackson
- kotlin
- security
- regexp
- upgrades/ecb42310286011ada450ff65b9b417509863549f
- src
- Compatibility/JDK9
- Likely Bugs
- Arithmetic
- Statements
- Metrics/Summaries
- Security/CWE/CWE-441
- Violations of Best Practice
- Dead Code
- Implementation Hiding
- Naming Conventions
- change-notes
- released
- utils/model-generator/internal
- test
- TestUtilities
- kotlin
- library-tests
- annotation_classes
- annotations/jvmName
- arrays-with-variances
- arrays
- call-int-to-char
- classes
- collection-literals
- comments
- controlflow
- basic
- CONSISTENCY
- dominance
- CONSISTENCY
- dataflow
- extensionMethod
- func
- notnullexpr
- summaries
- exprs_typeaccess
- exprs
- CONSISTENCY
- extensions
- fake_overrides
- all_kotlin
- kotlin_calling_java
- for-array-iterators
- generic-inner-classes
- generic-instance-methods
- generics-location
- generics
- inherited-callee
- inherited-collection-implementation
- inherited-default-value
- internal-constructor-called-from-java
- internal-public-alias
- java-kotlin-collection-type-generic-methods
- java-lang-number-conversions
- CONSISTENCY
- java-map-methods
- CONSISTENCY
- java_and_kotlin_internal
- java_and_kotlin
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmoverloads_generics
- jvmstatic-annotation
- lateinit
- maps-iterator-overloads
- methods
- ministdlib
- modifiers
- multiple_files
- parameter-defaults
- private-anonymous-types
- reflection
- special-method-getters
- static-method-calls
- stmts
- super-method-calls
- this
- trap
- vararg
- query-tests
- AbstractToConcreteCollection
- ConfusingMethodSignature
- ConstantLoopCondition
- MissingInstanceofInEquals
- PartiallyMaskedCatch
- UnderscoreIdentifier
- UnreadLocal
- UselessNullCheck
- UselessParameter
- WhitespaceContradictsPrecedence
- library-tests
- dataflow
- partial
- synth-global
- frameworks
- JaxWs
- android/intent
- multiply-bounded-wildcards
- structure
- structure
- wildcards-and-captured-types
- query-tests
- SpuriousJavadocParam
- lgtm-example-queries
- security/CWE-441
- misc
- bazel
- cmake
- legacy-support
- cpp
- csharp
- javascript
- java
- python
- suite-helpers
- change-notes/released
- python
- .vscode
- PoCs/XmlParsing
- ql
- consistency-queries
- examples
- snippets
- lib
- change-notes/released
- semmle/python
- dataflow
- new
- internal
- old
- frameworks
- Stdlib
- internal
- objects
- pointsto
- security
- dataflow
- regexp
- types
- src
- Security
- CWE-327
- CWE-798
- Variables
- analysis
- change-notes
- released
- experimental
- Security
- CWE-022bis
- CWE-1236
- CWE-340
- semmle/python
- frameworks
- libraries
- templates
- semmle/python/functions
- test
- TestUtilities
- experimental/query-tests/Security/CWE-022
- library-tests
- ApiGraphs/py3
- InlineExpectationsTest/missing-relevant-tag
- essa/ssa-compute
- tools/recorded-call-graph-metrics
- ql
- src/cg_trace
- ql
- extractor/src
- node-types/src
- ql
- consistency-queries
- examples
- src
- codeql_ql
- ast
- internal
- dataflow
- dependency
- style
- queries
- bugs
- diagnostics
- explore
- style
- summary
- test
- TestUtilities
- callgraph/packs
- other
- src
- ruby
- actions/create-extractor-pack
- ql
- consistency-queries
- examples
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow/internal
- frameworks
- core
- http_clients
- internal
- security
- regexp
- src
- change-notes
- released
- queries
- security
- cwe-094
- cwe-327
- summary
- test
- TestUtilities
- library-tests
- ast
- operations
- controlflow/graph
- dataflow
- api-graphs
- array-flow
- barrier-guards
- call-sensitivity
- hash-flow
- local
- ssa-flow
- frameworks
- active_support
- app/controllers
- http_clients
- modules
- query-tests
- experimental/improper-memoization
- security
- cwe-022
- cwe-079
- app
- controllers/foo
- views/foo/stores
- cwe-094
- cwe-300
- cwe-327
- cwe-918
- swift
- actions
- create-extractor-pack
- run-integration-tests
- run-ql-tests
- run-quick-tests
- setup-env
- codegen
- generators
- lib
- schema
- templates
- test
- extractor
- infra
- file
- remapping
- translators
- trap
- visitors
- integration-tests
- posix-only/hello-world
- ql
- lib
- codeql/swift
- controlflow/internal
- dataflow
- internal
- elements
- decl
- expr
- pattern
- stmt
- type
- frameworks/StandardLibrary
- generated
- decl
- expr
- pattern
- stmt
- type
- src
- queries
- Security
- CWE-079
- CWE-089
- CWE-135
- CWE-311
- CWE-312
- CWE-321
- CWE-327
- CWE-757
- CWE-760
- CWE-916
- Summary
- test
- TestUtilities
- extractor-tests
- generated
- File
- expr
- AnyHashableErasureExpr
- ArchetypeToSuperExpr
- ArrayToPointerExpr
- AwaitExpr
- ClassMetatypeToObjectExpr
- CollectionUpcastConversionExpr
- CovariantFunctionConversionExpr
- CovariantReturnConversionExpr
- DerivedToBaseExpr
- DestructureTupleExpr
- DifferentiableFunctionExpr
- DifferentiableFunctionExtractOriginalExpr
- DotSelfExpr
- ErasureExpr
- ExistentialMetatypeToObjectExpr
- ForeignObjectConversionExpr
- FunctionConversionExpr
- IdentityExpr
- ImplicitConversionExpr
- InOutToPointerExpr
- InjectIntoOptionalExpr
- LinearFunctionExpr
- LinearFunctionExtractOriginalExpr
- LinearToDifferentiableFunctionExpr
- LoadExpr
- MetatypeConversionExpr
- ParenExpr
- PointerToPointerExpr
- ProtocolMetatypeToObjectExpr
- ReifyPackExpr
- StringToPointerExpr
- UnderlyingToOpaqueExpr
- UnevaluatedInstanceExpr
- type/BuiltinType
- run_under
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- flowsources
- taint
- elements
- decl/abstractfunctiondecl
- location
- query-tests/Security
- CWE-079
- CWE-089
- CWE-312
- CWE-321
- CWE-327
- CWE-760
- CWE-916
- ECB-Encryption
- third_party
- fishhook
- picosha2
- swift-llvm-support
- tools
- test/qltest
- expected_failure_codes
- extractor_env
- extractor_options
- failing_run
- normal_run
- unexpected_return_code
- xcode-autobuilder
- tests
- hello-autobuilder
- hello-autobuilder.xcodeproj
- project.xcworkspace
- hello-workspace
- Hello.xcworkspace
- hello-workspace.xcodeproj
- project.xcworkspace
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,120 files changed
+45957
-67140
lines changedLines changed: 11 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
3 | 10 |
| |
4 | 11 |
| |
5 | 12 |
| |
6 | 13 |
| |
7 | 14 |
| |
| 15 | + | |
| 16 | + | |
| 17 | + | |
8 | 18 |
| |
9 | 19 |
| |
10 |
| - | |
| 20 | + | |
11 | 21 |
| |
12 | 22 |
| |
13 |
| - | |
14 |
| - | |
|
Lines changed: 11 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + |
Lines changed: 93 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + |
Lines changed: 12 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + |
Lines changed: 57 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
96 | 96 |
| |
97 | 97 |
| |
98 | 98 |
| |
| 99 | + | |
99 | 100 |
| |
100 |
| - | |
101 | 101 |
| |
102 | 102 |
| |
103 | 103 |
| |
| |||
202 | 202 |
| |
203 | 203 |
| |
204 | 204 |
| |
205 |
| - | |
| 205 | + | |
206 | 206 |
| |
207 | 207 |
| |
208 | 208 |
| |
|
Lines changed: 0 additions & 39 deletions
This file was deleted.
Lines changed: 0 additions & 45 deletions
This file was deleted.
Lines changed: 0 additions & 43 deletions
This file was deleted.
0 commit comments