File tree
2,369 files changed
+115574
-200423
lines changed- .github/workflows
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- ir/dataflow
- internal
- tainttracking1
- semantic/analysis
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- tainttracking1
- exprs
- ir
- dataflow
- internal
- tainttracking1
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- models
- implementations
- interfaces
- rangeanalysis
- security
- src
- Security/CWE
- CWE-078
- CWE-732
- change-notes/released
- experimental/Security/CWE
- CWE-369
- CWE-415
- test
- experimental/query-tests/Security/CWE/CWE-369/semmle/tests
- library-tests
- CPP-205
- allocators
- declarationEntry/more
- ir/range-analysis
- noexcept/copy_from_prototype
- templates/isfromtemplateinstantiation
- query-tests
- Critical/MissingCheckScanf
- Security/CWE/CWE-078/semmle/ExecTainted
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- extractor
- Semmle.Extraction.CSharp
- Entities
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- dotnet_build
- dotnet_pack
- dotnet_publish
- dotnet_run
- msbuild
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- scripts
- dotnet_test
- inherit-env-vars
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- scripts
- lib
- change-notes
- released
- semmle/code
- cil
- csharp
- commons
- dataflow
- internal
- tainttracking1
- dispatch
- exprs
- frameworks
- system
- collections
- runtime
- security/cryptography
- security/dataflow
- flowsources
- dotnet
- src
- Likely Bugs
- Stubs
- change-notes/released
- experimental
- Security Features
- JsonWebTokenHandler
- backdoor
- ir/implementation
- raw
- internal
- desugar
- internal
- unaliased_ssa
- internal
- test
- library-tests
- csharp11
- dataflow/library
- frameworks/EntityFramework
- query-tests
- Likely Bugs/StaticFieldWrittenByInstance
- Stubs
- All
- Minimal
- resources/stubs/_frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- docs/codeql
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- reusables
- go
- extractor
- cli
- go-autobuilder
- go-extractor
- diagnostics
- util
- ql
- integration-tests/all-platforms/go/diagnostics
- build-constraints-exclude-all-go-files
- work
- go-files-found-not-processed
- work
- subdir
- newer-go-version-needed
- work
- no-go-files-found
- work
- package-not-found-with-go-mod
- work
- package-not-found-without-go-mod
- work
- unsupported-relative-path
- work/main
- subpkg
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- tainttracking1
- frameworks
- stdlib
- security
- src
- Security/CWE-681
- change-notes/released
- test
- library-tests/semmle/go/dataflow/VarArgsWithFunctionModels
- query-tests/Security
- CWE-681
- CWE-918
- javascript
- extractor
- src/com/semmle
- js
- extractor
- parser
- ts/extractor
- tests/vue/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- extraction
- src
- test
- integration-tests/all-platforms
- diagnostics/syntax-error
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- AngularJS
- heuristics
- security
- dataflow
- src
- Security/CWE-020
- change-notes
- released
- test/query-tests/Security
- CWE-079/XssThroughDom
- CWE-089/untyped
- java
- documentation/library-coverage
- ql
- integration-tests
- all-platforms
- java/diagnostics
- android-gradle-incompatibility
- compilation-error
- dependency-error
- java-version-too-old
- maven-http-repository
- multiple-candidate-builds
- no-build-system
- no-gradle-test-classes
- kotlin/diagnostics/kotlin-version-too-new
- posix-only/kotlin/kotlin_double_interception
- code
- lib
- change-notes
- released
- ext
- semmle/code
- java
- dataflow
- internal
- tainttracking1
- deadcode
- frameworks
- android
- google
- jackson
- javaee/ejb
- os
- security
- xml
- src
- Metrics/Summaries
- Security/CWE
- CWE-022
- CWE-079
- CWE-113
- CWE-209
- CWE-327
- CWE-532
- CWE-681
- CWE-918
- change-notes/released
- experimental/Security/CWE/CWE-348
- utils/modelconverter
- test
- TestUtilities
- library-tests
- dataflow
- collections
- fluent-methods
- inoutbarriers
- partial
- state
- taint-format
- frameworks
- JaxWs
- android
- content-provider
- external-storage
- slice
- sources
- apache-commons-compress
- apache-http
- okhttp
- rabbitmq
- retrofit
- spring/controller
- pathsanitizer
- query-tests/security
- CWE-022/semmle/tests
- mad
- CWE-023/semmle/tests
- CWE-089/semmle/examples
- mad
- CWE-117
- CWE-266
- CWE-295/InsecureTrustManager
- CWE-441
- CWE-470
- CWE-489/webview-debugging
- CWE-532
- CWE-780
- CWE-918
- mad
- CWE-927
- stubs
- apache-commons-compress/org/apache/commons/compress/archivers
- tar
- zip
- apache-hive
- com/google/protobuf
- javax
- crypto
- jdo
- annotations
- datastore
- listener
- metadata
- query
- net
- security
- auth
- callback
- sasl
- transaction
- ws/rs/core
- org
- apache
- commons/logging
- hadoop
- conf
- fs
- permission
- hive
- metastore
- api
- columnstats/aggr
- model
- partition/spec
- security
- utils
- ql/io/sarg
- io
- retry
- ipc
- metrics
- protobuf
- metrics2
- lib
- util
- security
- authorize
- proto
- token
- delegation
- util
- concurrent
- hive/hcatalog/templeton
- tool
- htrace
- core
- shaded/fasterxml/jackson
- annotation
- core
- format
- io
- sym
- type
- util
- databind
- annotation
- cfg
- deser
- impl
- introspect
- jsonFormatVisitors
- jsonschema
- jsontype
- node
- ser
- impl
- std
- type
- util
- thrift
- meta_data
- protocol
- scheme
- transport
- datanucleus/enhancement
- slf4j
- event
- spi
- apache-http-4.4.13/org/apache/http
- client/utils
- util
- cargo/org/codehaus/cargo
- container/installer
- util
- log
- javafx-web
- com
- sun/javafx/tk
- zaxxer/hikari
- metrics
- io/micrometer/observation
- jakarta/ws/rs
- client
- core
- javafx
- animation
- beans
- binding
- property
- value
- collections
- transformation
- concurrent
- css
- event
- geometry
- print
- scene
- effect
- image
- input
- paint
- text
- transform
- web
- stage
- util
- javax
- net
- ssl
- security/cert
- servlet
- annotation
- descriptor
- http
- sql
- ws/rs
- client
- core
- org
- apache
- commons/logging
- http
- client
- config
- methods
- concurrent
- conn
- routing
- message
- params
- protocol
- codehaus/cargo
- container/installer
- util
- log
- jdbi/v3/core
- argument
- internal
- array
- codec
- collector
- config
- extension
- generic
- mapper
- qualifier
- result
- spi
- statement
- internal
- transaction
- postgresql
- util
- reactivestreams
- springframework
- boot/jdbc
- core
- codec
- io
- buffer
- support
- http
- client
- reactive
- support
- codec
- converter
- server
- reactive
- jdbc/datasource
- util
- web
- client
- reactive/function
- client
- util
- w3c/dom
- reactor
- core
- observability
- publisher
- scheduler
- util
- context
- function
- retry
- springframework-5.3.8/org/springframework/boot/jdbc
- misc
- codegen/templates
- suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- tainttracking1
- frameworks
- xml
- src
- Security/CWE-327
- change-notes/released
- experimental/Security/CWE-348
- test
- experimental
- dataflow/coverage
- library-tests/CallGraph
- code
- meta/debug
- library-tests/ApiGraphs/py3
- query-tests/Security/CWE-327-InsecureProtocol
- ql
- buramu
- extractor
- ruby
- downgrades/3595c826de6db850f16b9da265a54dbf24dd3126
- extractor/src
- ql
- integration-tests/all-platforms
- diagnostics
- syntax-error
- unknown-encoding
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- experimental
- frameworks
- actioncontroller
- core
- http_clients
- stdlib
- security
- regexp
- src
- change-notes
- released
- experimental/cwe-022-zipslip
- examples
- queries/security
- cwe-020
- cwe-079
- test
- library-tests/frameworks/action_controller
- query-tests
- diagnostics
- experimental/cwe-022-ZipSlip
- security/cwe-094/CodeInjection
- swift
- extractor
- config
- infra
- invocation
- mangler
- translators
- ql
- lib/codeql/swift
- dataflow
- internal
- tainttracking1
- elements
- expr
- type
- frameworks/StandardLibrary
- generated
- decl
- expr
- type
- security
- src/queries
- Security
- CWE-135
- CWE-311
- CWE-312
- Summary
- test
- extractor-tests/declarations
- library-tests
- ast
- dataflow
- dataflow
- flowsources
- taint
- core
- libraries
- elements
- expr
- arithmeticoperation
- assignment
- bitwiseopration
- type
- nominaltype
- pointertypes
- query-tests/Security
- CWE-089
- CWE-134
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,369 files changed
+115574
-200423
lines changedLines changed: 21 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + |
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
30 | 29 |
| |
31 |
| - | |
| 30 | + | |
32 | 31 |
| |
33 | 32 |
| |
34 | 33 |
| |
|
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2 | 2 |
| |
3 | 3 |
| |
4 | 4 |
| |
5 |
| - | |
6 |
| - | |
7 |
| - | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
|
Lines changed: 42 additions & 9 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
3 | 14 |
| |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
4 | 26 |
| |
5 | 27 |
| |
6 | 28 |
| |
7 | 29 |
| |
8 | 30 |
| |
9 | 31 |
| |
10 | 32 |
| |
11 |
| - | |
| 33 | + | |
12 | 34 |
| |
13 | 35 |
| |
14 | 36 |
| |
15 | 37 |
| |
16 |
| - | |
| 38 | + | |
17 | 39 |
| |
18 | 40 |
| |
19 | 41 |
| |
20 |
| - | |
| 42 | + | |
21 | 43 |
| |
22 | 44 |
| |
23 | 45 |
| |
24 |
| - | |
| 46 | + | |
25 | 47 |
| |
26 | 48 |
| |
27 | 49 |
| |
28 | 50 |
| |
29 | 51 |
| |
30 |
| - | |
| 52 | + | |
31 | 53 |
| |
32 | 54 |
| |
33 |
| - | |
| 55 | + | |
34 | 56 |
| |
35 | 57 |
| |
36 | 58 |
| |
37 | 59 |
| |
38 |
| - | |
| 60 | + | |
39 | 61 |
| |
40 | 62 |
| |
41 | 63 |
| |
42 |
| - | |
| 64 | + | |
43 | 65 |
| |
44 | 66 |
| |
45 | 67 |
| |
| |||
52 | 74 |
| |
53 | 75 |
| |
54 | 76 |
| |
55 |
| - | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
56 | 89 |
| |
57 | 90 |
| |
58 | 91 |
| |
|
Lines changed: 20 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
3 | 4 |
| |
4 | 5 |
| |
5 | 6 |
| |
| |||
75 | 76 |
| |
76 | 77 |
| |
77 | 78 |
| |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
78 | 88 |
| |
79 | 89 |
| |
80 | 90 |
| |
| |||
184 | 194 |
| |
185 | 195 |
| |
186 | 196 |
| |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
187 | 206 |
| |
188 | 207 |
| |
189 | 208 |
| |
| |||
243 | 262 |
| |
244 | 263 |
| |
245 | 264 |
| |
| 265 | + | |
246 | 266 |
| |
247 | 267 |
| |
248 | 268 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
| 2 | + | |
2 | 3 |
| |
3 | 4 |
| |
4 | 5 |
| |
| |||
21 | 22 |
| |
22 | 23 |
| |
23 | 24 |
| |
24 |
| - | |
| 25 | + | |
25 | 26 |
| |
26 | 27 |
| |
27 | 28 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 |
| |
2 | 6 |
| |
3 | 7 |
| |
|
Lines changed: 9 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + |
Lines changed: 12 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
0 commit comments