File tree
2,606 files changed
+124272
-59266
lines changed- change-notes/1.24
- config
- cpp
- config/suites
- cpp
- c
- ql
- src
- Architecture
- General Top-Level Information
- Refactoring Opportunities
- Best Practices
- Likely Errors
- Magic Constants
- Critical
- Documentation
- JPL_C
- LOC-2
- Rule 03
- Rule 04
- Rule 09
- LOC-4
- Rule 24
- Rule 26
- Rule 31
- Likely Bugs
- Arithmetic
- Conversion
- Format
- Likely Typos
- Memory Management
- Underspecified Functions
- Metrics
- Classes
- Dependencies
- Files
- Functions
- History
- Microsoft
- Power of 10
- Rule 1
- Rule 2
- Rule 4
- Rule 5
- Security/CWE
- CWE-119
- CWE-131
- CWE-190
- CWE-253
- CWE-428
- CWE-457
- CWE-732
- experimental
- Security/CWE/CWE-273
- external
- jsf
- 4.07 Header Files
- 4.09 Style
- 4.10 Classes
- 4.11 Namespaces
- 4.13 Functions
- 4.15 Declarations and Definitions
- 4.17 Types
- 4.21 Operators
- semmle/code/cpp
- commons
- unix
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- exprs
- headers
- internal
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- implementation
- aliased_ssa
- gvn
- internal
- internal
- internal
- raw
- gvn
- internal
- internal
- reachability
- unaliased_ssa
- gvn
- internal
- internal
- reachability
- internal
- metrics
- models
- implementations
- interfaces
- padding
- rangeanalysis
- security
- stmts
- valuenumbering
- test
- TestUtilities
- experimental
- library-tests
- CPP-205
- arg_matching
- arguments
- basic_blocks
- c++_exceptions
- constexpr_if
- controlflow
- guards-ir
- stackvariablereachability
- dataflow
- DefaultTaintTracking
- crement
- dataflow-tests
- fields
- security-taint
- taint-tests
- declarationEntry/declarationEntry
- deprecated
- destructors
- functions
- unused_mut
- unused
- ir
- constant_func
- escape
- ir
- points_to
- ssa
- lambdas
- captures
- cfg
- literals/literals
- locations/overloaded_operators
- members/getters
- multiple_declarations/variable_types
- nested_functions/nested_functions
- nulltermination
- numlines
- permissive
- pointsto/basic
- range_based_for
- rangeanalysis
- rangeanalysis
- signanalysis
- structs/mutual_recursion
- sub_basic_blocks
- syntax-zoo
- templates
- instantiations_functions
- isfromtemplateinstantiation
- valuenumbering/GlobalValueNumbering
- variables/variables
- virtual_functions/cfg
- vla
- query-tests
- Best Practices/Unused Entities/UnusedStaticFunctions
- Critical
- NewFree
- OverflowStatic
- Likely Bugs
- Arithmetic
- PointlessComparison
- UnsignedGEZero
- Memory Management
- StrncpyFlippedArgs
- SuspiciousCallToStrncat
- UnsafeUseOfStrcat
- RedundantNullCheckSimple
- Underspecified Functions
- Security/CWE
- CWE-119/semmle
- OverflowStatic
- StrncpyFlippedArgs
- CWE-129/semmle/ImproperArrayIndexValidation
- CWE-131/semmle/NoSpaceForZeroTerminator
- CWE-134/semmle
- argv
- funcs
- ifs
- CWE-190/semmle
- TaintedAllocationSize
- extreme
- uncontrolled
- wider_type
- CWE-807/semmle/TaintedCondition
- definitions
- successor-tests
- break_labels
- conditional_destructors
- exceptionhandler
- ellipsisexceptionhandler
- exceptionhandler
- pruning
- returnstmt
- stackvariables/stackvariables
- switchstmt/switchbody
- upgrades
- bd182f697bf1316c401421d64e582871331a69f4
- c9ac0461491edef3b1ab79f03d007a47522dda90
- csharp
- autobuilder
- Semmle.Autobuild.Tests
- Semmle.Autobuild
- extractor
- Semmle.Extraction.CIL.Driver
- Semmle.Extraction.CIL
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util.Tests
- Semmle.Util
- ql
- src
- API Abuse
- Bad Practices
- Implementation Hiding
- Magic Constants
- Complexity
- Concurrency
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- Metrics
- Callables
- Files
- RefTypes
- Security Features
- CWE-016
- CWE-020
- CWE-022
- CWE-091
- CWE-114
- CWE-209
- CWE-321
- CWE-327
- CWE-451
- CWE-798
- CWE-838
- Stubs
- Useless code
- experimental
- external
- tests
- semmle/code
- cil
- csharp
- commons
- controlflow
- internal
- dataflow
- flowsources
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- dispatch
- exprs
- frameworks
- system
- linq
- xml
- ir
- implementation
- internal
- raw
- gvn
- internal
- internal
- desugar
- reachability
- unaliased_ssa
- gvn
- internal
- internal
- reachability
- internal
- rangeanalysis
- metrics
- security
- cryptography
- dataflow
- flowsources
- sinks
- xml
- serialization
- dotnet
- test
- experimental
- library-tests
- assignments
- csharp7.3
- csharp7
- dataflow
- call-sensitivity
- defuse
- fields
- global
- local
- ssa-large
- generics
- ir
- ir
- offbyone
- query-tests
- AlertSuppression
- Dead Code/DeadStoreOfLocal
- Likely Bugs/DangerousNonShortCircuitLogic
- Nullness
- Security Features
- CWE-020
- CWE-022/ZipSlip
- CWE-643
- upgrades/cf21dd4151d107ab649a2a218e7f52e355c43906
- docs
- language
- global-sphinx-files/_templates
- learn-ql
- advanced
- cobol
- cpp
- java
- writing-queries
- ql-handbook
- ql-spec
- ql-training
- cpp
- java
- slide-snippets
- support
- javascript
- config/suites/javascript
- documentation
- extractor
- lib/typescript
- src
- src/com/semmle
- jcorn
- js
- ast
- extractor
- test
- parser
- ts/ast
- tests
- exprs/output/trap
- shebang/output/trap
- ts
- input
- output/trap
- ql
- examples/queries/dataflow/StoredXss
- src
- AngularJS
- Declarations
- Expressions
- LanguageFeatures
- Metrics
- Performance
- RegExp
- Security
- CWE-020
- CWE-078
- examples
- CWE-079
- examples
- CWE-116
- CWE-352
- CWE-400
- examples
- Statements
- experimental
- Summaries
- external
- meta
- analysis-quality
- extraction-metrics
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- AngularJS
- linters
- security
- dataflow
- performance
- test
- experimental
- library-tests
- Arrays
- CallGraphs/AnnotatedTest
- ClassNode
- Classes
- Constants
- CustomLoadStoreSteps
- DataFlow
- Decorators
- DependencyModuleImports
- FileTypes
- Flow
- InterProceduralFlow
- LocalObjects
- Modules
- NPM
- src/node_modules
- b/lib
- d
- PartialInvokeNode
- Promises
- RangeAnalysis
- RegExp
- Bounds
- EscapeInString
- MissingUnicodeFlag
- predecessors_and_successors
- SensitiveActions
- StringConcatenation
- StringOps/StartsWith
- TaintBarriers
- TaintTracking
- ThisExpr
- TorrentLibraries
- TypeScript
- CallSignatureTypes
- CallSignatures
- CompiledOutput
- ExportNamespaceSpecifier
- ImportMeta
- Namespaces
- PathMapping
- src/lib
- test
- PrivateFields
- RegressionTests
- ArrowReturn
- ImportSelf
- TraceResolution
- Tokens
- TypeAliases
- TypeAnnotations
- TypeOnlyImportExport
- frameworks
- ClientRequests
- Concepts
- Electron
- EventEmitter
- LazyCache
- NodeJSLib
- ReactJS
- SQL
- SocketIO
- UriLibraries
- WebSocket
- koa
- src
- typeahead
- meta/Extraction
- query-tests
- Declarations
- ConflictingFunctions
- DeclBeforeUse
- UnreachableOverloads
- UnusedProperty
- Expressions
- ExprHasNoEffect
- MissingAwait
- RedundantExpression
- SuspiciousPropAccess
- LanguageFeatures
- SpuriousArguments
- StrictModeCallStackIntrospection
- SyntaxError
- Performance/ReDoS
- Security
- CWE-020
- CWE-022/TaintedPath
- CWE-078
- CWE-079
- CWE-089
- typed
- untyped
- CWE-312
- CWE-352
- CWE-400
- PrototypePollutionUtility
- examples
- CWE-918
- Summaries
- Statements/UseOfReturnlessFunction
- upgrades
- 96b0a386b6fb8da2b5f2514f26154a10c906f9c5
- dad09eeeff5cf8c9c2b674d5053c63ab44e091df
- java
- ql
- src
- Advisory/Documentation
- Compatibility/JDK9
- Complexity
- Language Abuse
- Likely Bugs
- Arithmetic
- Comparison
- Concurrency
- Likely Typos
- Resource Leaks
- Statements
- Metrics
- Authors
- Callables
- Files
- Internal
- RefTypes
- Performance
- Security/CWE
- CWE-078
- CWE-089
- CWE-090
- CWE-113
- CWE-190
- CWE-352
- CWE-681
- CWE-798
- CWE-829
- CWE-835
- Violations of Best Practice
- Boolean Logic
- Boxed Types
- Comments
- Magic Constants
- Naming Conventions
- legacy
- config
- experimental
- Security/CWE
- CWE-094
- CWE-643
- external
- semmle/code
- java
- comparison
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- deadcode
- dispatch
- frameworks
- gwt
- jackson
- javaee
- ejb
- spring
- metrics
- metrics
- security
- xml
- test
- experimental
- library-tests
- constants
- dataflow
- call-sensitivity
- capture
- gettersetter
- null
- taint-ioutils
- taint-jackson
- taintgettersetter
- taintsources
- taint
- typepruning
- guards
- typeflow
- query-tests
- ConstantExpAppearsNonConstant
- LShiftLargerThanTypeWidth
- Nullness
- SuspiciousDateFormat
- security
- CWE-090
- CWE-829/semmle/tests
- stubs
- apache-commons-io-2.6
- org/apache/commons/io
- apache-ldap-1.0.2/org/apache/directory
- api/ldap/model
- cursor
- entry
- exception
- filter
- message
- name
- ldap/client/api
- esapi-2.0.1/org/owasp/esapi
- reference
- jackson-databind-2.10
- com/fasterxml/jackson
- core
- databind
- spring-ldap-2.3.2/org/springframework/ldap
- core
- filter
- query
- support
- springframework-5.2.3/org/springframework/web/bind/annotation
- unboundid-ldap-4.0.14/com/unboundid/ldap/sdk
- upgrades
- e7706df98aaefcf055f35f50582f2686f41c23bb
- python/ql
- examples/snippets
- src
- Classes
- Exceptions
- Expressions
- Comparisons
- Formatting
- Regex
- Filters
- Functions
- Imports
- Lexical
- Metrics
- Dependencies
- External
- History
- Internal
- Numerics
- Resources
- Security
- CVE-2018-1281
- CWE-020
- CWE-022
- examples
- CWE-078
- examples
- CWE-079
- CWE-089
- CWE-094
- CWE-209
- CWE-215
- CWE-295
- CWE-312
- CWE-326
- CWE-327
- CWE-377
- CWE-502
- CWE-601
- examples
- CWE-732
- CWE-798
- Statements
- Testing
- Variables
- analysis
- experimental
- external
- semmle
- crypto
- files
- python
- dataflow
- dependencies
- essa
- filters
- libraries
- objects
- pointsto
- security
- flow
- injection
- strings
- templates
- types
- values
- web
- bottle
- cherrypy
- client
- django
- falcon
- flask
- pyramid
- tornado
- turbogears
- twisted
- webob
- xml
- test
- 2
- library-tests
- ControlFlow/Exceptions
- PointsTo
- import_time
- imports
- metaclass
- origin_uniqueness
- classes
- attr
- mro
- comprehensions
- locations
- general
- keywords
- strings
- modules
- general
- package_members
- objects
- six
- types
- classes
- exceptions
- functions
- properties
- query-tests
- Expressions
- Imports/syntax_error
- 3
- library-tests
- ControlFlow/Exceptions
- PointsTo
- attributes
- consts
- import_time
- inheritance
- metaclass
- regressions/subprocess-assert
- typehints
- classes
- attr
- meta
- mro
- locations
- annotations
- general
- keywords
- modules
- general
- package_members
- six
- taint/unpacking
- types
- classes
- exceptions
- functions
- namespaces
- properties
- query-tests
- Expressions/UseofApply
- Imports
- encoding_error
- syntax_error
- Statements/iter
- Variables/undefined
- experimental
- library-tests
- ControlFlow
- PointsToSupport
- augassign
- comparison
- delete
- dominators
- general
- raising_stmts
- splitting
- ssa
- defns
- deletions
- phi-nodes
- undefined
- uses
- vars
- successors
- truefalse
- try
- DefUse
- DuplicateCode
- PointsTo
- absent
- api
- calls
- comparisons
- customise
- decorators
- extensions
- functions
- general
- global
- guarded
- import_star
- imports
- indexing
- inheritance
- local
- lookup
- metaclass
- new
- code
- properties
- regressions
- missing
- if-urlsplit-access
- re-compile
- wrong/classmethod
- returns
- subclass
- super
- attributes
- classes
- abstract
- attr
- mro
- comments
- comparisons
- comprehensions
- dependencies
- descriptors
- encoding
- examples/custom-sanitizer
- exceptions
- exprs
- ast
- compare
- strings
- filters
- generated
- tests
- formatting
- imports
- jump_to_defn
- locations
- elif
- implicit_concatenation
- negative_numbers
- nested_classes
- modules
- duplicate_name
- overlapping-paths
- spurious_init
- usage
- objects
- parameters
- regex
- scopes
- security
- command-execution
- sensitive
- state_tracking
- stmts
- general
- raise_stmt
- try_stmt
- with_stmt
- taint
- collections
- config
- dataflow
- example
- exception_traceback
- extensions
- general
- namedtuple
- strings
- unpacking
- thrift
- types
- attributes
- classattr
- classes
- exceptions
- functions
- properties
- variables
- definitions
- scopes
- web
- bottle
- cherrypy
- client
- requests
- six
- stdlib
- django
- falcon
- flask
- pyramid
- tornado
- turbogears
- twisted
- query-tests
- Exceptions
- general
- generators
- Expressions
- callable
- general
- Functions/general
- Imports
- PyCheckerTests
- pkg_notok
- pkg_ok
- deprecated
- unused
- Metrics/ratios
- Resources
- Security
- CWE-022
- CWE-078
- CWE-079
- CWE-094
- CWE-326
- CWE-327
- CWE-377
- CWE-502
- CWE-601
- CWE-732
- CWE-798
- lib
- django
- conf
- views
- fabric
- invoke
- Statements
- asserts
- general
- analysis/pointsto
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,606 files changed
+124272
-59266
lines changedLines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2 | 2 |
| |
3 | 3 |
| |
4 | 4 |
| |
5 |
| - | |
6 |
| - | |
| 5 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 | 3 |
| |
| 4 | + | |
4 | 5 |
| |
5 | 6 |
| |
6 | 7 |
| |
| |||
13 | 14 |
| |
14 | 15 |
| |
15 | 16 |
| |
| 17 | + | |
| 18 | + | |
| 19 | + | |
16 | 20 |
| |
17 | 21 |
| |
18 | 22 |
| |
|
Lines changed: 39 additions & 30 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 |
| - | |
| 5 | + | |
6 | 6 |
| |
7 |
| - | |
8 | 7 |
| |
9 |
| - | |
10 |
| - | |
| 8 | + | |
11 | 9 |
| |
12 |
| - | |
| 10 | + | |
13 | 11 |
| |
14 |
| - | |
| 12 | + | |
15 | 13 |
| |
16 |
| - | |
| 14 | + | |
17 | 15 |
| |
18 |
| - | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
19 | 21 |
| |
20 |
| - | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
21 | 26 |
| |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
| 27 | + | |
26 | 28 |
| |
27 |
| - | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
28 | 32 |
| |
29 |
| - | |
30 |
| - | |
| 33 | + | |
31 | 34 |
| |
32 |
| - | |
| 35 | + | |
33 | 36 |
| |
34 |
| - | |
35 |
| - | |
36 |
| - | |
37 |
| - | |
38 |
| - | |
39 |
| - | |
40 |
| - | |
| 37 | + | |
41 | 38 |
| |
42 |
| - | |
| 39 | + | |
43 | 40 |
| |
44 |
| - | |
| 41 | + | |
45 | 42 |
| |
46 |
| - | |
47 |
| - | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
48 | 57 |
| |
49 | 58 |
| |
50 | 59 |
| |
51 | 60 |
| |
52 | 61 |
| |
53 |
| - | |
| 62 | + | |
54 | 63 |
| |
55 | 64 |
| |
56 | 65 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| |||
13 | 13 |
| |
14 | 14 |
| |
15 | 15 |
| |
16 |
| - | |
| 16 | + |
Lines changed: 16 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
| 11 | + | |
11 | 12 |
| |
12 | 13 |
| |
13 | 14 |
| |
| |||
17 | 18 |
| |
18 | 19 |
| |
19 | 20 |
| |
| 21 | + | |
20 | 22 |
| |
21 | 23 |
| |
| 24 | + | |
22 | 25 |
| |
23 | 26 |
| |
24 | 27 |
| |
25 | 28 |
| |
| 29 | + | |
26 | 30 |
| |
27 | 31 |
| |
28 | 32 |
| |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
29 | 37 |
| |
30 | 38 |
| |
31 | 39 |
| |
| |||
36 | 44 |
| |
37 | 45 |
| |
38 | 46 |
| |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + |
Lines changed: 17 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
| 9 | + | |
9 | 10 |
| |
10 |
| - | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
11 | 15 |
| |
12 | 16 |
| |
13 | 17 |
| |
14 | 18 |
| |
15 | 19 |
| |
16 | 20 |
| |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
17 | 25 |
| |
18 | 26 |
| |
19 | 27 |
| |
20 | 28 |
| |
21 | 29 |
| |
22 | 30 |
| |
23 |
| - | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
24 | 34 |
| |
25 | 35 |
| |
26 | 36 |
| |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
27 | 41 |
| |
28 | 42 |
| |
29 | 43 |
| |
| 44 | + | |
30 | 45 |
| |
31 | 46 |
| |
32 |
| - | |
|
0 commit comments