File tree
1,667 files changed
+85581
-52733
lines changed- .vscode
- change-notes
- 1.24
- 1.25
- config
- cpp
- ql
- src
- Critical
- Documentation
- JPL_C/LOC-3/Rule 17
- Likely Bugs
- Protocols
- Underspecified Functions
- Metrics/History
- Security/CWE
- CWE-022
- CWE-079
- CWE-089
- CWE-114
- CWE-120
- CWE-134
- CWE-190
- CWE-290
- CWE-311
- CWE-313
- CWE-457
- CWE-468
- CWE-807
- codeql-suites
- experimental/semmle/code/cpp/rangeanalysis
- external
- tests
- filters
- semmle/code/cpp
- commons
- controlflow/internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- exprs
- internal
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- implementation
- aliased_ssa
- constant
- internal
- internal
- raw
- constant
- internal
- unaliased_ssa
- constant
- internal
- internal
- models
- implementations
- interfaces
- padding
- rangeanalysis
- security
- test
- experimental/library-tests/rangeanalysis
- arraylengthanalysis
- inboundsptr
- header-variant-tests/deduplication
- library-tests
- allocators
- attributes
- field_attributes
- var_attributes
- clang_ms
- conditions
- conversions
- dataflow
- DefaultTaintTracking
- dataflow-tests
- fields
- partialdefinitions
- taint-tests
- defuse
- functions/functions
- ir
- constant_func
- escape
- ir
- ssa
- types
- literals/uuidof
- rangeanalysis
- rangeanalysis
- signanalysis
- syntax-zoo
- templates
- instantiations_functions
- isfromtemplateinstantiation
- prototype_bodies
- type_instantiations
- type_sizes
- types
- integral_types_ms
- integral_types
- unnamed
- unspecified_type/types
- usings
- valuenumbering/GlobalValueNumbering
- variables/variables
- query-tests
- Critical
- NewFree
- OverflowCalculated
- Likely Bugs/Arithmetic/PointlessComparison
- Security/CWE
- CWE-022/semmle/tests
- CWE-079/semmle/CgiXss
- CWE-114/semmle/UncontrolledProcessOperation
- CWE-119/semmle/tests
- CWE-120/semmle/tests
- CWE-131/semmle/NoSpaceForZeroTerminator
- CWE-134/semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190/semmle
- ComparisonWithWiderType
- TaintedAllocationSize
- extreme
- uncontrolled
- wider_type
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-367/semmle
- CWE-468/semmle/SuspiciousAddWithSizeof
- CWE-807/semmle/TaintedCondition
- upgrades
- 2074f1cc7a3659ad555465a8025a8f2b7687896b
- 874439f4c501cb03a39fba053eef9d384216bbf2
- d6ca4ebb7680e241b647e78b96999eaf9d84e5b7
- csharp
- autobuilder
- Semmle.Autobuild.Tests
- Semmle.Autobuild
- extractor
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Types
- Semmle.Extraction
- Entities
- Semmle.Util.Tests
- Semmle.Util
- ql
- src
- API Abuse
- Security Features
- CWE-091
- CWE-114
- CWE-134
- CWE-201
- CWE-209
- CWE-451
- CWE-838
- codeql-suites
- experimental/CWE-099
- semmle/code
- csharp
- controlflow
- dataflow
- flowsources
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- exprs
- frameworks
- ir
- implementation
- internal
- raw
- internal
- common
- desugar
- internal
- unaliased_ssa
- internal
- internal
- rangeanalysis
- security/dataflow
- flowsinks
- flowsources
- dotnet
- test
- library-tests
- controlflow/graph
- csharp6
- csharp7
- dataflow
- callablereturnsarg
- collections
- fields
- flowsources/remote
- global
- library
- local
- types
- generics
- ir/ir
- overrides
- standalone
- controlflow
- errorrecovery
- regressions
- unification
- query-tests
- API Abuse
- FormatInvalid
- FormatMissingArgument
- FormatUnusedArgument
- Nullness
- Security Features/CWE-209
- upgrades/ad622770b3c38e7639883301e9e52ff1f3a4df4c
- docs
- language
- global-sphinx-files
- learn-ql
- beginner
- cpp
- csharp
- go
- javascript
- java
- python
- writing-queries
- ql-handbook
- ql-spec
- ql-training
- cpp
- java
- slide-snippets
- reusables
- support
- reusables
- javascript
- config/suites/javascript
- documentation
- extractor
- lib/typescript
- src/com/semmle/js
- extractor
- parser
- ql
- src
- AngularJS
- DOM
- Declarations
- Expressions
- JSDoc
- LanguageFeatures
- NodeJS
- Security
- CWE-020
- CWE-078
- examples
- CWE-079
- examples
- CWE-089/examples
- CWE-116
- examples
- CWE-134/examples
- CWE-327/examples
- CWE-352/examples
- CWE-400
- CWE-502/examples
- CWE-601/examples
- CWE-611/examples
- CWE-776/examples
- CWE-798/examples
- CWE-843/examples
- CWE-916/examples
- CWE-918/examples
- Statements
- codeql-suites
- experimental
- Security/CWE-94
- examples
- poi
- external
- filters
- meta
- SSA
- semmle/javascript
- dataflow
- internal
- explore
- frameworks
- AngularJS
- heuristics
- internal
- security
- dataflow
- test
- experimental/PoI
- library-tests
- AMD
- Arrays
- DataFlow
- DefUse
- Flow
- GlobalAccessPaths
- InterProceduralFlow
- LocalObjects
- ModuleImportNodes
- Modules
- NodeJS
- PackageExports
- lib1
- sublib
- Promises
- PropWrite
- RecursionPrevention
- Refinements
- SSA/GetRhsNode
- TaintTracking
- TypeScript
- CallResolution
- CallSignatureTypes
- RegressionTests/NegativeNumberType
- frameworks
- AngularJS
- modules
- scopes
- Collections
- Electron
- EventEmitter
- Express
- src
- NodeJSLib
- SQL
- SocketIO
- connect
- fastify
- src
- hapi
- jQuery
- koa
- restify
- variables
- query-tests
- Declarations/UnusedProperty
- Expressions
- ExprHasNoEffect
- ImplicitOperandConversion
- MisspelledVariableName
- UnknownDirective
- Security
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- lib
- subLib
- CWE-079
- CWE-089/untyped
- CWE-094/CodeInjection
- CWE-116/IncompleteSanitization
- CWE-338
- CWE-400
- PrototypePollutionUtility
- CWE-601/ClientSideUrlRedirect
- Statements/UselessConditional
- upgrades/03c078a7e6eec294f1457b3d20f9fec4427cb4af
- java
- ql
- src
- Advisory
- Documentation
- Naming
- Architecture/Dependencies
- Compatibility/JDK9
- codeql-suites
- config
- experimental
- CWE-532
- CWE-939
- Security/CWE
- CWE-016
- CWE-074
- CWE-1004
- semmle/code/java/frameworks
- spring
- external
- meta/ssa
- semmle/code
- java
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- dispatch
- frameworks
- gwt
- j2objc
- jackson
- javaee
- ejb
- jsf
- security
- xml
- test
- experimental
- query-tests/security
- CWE-016
- CWE-074
- stubs
- shiro-core-1.5.2/org/apache/shiro/jndi
- spring-ldap-2.3.2/org/springframework/ldap
- core
- filter
- query
- support
- springframework-5.2.3/org/springframework
- beans/factory
- boot
- actuate/autoconfigure/security/servlet
- security/servlet
- context
- core
- env
- io
- support
- jndi
- security
- config
- annotation
- web
- builders
- configurers
- web
- util/matcher
- web
- bind/annotation
- context
- library-tests
- Encryption
- UnsafeDeserialization
- dataflow
- gettersetter
- getter
- local-additional-taint
- switchexpr
- taintsources
- guards12
- structure
- query-tests
- Nullness
- RangeAnalysis
- stubs
- apache-commons-codec-1.14
- org/apache/commons/codec
- springframework-5.2.3
- org/springframework
- core/io
- lang
- util
- web/multipart
- upgrades/054d7e823b2c5b93bf2a14d5c22a107934fbc133
- python/ql
- examples/snippets
- src
- Classes
- Expressions
- Functions
- Imports
- Resources
- Security
- CWE-022
- CWE-312
- CWE-798
- Statements
- Variables
- analysis
- codeql-suites
- external
- semmle/python
- dataflow
- filters
- objects
- pointsto
- security
- injection
- strings
- types
- web
- bottle
- cherrypy
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- webob
- xml
- test
- 2/library-tests/types/exceptions
- 3
- library-tests
- PointsTo/consts
- taint/unpacking
- types/exceptions
- query-tests
- Classes/equals-attr
- Statements/iter
- library-tests
- PointsTo
- calls
- extensions
- new
- regressions/missing
- if-urlsplit-access
- re-compile
- uncalled-function
- examples/custom-sanitizer
- filters/tests
- taint
- collections
- config
- example
- extensions
- flowpath_regression
- general
- namedtuple
- strings
- unpacking
- types/exceptions
- web
- flask
- stdlib
- query-tests
- Classes
- Arguments
- equals-hash
- Expressions/Arguments
- Functions
- general
- overriding
- Imports/unused
- Security/CWE-327
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,667 files changed
+85581
-52733
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
22 |
| - | |
| 22 | + | |
23 | 23 |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + |
Lines changed: 10 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + |
Lines changed: 27 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + |
Lines changed: 14 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
4 |
| - | |
5 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
6 | 8 |
| |
7 | 9 |
| |
8 | 10 |
| |
9 | 11 |
| |
10 | 12 |
| |
11 | 13 |
| |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + |
Lines changed: 115 additions & 28 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
4 | 9 |
| |
5 |
| - | |
| 10 | + | |
| 11 | + | |
6 | 12 |
| |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 |
| - | |
| 13 | + | |
19 | 14 |
| |
20 |
| - | |
| 15 | + | |
| 16 | + | |
21 | 17 |
| |
22 |
| - | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
23 | 25 |
| |
24 |
| - | |
| 26 | + | |
25 | 27 |
| |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
26 | 36 |
| |
27 |
| - | |
28 |
| - | |
29 |
| - | |
30 |
| - | |
31 |
| - | |
32 |
| - | |
33 |
| - | |
| 37 | + | |
34 | 38 |
| |
35 |
| - | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
36 | 43 |
| |
37 |
| - | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
38 | 48 |
| |
39 |
| - | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + |
0 commit comments