File tree
907 files changed
+29891
-8280
lines changed- .github/workflows
- config
- cpp
- change-notes
- ql
- src
- Best Practices
- Magic Constants
- Critical
- Likely Bugs
- Arithmetic
- Conversion
- Format
- Likely Typos
- Memory Management
- OO
- Underspecified Functions
- Metrics/Files
- Security/CWE
- CWE-190
- CWE-428
- experimental/Security/CWE
- CWE-570
- CWE-691
- CWE-783
- CWE-788
- jsf/4.24 Control Flow Structures
- semmle/code/cpp
- controlflow
- internal
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- internal
- models
- implementations
- interfaces
- rangeanalysis
- security
- test
- experimental/query-tests/Security/CWE
- CWE-570/semmle/tests
- CWE-691/semmle/tests
- CWE-788/semmle/tests
- include
- library-tests
- dataflow
- dataflow-tests
- fields
- smart-pointers-taint
- taint-tests
- ir
- ir
- points_to
- ssa
- query-tests
- Critical/MemoryFreed
- Likely Bugs
- Likely Typos/AssignWhereCompareMeant
- Memory Management/ReturnStackAllocatedMemory
- Security/CWE
- CWE-190/semmle
- extreme
- tainted
- CWE-764/semmle/tests
- jsf/4.10 Classes/AV Rule 79
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- change-notes
- extractor
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Extractor
- Semmle.Extraction
- ql
- src
- API Abuse
- Diagnostics
- Language Abuse
- Likely Bugs
- Metrics
- Files
- Summaries
- Security Features
- CWE-011
- CWE-209
- Stubs
- codeql-suites
- experimental/ir/implementation
- raw
- internal
- unaliased_ssa
- internal
- semmle/code
- cil/internal
- csharp
- controlflow
- internal
- pressa
- dataflow
- internal
- basessa
- rangeanalysis
- dispatch
- exprs
- frameworks
- security/dataflow
- flowsources
- dotnet
- test
- experimental/ir/ir
- library-tests
- controlflow
- graph
- guards-large
- guards
- splits
- csharp7.1
- csharp7
- dataflow
- global
- library
- local
- modulusanalysis
- signanalysis
- tuples
- diagnostics
- expressions
- exprorstmtparent
- goto
- parameters
- standalone
- controlflow
- errorrecovery
- query-tests
- Metrics/Summaries
- Security Features
- CWE-089
- CWE-134
- Stubs
- resources/stubs
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- ql-language-reference
- support/reusables
- writing-codeql-queries
- ql-libraries/dataflow
- javascript
- change-notes
- externs/es
- extractor
- src/com/semmle
- js/parser
- ts/extractor
- tests/ts/output/trap
- ql
- examples/queries/dataflow
- BackendIdor
- DecodingAfterSanitization
- EvalTaint
- InformationDisclosure
- StoredXss
- TemplateInjection
- src
- Declarations
- Diagnostics
- LanguageFeatures
- Metrics/Dependencies
- NodeJS
- Security
- CWE-079
- CWE-295
- CWE-400
- CWE-611
- CWE-829
- Summary
- experimental
- Security
- CWE-1004
- CWE-614
- Summaries
- semmle/javascript/security
- meta/alerts
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- internal
- security
- dataflow
- performance
- test
- library-tests
- NPM
- src
- TaintTracking
- TypeScript
- BaseUrl
- A
- B
- src
- lib
- RegressionTests
- ImportSelf
- TemplateTypes
- TraceResolution
- frameworks
- Electron
- Redux
- SQL
- query-tests
- Diagnostics
- Performance/ReDoS
- lib/sublib
- Security
- CWE-022/TaintedPath
- CWE-078
- lib
- subLib2
- subLib3
- CWE-079
- ReflectedXss
- XssThroughDom
- CWE-1004
- CWE-295
- CWE-601/ClientSideUrlRedirect
- CWE-614
- CWE-730
- CWE-770
- CWE-918
- Summary
- src
- java
- change-notes
- ql
- src
- Diagnostics
- Likely Bugs
- Concurrency
- Frameworks/Swing
- Likely Typos
- Resource Leaks
- Metrics
- RefTypes
- Summaries
- Performance
- Security/CWE
- CWE-022
- CWE-094
- CWE-209
- CWE-297
- CWE-319
- CWE-327
- CWE-502
- CWE-611
- CWE-643
- CWE-798
- Violations of Best Practice
- Dead Code
- Undesirable Calls
- legacy
- experimental
- Security/CWE
- CWE-016
- CWE-094
- CWE-1004
- CWE-297
- CWE-347
- CWE-348
- CWE-352
- CWE-555
- CWE-600
- semmle/code/java/frameworks
- semmle/code
- java
- dataflow
- internal
- dispatch
- frameworks
- apache
- guava
- play
- spring
- security
- test
- experimental
- query-tests/security
- CWE-016
- CWE-074
- CWE-094
- CWE-1004
- CWE-347
- CWE-348
- CWE-352
- CWE-522
- CWE-555
- CWE-652
- CWE-918
- stubs
- groovy-all-3.0.7/groovy
- lang
- util
- jwtk-jjwt-0.11.2
- io/jsonwebtoken
- impl
- security
- library-tests
- dataflow
- external-models
- local-additional-taint
- records
- taint-format
- frameworks
- apache-commons-lang3
- guava
- literals-numeric
- printAst
- ssa
- query-tests
- Metrics
- StringFormat
- security
- CWE-022/semmle/tests
- CWE-113/semmle/tests
- CWE-190/semmle/tests
- CWE-502
- CWE-611
- CWE-643
- CWE-681/semmle/tests
- stubs
- dom4j-2.1.1/org/dom4j
- rule
- tree
- util
- xpath
- fastjson-1.2.74/com/alibaba/fastjson
- gson-2.8.6/com/google/gson
- java-ee-el/javax/el
- jaxb-api-2.3.1/javax/xml/bind
- jaxen-1.2.0/org/jaxen
- pattern
- jsr311-api-1.1.1/javax/ws/rs/core
- juel-2.2/de/odysseus/el
- util
- servlet-api-2.4/javax/servlet/http
- springframework-5.2.3/org/springframework
- beans/factory/annotation
- core/annotation
- security/web/csrf
- stereotype
- web/bind/annotation
- misc/suite-helpers
- python
- change-notes
- ql
- src
- Classes
- Diagnostics
- Functions
- Imports
- Metrics
- Security
- CVE-2018-1281
- CWE-327
- Summary
- Variables
- experimental
- Classes
- Functions
- typetracking
- external
- semmle/python
- dataflow/new
- internal
- frameworks
- pointsto
- test
- 3/library-tests/modules/entry_point
- experimental
- dataflow
- ApiGraphs
- tainttracking
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- unwanted-global-flow
- typetracking
- meta
- inline-taint-test-demo
- query-tests
- Classes/Naming
- Functions/general
- library-tests
- frameworks
- django-v2-v3
- testproj
- django
- fabric
- flask
- modeling-example
- stdlib
- tornado
- modules/__all__
- query-tests
- Diagnostics
- Security/CWE-327
- Summary
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
907 files changed
+29891
-8280
lines changedLines changed: 30 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + |
Lines changed: 8 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
22 | 27 |
| |
23 | 28 |
| |
24 | 29 |
| |
25 | 30 |
| |
26 | 31 |
| |
27 | 32 |
| |
28 |
| - | |
| 33 | + | |
29 | 34 |
| |
30 | 35 |
| |
31 | 36 |
| |
| |||
34 | 39 |
| |
35 | 40 |
| |
36 | 41 |
| |
37 |
| - | |
| 42 | + | |
38 | 43 |
| |
39 | 44 |
| |
40 | 45 |
| |
| |||
48 | 53 |
| |
49 | 54 |
| |
50 | 55 |
| |
51 |
| - | |
| 56 | + |
Lines changed: 5 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
8 | 9 |
| |
9 | 10 |
| |
10 | 11 |
| |
| |||
56 | 57 |
| |
57 | 58 |
| |
58 | 59 |
| |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
59 | 64 |
| |
60 | 65 |
| |
61 | 66 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
39 | 39 |
| |
40 | 40 |
| |
41 | 41 |
| |
42 |
| - | |
| 42 | + | |
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
38 | 38 |
| |
39 | 39 |
| |
40 | 40 |
| |
41 |
| - | |
| 41 | + | |
42 | 42 |
| |
43 | 43 |
| |
44 | 44 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
24 |
| - | |
| 24 | + | |
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
|
0 commit comments