File tree
1,161 files changed
+30954
-16980
lines changed- .github/workflows
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- change-notes
- ql
- src
- Diagnostics
- Likely Bugs
- Likely Typos
- Memory Management
- Metrics
- Dependencies
- Files
- Security/CWE/CWE-428
- Summary
- experimental/Security/CWE
- CWE-570
- CWE-691
- CWE-783
- CWE-788
- external/tests
- filters
- jsf/4.10 Classes
- semmle/code/cpp
- dataflow/internal
- exprs
- ir
- dataflow
- internal
- tainttracking3
- implementation/raw/internal
- models
- implementations
- interfaces
- security
- test
- experimental/query-tests/Security/CWE
- CWE-570/semmle/tests
- CWE-691/semmle/tests
- CWE-788/semmle/tests
- library-tests
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- dataflow-tests
- fields
- security-taint
- smart-pointers-taint
- taint-tests
- ir
- ir
- ssa
- syntax-zoo
- query-tests
- Critical/MemoryFreed
- Likely Bugs
- Likely Typos/AssignWhereCompareMeant
- Memory Management/ReturnStackAllocatedMemory
- Security/CWE
- CWE-022/semmle/tests
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114/semmle/UncontrolledProcessOperation
- CWE-120/semmle/tests
- CWE-134/semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190/semmle
- TaintedAllocationSize
- extreme
- tainted
- uncontrolled
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-764/semmle/tests
- CWE-807/semmle/TaintedCondition
- Summary
- jsf/4.10 Classes/AV Rule 79
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- change-notes
- config/suites/lgtm
- extractor
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp/Entities
- Expressions
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util.Tests
- ql
- src
- API Abuse
- Metrics
- Dependencies
- Files
- Security Features/CWE-937
- Stubs
- codeql-suites
- external
- filters
- semmle/code
- cil
- internal
- csharp
- commons
- controlflow/internal/pressa
- dataflow
- internal
- basessa
- dispatch
- exprs
- frameworks
- dotnet
- test
- library-tests
- controlflow
- graph
- splits
- csharp7.1
- csharp7
- dataflow
- async
- collections
- delegates
- fields
- functionpointers
- global
- library
- local
- modulusanalysis
- signanalysis
- tuples
- types
- exprorstmtparent
- frameworks/EntityFramework
- goto
- parameters
- standalone/controlflow
- query-tests
- Metrics
- Dependencies/ExternalDependencies
- Files/FLinesOfDuplicatedCode
- Security Features
- CWE-079/StoredXSS
- CWE-089
- CWE-338
- CWE-937
- Stubs
- resources/stubs
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- ql-language-reference
- support
- reusables
- writing-codeql-queries
- ql-libraries/dataflow
- javascript
- change-notes
- extractor
- src/com/semmle
- js
- extractor
- parser
- ts/extractor
- tests/ts/output/trap
- ql
- examples/queries/dataflow
- BackendIdor
- DecodingAfterSanitization
- EvalTaint
- InformationDisclosure
- StoredXss
- TemplateInjection
- src
- Comments
- Declarations
- Metrics
- Dependencies
- Security
- CWE-078
- CWE-295
- CWE-327
- Summary
- experimental
- Security/CWE-094
- Summaries
- external
- filters
- meta
- alerts
- analysis-quality
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- AngularJS
- internal
- security/dataflow
- test
- ApiGraphs/typed
- library-tests
- NPM
- src
- PackageExports
- RecursionPrevention
- TaintTracking
- TypeScript
- BaseUrl
- A
- B
- src
- lib
- ImportOutDir
- slashAndExtension
- src
- RegressionTests
- ImportSelf
- TemplateTypes
- TraceResolution
- frameworks
- ClientRequests
- Collections
- Electron
- EventEmitter
- ReactJS
- Redux
- SQL
- SocketIO
- WebSocket
- query-tests
- Security
- CWE-022/TaintedPath
- CWE-078
- lib
- subLib2
- subLib3
- subLib
- CWE-089/untyped
- CWE-295
- CWE-918
- Summary
- src
- external
- DuplicateFunction
- DuplicateToplevel
- SimilarFunction
- SimilarToplevel
- java
- change-notes
- ql
- src
- Likely Bugs/Likely Typos
- Metrics
- Dependencies
- Files
- Performance
- Security/CWE
- CWE-209
- CWE-327
- CWE-798
- Violations of Best Practice/Undesirable Calls
- experimental
- Security/CWE
- CWE-016
- CWE-036
- CWE-094
- CWE-1004
- CWE-117
- CWE-273
- CWE-295
- CWE-297
- CWE-312
- CWE-326
- CWE-346
- CWE-352
- CWE-489
- CWE-502
- CWE-522
- CWE-532
- CWE-548
- CWE-555
- CWE-598
- CWE-600
- CWE-652
- CWE-749
- CWE-755
- CWE-759
- CWE-927
- CWE-939
- semmle/code/java
- frameworks
- external
- filters
- meta/frameworks
- semmle/code
- java
- dataflow
- internal
- dispatch
- frameworks
- apache
- guava
- play
- security
- test
- experimental
- query-tests/security
- CWE-016
- CWE-074
- CWE-094
- CWE-1004
- CWE-297
- CWE-346
- CWE-352
- CWE-502
- CWE-522
- CWE-555
- CWE-652
- CWE-759
- CWE-918
- stubs/groovy-all-3.0.7/groovy
- lang
- util
- library-tests
- dataflow
- external-models
- lambda
- local-additional-taint
- records
- taint-format
- frameworks
- apache-commons-lang3
- guava
- literals-numeric
- literals
- literals
- printAst
- ssa
- query-tests
- StringFormat
- security
- CWE-022/semmle/tests
- CWE-113/semmle/tests
- CWE-190/semmle/tests
- CWE-502
- CWE-611
- CWE-681/semmle/tests
- stubs
- apache-commons-lang3-3.7/org/apache/commons/lang3
- fastjson-1.2.74/com/alibaba/fastjson
- gson-2.8.6/com/google/gson
- java-ee-el/javax/el
- jaxb-api-2.3.1/javax/xml/bind
- jsr311-api-1.1.1/javax/ws/rs/core
- juel-2.2/de/odysseus/el
- util
- saxon-xqj-9.x
- javax/xml/xquery
- net/sf/saxon
- xqj
- servlet-api-2.4/javax/servlet
- http
- springframework-5.2.3/org/springframework
- boot
- autoconfigure
- context/annotation
- core/annotation
- remoting
- httpinvoker
- rmi
- security/web/csrf
- stereotype
- web/bind/annotation
- python
- change-notes
- ql
- src
- Filters
- Lexical
- Metrics
- Dependencies
- experimental
- Classes
- Functions
- Security-old-dataflow
- CVE-2018-1281
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-094
- CWE-326
- CWE-502
- CWE-601
- semmle/python
- frameworks
- external
- semmle/python
- dataflow/new
- internal
- frameworks
- objects
- pointsto
- test
- 3/library-tests/modules/entry_point
- hash_bang
- namespace_package
- package
- name_main
- namespace_package
- package
- no_py_extension
- namespace_package
- package
- experimental
- dataflow/typetracking
- library-tests/frameworks
- flask
- yaml
- query-tests
- Classes/Naming
- Functions/general
- library-tests
- DuplicateCode
- frameworks
- cryptodome
- cryptography
- crypto
- dill
- django-v1
- django-v2-v3
- testapp
- migrations
- testproj
- django
- fabric
- flask
- invoke
- modeling-example
- mysql-connector-python
- mysqldb
- pymysql
- stdlib-py2
- stdlib-py3
- stdlib
- tornado
- yaml
- modules/__all__
- query-tests/UselessCode/DuplicateCode
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,161 files changed
+30954
-16980
lines changedLines changed: 30 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + |
Lines changed: 0 additions & 29 deletions
This file was deleted.
Lines changed: 8 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
36 | 36 |
| |
37 | 37 |
| |
38 | 38 |
| |
| 39 | + | |
39 | 40 |
| |
40 | 41 |
| |
41 | 42 |
| |
| |||
55 | 56 |
| |
56 | 57 |
| |
57 | 58 |
| |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
58 | 63 |
| |
59 | 64 |
| |
60 | 65 |
| |
| |||
376 | 381 |
| |
377 | 382 |
| |
378 | 383 |
| |
379 |
| - | |
380 | 384 |
| |
381 | 385 |
| |
382 | 386 |
| |
| |||
429 | 433 |
| |
430 | 434 |
| |
431 | 435 |
| |
432 |
| - | |
| 436 | + | |
| 437 | + | |
433 | 438 |
| |
434 | 439 |
| |
435 | 440 |
| |
436 | 441 |
| |
437 | 442 |
| |
438 |
| - | |
| 443 | + |
Lines changed: 29 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
8 | 9 |
| |
9 | 10 |
| |
10 | 11 |
| |
| |||
43 | 44 |
| |
44 | 45 |
| |
45 | 46 |
| |
| 47 | + | |
| 48 | + | |
46 | 49 |
| |
47 | 50 |
| |
48 | 51 |
| |
| |||
135 | 138 |
| |
136 | 139 |
| |
137 | 140 |
| |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
138 | 149 |
| |
139 | 150 |
| |
140 | 151 |
| |
| |||
153 | 164 |
| |
154 | 165 |
| |
155 | 166 |
| |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
156 | 179 |
| |
157 | 180 |
| |
158 | 181 |
| |
| |||
213 | 236 |
| |
214 | 237 |
| |
215 | 238 |
| |
| 239 | + | |
216 | 240 |
| |
217 | 241 |
| |
218 | 242 |
| |
| |||
273 | 297 |
| |
274 | 298 |
| |
275 | 299 |
| |
276 |
| - | |
| 300 | + | |
| 301 | + | |
277 | 302 |
| |
278 | 303 |
| |
279 | 304 |
| |
| |||
286 | 311 |
| |
287 | 312 |
| |
288 | 313 |
| |
| 314 | + | |
| 315 | + | |
289 | 316 |
| |
290 | 317 |
| |
291 | 318 |
| |
292 | 319 |
| |
293 |
| - | |
| 320 | + | |
294 | 321 |
| |
295 | 322 |
| |
296 | 323 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
20 |
| - | |
| 20 | + | |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 16 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + |
Lines changed: 137 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + |
Lines changed: 4 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
3 |
| - | |
| 2 | + | |
| 3 | + | |
4 | 4 |
| |
5 |
| - | |
| 5 | + | |
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
22 |
| - | |
| 22 | + |
0 commit comments