File tree
1,251 files changed
+95062
-17223
lines changed- .github
- actions/cache-query-compilation
- workflows
- cpp
- autobuilder/Semmle.Autobuild.Cpp.Tests
- ql
- lib
- change-notes/released
- experimental/semmle/code/cpp/ir/dataflow/internal
- semmle/code/cpp
- dataflow/internal
- ir/dataflow/internal
- src
- change-notes/released
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- extractor/Semmle.Extraction.CSharp
- Entities
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests/all-platforms/msbuild
- lib
- change-notes
- released
- semmle/code
- csharp
- dataflow/internal
- dotnet
- src
- Telemetry
- change-notes/released
- meta/frameworks
- test/library-tests
- csharp11
- dispatch
- scripts
- docs/codeql
- codeql-language-guides
- ql-language-reference
- reusables
- go
- ql
- integration-tests
- all-platforms/go
- go-get-without-modules-sample
- go-mod-sample
- make-sample
- ninja-sample
- linux-only/go
- dep-sample
- work
- vendor/golang.org/x/time
- rate
- glide-sample
- work
- vendor/golang.org/x/time
- rate
- lib
- change-notes
- released
- semmle/go
- dataflow/internal
- frameworks
- stdlib
- security
- src
- Diagnostics
- change-notes
- released
- test
- example-tests/snippets
- extractor-tests
- diagnostics
- CONSISTENCY
- go1.14
- library-tests/semmle/go
- Function
- IR
- Types
- CONSISTENCY
- concepts/HTTP
- dataflow/ArrayConversion
- frameworks/StdlibTaintFlow
- query-tests
- Diagnostics
- CONSISTENCY
- RedundantCode
- DeadStoreOfLocal/CONSISTENCY
- ImpossibleInterfaceNilCheck/CONSISTENCY
- Security/CWE-681
- vendor
- golang.org/x
- mod
- modfile
- module
- sys/execabs
- tools
- go
- gcexportdata
- internal/gcimporter
- packages
- internal
- gcimporter
- gocommand
- pkgbits
- tokeninternal
- typesinternal
- javascript/ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- src
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- frameworks
- internal
- security
- dataflow
- internal
- src
- Security
- CWE-078
- CWE-730
- change-notes/released
- test
- experimental/Security/CWE-918
- library-tests/CryptoLibraries
- query-tests/Security
- CWE-078/UnsafeShellCommandConstruction
- lib
- CWE-079
- UnsafeHtmlConstruction
- lib2
- src
- XssThroughDom
- CWE-089/untyped
- CWE-094/CodeInjection
- CWE-400/ReDoS
- lib
- subLib5
- subLib6
- CWE-730
- CWE-918
- java
- documentation/library-coverage
- downgrades/934bf10b4bd34cf648893efcd1d0d7be9471d39f
- kotlin-extractor/src/main/kotlin
- ql
- integration-tests/all-platforms
- java/diagnostics
- android-gradle-incompatibility
- gradle/wrapper
- project
- src/main
- java/com/github/androidsample
- compilation-error
- src
- main
- java/com/example
- resources
- test/java/com/example
- dependency-error
- src
- main
- java/com/example
- resources
- test/java/com/example
- java-version-too-old
- gradle
- wrapper
- src
- main/java/com/example
- test/java/com/example
- maven-http-repository
- src
- main
- java/com/example
- resources
- test/java/com/example
- multiple-candidate-builds
- maven-project-1
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-project-2
- src
- main
- java/com/example
- resources
- test/java/com/example
- no-build-system
- no-gradle-test-classes
- no-gradle-wrapper
- src
- main/java/com/example
- test/java/com/example
- kotlin
- compiler_arguments
- gradle/wrapper
- diagnostics/kotlin-version-too-new
- fake-kotlinc-source
- com/intellij
- mock
- openapi
- driver
- kotlin
- org/jetbrains/kotlin
- cli
- common
- arguments
- jvm
- config
- utils
- gradle_groovy_app
- gradle/wrapper
- gradle_kotlinx_serialization
- gradle/wrapper
- kotlin_kfunction
- gradle/wrapper
- lib
- change-notes
- released
- config
- ext
- semmle/code
- java
- dataflow
- internal
- dispatch/internal
- security
- upgrades/44d61b266bebf261cb027872646262e645efa059
- src
- Security/CWE
- CWE-022
- CWE-611
- Telemetry
- change-notes
- released
- experimental/Security/CWE/CWE-321
- utils
- flowtestcasegenerator
- modelgenerator/internal
- stub-generator
- test
- experimental/query-tests/security/CWE-321
- library-tests
- frameworks
- apache-commons-lang3
- jdk/java.net
- qlengine
- query-tests/security
- CWE-079/semmle/tests
- CWE-489/debuggable-attribute
- Testbuild
- CWE-524/res/layout
- CWE-798/semmle/tests
- CWE-926
- incomplete_provider_permissions
- stubs/mssql-jdbc-12.2.0
- com/microsoft/sqlserver/jdbc
- javax
- crypto
- spec
- naming
- security/auth
- sql
- org/ietf/jgss
- utils/modelgenerator/dataflow
- misc
- bazel
- codegen
- generators
- lib
- loaders
- templates
- test
- scripts
- suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- concepts
- internal
- dataflow/new/internal
- frameworks
- internal
- objects
- pointsto
- security/dataflow
- types
- src
- Security
- CWE-020-ExternalAPIs
- CWE-022/examples
- change-notes/released
- experimental
- Security
- CWE-022bis
- examples
- semmle/python/security
- meta/analysis-quality
- test
- 2
- library-tests/six
- query-tests/Imports/syntax_error
- experimental
- dataflow
- TestUtil
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage
- enclosing-callable
- exceptions
- fieldflow
- global-flow
- match
- pep_328
- regression
- strange-essaflow
- strange-pointsto-interaction-investigation
- src
- test-1-normal
- test-2-without-splitting
- test-3-max-import-depth-0
- test-4-max-import-depth-100
- test-5-max-import-depth-3
- test-6-max-import-depth-2
- summaries
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking
- variable-capture
- import-resolution
- package/subpackage2
- library-tests
- CallGraph-implicit-init
- CallGraph-imports
- pkg
- CallGraph
- code
- query-tests/Security
- CWE-022-TarSlip
- CWE-022-UnsafeUnpacking
- library-tests
- ApiGraphs/py3
- PointsTo/new
- filters/tests
- frameworks
- django-orm
- django-v2-v3/testproj
- flask
- stdlib
- query-tests/Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-732-WeakFilePermissions
- ql
- autobuilder/src
- buramu
- src
- tree-sitter-blame
- bindings
- node
- rust
- src
- tree_sitter
- extractor
- src
- generator
- src
- ql
- src
- codeql_ql
- ast
- internal
- experimental
- queries
- queries
- bugs
- performance
- reports
- test
- experimental
- queries/bugs/SumWithoutDomain
- ruby
- downgrades/ff289788b1552e32078788baa27152cc95b68f77
- extractor
- generator
- ql
- lib
- change-notes
- released
- codeql
- files
- ruby
- ast
- internal
- dataflow/internal
- frameworks
- core
- internal
- regexp
- security
- internal
- regexp
- upgrades/307ebf14d59930ba903d71d377f6f4129d0a6d22
- src
- change-notes/released
- queries/security
- cwe-020
- examples
- cwe-1333
- test
- library-tests
- ast
- control
- dataflow
- api-graphs
- call-sensitivity
- flow-summaries
- frameworks
- Twirp
- hello_world
- action_controller
- controllers
- action_dispatch
- app
- config
- controllers
- foo
- users
- action_view
- app
- components
- config
- controllers
- foo
- users
- graphql
- mutations
- resolvers
- types
- views/foo/bars
- core
- graphql
- app/graphql
- mutations
- resolvers
- types
- posix-spawn
- security
- query-tests
- diagnostics
- src
- experimental/improper-memoization
- security
- cwe-020/MissingFullAnchor
- impl
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-1333-polynomial-redos
- lib
- swift
- actions
- build-and-test
- run-integration-tests
- codegen
- generators
- lib
- schema
- templates
- extractor/trap
- ql
- lib/codeql/swift
- controlflow/internal
- dataflow
- internal
- elements
- expr
- stmt
- frameworks/StandardLibrary
- generated
- printast
- security
- test
- extractor-tests/generated
- Comment
- OtherAvailabilitySpec
- PlatformVersionAvailabilitySpec
- decl
- ConstructorDecl
- DestructorDecl
- EnumCaseDecl
- EnumElementDecl
- GenericTypeParamDecl
- InfixOperatorDecl
- PatternBindingDecl
- PostfixOperatorDecl
- PrecedenceGroupDecl
- PrefixOperatorDecl
- ProtocolDecl
- StructDecl
- SubscriptDecl
- TopLevelCodeDecl
- TypeAliasDecl
- expr
- Argument
- ArrayExpr
- AssignExpr
- AutoClosureExpr
- BinaryExpr
- BindOptionalExpr
- BooleanLiteralExpr
- CallExpr
- CaptureListExpr
- ClosureExpr
- CoerceExpr
- ConditionalCheckedCastExpr
- DeclRefExpr
- DefaultArgumentExpr
- DictionaryExpr
- DiscardAssignmentExpr
- DotSyntaxBaseIgnoredExpr
- DynamicTypeExpr
- FloatLiteralExpr
- ForceTryExpr
- ForceValueExpr
- ForcedCheckedCastExpr
- IfExpr
- InOutExpr
- IntegerLiteralExpr
- InterpolatedStringLiteralExpr
- IsExpr
- KeyPathApplicationExpr
- KeyPathDotExpr
- KeyPathExpr
- LazyInitializerExpr
- MagicIdentifierLiteralExpr
- MakeTemporarilyEscapableExpr
- MemberRefExpr
- NilLiteralExpr
- OneWayExpr
- OpaqueValueExpr
- OpenExistentialExpr
- OptionalEvaluationExpr
- OptionalTryExpr
- OtherConstructorDeclRefExpr
- PrefixUnaryExpr
- RebindSelfInConstructorExpr
- RegexLiteralExpr
- StringLiteralExpr
- SubscriptExpr
- SuperRefExpr
- TapExpr
- TryExpr
- TupleElementExpr
- TupleExpr
- TypeExpr
- VarargExpansionExpr
- pattern
- AnyPattern
- BindingPattern
- BoolPattern
- EnumElementPattern
- ExprPattern
- IsPattern
- NamedPattern
- OptionalSomePattern
- ParenPattern
- TuplePattern
- TypedPattern
- stmt
- BraceStmt
- BreakStmt
- CaseLabelItem
- CaseStmt
- ConditionElement
- ContinueStmt
- DeferStmt
- DoCatchStmt
- DoStmt
- FallthroughStmt
- ForEachStmt
- GuardStmt
- IfStmt
- RepeatWhileStmt
- ReturnStmt
- StmtCondition
- SwitchStmt
- ThrowStmt
- WhileStmt
- YieldStmt
- type
- ArraySliceType
- BoundGenericClassType
- BoundGenericEnumType
- BoundGenericStructType
- ClassType
- DependentMemberType
- DictionaryType
- EnumType
- ExistentialMetatypeType
- FunctionType
- GenericFunctionType
- GenericTypeParamType
- LValueType
- MetatypeType
- OptionalType
- ParenType
- ProtocolType
- StructType
- TypeAliasType
- TypeRepr
- UnboundGenericType
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- flowsources
- taint
- elements/expr/arithmeticoperation
- query-tests/Security
- CWE-022
- CWE-311
- third_party
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,251 files changed
+95062
-17223
lines changedLines changed: 103 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 |
| - | |
| 12 | + | |
13 | 13 |
| |
14 | 14 |
| |
15 | 15 |
| |
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
31 | 33 |
| |
32 | 34 |
| |
33 | 35 |
| |
| |||
37 | 39 |
| |
38 | 40 |
| |
39 | 41 |
| |
40 |
| - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
41 | 45 |
| |
42 | 46 |
| |
43 | 47 |
| |
44 | 48 |
| |
45 |
| - | |
46 |
| - | |
| 49 | + | |
| 50 | + | |
47 | 51 |
| |
48 | 52 |
| |
49 |
| - | |
50 |
| - | |
51 |
| - | |
52 | 53 |
| |
53 | 54 |
| |
54 | 55 |
| |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + |
Lines changed: 0 additions & 75 deletions
This file was deleted.
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
27 |
| - | |
| 27 | + | |
28 | 28 |
| |
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
| |
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
37 |
| - | |
| 37 | + |
Lines changed: 4 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| |||
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
50 |
| - | |
| 50 | + | |
51 | 51 |
| |
52 | 52 |
| |
53 |
| - | |
| 53 | + | |
54 | 54 |
| |
55 | 55 |
| |
56 | 56 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
24 | 24 |
| |
25 | 25 |
| |
26 |
| - | |
| 26 | + | |
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
|
Lines changed: 7 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 | 8 |
| |
16 | 9 |
| |
17 | 10 |
| |
| |||
22 | 15 |
| |
23 | 16 |
| |
24 | 17 |
| |
| 18 | + | |
| 19 | + | |
25 | 20 |
| |
26 | 21 |
| |
27 | 22 |
| |
| |||
34 | 29 |
| |
35 | 30 |
| |
36 | 31 |
| |
37 |
| - | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
38 | 35 |
| |
39 | 36 |
| |
40 | 37 |
| |
| |||
57 | 54 |
| |
58 | 55 |
| |
59 | 56 |
| |
| 57 | + | |
60 | 58 |
| |
61 | 59 |
| |
62 | 60 |
| |
| |||
65 | 63 |
| |
66 | 64 |
| |
67 | 65 |
| |
| 66 | + | |
68 | 67 |
| |
69 | 68 |
| |
70 | 69 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
8 | 9 |
| |
9 | 10 |
| |
10 | 11 |
| |
| |||
19 | 20 |
| |
20 | 21 |
| |
21 | 22 |
| |
| 23 | + | |
22 | 24 |
| |
23 | 25 |
| |
24 | 26 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
53 | 53 |
| |
54 | 54 |
| |
55 | 55 |
| |
56 |
| - | |
| 56 | + | |
57 | 57 |
|
Lines changed: 4 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2 | 2 |
| |
3 | 3 |
| |
4 | 4 |
| |
5 |
| - | |
6 |
| - | |
7 |
| - | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
8 | 8 |
| |
| 9 | + | |
9 | 10 |
| |
10 | 11 |
| |
11 | 12 |
| |
|
Lines changed: 8 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
131 | 131 |
| |
132 | 132 |
| |
133 | 133 |
| |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
134 | 142 |
| |
135 | 143 |
| |
136 | 144 |
| |
|
0 commit comments