File tree
2,268 files changed
+95427
-31433
lines changed- cpp
- autobuilder/Semmle.Autobuild.Cpp.Tests
- ql
- lib
- change-notes
- released
- semmle/code/cpp
- ir/dataflow
- internal
- models
- implementations
- interfaces
- rangeanalysis/new
- internal/semantic
- analysis
- src
- Likely Bugs/Memory Management
- Security/CWE
- CWE-114
- CWE-120
- CWE-134
- CWE-190
- Summary
- change-notes
- released
- experimental/cryptography/inventory/new_models
- test
- library-tests
- dataflow
- dataflow-tests
- source-sink-tests
- taint-tests
- ir
- modulus-analysis
- range-analysis
- sign-analysis
- syntax-zoo
- query-tests
- Likely Bugs/Memory Management/ReturnStackAllocatedMemory
- Security/CWE
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-119/semmle/tests
- CWE-120/semmle/tests
- CWE-134/semmle/globalVars
- CWE-190
- SAMATE
- semmle/tainted
- CWE-193
- CWE-197/SAMATE/IntegerOverflowTainted
- CWE-457/semmle/tests
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp
- Entities
- Populators
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities/Base
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- examples/snippets
- integration-tests
- all-platforms
- diag_recursive_generics
- dotnet_pack
- posix-only
- dotnet_test_mstest
- dotnet_test
- standalone_dependencies_multi_target
- standalone_dependencies_nuget
- standalone_dependencies
- windows-only/standalone_dependencies
- lib
- Linq
- change-notes/released
- ext
- generated
- semmle/code
- asp
- cil
- csharp
- commons
- controlflow/internal
- dataflow
- internal
- rangeanalysis
- frameworks
- microsoft
- system
- collections
- data
- linq
- runtime
- security/cryptography
- text
- threading
- test
- security
- auth
- cryptography
- dataflow
- flowsinks
- flowsources
- xml
- serialization
- dotnet
- src
- API Abuse
- Bad Practices
- Naming Conventions
- Concurrency
- Dead Code
- Documentation
- Input Validation
- Likely Bugs
- Collections
- LeapYear
- Metrics/Summaries
- Security Features
- CWE-091
- CWE-114
- CWE-327
- CWE-384
- Telemetry
- change-notes/released
- experimental
- CWE-918
- Security Features
- CWE-327/Azure
- CWE-759
- JsonWebTokenHandler
- Serialization
- backdoor
- ir
- implementation/raw/internal/desugar
- internal
- meta/frameworks
- utils
- modelconverter
- modeleditor
- modelgenerator/internal
- test
- TestUtilities
- library-tests
- assemblies
- assignables
- async
- attributes
- cil
- attributes
- consistency
- dataflow
- enums
- functionPointers
- init-only-prop
- regressions
- typeAnnotations
- comments
- commons/Disposal
- constructors
- conversion
- operator
- reftype
- csharp10
- csharp11
- csharp7.3
- csharp8
- csharp9
- dataflow
- async
- callablereturnsarg
- external-models
- library
- tuples
- types
- definitions
- delegates
- dispatch
- enums
- events
- expressions
- extension-method-call
- fields
- frameworks
- EntityFramework
- sql
- system
- Dispose
- Equals
- generics
- indexers
- members
- methods
- namespaces
- nestedtypes
- operators
- overrides
- parameters
- properties
- regressions
- standalone/assemblyattribute
- tostringwithtypes
- types
- unification
- query-tests
- API Abuse
- IncorrectCompareToSignature
- NonOverridingMethod
- Dead Code/Tests
- Documentation
- Likely Bugs/InconsistentCompareTo
- Telemetry
- LibraryUsage
- SupportedExternalApis
- Useless Code/PointlessForwardingMethod
- utils
- modeleditor
- modelgenerator
- dataflow
- typebasedflow
- tools
- docs
- codeql
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- reusables
- writing-codeql-queries
- ql-libraries/dataflow
- go
- extractor
- vendor
- golang.org/x
- sys/execabs
- tools
- go
- internal/packagesdriver
- packages
- types/objectpath
- internal
- gocommand
- typesinternal
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes/released
- semmle/go
- dataflow
- internal
- frameworks
- src
- change-notes/released
- experimental
- CWE-287
- examples
- CWE-942
- test
- experimental
- CWE-287
- vendor
- gopkg.in/ldap.v2
- CWE-942
- vendor
- github.com
- gin-contrib/cors
- gin-gonic/gin
- library-tests/semmle/go
- dataflow/ArrayConversion
- frameworks/Beego
- javascript
- downgrades
- externs
- extractor
- lib/typescript
- parser-tests
- src/com/semmle/js/extractor
- tests
- test/com/semmle/js/extractor/test
- ql
- lib
- change-notes/released
- semmle/javascript
- frameworks
- internal
- security
- dataflow
- regexp
- src
- Performance
- Security
- CWE-079
- CWE-117
- CWE-327
- Summary
- change-notes/released
- test/query-tests/Security/CWE-327
- java
- documentation/library-coverage
- kotlin-extractor
- src/main/kotlin
- ql
- automodel
- src
- change-notes/released
- test
- AutomodelApplicationModeExtraction
- AutomodelFrameworkModeExtraction
- com/github/codeql/test
- integration-tests/all-platforms/java
- android-sample-kotlin-build-script-no-wrapper
- android-sample-kotlin-build-script
- android-sample-no-wrapper
- android-sample-old-style-kotlin-build-script-no-wrapper
- android-sample-old-style-kotlin-build-script
- android-sample-old-style-no-wrapper
- android-sample-old-style
- android-sample
- diagnostics/java-version-too-old
- lib
- change-notes/released
- ext
- semmle/code/java
- dataflow
- internal
- rangeanalysis
- frameworks
- security
- regexp
- src
- Security/CWE
- CWE-022
- CWE-502
- CWE-730
- change-notes/released
- test
- library-tests/dataflow
- collections
- modulus-analysis
- range-analysis
- query-tests/security
- CWE-022/semmle/tests
- CWE-502
- misc
- bazel/cmake
- codegen
- generators
- lib
- templates
- test
- scripts/models-as-data
- suite-helpers
- change-notes/released
- python
- downgrades/728c6d65e61d808ae276013ebc15abc3a97aaef1
- ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new/internal
- frameworks
- internal
- security/regexp
- upgrades/0565f7466437d52e1dc64a3b930926ab2f60cd64
- src
- Security
- CWE-327
- CWE-730
- Summary
- change-notes/released
- experimental/cryptography/inventory
- new_models
- old_models
- test
- 2
- library-tests
- ControlFlow/Exceptions
- PointsTo/imports2
- package
- classes/attr
- comprehensions
- modules
- general
- package_members
- usage
- types/properties
- query-tests/Summary
- 3
- library-tests
- ControlFlow/Exceptions
- PointsTo
- import_time
- imports
- package
- classes
- attr
- meta
- modules
- package_members
- usage
- types
- functions
- properties
- query-tests/Summary
- experimental
- dataflow
- basic
- calls
- consistency
- coverage-py2
- coverage-py3
- coverage
- exceptions
- fieldflow
- global-flow
- match
- model-summaries
- module-initialization
- path-graph
- regression
- sensitive-data
- summaries
- tainttracking
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking-summaries
- typetracking_imports
- typetracking
- variable-capture
- import-resolution
- library-tests
- CallGraph-implicit-init
- CallGraph-imports
- CallGraph
- meta/inline-taint-test-demo
- library-tests
- ApiGraphs
- py2
- py3
- ControlFlow
- augassign
- comparison
- dominators
- except
- general
- ssa/deletions
- InlineExpectationsTest/missing-relevant-tag
- PEP695
- PointsTo
- functions
- imports
- inheritance
- lookup
- new
- attributes
- classes/attr
- comments
- essa/ssa-compute
- exceptions
- frameworks
- aioch
- aiofiles
- aiofile
- aiohttp
- aiomysql
- aiopg
- aiosqlite
- anyio
- asyncpg
- baize
- cassandra-driver
- cherrypy
- clickhouse_driver
- cryptodome
- cryptography
- crypto
- cx_Oracle
- dill
- django-orm
- django-v1
- django-v2-v3
- django
- fabric
- fastapi
- flask_admin
- flask_sqlalchemy
- flask
- httpx
- idna
- internal-ql-helpers
- invoke
- jmespath
- joblib
- libtaxii
- lxml
- markupsafe
- multidict
- mysql-connector-python
- mysqldb
- numpy
- oracledb
- pandas
- peewee
- phoenixdb
- pycurl
- pymssql
- pymysql
- pyodbc
- requests
- rest_framework
- rsa
- ruamel.yaml
- sanic
- serverless
- simplejson
- sqlalchemy
- starlette
- stdlib-py2
- stdlib-py3
- stdlib
- toml
- tornado
- twisted
- ujson
- urllib3
- xmltodict
- yaml
- yarl
- imports
- locations/negative_numbers
- modules/usage
- parentheses
- regex
- stmts
- general
- raise_stmt
- try_stmt
- with_stmt
- types/properties
- query-tests
- Expressions/general
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-022-PathInjection
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-209-StackTraceExposure
- CWE-327-BrokenCryptoAlgorithm
- CWE-943-NoSqlInjection
- Statements/ReturnOrYieldOutsideOfFunction
- ql
- extractor
- ruby/ql
- lib
- change-notes/released
- codeql/ruby
- controlflow
- dataflow
- internal
- frameworks/core
- internal
- security
- regexp
- src
- change-notes/released
- queries/security
- cwe-1333
- cwe-327
- test
- library-tests
- dataflow
- array-flow
- hash-flow
- local
- variables
- query-tests/security/cwe-327
- swift
- downgrades
- 04ef9ecaa9e06a587f252f147462861e3d32846a
- 556e495d498c9c01286088785b590a7e80f0bb0b
- fcc7b497930add320fabeed9b228b264bc847ae6
- extractor
- infra
- mangler
- translators
- ql
- lib
- change-notes
- released
- codeql/swift
- controlflow/internal
- dataflow/internal
- elements
- decl
- expr
- pattern
- stmt
- type
- frameworks/StandardLibrary
- generated
- decl
- expr
- pattern
- stmt
- type
- security
- upgrades
- 04ef9ecaa9e06a587f252f147462861e3d32846a
- 7c17e1f4b2d30f2da05bfa667c621ddd418eb151
- fcc7b497930add320fabeed9b228b264bc847ae6
- src
- change-notes
- released
- queries/Security/CWE-078
- test
- TestUtilities
- extractor-tests
- expressions
- generated
- decl/ModuleDecl
- expr
- CopyExpr
- IdentityExpr
- MethodLookupExpr
- PackExpansionExpr
- SingleValueStmtExpr
- type/PackType
- library-tests
- ast
- controlflow/graph
- dataflow
- capture
- dataflow
- taint
- core
- libraries
- elements/expr/methodlookup
- query-tests/Security
- CWE-022
- CWE-078
- CWE-311
- CWE-321
- third_party
- swift-llvm-support/patches
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,268 files changed
+95427
-31433
lines changedLines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
145 | 145 |
| |
146 | 146 |
| |
147 | 147 |
| |
148 |
| - | |
| 148 | + | |
149 | 149 |
| |
150 |
| - | |
| 150 | + | |
151 | 151 |
| |
152 | 152 |
| |
153 | 153 |
| |
|
Lines changed: 14 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
1 | 15 |
| |
2 | 16 |
| |
3 | 17 |
| |
|
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 13 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + | |
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
|
Lines changed: 14 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
34 | 39 |
| |
35 | 40 |
| |
36 | 41 |
| |
| |||
48 | 53 |
| |
49 | 54 |
| |
50 | 55 |
| |
51 |
| - | |
| 56 | + | |
52 | 57 |
| |
53 | 58 |
| |
54 | 59 |
| |
55 | 60 |
| |
56 | 61 |
| |
57 | 62 |
| |
58 |
| - | |
59 |
| - | |
60 |
| - | |
61 |
| - | |
62 |
| - | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
63 | 71 |
| |
64 | 72 |
| |
65 | 73 |
| |
|
Lines changed: 50 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
81 | 81 |
| |
82 | 82 |
| |
83 | 83 |
| |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
84 | 92 |
| |
85 | 93 |
| |
86 | 94 |
| |
| |||
131 | 139 |
| |
132 | 140 |
| |
133 | 141 |
| |
134 |
| - | |
135 |
| - | |
136 |
| - | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
137 | 151 |
| |
138 | 152 |
| |
139 | 153 |
| |
| |||
173 | 187 |
| |
174 | 188 |
| |
175 | 189 |
| |
176 |
| - | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
177 | 201 |
| |
178 | 202 |
| |
179 | 203 |
| |
| |||
621 | 645 |
| |
622 | 646 |
| |
623 | 647 |
| |
| 648 | + | |
| 649 | + | |
| 650 | + | |
| 651 | + | |
| 652 | + | |
| 653 | + | |
| 654 | + | |
| 655 | + | |
| 656 | + | |
| 657 | + | |
| 658 | + | |
| 659 | + | |
| 660 | + | |
| 661 | + | |
| 662 | + | |
| 663 | + | |
| 664 | + | |
| 665 | + | |
624 | 666 |
| |
625 | 667 |
| |
626 | 668 |
| |
| |||
632 | 674 |
| |
633 | 675 |
| |
634 | 676 |
| |
635 |
| - | |
| 677 | + | |
636 | 678 |
| |
637 | 679 |
| |
638 |
| - | |
| 680 | + | |
639 | 681 |
| |
640 | 682 |
| |
641 | 683 |
| |
642 | 684 |
| |
643 | 685 |
| |
644 | 686 |
| |
645 |
| - | |
| 687 | + | |
646 | 688 |
| |
647 | 689 |
| |
648 |
| - | |
| 690 | + | |
649 | 691 |
| |
650 | 692 |
| |
651 | 693 |
| |
|
Lines changed: 82 additions & 40 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
37 |
| - | |
| 37 | + | |
| 38 | + | |
38 | 39 |
| |
39 | 40 |
| |
40 | 41 |
| |
| |||
346 | 347 |
| |
347 | 348 |
| |
348 | 349 |
| |
349 |
| - | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
350 | 353 |
| |
351 | 354 |
| |
352 | 355 |
| |
353 | 356 |
| |
354 | 357 |
| |
355 | 358 |
| |
356 | 359 |
| |
357 |
| - | |
| 360 | + | |
358 | 361 |
| |
359 | 362 |
| |
360 | 363 |
| |
| |||
432 | 435 |
| |
433 | 436 |
| |
434 | 437 |
| |
| 438 | + | |
| 439 | + | |
| 440 | + | |
| 441 | + | |
435 | 442 |
| |
436 | 443 |
| |
437 | 444 |
| |
| |||
448 | 455 |
| |
449 | 456 |
| |
450 | 457 |
| |
451 |
| - | |
452 |
| - | |
453 |
| - | |
454 |
| - | |
455 |
| - | |
456 |
| - | |
457 |
| - | |
458 |
| - | |
459 |
| - | |
460 |
| - | |
461 |
| - | |
462 |
| - | |
463 | 458 |
| |
464 | 459 |
| |
465 | 460 |
| |
| |||
473 | 468 |
| |
474 | 469 |
| |
475 | 470 |
| |
476 |
| - | |
477 |
| - | |
478 |
| - | |
479 |
| - | |
480 |
| - | |
481 |
| - | |
482 |
| - | |
483 |
| - | |
484 |
| - | |
485 |
| - | |
486 |
| - | |
487 |
| - | |
488 | 471 |
| |
489 | 472 |
| |
490 | 473 |
| |
| |||
1293 | 1276 |
| |
1294 | 1277 |
| |
1295 | 1278 |
| |
1296 |
| - | |
1297 |
| - | |
1298 |
| - | |
| 1279 | + | |
| 1280 | + | |
| 1281 | + | |
| 1282 | + | |
| 1283 | + | |
| 1284 | + | |
| 1285 | + | |
| 1286 | + | |
| 1287 | + | |
| 1288 | + | |
| 1289 | + | |
| 1290 | + | |
| 1291 | + | |
| 1292 | + | |
| 1293 | + | |
| 1294 | + | |
| 1295 | + | |
| 1296 | + | |
| 1297 | + | |
| 1298 | + | |
| 1299 | + | |
| 1300 | + | |
| 1301 | + | |
| 1302 | + | |
| 1303 | + | |
| 1304 | + | |
| 1305 | + | |
| 1306 | + | |
| 1307 | + | |
| 1308 | + | |
| 1309 | + | |
| 1310 | + | |
| 1311 | + | |
| 1312 | + | |
| 1313 | + | |
| 1314 | + | |
| 1315 | + | |
| 1316 | + | |
| 1317 | + | |
| 1318 | + | |
| 1319 | + | |
1299 | 1320 |
| |
1300 |
| - | |
1301 |
| - | |
| 1321 | + | |
| 1322 | + | |
| 1323 | + | |
| 1324 | + | |
| 1325 | + | |
1302 | 1326 |
| |
1303 | 1327 |
| |
| 1328 | + | |
| 1329 | + | |
| 1330 | + | |
| 1331 | + | |
| 1332 | + | |
| 1333 | + | |
| 1334 | + | |
| 1335 | + | |
| 1336 | + | |
| 1337 | + | |
| 1338 | + | |
| 1339 | + | |
| 1340 | + | |
| 1341 | + | |
1304 | 1342 |
| |
1305 | 1343 |
| |
1306 |
| - | |
| 1344 | + | |
1307 | 1345 |
| |
1308 | 1346 |
| |
1309 | 1347 |
| |
| 1348 | + | |
| 1349 | + | |
| 1350 | + | |
| 1351 | + | |
| 1352 | + | |
| 1353 | + | |
| 1354 | + | |
| 1355 | + | |
| 1356 | + | |
1310 | 1357 |
| |
1311 | 1358 |
| |
1312 |
| - | |
1313 |
| - | |
1314 |
| - | |
1315 |
| - | |
1316 |
| - | |
1317 |
| - | |
| 1359 | + | |
1318 | 1360 |
| |
1319 | 1361 |
| |
1320 |
| - | |
| 1362 | + | |
1321 | 1363 |
| |
1322 | 1364 |
| |
1323 | 1365 |
| |
|
0 commit comments