File tree
677 files changed
+1658
-18189
lines changed- config
- cpp/ql
- lib
- change-notes
- semmle/code/cpp
- dataflow
- internal
- tainttracking1
- tainttracking2
- new
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation/raw/internal
- models
- implementations
- interfaces
- src/Security/CWE
- CWE-078
- CWE-570
- test
- library-tests
- dataflow
- asExpr
- dataflow-tests
- external-models
- fields
- models-as-data
- parameters-without-defs
- smart-pointers-taint
- source-sink-tests
- taint-tests
- ir
- modulus-analysis
- range-analysis
- sign-analysis
- types
- query-tests/Security/CWE/CWE-193
- csharp/ql
- lib
- change-notes
- experimental/code/csharp/Cryptography
- semmle/code/csharp
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- frameworks
- system
- security
- dataflow
- xml
- src/experimental/dataflow/flowsources
- go/ql
- lib
- change-notes
- semmle/go
- dataflow
- internal
- tainttracking1
- tainttracking2
- security
- src
- Security/CWE-640
- experimental
- CWE-090
- CWE-1004
- CWE-327
- CWE-74
- CWE-807
- CWE-918
- test
- experimental
- CWE-522-DecompressionBombs
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- Function
- Types
- concepts
- HTTP
- LoggerCall
- dataflow
- ExternalFlowInheritance
- PromotedMethods
- flowsources/local
- environment
- file
- stdin
- frameworks
- Afero
- BeegoOrm
- CouchbaseV1
- ElazarlGoproxy
- Fasthttp
- Fiber
- GoKit
- GoMicro
- Iris
- K8sIoClientGo
- Macaron
- NoSQL
- Revel
- SQL
- Gorm
- Sqlx
- bun
- gogf
- gorqlite
- StdlibTaintFlow
- Yaml
- gqlgen
- query-tests/Security/CWE-681
- javascript/ql/test/library-tests
- EndpointNaming
- threat-models/sources
- java/ql
- integration-tests/kotlin/all-platforms/default-parameter-mad-flow
- lib
- change-notes
- semmle/code/java
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- frameworks
- security
- src/experimental
- Security/CWE
- CWE-208
- CWE-625
- semmle/code/java/security
- test
- library-tests
- dataflow
- callback-dispatch
- entrypoint-types
- flowfeature
- state
- taintsources
- frameworks
- JaxWs
- android/taint-database
- guava/handwritten
- jms
- rabbitmq
- neutrals/neutralsinks
- xml
- query-tests/security
- CWE-023/semmle/tests
- CWE-074
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- CWE-094
- CWE-1204
- CWE-200/semmle/tests
- SensitiveNotification
- SensitiveTextView
- CWE-273
- CWE-287
- InsecureKeys
- Test1
- Test2
- InsecureLocalAuth
- CWE-295
- AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- Test5
- ImproperWebVeiwCertificateValidation
- InsecureTrustManager
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-326
- CWE-330
- CWE-347
- CWE-352
- CWE-470
- CWE-489/debuggable-attribute
- CWE-502
- CWE-522
- CWE-524
- CWE-643
- CWE-730
- CWE-749
- CWE-798/semmle/tests
- CWE-807/semmle/tests
- CWE-917
- CWE-918
- CWE-925
- CWE-926
- incomplete_provider_permissions
- CWE-927
- misc
- bazel/3rdparty/tree_sitter_extractors_deps
- codegen
- generators
- lib
- loaders
- templates
- test
- python
- extractor
- ql
- lib
- change-notes
- semmle/python
- dataflow/new
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- security/dataflow
- src
- Security/CWE-020-ExternalAPIs
- semmle/python/functions
- test
- TestUtilities/dataflow
- experimental
- import-resolution
- library-tests
- CallGraph-implicit-init
- CallGraph-imports
- CallGraph
- meta/inline-taint-test-demo
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-074-RemoteCommandExecution
- CWE-409
- library-tests
- ApiGraphs/py2
- InlineExpectationsTest/missing-relevant-tag
- dataflow
- basic
- calls
- coverage-py2
- coverage-py3
- coverage
- exceptions
- fieldflow
- global-flow
- global-or-captured-vars
- match
- model-summaries
- module-initialization
- path-graph
- sensitive-data
- summaries
- tainttracking
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- isinstance
- unwanted-global-flow
- typetracking-summaries
- typetracking_imports
- typetracking
- variable-capture
- essa/ssa-compute
- frameworks
- aioch
- aiofiles
- aiofile
- aiohttp
- aiomysql
- aiopg
- aiosqlite
- anyio
- asyncpg
- baize
- bottle
- cassandra-driver
- cherrypy
- clickhouse_driver
- cryptodome
- cryptography
- crypto
- cx_Oracle
- dill
- django-orm
- django-v1
- django-v2-v3
- django
- fabric
- fastapi
- flask_admin
- flask_sqlalchemy
- flask
- gradio
- httpx
- idna
- internal-ql-helpers
- invoke
- jmespath
- joblib
- jsonpickle
- libtaxii
- lxml
- markupsafe
- multidict
- mysql-connector-python
- mysqldb
- numpy
- oracledb
- pandas
- paramiko
- peewee
- pexpect
- phoenixdb
- psycopg
- pycurl
- pymssql
- pymysql
- pyodbc
- pyramid
- requests
- rest_framework
- rsa
- ruamel.yaml
- sanic
- serverless
- simplejson
- sqlalchemy
- starlette
- stdlib-py2
- stdlib-py3
- stdlib
- streamlit
- toml
- torch
- tornado
- twisted
- ujson
- urllib3
- urllib
- xmltodict
- yaml
- yarl
- regexparser
- regex
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-022-PathInjection
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-209-StackTraceExposure
- CWE-943-NoSqlInjection
- ruby/ql
- lib
- change-notes
- codeql/ruby
- dataflow/internal
- tainttracking1
- experimental
- security
- regexp
- test
- library-tests
- concepts
- dataflow
- api-graphs
- array-flow
- barrier-guards
- global
- hash-flow
- query-tests
- experimental/improper-memoization
- security
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-300
- cwe-829
- rust
- extractor
- src
- generated
- translate
- ql
- integration-tests
- hello-project
- hello-workspace
- lib
- codeql
- files
- rust
- dataflow/internal
- elements/internal
- generated
- src/queries
- diagnostics
- security/CWE-696
- summary
- test
- extractor-tests/File
- library-tests
- dataflow/local
- variables
- query-tests
- diagnostics
- security
- CWE-089
- CWE-696
- schema
- swift/ql
- lib
- change-notes
- codeql/swift/dataflow
- internal
- tainttracking1
- test
- library-tests
- dataflow
- capture
- dataflow
- flowsources
- taint
- core
- libraries
- regex
- query-tests/Security
- CWE-022/PathInjection
- CWE-312
- CWE-611
- CWE-946
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
677 files changed
+1658
-18189
lines changedLines changed: 4 additions & 2 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
68 | 68 |
| |
69 | 69 |
| |
70 | 70 |
| |
71 |
| - | |
| 71 | + | |
72 | 72 |
| |
73 | 73 |
| |
74 | 74 |
| |
|
Lines changed: 0 additions & 54 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
3 |
| - | |
4 |
| - | |
5 |
| - | |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
26 |
| - | |
27 |
| - | |
28 |
| - | |
29 |
| - | |
30 |
| - | |
31 |
| - | |
32 |
| - | |
33 |
| - | |
34 |
| - | |
35 |
| - | |
36 |
| - | |
37 |
| - | |
38 |
| - | |
39 |
| - | |
40 |
| - | |
41 |
| - | |
42 |
| - | |
43 |
| - | |
44 |
| - | |
45 |
| - | |
46 |
| - | |
47 |
| - | |
48 |
| - | |
49 |
| - | |
50 |
| - | |
51 |
| - | |
52 |
| - | |
53 |
| - | |
54 |
| - | |
55 |
| - | |
56 | 2 |
| |
57 | 3 |
| |
58 | 4 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
32 |
| - | |
| 32 | + | |
33 | 33 |
|
Lines changed: 0 additions & 22 deletions
This file was deleted.
Lines changed: 0 additions & 22 deletions
This file was deleted.
Lines changed: 0 additions & 22 deletions
This file was deleted.
Lines changed: 0 additions & 39 deletions
This file was deleted.
0 commit comments