File tree
1,347 files changed
+34215
-10003
lines changed- .github/workflows
- config
- cpp
- downgrades
- ql
- examples
- lib
- change-notes
- released
- semmle/code/cpp
- controlflow
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa/gvn/internal
- raw/gvn/internal
- unaliased_ssa/gvn/internal
- models/implementations
- rangeanalysis/new/internal/semantic
- analysis
- src
- Critical
- Likely Bugs/Memory Management
- Security/CWE
- CWE-119
- CWE-190
- change-notes
- released
- experimental/Security/CWE/CWE-193
- test
- experimental/query-tests/Security/CWE/CWE-193
- array-access
- constant-size
- pointer-deref
- library-tests
- controlflow/guards-ir
- dataflow
- dataflow-tests
- fields
- taint-tests
- ir
- ir
- range-analysis
- query-tests/Security/CWE
- CWE-119
- SAMATE
- semmle/tests
- CWE-190/semmle
- ComparisonWithWiderType
- tainted
- CWE-457/semmle/tests
- csharp
- downgrades
- extractor
- Semmle.Extraction.CSharp.Standalone
- Properties
- Semmle.Extraction.CSharp/Extractor
- Semmle.Extraction.Tests
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- test
- consistency-queries
- examples
- integration-tests
- lib
- change-notes
- released
- semmle/code
- csharp
- dataflow
- internal
- frameworks
- security
- auth
- dataflow
- dotnet
- src
- Security Features/CWE-285
- Telemetry
- change-notes/released
- experimental/ir/implementation
- raw/gvn/internal
- unaliased_ssa/gvn/internal
- test
- TestUtilities
- library-tests/dataflow
- fields
- operators
- patterns
- tuples
- query-tests
- API Abuse
- CallToGCCollect
- CallToObsoleteMethod
- ClassDoesNotImplementEquals
- ClassImplementsICloneable
- DisposeNotCalledOnException
- FormatInvalid
- InconsistentEqualsGetHashCode
- IncorrectCompareToSignature
- IncorrectEqualsSignature
- MissingDisposeCall
- MissingDisposeMethod
- NoDisposeCallOnLocalIDisposable
- NonOverridingMethod
- NullArgumentToEquals
- UncheckedReturnValue
- AlertSuppression
- Security Features/CWE-285/MissingAccessControl
- MVCTests
- WebFormsTests
- Test1
- Test2
- Test3
- A
- B
- C
- Stubs/Minimal
- Telemetry/LibraryUsage
- resources
- assemblies
- stubs
- docs/codeql
- codeql-for-visual-studio-code
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- go
- downgrades
- external-packs/codeql/suite-helpers/0.0.2
- extractor
- cli/go-autobuilder
- diagnostics
- util
- ql
- config/legacy-support
- examples
- integration-tests
- all-platforms/go
- bazel-sample-1
- bazel-sample-2
- diagnostics
- build-constraints-exclude-all-go-files
- go-files-found-not-processed
- work/subdir
- newer-go-version-needed
- package-not-found-with-go-mod
- single-go-mod-and-go-files-not-under-it
- subdir
- subsubdir
- single-go-mod-in-root
- subdir
- single-go-mod-not-in-root
- subdir
- subsubdir
- single-go-work-not-in-root
- modules
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-nested-none-in-root
- subdir0
- subdir1
- subsubdir1
- subdir2
- two-go-mods-nested-one-in-root
- subdir1
- subsubdir1
- subdir2
- two-go-mods-not-nested
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- linux-only/go
- dep-sample
- glide-sample
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- frameworks
- security
- src
- Security/CWE-117
- change-notes/released
- test
- TestUtilities
- experimental
- CWE-134
- CWE-918
- library-tests/semmle/go
- dataflow
- ExternalFlow
- vendor/github.com/nonexistent/test
- FlowSteps
- GenericFunctionsAndTypes
- frameworks
- Beego
- ElazarlGoproxy
- SQL
- bun
- vendor
- github.com/uptrace/bun
- dialect/sqlitedialect
- driver/sqliteshim
- TaintSteps
- Yaml
- query-tests/Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-117
- CWE-327
- CWE-338/InsecureRandomness
- CWE-352
- javascript
- downgrades
- ql
- examples
- experimental/adaptivethreatmodeling
- lib
- modelbuilding
- model
- src
- test
- integration-tests/all-platforms
- lib
- change-notes
- released
- semmle/javascript
- frameworks
- data/internal
- security
- dataflow
- src
- Security
- CWE-094/examples
- CWE-798
- examples
- change-notes
- released
- test/query-tests/Security
- CWE-022/TaintedPath
- CWE-094/CodeInjection
- webix
- CWE-116/IncompleteSanitization
- CWE-915/PrototypePollutingMergeCall
- webix
- java
- documentation/library-coverage
- downgrades
- kotlin-extractor
- src/main/kotlin
- utils
- ql
- consistency-queries
- examples
- integration-tests
- all-platforms
- java
- android-sample-old-style-kotlin-build-script-no-wrapper
- project
- android-sample-old-style-kotlin-build-script
- project
- android-sample-old-style-no-wrapper
- project
- android-sample-old-style
- project
- kotlin
- annotation-id-consistency
- default-parameter-mad-flow
- gradle_kotlinx_serialization
- kotlin-interface-inherited-default
- kotlin_java_static_fields
- linux-only/kotlin
- custom_plugin
- posix-only/kotlin
- lib
- change-notes
- released
- ext
- experimental
- generated
- semmle/code/java
- dataflow
- internal
- dispatch
- frameworks
- apache
- google
- jackson
- kotlin
- security
- src
- Security/CWE/CWE-078
- Telemetry
- change-notes
- released
- experimental/Security/CWE/CWE-078
- utils/flowtestcasegenerator
- test
- TestUtilities
- ext/TestModels
- kotlin/library-tests/dataflow/summaries
- library-tests
- dataflow
- callctx
- collections
- fluent-methods
- stream-collect
- synth-global
- taint-format
- taint-gson
- taint-jackson
- frameworks
- JaxWs
- android
- asynctask
- content-provider-summaries
- content-provider
- external-storage
- flow-steps
- intent
- notification
- slice
- sources
- uri
- widget
- apache-ant
- apache-collections
- apache-commons-compress
- apache-commons-lang3
- apache-http
- gson
- guava/generated
- cache
- collect
- hudson
- jackson
- javax-json
- jdk
- java.io
- java.net
- java.nio.file
- json-java
- netty
- generated
- manual
- okhttp
- play
- rabbitmq
- ratpack
- retrofit
- spring
- beans
- cache
- context
- controller
- data
- http
- ui
- util
- validation
- webmultipart
- webutil
- stapler
- stream
- thymeleaf
- logging
- optional
- pathsanitizer
- paths
- regex
- scanner
- query-tests
- Telemetry/SupportedExternalApis
- security
- CWE-078
- CWE-117
- CWE-266
- CWE-441
- CWE-470
- CWE-489/webview-debugging
- CWE-502
- CWE-532
- CWE-611
- CWE-749
- CWE-780
- CWE-927
- stubs/serialkiller-4.0.0/org/nibblesec/tools
- misc
- bazel
- legacy-support
- cpp
- csharp
- javascript
- java
- python
- suite-helpers
- change-notes/released
- python
- downgrades
- ql
- consistency-queries
- examples
- lib
- change-notes
- released
- semmle/python
- dataflow
- new
- internal
- old
- frameworks
- data/internal
- security
- dataflow
- injection
- web
- bottle
- cherrypy
- client
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- src
- Security/CWE-798
- change-notes
- released
- test
- 3/library-tests/taint
- strings
- unpacking
- experimental
- dataflow
- TestUtil
- basic
- coverage-py2
- coverage-py3
- coverage
- exceptions
- fieldflow
- match
- model-summaries
- module-initialization
- regression
- summaries
- tainttracking
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking-summaries
- typetracking_imports
- typetracking
- variable-capture
- library-tests/CallGraph
- meta
- debug
- inline-taint-test-demo
- query-tests/Security/CWE-022-UnsafeUnpacking
- library-tests
- examples/custom-sanitizer
- frameworks
- aioch
- aiohttp
- aiomysql
- aiopg
- aiosqlite
- asyncpg
- cassandra-driver
- clickhouse_driver
- cryptodome
- cryptography
- crypto
- cx_Oracle
- dill
- django-orm
- django-v1
- django-v2-v3
- django
- fabric
- fastapi
- flask_admin
- flask_sqlalchemy
- flask
- httpx
- idna
- invoke
- jmespath
- libtaxii
- lxml
- markupsafe
- multidict
- mysql-connector-python
- mysqldb
- oracledb
- peewee
- phoenixdb
- pycurl
- pymssql
- pymysql
- pyodbc
- requests
- rest_framework
- rsa
- ruamel.yaml
- simplejson
- sqlalchemy
- stdlib-py2
- stdlib-py3
- stdlib
- toml
- tornado
- twisted
- ujson
- urllib3
- xmltodict
- yaml
- yarl
- regex
- security
- command-execution
- fabric-v1-execute
- taint
- collections
- config
- example
- exception_traceback
- flowpath_regression
- general
- namedtuple
- strings
- unpacking
- query-tests/Security
- CWE-022-PathInjection
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-611-Xxe
- CWE-798-HardcodedCredentials
- tools/recorded-call-graph-metrics/ql
- ql
- buramu
- extractor
- ql
- consistency-queries
- examples
- src
- codeql_ql
- ast
- internal
- style
- queries
- performance
- style
- test
- callgraph/packs
- lib
- other
- src
- printAst
- queries
- performance/AbstractClassImport
- style
- DeadCode
- FieldOnlyUsedInCharPred
- MissingOverride
- ruby
- downgrades
- ql
- consistency-queries
- examples
- integration-tests/all-platforms
- lib
- change-notes
- released
- codeql
- ruby
- dataflow/internal
- experimental
- frameworks
- actiondispatch/internal
- core
- data
- internal
- rack/internal
- regexp/internal
- security
- typetracking
- internal
- src
- change-notes
- released
- queries
- diagnostics
- security/cwe-829
- test
- TestUtilities
- library-tests
- dataflow
- api-graphs
- array-flow
- call-sensitivity
- flow-summaries
- global
- hash-flow
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- frameworks
- Twirp
- action_controller
- action_dispatch
- action_mailer
- active_record
- active_resource
- active_support
- arel
- json
- rack
- sinatra
- sqlite3
- query-tests/security
- cwe-079
- app/views/foo/stores
- cwe-089
- cwe-829
- swift
- codegen
- downgrades
- extractor
- infra
- integration-tests
- ql
- consistency-queries
- examples
- lib
- change-notes
- released
- codeql/swift
- dataflow
- internal
- frameworks/StandardLibrary
- regex
- internal
- src
- change-notes/released
- queries/Summary
- test
- extractor-tests
- declarations/CONSISTENCY
- expressions/CONSISTENCY
- generated/decl/EnumDecl/CONSISTENCY
- statements/CONSISTENCY
- library-tests
- ast
- CONSISTENCY
- controlflow/graph/CONSISTENCY
- dataflow
- dataflow
- taint/libraries
- CONSISTENCY
- elements/decl
- enumdecl/CONSISTENCY
- function/CONSISTENCY
- regex
- test_fragment_licenses
- query-tests/Security
- CWE-079
- CWE-089
- CONSISTENCY
- CWE-094
- CWE-1204
- CONSISTENCY
- CWE-134
- CWE-259/CONSISTENCY
- CWE-311
- CONSISTENCY
- CWE-312/CONSISTENCY
- CWE-321
- CONSISTENCY
- CWE-327/CONSISTENCY
- CWE-328/CONSISTENCY
- CWE-611/CONSISTENCY
- CWE-757/CONSISTENCY
- CWE-760
- CONSISTENCY
- CWE-916/CONSISTENCY
- third_party
- swift-llvm-support/patches
- xcode-autobuilder/tests
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,347 files changed
+34215
-10003
lines changedLines changed: 29 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + |
Lines changed: 7 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
| 8 | + | |
9 | 9 |
| |
10 |
| - | |
| 10 | + | |
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
| |||
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
24 | 29 |
| |
25 | 30 |
| |
26 | 31 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
523 | 523 |
| |
524 | 524 |
| |
525 | 525 |
| |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
526 | 530 |
| |
527 | 531 |
| |
528 | 532 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2 | 2 |
| |
3 | 3 |
| |
4 | 4 |
| |
| 5 | + |
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + |
Lines changed: 22 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
1 | 23 |
| |
2 | 24 |
| |
3 | 25 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 5 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
4 | 5 |
| |
5 | 6 |
| |
6 |
| - | |
| 7 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 9 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + |
0 commit comments