File tree
893 files changed
+16760
-17946
lines changed- .github
- workflows
- cpp/ql
- lib
- change-notes
- semmle/code/cpp
- controlflow
- internal
- dataflow/internal
- ir
- dataflow/internal
- ssa0
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- rangeanalysis
- src
- Security/CWE/CWE-020
- ir
- experimental/Security/CWE/CWE-193
- external
- test
- experimental/query-tests/Security/CWE/CWE-193/pointer-deref
- library-tests/dataflow
- fields
- taint-tests
- csharp
- extractor
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp/Entities
- ql
- consistency-queries
- integration-tests/posix-only
- dotnet_test_mstest
- dotnet_test
- lib
- change-notes
- ext
- semmle/code
- asp
- cil
- csharp
- commons
- dataflow
- internal
- frameworks
- security/dataflow
- src
- Bad Practices/Implementation Hiding
- Complexity
- experimental/ir/implementation
- internal
- raw
- internal
- desugar/internal
- unaliased_ssa
- internal
- test
- experimental/CWE-918
- library-tests
- dataflow
- collections
- delegates
- external-models
- global
- library
- frameworks/EntityFramework
- query-tests
- Bad Practices/Implementation Hiding/ExposeRepresentation
- Security Features
- CWE-079/StoredXSS
- CWE-327/InsecureSQLConnection
- CWE-338
- tools
- docs/codeql
- ql-language-reference
- reusables
- go
- extractor/cli/go-autobuilder
- ql
- lib/semmle/go/dataflow/internal
- test
- example-tests/snippets
- experimental/frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- Function
- Types
- concepts
- HTTP
- LoggerCall
- dataflow
- ArrayConversion
- ExternalFlowVarArgs
- FlowSteps
- GuardingFunctions
- ListOfConstantsSanitizerGuards
- PromotedFields
- PromotedMethods
- TypeAssertions
- VarArgsWithFunctionModels
- VarArgs
- frameworks
- CouchbaseV1
- EvanphxJsonPatch
- GoKit
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- K8sIoClientGo
- NoSQL
- Revel
- StdlibTaintFlow
- TaintSteps
- Zap
- query-tests/Security/CWE-681
- javascript
- extractor
- lib/typescript
- src
- src/com/semmle
- js/extractor
- ts/extractor
- ql
- experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling
- lib
- Expressions
- change-notes
- semmle/javascript
- dataflow
- dependencies
- frameworks
- internal
- security
- dataflow
- src
- Declarations
- Security/CWE-089
- examples
- change-notes
- experimental/heuristics/ql/src/Security/CWE-089
- test
- library-tests
- DataExtensions
- JSX
- frameworks/ReactJS
- query-tests
- RegExp/RegExpAlwaysMatches
- Security
- CWE-020/MissingRegExpAnchor
- CWE-089
- typed
- untyped
- CWE-730
- tutorials/Validating RAML-based APIs
- java
- documentation/library-coverage
- kotlin-explorer
- src/main/kotlin
- kotlin-extractor
- src/main/kotlin
- utils
- versions
- v_1_4_32
- v_1_8_0
- ql
- integration-tests/all-platforms/kotlin/default-parameter-mad-flow
- lib
- change-notes
- ext
- semmle/code
- java
- controlflow/internal
- dataflow
- internal
- deadcode
- frameworks
- hudson
- jackson
- javaee
- ejb
- jsf
- spring
- struts
- security
- xml
- src
- Metrics/Summaries
- Security/CWE/CWE-022
- Telemetry
- Violations of Best Practice/Implementation Hiding
- change-notes
- experimental
- Security/CWE
- CWE-073
- CWE-089
- CWE-200
- semmle/code/xml
- semmle/code/xml
- test
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-200
- CWE-470
- CWE-552
- CWE-598
- CWE-755
- ext/TestModels
- kotlin/library-tests/dataflow/summaries
- library-tests
- dataflow
- callback-dispatch
- entrypoint-types
- local-additional-taint
- state
- taintsources
- dispatch
- frameworks
- JaxWs
- android/taint-database
- apache-collections
- gson
- guava/handwritten
- jms
- rabbitmq
- neutrals/neutralsinks
- xml
- query-tests
- ExposeRepresentation
- Metrics/GeneratedVsManualCoverage/TopJdkApisTest
- Telemetry/SupportedExternalSinks
- security
- CWE-023/semmle/tests
- CWE-074
- CWE-078
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- CWE-094
- CWE-1204
- CWE-273
- CWE-295
- AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- Test5
- ImproperWebVeiwCertificateValidation
- InsecureTrustManager
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-326
- CWE-347
- CWE-470
- CWE-489/debuggable-attribute
- CWE-502
- CWE-522
- CWE-524
- CWE-643
- CWE-730
- CWE-749
- CWE-798/semmle/tests
- CWE-807/semmle/tests
- CWE-917
- CWE-918
- CWE-925
- CWE-926
- incomplete_provider_permissions
- CWE-927
- CWE-940
- stubs/jenkins/hudson
- misc/codegen
- generators
- lib
- loaders
- templates
- test
- python
- ql
- lib
- change-notes
- semmle/python
- dataflow
- new/internal
- old
- frameworks
- pointsto
- security
- dataflow
- flow
- injection
- types
- src
- Expressions
- Security
- CWE-020-ExternalAPIs
- CWE-502
- Statements
- change-notes
- experimental
- Security/CWE-074/paramiko
- semmle/python
- security
- injection
- test
- 2/query-tests
- Expressions
- Imports/syntax_error
- 3/query-tests/Imports/syntax_error
- experimental
- dataflow
- calls
- coverage
- global-flow
- sensitive-data
- variable-capture
- import-resolution
- library-tests
- CallGraph-implicit-init
- CallGraph-imports
- CallGraph
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-1236
- library-tests
- ApiGraphs/py2
- InlineExpectationsTest/missing-relevant-tag
- essa/ssa-compute
- frameworks
- flask
- internal-ql-helpers
- security/sensitive
- web
- bottle
- cherrypy
- client
- requests
- six
- stdlib
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-285-PamAuthorization
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- Statements/general
- tools/recorded-call-graph-metrics/ql/lib
- ql
- buramu
- extractor
- ql/test/dataflow/getAStringValue
- ruby/ql
- consistency-queries
- lib
- change-notes
- codeql/ruby
- ast
- controlflow
- dataflow/internal
- frameworks
- actioncontroller
- actiondispatch/internal
- core
- security
- typetracking
- src
- change-notes
- queries/security/cwe-502
- test
- library-tests
- concepts
- dataflow
- api-graphs
- array-flow
- barrier-guards
- local
- type-tracker
- frameworks
- action_dispatch
- app/controllers
- pathname
- query-tests
- experimental/improper-memoization
- security
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-300
- cwe-502/unsafe-deserialization
- swift
- extractor
- infra/file
- trap
- logging
- ql
- lib/codeql/swift
- dataflow/internal
- elements
- decl
- frameworks/StandardLibrary
- security
- src
- diagnostics
- queries/Summary
- test/query-tests/Security
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-311
- CWE-321
- CWE-760
- tools/autobuilder-diagnostics
- xcode-autobuilder
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
893 files changed
+16760
-17946
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
2 | 2 |
| |
3 | 3 |
|
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
| 14 | + | |
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
24 | 23 |
| |
25 | 24 |
| |
26 | 25 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| 13 | + | |
13 | 14 |
| |
14 | 15 |
| |
15 | 16 |
| |
|
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
11 |
| - | |
12 | 11 |
| |
13 | 12 |
| |
14 | 13 |
| |
|
Lines changed: 6 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + |
Lines changed: 0 additions & 14 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
176 | 176 |
| |
177 | 177 |
| |
178 | 178 |
| |
179 |
| - | |
180 |
| - | |
181 |
| - | |
182 |
| - | |
183 |
| - | |
184 |
| - | |
185 |
| - | |
186 |
| - | |
187 |
| - | |
188 |
| - | |
189 |
| - | |
190 |
| - | |
191 |
| - | |
192 |
| - | |
193 | 179 |
| |
194 | 180 |
| |
195 | 181 |
| |
|
Lines changed: 0 additions & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
31 |
| - | |
32 |
| - | |
33 | 30 |
| |
34 | 31 |
| |
35 | 32 |
| |
| |||
239 | 236 |
| |
240 | 237 |
| |
241 | 238 |
| |
242 |
| - | |
243 |
| - | |
244 |
| - | |
245 | 239 |
| |
246 | 240 |
| |
247 | 241 |
| |
| |||
286 | 280 |
| |
287 | 281 |
| |
288 | 282 |
| |
289 |
| - | |
290 |
| - | |
291 |
| - | |
292 | 283 |
| |
293 | 284 |
| |
294 | 285 |
| |
295 | 286 |
| |
296 | 287 |
| |
297 | 288 |
| |
298 | 289 |
| |
299 |
| - | |
300 |
| - | |
301 |
| - | |
302 | 290 |
| |
303 | 291 |
| |
304 | 292 |
| |
|
Lines changed: 0 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 | 17 |
| |
21 | 18 |
| |
22 | 19 |
| |
|
Lines changed: 0 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
312 | 312 |
| |
313 | 313 |
| |
314 | 314 |
| |
315 |
| - | |
316 |
| - | |
317 |
| - |
Lines changed: 0 additions & 9 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1385 | 1385 |
| |
1386 | 1386 |
| |
1387 | 1387 |
| |
1388 |
| - | |
1389 |
| - | |
1390 |
| - | |
1391 | 1388 |
| |
1392 | 1389 |
| |
1393 | 1390 |
| |
| |||
1398 | 1395 |
| |
1399 | 1396 |
| |
1400 | 1397 |
| |
1401 |
| - | |
1402 |
| - | |
1403 |
| - | |
1404 | 1398 |
| |
1405 | 1399 |
| |
1406 | 1400 |
| |
| |||
1410 | 1404 |
| |
1411 | 1405 |
| |
1412 | 1406 |
| |
1413 |
| - | |
1414 |
| - | |
1415 |
| - | |
1416 | 1407 |
|
0 commit comments