File tree
1,422 files changed
+114302
-86157
lines changed- .devcontainer
- .github/workflows
- config
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- rangeanalysis
- extensions
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn
- internal
- internal
- raw
- gvn
- internal
- reachability
- unaliased_ssa
- gvn
- internal
- reachability
- internal
- models
- implementations
- interfaces
- rangeanalysis/new
- internal/semantic
- analysis
- security
- valuenumbering
- upgrades/282c13bfdbcbd57a887972b47a471342a4ad5507
- src
- Critical
- JPL_C/LOC-4/Rule 23
- Likely Bugs
- Likely Typos
- Memory Management
- Metrics/Dependencies
- Security/CWE
- CWE-020
- ir
- CWE-079
- CWE-295
- CWE-327
- change-notes
- released
- experimental
- Likely Bugs
- Security/CWE
- CWE-078
- CWE-1041
- CWE-675
- external
- test
- experimental/query-tests/Security/CWE
- CWE-119
- CWE-193/pointer-deref
- library-tests
- blocks/cpp
- dataflow
- dataflow-tests
- fields
- identity_string
- ir
- ir
- ssa
- locations/constants
- loops
- syntax-zoo
- query-tests/Likely Bugs/Format/NonConstantFormat
- csharp
- documentation/library-coverage
- extractor/Semmle.Extraction.CSharp/Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- dotnet_run
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- warn_as_error
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- lib
- Linq
- change-notes
- released
- ext
- generated
- semmle/code
- cil
- csharp
- commons
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- security
- cryptography
- dataflow
- flowsinks
- src
- Bad Practices/Comments
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- Statements
- Security Features
- CWE-352
- CWE-502
- CWE-838
- change-notes/released
- experimental
- Security Features
- CWE-759
- backdoor
- dataflow/flowsources
- ir
- implementation
- internal
- raw
- gvn
- internal
- common
- desugar
- internal
- unaliased_ssa
- gvn
- internal
- internal
- rangeanalysis
- utils
- modelconverter
- modelgenerator/internal
- test
- experimental
- Security Features/backdoor
- ir/offbyone/CONSISTENCY
- library-tests
- assemblies
- cil
- attributes/CONSISTENCY
- consistency/CONSISTENCY
- dataflow
- CONSISTENCY
- enums/CONSISTENCY
- functionPointers/CONSISTENCY
- init-only-prop/CONSISTENCY
- pdbs/CONSISTENCY
- regressions/CONSISTENCY
- typeAnnotations/CONSISTENCY
- commons/Disposal/CONSISTENCY
- controlflow
- graph/CONSISTENCY
- guards/CONSISTENCY
- splits/CONSISTENCY
- csharp11/cil/CONSISTENCY
- csharp7
- dataflow
- async
- collections
- content
- defuse/CONSISTENCY
- external-models
- fields
- global
- CONSISTENCY
- ssa/CONSISTENCY
- tuples
- types
- frameworks/EntityFramework
- query-tests
- API Abuse/NoDisposeCallOnLocalIDisposable/CONSISTENCY
- Nullness/CONSISTENCY
- Security Features
- CWE-022/ZipSlip/CONSISTENCY
- CWE-079/StoredXSS
- CWE-312
- CWE-338
- CWE-359
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- utils/modelgenerator/dataflow
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- query-help
- reusables
- go
- extractor
- cli
- go-autobuilder
- go-bootstrap
- go-tokenizer
- diagnostics
- srcarchive
- trap
- ql
- integration-tests/all-platforms/go/diagnostics
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- lib
- change-notes/released
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- RedundantCode
- Security
- CWE-020
- CWE-327
- change-notes/released
- experimental
- CWE-79
- Unsafe
- test
- experimental/CWE-79
- library-tests/semmle/go/frameworks
- StdlibTaintFlow
- Yaml
- query-tests/Security/CWE-079
- javascript
- extractor
- lib/typescript/src
- src/com/semmle/js
- extractor
- parser
- tests/json/output/trap
- ql
- examples/queries/dataflow/DecodingAfterSanitization
- lib
- Declarations
- Expressions
- change-notes/released
- semmle/javascript
- dataflow
- internal
- explore
- frameworks
- AngularJS
- heuristics
- linters
- security
- dataflow
- regexp
- upgrades/c8859f3725d4b070a877f8792214582d517c8a9b
- src
- Comments
- DOM
- Declarations
- Expressions
- LanguageFeatures
- RegExp
- Security
- CWE-020
- CWE-915
- Statements
- change-notes
- released
- experimental/poi
- external
- meta
- analysis-quality
- test
- ApiGraphs/call-nodes
- library-tests
- Barriers
- DOM
- Extend
- HtmlSanitizers
- JSON
- JsonParsers
- LabelledBarrierGuards
- ModuleImportNodes
- TaintTracking
- TypeScript
- LocalTypeResolution
- RegressionTests/GenericTypeAlias
- TypeTracking
- frameworks
- Angular2
- Express
- src
- typed_src
- HTTP-heuristics
- Nest
- Testing/customised
- query-tests/Security
- CWE-078
- CommandInjection
- IndirectCommandInjection
- CWE-079
- DomBasedXss
- ReflectedXss
- CWE-094/CodeInjection
- CWE-502
- testUtilities
- tutorials
- Introducing the JavaScript libraries
- Validating RAML-based APIs
- java
- documentation/library-coverage
- ql
- lib
- change-notes
- released
- ext
- experimental
- generated
- semmle/code
- configfiles
- java
- controlflow/unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- frameworks
- frameworks
- apache
- camel
- gigaspaces
- javaee
- jsf
- spring
- security
- internal
- src
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Language Abuse
- Likely Bugs
- Comparison
- Statements
- Metrics/Summaries
- Security/CWE
- CWE-078
- CWE-079
- CWE-089
- CWE-113
- CWE-129
- CWE-134
- CWE-190
- CWE-200
- CWE-209
- CWE-297
- CWE-327
- CWE-601
- CWE-614
- CWE-643
- CWE-681
- CWE-807
- Telemetry
- change-notes/released
- experimental/Security/CWE
- CWE-036
- CWE-094
- CWE-299
- CWE-327
- CWE-346
- CWE-502
- utils
- modelconverter
- modelgenerator/internal
- test
- TestUtilities
- experimental/query-tests/security
- CWE-020
- CWE-089/src/main
- CWE-200
- CWE-299
- CWE-327
- CWE-400
- CWE-601
- ext/TestModels
- library-tests
- annotations
- dataflow
- partial
- taintsources
- taint
- frameworks
- JaxWs
- android/slice
- netty/manual
- okhttp
- retrofit
- spring/util
- query-tests
- Metrics/GeneratedVsManualCoverage/TopJdkApisTest
- TopJdkApis/java/lang
- security
- CWE-022/semmle/tests
- mad
- CWE-078
- CWE-190/semmle/tests
- CWE-643
- stubs/jwtk-jjwt-0.11.2/io/jsonwebtoken
- utils/modelgenerator/dataflow
- misc
- codegen
- lib
- templates
- test
- suite-helpers
- change-notes/released
- python
- downgrades/0355ecf0ac589e66467a378e0e9d60f41ee4a757
- ql
- lib
- change-notes
- released
- semmle/python
- concepts
- dataflow/new/internal
- frameworks
- security/dataflow
- upgrades/47e552c4357a04c5735355fad818630daee4a5ac
- src
- Security
- CWE-020-ExternalAPIs
- CWE-295
- Variables
- change-notes/released
- experimental
- Security/CWE-074/paramiko
- semmle/python
- external
- test
- experimental
- dataflow
- TestUtil
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage
- exceptions
- fieldflow
- global-flow
- match
- module-initialization
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests/CallGraph
- meta
- debug
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-074/paramiko
- CWE-079
- CWE-113
- CWE-1236
- CWE-208/TimingAttackAgainstSensitiveInfo
- CWE-327-UnsafeUsageOfClientSideEncryptionVersion
- CWE-522
- CWE-614
- CWE-943
- library-tests
- ApiGraphs
- py2
- py3
- Yaml
- frameworks/django-orm
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-285-PamAuthorization
- CWE-295-MissingHostKeyValidation
- CWE-327-WeakSensitiveDataHashing
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-918-ServerSideRequestForgery
- ql
- extractor/src
- ruby/ql
- lib
- change-notes
- released
- codeql/ruby
- dataflow/internal
- filters
- frameworks
- core
- data/internal
- security
- src
- change-notes/released
- experimental/template-injection/examples
- queries/meta/internal
- test
- library-tests
- dataflow
- api-graphs
- array-flow
- call-sensitivity
- flow-summaries
- global
- hash-flow
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- sinatra
- sqlite3
- query-tests
- experimental
- TemplateInjection
- cwe-022-ZipSlip
- manually-check-http-verb
- weak-params
- security
- cwe-020/MissingFullAnchor
- cwe-022
- cwe-078
- CommandInjection
- KernelOpen
- UnsafeShellCommandConstruction
- cwe-079
- cwe-089
- cwe-094
- CodeInjection
- UnsafeCodeConstruction
- cwe-117
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-134
- cwe-209
- cwe-312
- cwe-502
- oj-global-options
- unsafe-deserialization
- cwe-506
- cwe-601
- cwe-611
- libxml-backend
- xxe
- cwe-732
- cwe-798
- cwe-807-user-controlled-bypass
- cwe-829
- cwe-912
- cwe-918
- decompression-api
- swift
- downgrades/ba4171b90d0665b40e9e203bac9e3d4a0b2d03ec
- extractor
- infra
- file
- invocation
- mangler
- remapping
- translators
- trap
- integration-tests
- linux-only/RegexLiteralExpr
- osx-only/autobuilder
- failure
- hello-failure.xcodeproj
- project.xcworkspace
- no-build-system
- posix-only
- cross-references
- deduplication
- hello-world
- linkage-awareness
- logging
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- type
- frameworks
- StandardLibrary
- Xml
- generated
- decl
- expr
- printast
- security
- upgrades/f937d9e63094280b7ec0ef26c70310daad5c1f79
- src/queries/Security
- CWE-079
- CWE-135
- CWE-311
- CWE-312
- CWE-943
- test
- extractor-tests
- expressions
- generated
- decl
- Accessor
- CapturedDecl
- ConcreteVarDecl
- Deinitializer
- Initializer
- NamedFunction
- ParamDecl
- expr
- ExplicitClosureExpr
- InitializerRefCallExpr
- LazyInitializationExpr
- OtherInitializerRefExpr
- RebindSelfInInitializerExpr
- type
- DynamicSelfType
- TupleType
- types
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- taint/core
- elements
- decl
- abstractfunctiondecl
- function
- expr/methodlookup
- query-tests/Security
- CWE-022
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-135
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-327
- CWE-611
- CWE-757
- CWE-760
- CWE-916
- third_party
- tools
- xcode-autobuilder
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,422 files changed
+114302
-86157
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
|
Lines changed: 46 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + |
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
43 |
| - | |
44 | 43 |
| |
45 | 44 |
| |
46 | 45 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 |
| |
2 | 6 |
| |
3 | 7 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
0 commit comments