File tree
1,678 files changed
+111093
-79121
lines changed- .devcontainer
- .github/workflows
- .vscode
- config
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp/rangeanalysis
- extensions
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn
- internal
- internal
- raw
- gvn
- internal
- reachability
- unaliased_ssa
- gvn
- internal
- reachability
- internal
- models
- implementations
- interfaces
- rangeanalysis/new
- internal/semantic
- analysis
- security
- valuenumbering
- upgrades/282c13bfdbcbd57a887972b47a471342a4ad5507
- src
- Critical
- JPL_C/LOC-4/Rule 23
- Likely Bugs
- Likely Typos
- Memory Management
- Metrics/Dependencies
- Security/CWE
- CWE-020
- ir
- CWE-079
- CWE-295
- CWE-327
- change-notes
- released
- experimental
- Likely Bugs
- Security/CWE
- CWE-078
- CWE-1041
- CWE-193
- CWE-675
- external
- test
- TestUtilities/dataflow
- experimental/query-tests/Security/CWE
- CWE-119
- CWE-193/pointer-deref
- library-tests
- blocks/cpp
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- globals
- dataflow-tests
- fields
- smart-pointers-taint
- source-sink-tests
- taint-tests
- identity_string
- ir
- ir
- modulus-analysis
- points_to
- range-analysis
- sign-analysis
- ssa
- types
- locations/constants
- loops
- syntax-zoo
- query-tests
- Critical/MemoryFreed
- Likely Bugs/Format/NonConstantFormat
- Security/CWE/CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- csharp
- extractor/Semmle.Extraction.CSharp
- Entities
- Expressions/ObjectCreation
- Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests/posix-only/warn_as_error
- lib
- Linq
- change-notes
- released
- ext
- generated
- semmle/code
- cil
- csharp
- commons
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- frameworks
- security
- cryptography
- dataflow
- flowsinks
- src
- Bad Practices/Comments
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- Statements
- Security Features
- CWE-352
- CWE-502
- change-notes/released
- experimental
- Security Features
- CWE-759
- backdoor
- dataflow/flowsources
- ir
- implementation
- internal
- raw
- gvn
- internal
- common
- desugar
- internal
- unaliased_ssa
- gvn
- internal
- internal
- rangeanalysis
- utils
- modelconverter
- modelgenerator/internal
- test
- experimental/Security Features/backdoor
- library-tests
- assemblies
- cil/dataflow
- dataflow
- external-models
- library
- frameworks/EntityFramework
- parameters
- query-tests/Security Features
- CWE-117
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- resources/stubs
- utils/modelgenerator/dataflow
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- ql-language-reference
- query-help
- reusables
- writing-codeql-queries
- go
- codeql-tools
- extractor
- cli
- go-autobuilder
- go-bootstrap
- go-tokenizer
- diagnostics
- srcarchive
- trap
- ql
- integration-tests/all-platforms/go/diagnostics
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- lib
- change-notes
- released
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- RedundantCode
- Security
- CWE-020
- CWE-327
- CWE-352
- CWE-601
- change-notes/released
- experimental
- CWE-134
- CWE-203
- CWE-79
- Unsafe
- frameworks
- test
- TestUtilities
- experimental
- CWE-134
- CWE-203
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- dataflow
- ExternalFlowVarArgs
- Nodes
- VarArgs
- frameworks
- SQL/Gorm
- StdlibTaintFlow
- Yaml
- javascript
- downgrades/8accf0f930bcb8b42d69fd7ef7b4372604f551ed
- ql
- examples/queries/dataflow/DecodingAfterSanitization
- experimental/adaptivethreatmodeling
- lib/experimental/adaptivethreatmodeling
- modelbuilding/extraction
- lib
- Declarations
- Expressions
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- explore
- frameworks
- AngularJS
- heuristics
- linters
- meta
- security
- dataflow
- upgrades
- 4d00210ca570d55c4833af11d3372b774dbc63f2
- c8859f3725d4b070a877f8792214582d517c8a9b
- src
- Comments
- DOM
- Declarations
- Expressions
- LanguageFeatures
- Performance
- RegExp
- Security
- CWE-020
- CWE-078/examples
- CWE-094
- examples
- CWE-807
- CWE-915
- examples
- Statements
- change-notes
- released
- experimental
- Security/CWE-094
- poi
- external
- meta
- analysis-quality
- test
- ApiGraphs/call-nodes
- experimental/Security/CWE-094
- library-tests
- Barriers
- DOM
- Extend
- HtmlSanitizers
- JsonParsers
- LabelledBarrierGuards
- ModuleImportNodes
- NPM
- src
- node_modules/parent-module
- sub-module
- TaintTracking
- TypeScript/LocalTypeResolution
- TypeTracking
- frameworks/Testing/customised
- query-tests/Security
- CWE-078
- CommandInjection
- IndirectCommandInjection
- CWE-079/ReflectedXss
- CWE-094
- CodeInjection
- ExpressionInjection
- .github/workflows
- action1
- action2
- testUtilities
- tutorials
- Introducing the JavaScript libraries
- Validating RAML-based APIs
- java
- documentation/library-coverage
- kotlin-extractor/src/main
- java/com/semmle/extractor/java
- kotlin
- ql
- integration-tests/all-platforms/java/diagnostics/java-version-too-old
- lib
- change-notes
- released
- ext
- experimental
- generated
- semmle/code
- configfiles
- java
- controlflow/unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- frameworks
- frameworks
- apache
- camel
- gigaspaces
- javaee
- jsf
- javase
- rundeck
- spring
- security
- internal
- src
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Language Abuse
- Likely Bugs
- Comparison
- Statements
- Security/CWE
- CWE-078
- CWE-079
- CWE-089
- CWE-113
- CWE-129
- CWE-134
- CWE-190
- CWE-200
- CWE-209
- CWE-297
- CWE-327
- CWE-601
- CWE-614
- CWE-643
- CWE-681
- CWE-730
- CWE-807
- Telemetry
- change-notes
- released
- experimental/Security/CWE
- CWE-036
- CWE-094
- CWE-299
- CWE-327
- CWE-346
- CWE-502
- CWE-611
- utils
- modelconverter
- modelgenerator/internal
- test
- TestUtilities
- experimental/query-tests/security/CWE-611
- library-tests
- annotations
- dataflow/taintsources
- query-tests/security
- CWE-022/semmle/tests
- mad
- CWE-089/semmle/examples
- CWE-094
- CWE-611
- CWE-643
- CWE-918
- stubs
- groovy-all-3.0.7/groovy
- lang
- text
- jwtk-jjwt-0.11.2/io/jsonwebtoken
- springframework-5.3.8/org/springframework/jdbc
- core
- namedparam
- support
- utils/modelgenerator/dataflow
- misc
- bazel
- codegen
- lib
- templates
- test
- scripts
- suite-helpers
- change-notes/released
- python
- downgrades/0565f7466437d52e1dc64a3b930926ab2f60cd64
- ql
- lib
- change-notes
- released
- semmle/python
- concepts
- dataflow/new
- internal
- frameworks
- regexp
- internal
- security
- dataflow
- regexp
- upgrades/0355ecf0ac589e66467a378e0e9d60f41ee4a757
- src
- Expressions/Regex
- Security
- CWE-020-ExternalAPIs
- CWE-020
- CWE-116
- CWE-730
- Variables
- change-notes/released
- experimental
- Security/CWE-176
- semmle/python
- external
- test
- experimental
- dataflow
- TestUtil
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage
- exceptions
- fieldflow
- global-flow
- match
- module-initialization
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests/CallGraph
- meta
- debug
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-079
- CWE-113
- CWE-1236
- CWE-176
- CWE-208/TimingAttackAgainstSensitiveInfo
- CWE-327-UnsafeUsageOfClientSideEncryptionVersion
- CWE-522
- CWE-614
- CWE-943
- library-tests
- ApiGraphs
- py2
- py3
- frameworks/django-orm
- regexparser
- regex
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-285-PamAuthorization
- CWE-327-WeakSensitiveDataHashing
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-918-ServerSideRequestForgery
- ql
- buramu
- extractor
- src
- ql
- src
- codeql_ql
- ast
- internal
- style
- codeql
- queries/bugs
- test
- callgraph
- queries/style
- ImplicitThis
- OmittableExists
- tools
- ruby
- actions/create-extractor-pack
- downgrades/f9f0f4023e433184fda76f595247bf448b782135
- extractor/src
- ql
- lib
- change-notes
- released
- codeql
- ruby
- controlflow
- dataflow/internal
- filters
- frameworks
- core
- data/internal
- regexp/internal
- security
- typetracking
- upgrades/ff289788b1552e32078788baa27152cc95b68f77
- src
- change-notes
- released
- experimental/template-injection/examples
- queries
- meta/internal
- security/cwe-1333
- test
- library-tests
- dataflow
- api-graphs
- local
- frameworks/sqlite3
- modules
- query-tests/experimental/TemplateInjection
- swift
- actions/build-and-test
- extractor
- infra
- file
- log
- invocation
- remapping
- translators
- trap
- integration-tests
- linux-only
- RegexLiteralExpr
- autobuilder/unsupported-os
- osx-only/autobuilder
- failure
- hello-failure.xcodeproj
- project.xcworkspace
- no-build-system
- no-swift-with-spm
- hello-objective.xcodeproj
- project.xcworkspace
- hello-objective
- no-swift
- hello-objective.xcodeproj
- project.xcworkspace
- hello-objective
- no-xcode-with-spm
- only-tests-with-spm
- hello-tests.xcodeproj
- project.xcworkspace
- only-tests
- hello-tests.xcodeproj
- project.xcworkspace
- logging
- tests/assertion-diagnostics
- ql
- examples
- snippets
- lib
- codeql/swift
- dataflow
- internal
- elements
- decl
- expr
- pattern
- type
- frameworks
- StandardLibrary
- UIKit
- Xml
- generated
- decl
- expr
- pattern
- stmt
- type
- security
- src
- queries/Security/CWE-321
- test
- extractor-tests/generated
- decl/CapturedDecl
- expr
- IdentityExpr
- ImplicitConversionExpr
- library-tests
- ast
- dataflow
- dataflow
- flowsources
- taint
- core
- libraries
- query-tests/Security
- CWE-022
- CWE-311
- CWE-312
- CWE-321
- CWE-611
- CWE-757
- CWE-946
- third_party
- tools
- autobuilder-diagnostics
- xcode-autobuilder
- tests
- hello-tests
- hello-tests.xcodeproj
- project.xcworkspace
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,678 files changed
+111093
-79121
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
|
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
30 |
| - | |
| 30 | + | |
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
34 |
| - | |
35 |
| - | |
| 34 | + | |
| 35 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
32 | 32 |
| |
33 | 33 |
| |
34 | 34 |
| |
35 |
| - | |
| 35 | + | |
36 | 36 |
| |
37 | 37 |
| |
38 | 38 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
61 | 61 |
| |
62 | 62 |
| |
63 | 63 |
| |
64 |
| - | |
| 64 | + | |
65 | 65 |
| |
66 | 66 |
| |
67 | 67 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
| 20 | + | |
| 21 | + | |
20 | 22 |
|
Lines changed: 46 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + |
Lines changed: 17 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
25 | 41 |
| |
26 | 42 |
| |
27 |
| - | |
| 43 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
| 43 | + | |
| 44 | + | |
| 45 | + |
Lines changed: 33 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + |
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
50 |
| - | |
51 | 50 |
| |
52 | 51 |
| |
53 | 52 |
| |
|
0 commit comments