File tree
1,736 files changed
+117872
-89044
lines changed- .devcontainer
- .github/workflows
- config
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- rangeanalysis
- extensions
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn
- internal
- internal
- raw
- gvn
- internal
- reachability
- unaliased_ssa
- gvn
- internal
- reachability
- internal
- models
- implementations
- interfaces
- rangeanalysis/new
- internal/semantic
- analysis
- security
- valuenumbering
- upgrades/282c13bfdbcbd57a887972b47a471342a4ad5507
- src
- Critical
- JPL_C/LOC-4/Rule 23
- Likely Bugs
- Likely Typos
- Memory Management
- Metrics/Dependencies
- Security/CWE
- CWE-020
- ir
- CWE-079
- CWE-295
- CWE-327
- change-notes
- released
- experimental
- Likely Bugs
- Security/CWE
- CWE-078
- CWE-1041
- CWE-193
- CWE-675
- external
- test
- experimental/query-tests/Security/CWE
- CWE-119
- CWE-193/pointer-deref
- library-tests
- blocks/cpp
- dataflow
- dataflow-tests
- fields
- identity_string
- ir
- ir
- range-analysis
- ssa
- locations/constants
- loops
- syntax-zoo
- query-tests/Likely Bugs/Format/NonConstantFormat
- csharp
- extractor/Semmle.Extraction.CSharp/Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- dotnet_run
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- warn_as_error
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- lib
- Linq
- change-notes
- released
- ext/generated
- semmle/code
- cil
- csharp
- commons
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- security
- cryptography
- dataflow
- src
- Bad Practices/Comments
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- Statements
- Security Features
- CWE-352
- CWE-502
- CWE-838
- change-notes/released
- experimental
- Security Features
- CWE-759
- backdoor
- dataflow/flowsources
- ir
- implementation
- internal
- raw
- gvn
- internal
- common
- desugar
- internal
- unaliased_ssa
- gvn
- internal
- internal
- rangeanalysis
- utils
- modelconverter
- modelgenerator/internal
- test
- experimental/Security Features/backdoor
- library-tests
- assemblies
- cil/dataflow
- csharp7
- dataflow
- async
- collections
- content
- external-models
- fields
- global
- tuples
- types
- frameworks/EntityFramework
- query-tests/Security Features
- CWE-079/StoredXSS
- CWE-338
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- utils/modelgenerator/dataflow
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- ql-language-reference
- query-help
- reusables
- writing-codeql-queries
- go
- codeql-tools
- extractor
- cli
- go-autobuilder
- go-bootstrap
- go-tokenizer
- diagnostics
- srcarchive
- trap
- ql
- integration-tests/all-platforms/go/diagnostics
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- lib
- change-notes
- released
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- RedundantCode
- Security
- CWE-020
- CWE-327
- CWE-352
- CWE-601
- change-notes/released
- experimental
- CWE-134
- CWE-203
- CWE-79
- Unsafe
- frameworks
- test
- TestUtilities
- experimental
- CWE-134
- CWE-203
- CWE-79
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- dataflow
- ExternalFlowVarArgs
- Nodes
- VarArgs
- frameworks
- SQL/Gorm
- StdlibTaintFlow
- Yaml
- query-tests/Security/CWE-079
- javascript
- extractor
- lib/typescript/src
- src/com/semmle/js
- extractor
- parser
- tests/json/output/trap
- ql
- examples/queries/dataflow/DecodingAfterSanitization
- experimental/adaptivethreatmodeling
- lib/experimental/adaptivethreatmodeling
- modelbuilding/extraction
- lib
- Declarations
- Expressions
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- explore
- frameworks
- AngularJS
- heuristics
- linters
- meta
- security
- dataflow
- regexp
- upgrades/c8859f3725d4b070a877f8792214582d517c8a9b
- src
- Comments
- DOM
- Declarations
- Expressions
- LanguageFeatures
- RegExp
- Security
- CWE-020
- CWE-078/examples
- CWE-094
- examples
- CWE-807
- CWE-915
- examples
- Statements
- change-notes
- released
- experimental
- Security/CWE-094
- poi
- external
- meta
- analysis-quality
- test
- ApiGraphs/call-nodes
- experimental/Security/CWE-094
- library-tests
- Barriers
- DOM
- Extend
- HtmlSanitizers
- JSON
- JsonParsers
- LabelledBarrierGuards
- ModuleImportNodes
- TaintTracking
- TypeScript
- LocalTypeResolution
- RegressionTests/GenericTypeAlias
- TypeTracking
- frameworks
- Angular2
- Express
- src
- typed_src
- HTTP-heuristics
- Nest
- Testing/customised
- query-tests/Security
- CWE-078
- CommandInjection
- IndirectCommandInjection
- CWE-079
- DomBasedXss
- ReflectedXss
- CWE-094
- CodeInjection
- ExpressionInjection
- .github/workflows
- action1
- action2
- CWE-502
- testUtilities
- tutorials
- Introducing the JavaScript libraries
- Validating RAML-based APIs
- java
- documentation/library-coverage
- kotlin-extractor/src/main
- java/com/semmle/extractor/java
- kotlin
- ql
- lib
- change-notes
- released
- ext
- experimental
- generated
- semmle/code
- configfiles
- java
- controlflow/unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- frameworks
- frameworks
- apache
- camel
- gigaspaces
- javaee
- jsf
- spring
- security
- internal
- src
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Language Abuse
- Likely Bugs
- Comparison
- Statements
- Security/CWE
- CWE-078
- CWE-079
- CWE-089
- CWE-113
- CWE-129
- CWE-134
- CWE-190
- CWE-200
- CWE-209
- CWE-297
- CWE-327
- CWE-601
- CWE-614
- CWE-643
- CWE-681
- CWE-807
- Telemetry
- change-notes
- released
- experimental/Security/CWE
- CWE-036
- CWE-094
- CWE-299
- CWE-327
- CWE-346
- CWE-502
- utils
- modelconverter
- modelgenerator/internal
- test
- TestUtilities
- experimental/query-tests/security
- CWE-020
- CWE-089/src/main
- CWE-200
- CWE-299
- CWE-327
- CWE-400
- CWE-601
- ext/TestModels
- library-tests
- annotations
- dataflow
- partial
- taintsources
- taint
- query-tests/security
- CWE-078
- CWE-190/semmle/tests
- CWE-611
- CWE-643
- stubs/jwtk-jjwt-0.11.2/io/jsonwebtoken
- utils/modelgenerator/dataflow
- misc
- bazel
- codegen
- lib
- templates
- test
- suite-helpers
- change-notes/released
- python
- downgrades/0355ecf0ac589e66467a378e0e9d60f41ee4a757
- ql
- lib
- change-notes
- released
- semmle/python
- concepts
- dataflow/new
- internal
- frameworks
- regexp
- internal
- security
- dataflow
- regexp
- upgrades/47e552c4357a04c5735355fad818630daee4a5ac
- src
- Expressions/Regex
- Security
- CWE-020-ExternalAPIs
- CWE-020
- CWE-116
- CWE-730
- Variables
- change-notes/released
- experimental
- Security/CWE-074/paramiko
- semmle/python
- external
- test
- experimental
- dataflow
- TestUtil
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage
- exceptions
- fieldflow
- global-flow
- match
- module-initialization
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests/CallGraph
- meta
- debug
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-074/paramiko
- CWE-079
- CWE-113
- CWE-1236
- CWE-208/TimingAttackAgainstSensitiveInfo
- CWE-327-UnsafeUsageOfClientSideEncryptionVersion
- CWE-522
- CWE-614
- CWE-943
- library-tests
- ApiGraphs
- py2
- py3
- Yaml
- frameworks/django-orm
- regexparser
- regex
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-285-PamAuthorization
- CWE-327-WeakSensitiveDataHashing
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-918-ServerSideRequestForgery
- ql
- extractor/src
- ql
- src
- codeql_ql/style
- codeql
- test
- callgraph
- queries/style/ImplicitThis
- ruby
- extractor/src
- ql
- lib
- change-notes
- released
- codeql/ruby
- controlflow
- dataflow/internal
- filters
- frameworks
- core
- data/internal
- regexp/internal
- security
- typetracking
- src
- change-notes/released
- experimental/template-injection/examples
- queries/meta/internal
- test
- library-tests
- dataflow
- api-graphs
- array-flow
- call-sensitivity
- flow-summaries
- global
- hash-flow
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- sinatra
- sqlite3
- query-tests
- experimental
- TemplateInjection
- cwe-022-ZipSlip
- manually-check-http-verb
- weak-params
- security
- cwe-020/MissingFullAnchor
- cwe-022
- cwe-078
- CommandInjection
- KernelOpen
- UnsafeShellCommandConstruction
- cwe-079
- cwe-089
- cwe-094
- CodeInjection
- UnsafeCodeConstruction
- cwe-117
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-134
- cwe-209
- cwe-312
- cwe-502
- oj-global-options
- unsafe-deserialization
- cwe-506
- cwe-601
- cwe-611
- libxml-backend
- xxe
- cwe-732
- cwe-798
- cwe-807-user-controlled-bypass
- cwe-829
- cwe-912
- cwe-918
- decompression-api
- swift
- downgrades/ba4171b90d0665b40e9e203bac9e3d4a0b2d03ec
- extractor
- infra
- file
- log
- invocation
- remapping
- translators
- trap
- integration-tests
- linux-only
- RegexLiteralExpr
- autobuilder/unsupported-os
- osx-only/autobuilder
- failure
- hello-failure.xcodeproj
- project.xcworkspace
- no-build-system
- no-swift-with-spm
- hello-objective.xcodeproj
- project.xcworkspace
- hello-objective
- no-swift
- hello-objective.xcodeproj
- project.xcworkspace
- hello-objective
- no-xcode-with-spm
- only-tests-with-spm
- hello-tests.xcodeproj
- project.xcworkspace
- only-tests
- hello-tests.xcodeproj
- project.xcworkspace
- posix-only
- cross-references
- deduplication
- hello-world
- linkage-awareness
- logging
- ql
- examples
- snippets
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- pattern
- type
- frameworks
- StandardLibrary
- UIKit
- Xml
- generated
- decl
- expr
- pattern
- stmt
- type
- printast
- security
- upgrades/f937d9e63094280b7ec0ef26c70310daad5c1f79
- src
- queries/Security
- CWE-079
- CWE-135
- CWE-943
- test
- extractor-tests
- expressions
- generated
- decl
- Accessor
- CapturedDecl
- ConcreteVarDecl
- Deinitializer
- Initializer
- NamedFunction
- ParamDecl
- expr
- ExplicitClosureExpr
- InitializerRefCallExpr
- LazyInitializationExpr
- OtherInitializerRefExpr
- RebindSelfInInitializerExpr
- type/DynamicSelfType
- types
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- flowsources
- taint/core
- elements
- decl
- abstractfunctiondecl
- function
- expr/methodlookup
- query-tests/Security
- CWE-022
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-135
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-327
- CWE-611
- CWE-757
- CWE-760
- CWE-916
- third_party
- tools
- autobuilder-diagnostics
- xcode-autobuilder
- tests
- hello-tests
- hello-tests.xcodeproj
- project.xcworkspace
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,736 files changed
+117872
-89044
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
|
Lines changed: 46 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + |
Lines changed: 0 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
43 |
| - | |
44 | 43 |
| |
45 | 44 |
| |
46 | 45 |
| |
47 | 46 |
| |
48 | 47 |
| |
49 | 48 |
| |
50 | 49 |
| |
51 |
| - | |
52 | 50 |
| |
53 | 51 |
| |
54 | 52 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 |
| |
2 | 6 |
| |
3 | 7 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
0 commit comments