File tree
1,141 files changed
+48778
-40008
lines changed- .github/workflows
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- ql
- lib
- change-notes/released
- semmle/code/cpp
- dataflow/internal
- tainttracking1
- tainttracking2
- exprs
- ir
- dataflow/internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation/raw/internal
- models
- implementations
- src
- Critical
- Metrics/Internal
- Security/CWE/CWE-611
- change-notes/released
- test
- examples/expressions
- experimental/query-tests/Security/CWE/CWE-416
- library-tests
- CPP-205
- compiler_generated
- dataflow/dataflow-tests
- ir
- ir
- modulus-analysis
- range-analysis
- sign-analysis
- ssa
- types
- syntax-zoo
- query-tests
- Critical/MemoryFreed
- Likely Bugs/Format/NonConstantFormat
- Security/CWE
- CWE-022/semmle/tests
- CWE-078/semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114/SAMATE/UncontrolledProcessOperation
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- consts
- CWE-190/semmle
- TaintedAllocationSize
- tainted
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-497/semmle/tests
- CWE-807/semmle/TaintedCondition
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Collections
- ObjectCreation
- Patterns
- Extractor
- Populators
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util.Tests
- Semmle.Util
- ToolStatusPage
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms/diag_recursive_generics
- posix-only
- standalone_dependencies_executing_runtime
- standalone_dependencies_nuget_config_error_timeout
- proj
- lib
- change-notes/released
- ext
- semmle/code/csharp
- commons
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- exprs
- frameworks
- security/dataflow
- src
- Telemetry
- change-notes/released
- utils
- modelconverter
- modeleditor
- test
- experimental/Security Features/CWE-759
- library-tests
- attributes
- comments
- constructors
- controlflow
- graph
- guards
- csharp11
- csharp6
- csharp7.2
- csharp7
- csharp8
- csharp9
- dataflow
- async
- collections
- external-models
- global
- library
- threat-models
- typeflow-dispatch
- definitions
- dispatch
- dynamic
- enums
- events
- expressions
- fields
- frameworks
- EntityFramework
- system
- Dispose
- Equals
- generics
- indexers
- overrides
- unification
- query-tests
- Nullness
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- CWE-838
- docs/codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- reusables
- go
- extractor
- toolchain
- integration-tests-lib
- ql
- consistency-queries
- change-notes/released
- integration-tests
- all-platforms/go
- bazel-sample-1
- bazel-sample-2
- diagnostics
- build-constraints-exclude-all-go-files
- go-files-found-not-processed
- invalid-toolchain-version
- newer-go-version-needed
- no-go-files-found
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- unsupported-relative-path
- go-get-without-modules-sample
- go-mod-sample
- go-mod-without-version
- go-version-bump
- make-sample
- mixed-layout
- ninja-sample
- single-go-mod-and-go-files-not-under-it
- single-go-mod-in-root
- single-go-mod-not-in-root
- single-go-work-not-in-root
- two-go-mods-nested-none-in-root
- two-go-mods-nested-one-in-root
- two-go-mods-not-nested
- two-go-mods-one-failure
- linux-only/go
- dep-sample
- glide-sample
- lib
- change-notes/released
- semmle/go
- controlflow
- dataflow
- internal
- tainttracking1
- tainttracking2
- frameworks/stdlib
- internal
- security
- src
- change-notes/released
- test
- experimental
- CWE-090
- CWE-203
- CWE-287
- CWE-369
- CWE-522-DecompressionBombs
- CWE-74
- CWE-79
- CWE-918
- extractor-tests/no-intermediate-strings
- library-tests/semmle/go
- controlflow/ControlFlowGraph
- dataflow
- DefaultTaintSanitizer
- HiddenNodes
- Switch
- frameworks
- BeegoOrm
- Beego
- Echo
- Encoding
- Revel
- Twirp
- XNetHtml
- query-tests/Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-327
- CWE-338/InsecureRandomness
- CWE-347
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- CWE-918
- javascript/ql
- lib
- change-notes/released
- semmle/javascript
- dataflow/internal
- frameworks
- data/internal
- src
- Expressions
- change-notes/released
- test
- library-tests
- CallGraphs/AnnotatedTest
- Directives
- frameworks/data
- query-tests/Expressions/UnknownDirective
- java
- documentation/library-coverage
- kotlin-extractor
- src/main/kotlin/utils/versions
- v_1_5_0
- v_1_9_0-Beta
- v_2_0_0-RC1
- ql
- automodel
- src
- change-notes/released
- test
- AutomodelApplicationModeExtraction
- AutomodelFrameworkModeExtraction/com/github/codeql/test
- integration-tests/all-platforms/kotlin/diagnostics/kotlin-version-too-new
- lib
- change-notes/released
- ext/generated
- semmle/code
- java
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- dispatch
- frameworks/spring
- regex
- security
- xml
- src
- Advisory/Documentation
- Likely Bugs/Arithmetic
- Telemetry
- change-notes/released
- utils
- flowtestcasegenerator
- modelconverter
- modeleditor
- test-kotlin2/library-tests/exprs
- test
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208/TimingAttackAgainstSignagure
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- library-tests
- dataflow
- local-additional-taint
- threat-models
- frameworks
- JaxWs
- apache-commons-lang3
- query-tests
- Metrics/GeneratedVsManualCoverage/TopJdkApisTest
- SpuriousJavadocParam
- security
- CWE-022/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests/TempDirLocalInformationDisclosure
- CWE-297
- CWE-311/CWE-319
- CWE-327/semmle/tests
- CWE-601/semmle/tests
- CWE-681/semmle/tests
- CWE-807/semmle/tests
- utils
- modeleditor
- modelgenerator/dataflow
- misc/suite-helpers
- change-notes/released
- python
- extractor
- buildtools
- cli-integration-test
- force-enable-library-extraction
- repo_dir
- ignore-venv
- tsg-python
- tsp
- ql
- consistency-queries
- lib
- change-notes/released
- semmle/python
- dataflow/new
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- frameworks
- data
- internal
- xml
- src
- Security/CWE-020-ExternalAPIs
- change-notes/released
- test
- experimental
- dataflow
- summaries
- typetracking
- library-tests/CallGraph
- code
- query-tests/Security
- CWE-022-TarSlip
- CWE-022-UnsafeUnpacking
- CWE-074-TemplateInjection
- CWE-079
- CWE-091-XsltInjection
- CWE-113
- CWE-1236
- CWE-176
- CWE-287-ConstantSecretKey
- CWE-522
- CWE-614
- CWE-770
- library-tests
- essa/ssa-compute/CONSISTENCY
- frameworks
- django-orm
- modeling-example
- web/zope
- query-tests/Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-285-PamAuthorization
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-918-ServerSideRequestForgery
- CWE-943-NoSqlInjection
- lib
- Crypto
- Cipher
- PublicKey
- cheetah/Template
- cherrypy
- cryptography
- hazmat
- primitives
- asymmetric
- ciphers
- django
- conf
- db
- models
- http
- views
- fabric
- falcon
- flask
- invoke
- libxml2
- lxml
- os
- paramiko
- pyOpenSSL
- pyramid
- tornado
- twisted
- web
- zope
- interface
- ql
- buramu
- extractor
- ql/src/codeql-suites
- ruby/ql
- lib
- change-notes/released
- codeql/ruby
- ast/internal
- controlflow/internal
- dataflow
- internal
- tainttracking1
- frameworks
- data
- internal
- security
- typetracking/internal
- src
- change-notes/released
- queries/security
- cwe-078
- examples
- cwe-116
- cwe-117/examples
- cwe-352
- examples
- cwe-601
- examples
- cwe-915
- examples
- utils/modeleditor
- test
- library-tests
- controlflow/graph
- dataflow
- barrier-guards
- call-sensitivity
- global
- local
- regressions
- summaries
- frameworks
- gemfile
- json
- query-tests
- experimental
- LdapInjection
- TemplateInjection
- XPathInjection
- cwe-502
- security
- cwe-022
- cwe-078/CommandInjection
- cwe-079
- lib
- cwe-089
- cwe-094/CodeInjection
- cwe-117
- cwe-1333-regexp-injection
- cwe-134
- cwe-312
- cwe-352
- railsapp
- app/controllers
- config
- cwe-502/unsafe-deserialization
- cwe-601
- cwe-915
- cwe-918
- swift
- actions/run-integration-tests
- ql
- lib
- change-notes/released
- codeql/swift/dataflow
- internal
- tainttracking1
- src
- change-notes/released
- test/query-tests/Security/CWE-311
- third_party
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,141 files changed
+48778
-40008
lines changedLines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
| 9 | + | |
9 | 10 |
| |
10 | 11 |
| |
11 | 12 |
| |
| |||
22 | 23 |
| |
23 | 24 |
| |
24 | 25 |
| |
| 26 | + | |
25 | 27 |
| |
26 | 28 |
| |
27 | 29 |
| |
28 | 30 |
| |
| 31 | + | |
29 | 32 |
| |
30 | 33 |
| |
31 | 34 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
31 | 31 |
| |
32 | 32 |
| |
33 | 33 |
| |
| 34 | + | |
| 35 | + | |
34 | 36 |
| |
35 | 37 |
| |
36 | 38 |
| |
|
Lines changed: 0 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
251 | 251 |
| |
252 | 252 |
| |
253 | 253 |
| |
254 |
| - | |
255 |
| - | |
256 |
| - | |
257 |
| - | |
258 |
| - | |
259 |
| - | |
260 | 254 |
| |
261 | 255 |
| |
262 | 256 |
| |
|
Lines changed: 4 additions & 22 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
203 | 203 |
| |
204 | 204 |
| |
205 | 205 |
| |
| 206 | + | |
| 207 | + | |
206 | 208 |
| |
207 | 209 |
| |
208 | 210 |
| |
| |||
250 | 252 |
| |
251 | 253 |
| |
252 | 254 |
| |
253 |
| - | |
254 |
| - | |
255 |
| - | |
256 |
| - | |
257 |
| - | |
258 |
| - | |
| 255 | + | |
259 | 256 |
| |
260 | 257 |
| |
261 | 258 |
| |
| |||
265 | 262 |
| |
266 | 263 |
| |
267 | 264 |
| |
268 |
| - | |
269 |
| - | |
270 |
| - | |
271 |
| - | |
272 |
| - | |
273 |
| - | |
274 |
| - | |
275 |
| - | |
276 |
| - | |
277 |
| - | |
278 |
| - | |
279 |
| - | |
280 |
| - | |
281 |
| - | |
282 |
| - | |
283 |
| - | |
| 265 | + | |
284 | 266 |
| |
285 | 267 |
| |
286 | 268 |
| |
|
Lines changed: 0 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
30 |
| - | |
31 |
| - | |
32 | 29 |
| |
33 | 30 |
| |
34 | 31 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
20 |
| - | |
| 20 | + | |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 |
| |
2 | 6 |
| |
3 | 7 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
Lines changed: 3 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + | |
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
| 12 | + | |
12 | 13 |
| |
13 | 14 |
| |
| 15 | + | |
14 | 16 |
|
0 commit comments