File tree
8,038 files changed
+530770
-265219
lines changed- .devcontainer
- .github
- workflows
- .vscode
- config
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- downgrades
- 19887dbd33327fb07d54251786e0cb2578539775
- ql
- examples
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- ir/dataflow
- internal
- ssa0
- tainttracking1
- tainttracking2
- tainttracking3
- rangeanalysis
- extensions
- security
- semantic
- analysis
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- new
- exprs
- ir
- dataflow
- internal
- ssa0
- tainttracking1
- implementation
- aliased_ssa
- gvn
- internal
- internal
- internal
- raw
- gvn
- internal
- internal
- reachability
- unaliased_ssa
- gvn
- internal
- internal
- reachability
- internal
- models
- implementations
- interfaces
- rangeanalysis
- new
- internal/semantic
- analysis
- security
- InvalidPointerDereference
- boostorg/asio
- valuenumbering
- upgrades
- 282c13bfdbcbd57a887972b47a471342a4ad5507
- a5bb28ed29f73855d64cc5f939cef977fa8fd19a
- src
- Critical
- JPL_C/LOC-4/Rule 23
- Likely Bugs
- Conversion
- Format
- Leap Year
- Likely Typos
- Memory Management
- Protocols
- Metrics/Dependencies
- Security/CWE
- CWE-020
- ir
- CWE-022
- CWE-078
- CWE-079
- CWE-119
- CWE-129
- CWE-131
- CWE-190
- CWE-191
- CWE-295
- CWE-311
- CWE-313
- CWE-319
- CWE-326
- CWE-327
- CWE-428
- CWE-497
- CWE-611
- CWE-732
- change-notes
- released
- experimental
- Likely Bugs
- Security/CWE
- CWE-020
- CWE-078
- CWE-1041
- CWE-190
- CWE-193
- CWE-285
- CWE-359
- CWE-415
- CWE-675
- CWE-787
- CWE-788
- external
- test
- TestUtilities/dataflow
- examples/docs-examples
- analyzing-data-flow-in-cpp
- experimental
- library-tests/rangeanalysis/strlenliteral
- query-tests/Security/CWE
- CWE-020/NoCheckBeforeUnsafePutUser
- CWE-078
- CWE-119
- CWE-190
- AllocMultiplicationOverflow
- IfStatementAdditionOverflow
- CWE-193
- array-access
- constant-size
- pointer-deref
- CWE-359/semmle/tests
- library-tests
- CPP-205
- allocators
- attributes/type_attributes
- blocks/cpp
- constants/constants
- controlflow/guards-ir
- dataflow
- DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- globals
- additional-flow-to-parameter
- crement
- dataflow-edge-tests
- dataflow-tests
- fields
- recursion
- security-taint
- smart-pointers-taint
- source-sink-tests
- taint-tests
- declarationEntry/more
- identity_string
- ir
- ir
- modulus-analysis
- points_to
- range-analysis
- sign-analysis
- ssa
- types
- lambdas/captures
- literals/aggregate_literals
- locations/constants
- loops
- noexcept/copy_from_prototype
- structs/compatible_c
- syntax-zoo
- templates
- extern
- isfromtemplateinstantiation
- query-tests
- Critical
- MemoryFreed
- MissingCheckScanf
- OverflowStatic
- Likely Bugs
- Conversion/CastArrayPointerArithmetic
- Format/NonConstantFormat
- Leap Year/Adding365DaysPerYear
- Memory Management/NtohlArrayNoBound
- Protocols
- RedundantNullCheckSimple
- Security/CWE
- CWE-022/semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-119
- SAMATE
- semmle/tests
- CWE-120/semmle/tests
- CWE-129/semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- consts
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- ComparisonWithWiderType
- TaintedAllocationSize
- tainted
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests
- CWE-457/semmle/tests
- CWE-497
- SAMATE
- semmle/tests
- CWE-611
- CWE-807/semmle/TaintedCondition
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- downgrades
- extractor
- Semmle.Extraction.CSharp.Standalone
- Properties
- Semmle.Extraction.CSharp
- Entities
- Expressions
- ObjectCreation
- Extractor
- Semmle.Extraction.Tests
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- test
- consistency-queries
- examples
- integration-tests
- all-platforms
- cshtml
- Views/Home
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- dotnet_build
- dotnet_pack
- dotnet_publish
- dotnet_run
- msbuild
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- scripts
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- warn_as_error
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- scripts
- lib
- Linq
- change-notes
- released
- ext
- generated
- semmle/code
- asp
- cil
- csharp
- commons
- dataflow
- internal
- rangeanalysis
- tainttracking1
- dispatch
- exprs
- frameworks
- system
- collections
- runtime
- security/cryptography
- security
- auth
- cryptography
- dataflow
- flowsinks
- flowsources
- xml
- dotnet
- src
- API Abuse
- Bad Practices
- Comments
- Implementation Hiding
- Complexity
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- LeapYear
- Statements
- Security Features
- CWE-011
- CWE-020
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-090
- CWE-091
- CWE-094
- CWE-099
- CWE-112
- CWE-114
- CWE-117
- CWE-134
- CWE-201
- CWE-209
- CWE-285
- CWE-312
- CWE-321
- CWE-327
- CWE-352
- CWE-359
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-730
- CWE-798
- CWE-807
- CWE-838
- Stubs
- Telemetry
- change-notes/released
- experimental
- CWE-099
- CWE-918
- Security Features
- CWE-1004
- CWE-614
- CWE-759
- JsonWebTokenHandler
- Serialization
- backdoor
- dataflow/flowsources
- ir
- implementation
- internal
- raw
- gvn
- internal
- internal
- common
- desugar
- internal
- unaliased_ssa
- gvn
- internal
- internal
- internal
- rangeanalysis
- utils
- modelconverter
- modelgenerator
- internal
- test
- TestUtilities
- experimental
- CWE-918
- Security Features
- CWE-759
- backdoor
- library-tests
- assemblies
- cil/dataflow
- csharp7
- dataflow
- async
- call-sensitivity
- callablereturnsarg
- collections
- content
- delegates
- external-models
- fields
- global
- library
- operators
- patterns
- tuples
- types
- dispatch
- frameworks
- EntityFramework
- JsonNET
- NHibernate
- sql
- parameters
- security/dataflow/flowsources
- query-tests
- API Abuse
- CallToGCCollect
- CallToObsoleteMethod
- ClassDoesNotImplementEquals
- ClassImplementsICloneable
- DisposeNotCalledOnException
- FormatInvalid
- InconsistentEqualsGetHashCode
- IncorrectCompareToSignature
- IncorrectEqualsSignature
- MissingDisposeCall
- MissingDisposeMethod
- NoDisposeCallOnLocalIDisposable
- NonOverridingMethod
- NullArgumentToEquals
- UncheckedReturnValue
- AlertSuppression
- Bad Practices/Implementation Hiding/ExposeRepresentation
- Security Features
- CWE-011
- bad1
- bad2
- good1
- good2
- CWE-016
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-119
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-248/MissingASPNETGlobalErrorHandler
- WebConfigOffButGlobal
- WebConfigOff
- CWE-285/MissingAccessControl
- MVCTests
- WebFormsTests
- Test1
- Test2
- Test3
- A
- B
- C
- CWE-312
- CWE-327/InsecureSQLConnection
- CWE-338
- CWE-352
- global
- missing
- CWE-359
- CWE-384
- CWE-451/MissingXFrameOptions
- CodeAddedHeader
- NoHeader
- WebConfigAddedHeader
- CWE-502
- DeserializedDelegate
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- UnsafeDeserialization
- CWE-539/PersistentCookie
- CWE-548
- CWE-601/UrlRedirect
- CWE-614/RequireSSL
- AddedInCode
- AddedInForms
- HttpCookiesCorrect
- RequireSSLMissing
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- Stubs
- All
- Minimal
- Telemetry/LibraryUsage
- resources
- assemblies
- stubs
- _frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- utils/modelgenerator
- dataflow
- typebasedflow
- tools
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- ql-language-reference
- ql-training
- cpp
- java
- slide-snippets
- query-help
- reusables
- writing-codeql-queries
- go
- codeql-tools
- downgrades
- external-packs/codeql/suite-helpers/0.0.2
- extractor
- cli
- go-autobuilder
- go-bootstrap
- go-extractor
- go-tokenizer
- diagnostics
- srcarchive
- trap
- util
- ql
- config/legacy-support
- examples
- integration-tests
- all-platforms/go
- bazel-sample-1
- bazel-sample-2
- diagnostics
- build-constraints-exclude-all-go-files
- work
- go-files-found-not-processed
- work
- subdir
- newer-go-version-needed
- work
- no-go-files-found
- work
- package-not-found-with-go-mod
- work
- package-not-found-without-go-mod
- work
- unsupported-relative-path
- work/main
- subpkg
- single-go-mod-and-go-files-not-under-it
- subdir
- subsubdir
- single-go-mod-in-root
- subdir
- single-go-mod-not-in-root
- subdir
- subsubdir
- single-go-work-not-in-root
- modules
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-nested-none-in-root
- subdir0
- subdir1
- subsubdir1
- subdir2
- two-go-mods-nested-one-in-root
- subdir1
- subsubdir1
- subdir2
- two-go-mods-not-nested
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- linux-only/go
- dep-sample
- glide-sample
- lib
- change-notes
- released
- ext
- semmle/go
- controlflow
- dataflow
- barrierguardutil
- internal
- tainttracking1
- dependencies
- frameworks
- stdlib
- security
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-020
- CWE-022
- CWE-117
- CWE-295
- CWE-326
- CWE-327
- CWE-352
- CWE-601
- CWE-681
- change-notes
- released
- experimental
- CWE-1004
- CWE-203
- CWE-285
- CWE-321
- CWE-327
- CWE-74
- CWE-79
- CWE-918
- CWE-942
- Unsafe
- frameworks
- test
- TestUtilities
- example-tests/snippets
- experimental
- CWE-203
- CWE-321
- vendor
- github.com
- gin-gonic/gin
- gogf/gf-jwt/v2
- golang-jwt/jwt/v4
- iris-contrib/middleware/jwt
- kataras
- iris/v12/middleware/jwt
- jwt
- CWE-369
- CWE-74
- CWE-79
- CWE-918
- frameworks
- CleverGo
- Fiber
- extractor-tests/diagnostics
- library-tests/semmle/go
- Function
- Packages
- Types
- concepts
- HTTP
- LoggerCall
- dataflow
- ArrayConversion
- CallGraph
- ExternalFlowVarArgs
- ExternalFlow
- vendor/github.com/nonexistent/test
- FlowSteps
- FunctionInputsAndOutputs
- GenericFunctionsAndTypes
- GuardingFunctions
- HiddenNodes
- ListOfConstantsSanitizerGuards
- Nodes
- PromotedFields
- PromotedMethods
- TypeAssertions
- VarArgsWithFunctionModels
- VarArgs
- frameworks
- Beego
- CouchbaseV1
- Echo
- ElazarlGoproxy
- EvanphxJsonPatch
- vendor/github.com/evanphx/json-patch/v5
- GoKit
- GoMicro
- client
- proto
- vendor
- go-micro.dev/v4
- api
- client
- server
- google.golang.org/protobuf
- internal/impl
- proto
- reflect/protoreflect
- runtime
- protoiface
- protoimpl
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- K8sIoClientGo
- NoSQL
- Revel
- SQL
- Gorm
- bun
- vendor
- github.com/uptrace/bun
- dialect/sqlitedialect
- driver/sqliteshim
- go-pg
- vendor
- github.com/go-pg/pg/v10
- orm
- vendor/github.com/go-pg/pg/orm
- StdlibTaintFlow
- TaintSteps
- XNetHtml
- vendor/golang.org/x/net/html
- Yaml
- Zap
- gqlgen
- graph
- model
- vendor
- github.com/99designs/gqlgen/graphql
- query-tests/Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-117
- CWE-312
- CWE-327
- CWE-338/InsecureRandomness
- CWE-352
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- CWE-681
- CWE-918
- java
- documentation/library-coverage
- downgrades
- 7cbc85b1f3ecda39661ad4806dedbd0973d2c4c0
- ecfcf050952e54b1155fc89525db84af6ad34aaf
- kotlin-explorer
- src/main/kotlin
- kotlin-extractor
- src/main
- java/com/semmle
- extractor/java
- util/files
- kotlin
- utils
- versions
- v_1_4_32
- v_1_8_0
- ql
- consistency-queries
- examples
- integration-tests
- all-platforms
- java
- android-sample-old-style-kotlin-build-script-no-wrapper
- project
- android-sample-old-style-kotlin-build-script
- project
- android-sample-old-style-no-wrapper
- project
- android-sample-old-style
- project
- diagnostics
- android-gradle-incompatibility
- compilation-error
- dependency-error
- java-version-too-old
- maven-http-repository
- .mvn/wrapper
- multiple-candidate-builds
- no-build-system
- no-gradle-test-classes
- no-gradle-wrapper
- kotlin
- annotation-id-consistency
- default-parameter-mad-flow
- diagnostics/kotlin-version-too-new
- file_classes
- gradle_kotlinx_serialization
- kotlin-interface-inherited-default
- kotlin_java_static_fields
- linux-only/kotlin
- custom_plugin
- posix-only/kotlin
- kotlin_double_interception
- code
- lib
- change-notes
- released
- config
- ext
- experimental
- generated
- semmle/code
- configfiles
- java
- controlflow
- internal
- unreachableblocks
- dataflow
- internal
- rangeanalysis
- tainttracking1
- deadcode
- frameworks
- dispatch
- frameworks
- android
- apache
- camel
- gigaspaces
- google
- hudson
- jackson
- javaee
- ejb
- jsf
- javase
- kotlin
- rundeck
- spring
- stapler
- struts
- os
- regex
- security
- internal
- regexp
- xml
- upgrades
- 7cbc85b1f3ecda39661ad4806dedbd0973d2c4c0
- 934bf10b4bd34cf648893efcd1d0d7be9471d39f
- src
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Language Abuse
- Likely Bugs/Comparison
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
8,038 files changed
+530770
-265219
lines changedLines changed: 7 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
2 | 8 |
| |
3 | 9 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
|
Lines changed: 21 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + |
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
| 14 | + | |
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
24 | 23 |
| |
25 | 24 |
| |
26 | 25 |
| |
|
Lines changed: 0 additions & 102 deletions
This file was deleted.
Lines changed: 0 additions & 12 deletions
This file was deleted.
Lines changed: 3 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
| 11 | + | |
11 | 12 |
| |
12 | 13 |
| |
13 |
| - | |
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
| |||
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
29 |
| - | |
| 29 | + | |
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
33 |
| - | |
| 33 | + | |
34 | 34 |
|
Lines changed: 29 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
| 15 | + | |
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
|
0 commit comments