File tree
950 files changed
+33524
-6161
lines changed- config
- cpp/ql
- lib
- change-notes
- released
- semmle/code/cpp
- dataflow/internal
- ir/dataflow/internal
- models/implementations
- src
- Security/CWE/CWE-119
- change-notes/released
- test
- experimental/query-tests/Security/CWE/CWE-193/pointer-deref
- library-tests/dataflow
- dataflow-tests
- taint-tests
- query-tests/Security/CWE/CWE-119/semmle/tests
- csharp
- documentation/library-coverage
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- lib
- change-notes
- released
- semmle/code/csharp
- dataflow
- internal
- security/dataflow
- src
- Security Features/CWE-022
- change-notes
- released
- test
- TestUtilities
- library-tests/dataflow
- fields
- operators
- patterns
- tuples
- query-tests
- API Abuse
- CallToGCCollect
- CallToObsoleteMethod
- ClassDoesNotImplementEquals
- ClassImplementsICloneable
- DisposeNotCalledOnException
- FormatInvalid
- InconsistentEqualsGetHashCode
- IncorrectCompareToSignature
- IncorrectEqualsSignature
- MissingDisposeCall
- MissingDisposeMethod
- NoDisposeCallOnLocalIDisposable
- NonOverridingMethod
- NullArgumentToEquals
- UncheckedReturnValue
- AlertSuppression
- Security Features
- CWE-011
- CWE-016
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-119
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-248/MissingASPNETGlobalErrorHandler
- WebConfigOffButGlobal
- WebConfigOff
- CWE-312
- CWE-338
- CWE-352
- global
- missing
- CWE-359
- CWE-384
- CWE-451/MissingXFrameOptions
- CodeAddedHeader
- NoHeader
- WebConfigAddedHeader
- CWE-502
- DeserializedDelegate
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- UnsafeDeserialization
- CWE-539/PersistentCookie
- CWE-548
- CWE-601/UrlRedirect
- CWE-614/RequireSSL
- AddedInCode
- AddedInForms
- HttpCookiesCorrect
- RequireSSLMissing
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- resources
- assemblies
- stubs
- docs/codeql
- codeql-for-visual-studio-code
- images/codeql-for-visual-studio-code
- ql-language-reference
- go/ql
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- security
- src
- Security
- CWE-022
- CWE-117
- change-notes
- released
- test
- TestUtilities
- experimental
- CWE-134
- CWE-918
- library-tests/semmle/go
- dataflow
- ExternalFlow
- vendor/github.com/nonexistent/test
- GenericFunctionsAndTypes
- frameworks
- Beego
- ElazarlGoproxy
- SQL
- Yaml
- query-tests/Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-117
- CWE-327
- CWE-338/InsecureRandomness
- CWE-352
- javascript/ql
- lib
- change-notes
- released
- semmle/javascript/frameworks/data/internal
- src
- Security
- CWE-022
- CWE-094/examples
- CWE-798
- examples
- change-notes
- released
- java
- documentation/library-coverage
- downgrades/ecfcf050952e54b1155fc89525db84af6ad34aaf
- kotlin-extractor/src/main
- java/com/semmle/util/files
- kotlin
- utils
- versions
- v_1_4_32
- v_1_8_0
- ql
- lib
- change-notes
- released
- config
- ext
- semmle/code/java
- dataflow
- internal
- frameworks
- hudson
- stapler
- security
- upgrades/7cbc85b1f3ecda39661ad4806dedbd0973d2c4c0
- src
- Security/CWE/CWE-022
- Telemetry
- change-notes
- released
- utils/flowtestcasegenerator
- test
- TestUtilities
- ext/TestModels
- kotlin/library-tests
- classes
- dataflow/summaries
- library-tests
- dataflow
- callctx
- collections
- fluent-methods
- stream-collect
- synth-global
- taint-format
- taint-gson
- taint-jackson
- taintsources
- frameworks
- JaxWs
- android
- asynctask
- content-provider-summaries
- content-provider
- external-storage
- flow-steps
- intent
- notification
- slice
- sources
- uri
- widget
- apache-ant
- apache-collections
- apache-commons-compress
- apache-commons-lang3
- apache-http
- gson
- guava/generated
- cache
- collect
- hudson
- jackson
- javax-json
- jdk
- java.io
- java.net
- java.nio.file
- json-java
- netty
- generated
- manual
- okhttp
- play
- rabbitmq
- ratpack
- retrofit
- spring
- beans
- cache
- context
- controller
- data
- http
- ui
- util
- validation
- webmultipart
- webutil
- stapler
- stream
- thymeleaf
- logging
- optional
- pathsanitizer
- paths
- regex
- scanner
- query-tests/security
- CWE-117
- CWE-266
- CWE-441
- CWE-470
- CWE-489/webview-debugging
- CWE-532
- CWE-611
- CWE-780
- CWE-927
- stubs
- javax-annotation-api-1.3.2/javax/annotation
- jenkins/hudson/model
- stapler-1.263/org/kohsuke/stapler
- misc/suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow
- new/internal
- old
- frameworks/data/internal
- security
- injection
- web
- bottle
- cherrypy
- client
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- src
- Security/CWE-798
- change-notes
- released
- experimental/Security/CWE-022
- test
- 3/library-tests/taint
- strings
- unpacking
- experimental
- dataflow
- TestUtil
- basic
- coverage
- exceptions
- fieldflow
- match
- module-initialization
- regression
- summaries
- tainttracking
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking-summaries
- typetracking_imports
- typetracking
- variable-capture
- meta
- debug
- inline-taint-test-demo
- query-tests/Security/CWE-022-UnsafeUnpacking
- library-tests
- examples/custom-sanitizer
- frameworks
- aioch
- aiohttp
- aiomysql
- aiopg
- aiosqlite
- asyncpg
- cassandra-driver
- clickhouse_driver
- cryptodome
- cryptography
- crypto
- cx_Oracle
- dill
- django-orm
- django-v1
- django-v2-v3
- django
- fabric
- fastapi
- flask_admin
- flask_sqlalchemy
- flask
- httpx
- idna
- invoke
- jmespath
- libtaxii
- lxml
- markupsafe
- multidict
- mysql-connector-python
- mysqldb
- oracledb
- peewee
- phoenixdb
- pycurl
- pymssql
- pymysql
- pyodbc
- requests
- rest_framework
- rsa
- ruamel.yaml
- simplejson
- sqlalchemy
- stdlib-py2
- stdlib-py3
- stdlib
- toml
- tornado
- twisted
- ujson
- urllib3
- xmltodict
- yaml
- yarl
- regex
- security
- command-execution
- fabric-v1-execute
- taint
- collections
- config
- example
- exception_traceback
- flowpath_regression
- general
- namedtuple
- strings
- unpacking
- query-tests/Security
- CWE-022-PathInjection
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-798-HardcodedCredentials
- ql/ql
- src
- codeql_ql/ast
- internal
- queries
- performance
- style
- test/queries
- performance/AbstractClassImport
- style
- FieldOnlyUsedInCharPred
- MissingOverride
- ruby
- extractor
- ql
- lib
- change-notes
- released
- codeql/ruby
- dataflow/internal
- frameworks
- actiondispatch/internal
- data/internal
- rack/internal
- regexp/internal
- security
- typetracking
- internal
- src
- change-notes
- released
- experimental/cwe-022-zipslip
- queries/security/cwe-829
- test
- TestUtilities
- library-tests
- dataflow
- array-flow
- call-sensitivity
- flow-summaries
- global
- hash-flow
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- rack
- sinatra
- query-tests/security/cwe-829
- swift
- actions
- build-and-test
- run-integration-tests
- downgrades/147e087e57e51b2eb41e75c9c97380d0e6c20ecb
- extractor
- infra
- translators
- logging
- ql
- lib
- change-notes
- released
- codeql/swift
- dataflow
- internal
- generated
- expr
- regex
- internal
- upgrades/44e36e15e90bc1535964d9b86b3cd06a8b0d26e3
- src
- change-notes
- released
- queries/Summary
- test
- extractor-tests
- errors
- generated
- decl/NamedFunction
- expr/MethodLookupExpr
- CONSISTENCY
- run_under
- updates
- library-tests
- ast
- dataflow/dataflow
- regex
- test_fragment_licenses
- query-tests/Security
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-311
- CWE-321
- CWE-760
- third_party
- swift-llvm-support
- patches
- tools
- autobuilder-diagnostics
- diagnostics
- test/qltest
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
950 files changed
+33524
-6161
lines changedLines changed: 7 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
2 | 8 |
| |
3 | 9 |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
523 | 523 |
| |
524 | 524 |
| |
525 | 525 |
| |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
526 | 530 |
| |
527 | 531 |
| |
528 | 532 |
| |
|
Lines changed: 8 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
1 | 9 |
| |
2 | 10 |
| |
3 | 11 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 5 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
4 | 5 |
| |
5 | 6 |
| |
6 |
| - | |
| 7 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + | |
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
|
Lines changed: 0 additions & 20 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
37 |
| - | |
38 |
| - | |
39 |
| - | |
40 |
| - | |
41 |
| - | |
42 |
| - | |
43 |
| - | |
44 |
| - | |
45 | 37 |
| |
46 | 38 |
| |
47 | 39 |
| |
| |||
183 | 175 |
| |
184 | 176 |
| |
185 | 177 |
| |
186 |
| - | |
187 |
| - | |
188 |
| - | |
189 |
| - | |
190 |
| - | |
191 |
| - | |
192 | 178 |
| |
193 | 179 |
| |
194 | 180 |
| |
| |||
213 | 199 |
| |
214 | 200 |
| |
215 | 201 |
| |
216 |
| - | |
217 |
| - | |
218 |
| - | |
219 |
| - | |
220 |
| - | |
221 |
| - | |
222 | 202 |
| |
223 | 203 |
| |
224 | 204 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
2021 | 2021 |
| |
2022 | 2022 |
| |
2023 | 2023 |
| |
2024 |
| - | |
| 2024 | + | |
| 2025 | + | |
2025 | 2026 |
| |
2026 | 2027 |
| |
2027 | 2028 |
| |
|
Lines changed: 6 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
235 | 235 |
| |
236 | 236 |
| |
237 | 237 |
| |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
238 | 244 |
| |
239 | 245 |
| |
240 | 246 |
| |
|
0 commit comments