File tree
6,915 files changed
+326507
-137339
lines changed- .devcontainer
- .github
- codeql
- workflows
- .vscode
- actions
- extractor
- tools
- ql
- lib
- change-notes
- codeql
- actions
- Violations Of Best Practices
- ast/internal
- config
- controlflow
- internal
- dataflow
- internal
- ideContextual
- security
- files
- ext
- config
- generated
- composite-actions
- reusable-workflows
- manual
- ide-contextual-queries
- src
- Debug
- Models
- Security
- CWE-074
- CWE-077
- CWE-078
- CWE-088
- CWE-094
- CWE-1395
- CWE-200
- CWE-275
- CWE-284
- CWE-285
- CWE-312
- CWE-349
- CWE-367
- CWE-571
- CWE-829
- CWE-918
- Violations Of Best Practice/CodeQL
- change-notes
- codeql-suites
- test
- library-tests
- .github/workflows
- query-tests
- Models
- .github/workflows
- action1
- Security
- CWE-074
- .github/workflows
- CWE-077
- .github
- actions
- download-artifact-2
- download-artifact
- workflows
- CWE-078
- .github
- actions/run-airbyte-ci
- workflows
- CWE-088
- .github/workflows
- CWE-094
- .github
- actions
- action1
- action2
- action3
- action4
- action5
- action6
- action7
- external
- TestOrg/TestRepo/.github/actions/clone-repo
- ultralytics/actions
- workflows
- external/TestOrg/TestRepo/.github/workflows
- CWE-1395
- .github/workflows
- CWE-200
- .github/workflows
- CWE-275
- .github/workflows
- CWE-284
- .github/workflows
- CWE-285
- .github/workflows
- CWE-312
- .github/workflows
- CWE-349
- .github/workflows
- CWE-367
- .github/workflows
- CWE-571
- .github/workflows
- CWE-829
- .github
- actions
- dangerous-git-checkout
- download-artifact-2
- download-artifact
- workflows
- external/TestOrg/TestRepo/.github/workflows
- CWE-918
- .github/workflows
- SyntaxError
- .github/workflows
- Violations Of Best Practice/CodeQL
- .github/workflows
- config
- cpp
- downgrades
- 4813509d85b45ae17421c036905199f7324cf228
- c3881af7e5b247d126aea68a1901b4497adf3d83
- d6a03a00b9824f27241b58b8e18208f31c03904a
- e51fad7a2436caefab0c6bd52f05e28e7cce4d92
- f0156f5f88ab5967c79162012c20f30600ca5ebf
- f786eb3f5dfddb0ac914ab09551bf1c5c64b47c0
- ql
- lib
- change-notes
- released
- ext
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- tainttracking1
- tainttracking2
- new
- exprs
- internal
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- gvn
- internal
- raw
- gvn
- internal
- unaliased_ssa
- gvn
- models
- implementations
- interfaces
- rangeanalysis/new/internal/semantic/analysis
- upgrades
- 4813509d85b45ae17421c036905199f7324cf228
- 6f5d51e89e762fe4609fd4ac8ee3afb04221e873
- c3881af7e5b247d126aea68a1901b4497adf3d83
- d6a03a00b9824f27241b58b8e18208f31c03904a
- e51fad7a2436caefab0c6bd52f05e28e7cce4d92
- f0156f5f88ab5967c79162012c20f30600ca5ebf
- utils/test
- dataflow
- internal
- src
- Best Practices
- Unused Entities
- Critical
- Likely Bugs
- Arithmetic
- Format
- Memory Management
- Underspecified Functions
- Metrics/Internal
- Security/CWE
- CWE-078
- CWE-120
- CWE-570
- Telemetry
- change-notes
- released
- experimental/Best Practices
- jsf/4.13 Functions
- test
- TestUtilities
- examples/expressions
- experimental
- library-tests/rangeanalysis/rangeanalysis
- query-tests/Security/CWE/CWE-193/constant-size
- library-tests
- arguments
- basic_blocks
- blocks
- capture
- cpp
- c
- deduplication
- builtins/type_traits
- c++_exceptions
- clang_builtin_macros
- complex_numbers
- constants/addresses
- constexpr_if
- controlflow
- guards-ir
- guards
- conversions
- cpp11_g
- dataflow
- asExpr
- dataflow-tests
- external-models
- fields
- models-as-data
- parameters-without-defs
- smart-pointers-taint
- source-sink-tests
- taint-tests
- declarationEntry
- declarationEntry
- more
- declaration
- destructors
- exprs/implicitly_declared
- extraction_errors
- fold
- functionpointerish
- ir
- ir
- modulus-analysis
- multiple-entry-points
- points_to
- range-analysis
- sign-analysis
- ssa
- types
- lambdas/cfg
- parameters/toStrings
- pointsto/basic
- proxy_class
- rvalueCast
- scopes/parents
- specifiers2
- structs/compatible_c
- sub_basic_blocks
- syntax-zoo
- type_sizes
- types/datasizeof
- udl
- unspecified_type/types
- vector_types
- virtual_functions/cfg
- vla
- query-tests
- Best Practices
- GuardedFree
- Unused Entities/UnusedStaticFunctions
- Critical
- MissingCheckScanf
- SizeCheck
- Likely Bugs
- Format
- WrongNumberOfFormatArguments
- WrongTypeFormatArguments
- Buildless
- Builtin
- Microsoft_no_wchar
- Memory Management/ReturnStackAllocatedMemory
- Underspecified Functions
- Metrics/Dependencies
- Security/CWE
- CWE-022/semmle/tests
- CWE-120/semmle/tests
- CWE-193
- successor-tests
- break_labels
- conditional_destructors
- exceptionhandler
- ellipsisexceptionhandler
- exceptionhandler
- pruning
- returnstmt
- stackvariables/stackvariables
- switchstmt/switchbody
- csharp
- .config
- .paket
- .vscode
- actions/create-extractor-pack
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- SourceGenerators/DotnetSourceGeneratorWrapper
- Semmle.Extraction.CSharp.DependencyStubGenerator
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp
- CodeAnalysisExtensions
- Comments
- Entities
- Base
- Compilations
- Expressions
- ObjectCreation
- Patterns
- Locations
- Statements
- Types
- Extractor
- Trap
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities
- Base
- Semmle.Util.Tests
- Semmle.Util
- Logging
- Testrunner
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- binlog_multiple
- a
- b
- binlog
- a
- b
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_failed
- standalone_resx
- standalone_winforms
- standalone
- linux
- compiler_args
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- standalone_dependencies_executing_runtime
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout/proj
- standalone_dependencies_nuget_config_error/proj
- standalone_dependencies_nuget_config_fallback/proj
- standalone_dependencies_nuget_no_sources/proj
- standalone_dependencies_nuget_versions
- d1
- d2
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows/standalone_dependencies
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- generated
- semmle/code/csharp
- commons
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- dispatch
- frameworks
- system
- collections
- security
- dataflow
- xml
- telemetry
- utils/test
- internal
- src
- Likely Bugs
- Security Features/CWE-209
- Telemetry
- change-notes
- released
- experimental/dataflow/flowsources
- meta/frameworks
- utils
- modeleditor
- modelgenerator/internal
- test
- TestUtilities
- experimental/Security Features/CWE-759
- library-tests
- arguments
- assemblies
- comments
- conversion
- operator
- reftype
- csharp9
- dataflow
- async
- barrier-guards
- collections
- constructors
- external-models
- fields
- flowsources/stored
- database/dapper
- file
- global
- library
- operators
- patterns
- threat-models
- tuples
- typeflow-dispatch
- types
- dispatch
- frameworks
- EntityFramework
- format
- generics
- methods
- parameters
- statements
- strings
- tuples
- query-tests
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- CWE-838
- Telemetry/DatabaseQuality
- Useless Code/UnusedLabel
- resources/stubs
- Amazon.Lambda.APIGatewayEvents/2.7.0
- Amazon.Lambda.Core/2.2.0
- Antlr3.Runtime/3.5.1
- Dapper/2.1.24
- EntityFramework/6.4.4
- Iesi.Collections/4.0.4
- Microsoft.CSharp/4.7.0
- Microsoft.Extensions.DependencyInjection.Abstractions/6.0.0
- Microsoft.Extensions.DependencyInjection/6.0.0
- Microsoft.Extensions.Http/6.0.0
- Microsoft.Extensions.Logging.Abstractions/6.0.0
- Microsoft.Extensions.Logging/6.0.0
- Microsoft.Extensions.Options/6.0.0
- Microsoft.Extensions.Primitives/6.0.0
- Microsoft.NETCore.Platforms
- 1.1.0
- 3.1.0
- Microsoft.NETCore.Targets/1.1.0
- Microsoft.Win32.Primitives/4.3.0
- Microsoft.Win32.Registry/4.7.0
- Microsoft.Win32.SystemEvents/6.0.0
- NETStandard.Library/1.6.1
- NHibernate/5.4.7
- Newtonsoft.Json/13.0.3
- Remotion.Linq.EagerFetching/2.2.0
- Remotion.Linq/2.2.0
- ServiceStack.Client/8.0.0
- ServiceStack.Common/8.0.0
- ServiceStack.Interfaces/8.0.0
- ServiceStack.OrmLite.SqlServer/8.0.0
- ServiceStack.OrmLite/8.0.0
- ServiceStack.Text/8.0.0
- ServiceStack/8.0.0
- Stub.System.Data.SQLite.Core.NetStandard/1.0.118
- System.AppContext/4.3.0
- System.Buffers/4.3.0
- System.CodeDom/4.7.0
- System.Collections.Concurrent/4.3.0
- System.Collections.NonGeneric/4.3.0
- System.Collections/4.3.0
- System.ComponentModel.Annotations/5.0.0
- System.ComponentModel.Primitives/4.3.0
- System.ComponentModel/4.3.0
- System.Configuration.ConfigurationManager
- 6.0.0
- 8.0.0
- System.Console/4.3.0
- System.Data.OleDb/8.0.0
- System.Data.SQLite.Core/1.0.118
- System.Data.SQLite.EF6/1.0.118
- System.Data.SQLite/1.0.118
- System.Data.SqlClient/4.8.5
- System.Diagnostics.Debug/4.3.0
- System.Diagnostics.DiagnosticSource/6.0.0
- System.Diagnostics.EventLog/8.0.0
- System.Diagnostics.PerformanceCounter/8.0.0
- System.Diagnostics.Tools/4.3.0
- System.Diagnostics.Tracing/4.3.0
- System.Drawing.Common/6.0.0
- System.Dynamic.Runtime/4.3.0
- System.Globalization.Calendars/4.3.0
- System.Globalization.Extensions/4.3.0
- System.Globalization/4.3.0
- System.IO.Compression.ZipFile/4.3.0
- System.IO.Compression/4.3.0
- System.IO.FileSystem.Primitives/4.3.0
- System.IO.FileSystem/4.3.0
- System.IO/4.3.0
- System.Linq.Expressions/4.3.0
- System.Linq.Queryable/4.0.1
- System.Linq/4.3.0
- System.Memory/4.5.5
- System.Net.Http/4.3.0
- System.Net.Primitives/4.3.0
- System.Net.Sockets/4.3.0
- System.ObjectModel/4.3.0
- System.Reflection.Emit.ILGeneration/4.3.0
- System.Reflection.Emit.Lightweight/4.7.0
- System.Reflection.Emit/4.7.0
- System.Reflection.Extensions/4.3.0
- System.Reflection.Primitives/4.3.0
- System.Reflection.TypeExtensions/4.7.0
- System.Reflection/4.3.0
- System.Resources.ResourceManager/4.3.0
- System.Runtime.CompilerServices.Unsafe/6.0.0
- System.Runtime.Extensions/4.3.0
- System.Runtime.Handles/4.3.0
- System.Runtime.InteropServices.RuntimeInformation/4.3.0
- System.Runtime.InteropServices/4.3.0
- System.Runtime.Numerics/4.3.0
- System.Runtime.Serialization.Formatters/4.3.0
- System.Runtime.Serialization.Primitives/4.3.0
- System.Runtime/4.3.0
- System.Security.AccessControl
- 4.7.0
- 6.0.0
- System.Security.Cryptography.Algorithms/4.3.0
- System.Security.Cryptography.Cng/4.3.0
- System.Security.Cryptography.Csp/4.3.0
- System.Security.Cryptography.Encoding/4.3.0
- System.Security.Cryptography.OpenSsl/4.3.0
- System.Security.Cryptography.Primitives/4.3.0
- System.Security.Cryptography.ProtectedData
- 6.0.0
- 8.0.0
- System.Security.Cryptography.X509Certificates/4.3.0
- System.Security.Permissions/6.0.0
- System.Security.Principal.Windows/4.7.0
- System.Text.Encoding.Extensions/4.3.0
- System.Text.Encoding/4.3.0
- System.Text.RegularExpressions/4.3.0
- System.Threading.Tasks.Extensions/4.3.0
- System.Threading.Tasks/4.3.0
- System.Threading.Timer/4.3.0
- System.Threading/4.3.0
- System.Windows.Extensions/6.0.0
- System.Xml.ReaderWriter/4.3.0
- System.Xml.XDocument/4.3.0
- System.Xml.XmlDocument/4.3.0
- _frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- runtime.debian.8-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.fedora.23-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.fedora.24-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.native.System.Data.SqlClient.sni/4.7.0
- runtime.native.System.IO.Compression/4.3.0
- runtime.native.System.Net.Http/4.3.0
- runtime.native.System.Security.Cryptography.Apple/4.3.0
- runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.native.System/4.3.0
- runtime.opensuse.13.2-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.Apple/4.3.0
- runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.14.04-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.16.04-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.16.10-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.win-arm64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x86.runtime.native.System.Data.SqlClient.sni/4.4.0
- utils
- inline-tests
- queries
- modeleditor
- modelgenerator
- dataflow
- typebasedflow
- scripts
- stubs
- docs/codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- ql-language-reference
- reusables
- go
- actions/test
- documentation/library-coverage
- extractor
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes
- released
- ext
- semmle/go
- controlflow
- dataflow
- internal
- tainttracking1
- tainttracking2
- frameworks
- stdlib
- security
- utils/test
- internal
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-640
- CWE-681
- change-notes/released
- experimental
- CWE-090
- CWE-1004
- CWE-327
- CWE-74
- CWE-807
- CWE-918
- test
- TestUtilities
- experimental
- CWE-090
- CWE-203
- CWE-287
- CWE-369
- CWE-522-DecompressionBombs
- CWE-74
- CWE-79
- CWE-918
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- Function
- PrintAst
- Types
- pkg1
- pkg2
- aliases
- DataflowFields
- InterfaceImpls
- concepts
- HTTP
- LoggerCall
- dataflow
- ArrayConversion
- ChannelField
- DefaultTaintSanitizer
- ExternalFlowInheritance
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
6,915 files changed
+326507
-137339
lines changedLines changed: 8 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
3 | 2 |
| |
4 | 3 |
| |
5 | 4 |
| |
| |||
24 | 23 |
| |
25 | 24 |
| |
26 | 25 |
| |
27 |
| - | |
28 |
| - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
29 | 34 |
| |
30 | 35 |
|
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
11 |
| - |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
| 2 | + | |
2 | 3 |
| |
3 | 4 |
| |
4 | 5 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
86 | 86 |
| |
87 | 87 |
| |
88 | 88 |
| |
89 |
| - | |
| 89 | + | |
| 90 | + |
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
| 12 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
38 | 38 |
| |
39 | 39 |
| |
40 | 40 |
| |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
41 | 45 |
| |
42 | 46 |
| |
43 | 47 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
20 |
| - | |
| 20 | + | |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
33 |
| - | |
| 33 | + | |
| 34 | + | |
34 | 35 |
| |
35 | 36 |
| |
36 | 37 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
33 |
| - | |
| 33 | + | |
34 | 34 |
| |
35 | 35 |
| |
36 | 36 |
| |
|
0 commit comments