File tree
1,190 files changed
+82241
-62536
lines changed- .devcontainer
- .github/workflows
- config
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- rangeanalysis
- extensions
- semmle/code/cpp
- commons
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn
- internal
- internal
- raw
- gvn
- internal
- reachability
- unaliased_ssa
- gvn
- internal
- reachability
- internal
- models
- implementations
- interfaces
- rangeanalysis/new
- internal/semantic
- analysis
- security
- valuenumbering
- src
- Critical
- JPL_C/LOC-4/Rule 23
- Likely Bugs
- Likely Typos
- Memory Management
- Metrics/Dependencies
- Security/CWE
- CWE-020
- ir
- CWE-079
- CWE-295
- CWE-327
- change-notes
- released
- experimental
- Likely Bugs
- Security/CWE
- CWE-078
- CWE-1041
- CWE-675
- external
- test
- experimental/query-tests/Security/CWE/CWE-119
- library-tests
- blocks/cpp
- dataflow
- dataflow-tests
- fields
- identity_string
- ir
- ir
- ssa
- locations/constants
- loops
- syntax-zoo
- query-tests/Likely Bugs/Format/NonConstantFormat
- csharp
- extractor/Semmle.Extraction.CSharp/Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests/posix-only/warn_as_error
- lib
- Linq
- change-notes
- released
- ext/generated
- semmle/code
- cil
- csharp
- commons
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- security
- cryptography
- dataflow
- src
- Bad Practices/Comments
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- Statements
- Security Features
- CWE-352
- CWE-502
- change-notes/released
- experimental
- Security Features
- CWE-759
- backdoor
- dataflow/flowsources
- ir
- implementation
- internal
- raw
- gvn
- internal
- common
- desugar
- internal
- unaliased_ssa
- gvn
- internal
- internal
- rangeanalysis
- utils
- modelconverter
- modelgenerator/internal
- test
- experimental
- Security Features/backdoor
- ir/offbyone/CONSISTENCY
- library-tests
- assemblies
- cil
- attributes/CONSISTENCY
- consistency/CONSISTENCY
- dataflow
- CONSISTENCY
- enums/CONSISTENCY
- functionPointers/CONSISTENCY
- init-only-prop/CONSISTENCY
- pdbs/CONSISTENCY
- regressions/CONSISTENCY
- typeAnnotations/CONSISTENCY
- commons/Disposal/CONSISTENCY
- controlflow
- graph/CONSISTENCY
- guards/CONSISTENCY
- splits/CONSISTENCY
- csharp11/cil/CONSISTENCY
- dataflow
- content
- defuse/CONSISTENCY
- global/CONSISTENCY
- ssa/CONSISTENCY
- query-tests
- API Abuse/NoDisposeCallOnLocalIDisposable/CONSISTENCY
- Nullness/CONSISTENCY
- Security Features
- CWE-022/ZipSlip/CONSISTENCY
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- utils/modelgenerator/dataflow
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- reusables
- go
- extractor
- cli
- go-autobuilder
- go-bootstrap
- go-tokenizer
- diagnostics
- srcarchive
- trap
- ql
- lib
- change-notes/released
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- RedundantCode
- Security
- CWE-020
- CWE-327
- change-notes/released
- experimental
- CWE-79
- Unsafe
- test
- experimental/CWE-79
- library-tests/semmle/go/frameworks
- StdlibTaintFlow
- Yaml
- query-tests/Security/CWE-079
- javascript
- extractor
- src/com/semmle/js/parser
- tests/json/output/trap
- ql
- examples/queries/dataflow/DecodingAfterSanitization
- lib
- Declarations
- Expressions
- change-notes/released
- semmle/javascript
- dataflow
- internal
- explore
- frameworks
- AngularJS
- heuristics
- linters
- security
- dataflow
- regexp
- upgrades/c8859f3725d4b070a877f8792214582d517c8a9b
- src
- Comments
- DOM
- Declarations
- Expressions
- LanguageFeatures
- RegExp
- Security
- CWE-020
- CWE-915
- Statements
- change-notes
- released
- experimental/poi
- external
- meta
- analysis-quality
- test
- ApiGraphs/call-nodes
- library-tests
- Barriers
- DOM
- Extend
- HtmlSanitizers
- JSON
- JsonParsers
- LabelledBarrierGuards
- ModuleImportNodes
- TaintTracking
- TypeScript/LocalTypeResolution
- TypeTracking
- frameworks
- Angular2
- Testing/customised
- query-tests/Security
- CWE-078
- CommandInjection
- IndirectCommandInjection
- CWE-079
- DomBasedXss
- ReflectedXss
- CWE-094/CodeInjection
- CWE-502
- testUtilities
- tutorials
- Introducing the JavaScript libraries
- Validating RAML-based APIs
- java
- documentation/library-coverage
- ql
- lib
- change-notes
- released
- ext
- experimental
- generated
- semmle/code
- configfiles
- java
- controlflow/unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- frameworks
- frameworks
- apache
- camel
- gigaspaces
- javaee
- jsf
- spring
- security
- internal
- src
- Frameworks/Spring/Architecture/Refactoring Opportunities
- Language Abuse
- Likely Bugs
- Comparison
- Statements
- Security/CWE
- CWE-078
- CWE-079
- CWE-089
- CWE-113
- CWE-129
- CWE-134
- CWE-190
- CWE-200
- CWE-209
- CWE-297
- CWE-327
- CWE-601
- CWE-614
- CWE-643
- CWE-681
- CWE-807
- change-notes/released
- experimental/Security/CWE
- CWE-036
- CWE-094
- CWE-299
- CWE-327
- CWE-346
- CWE-502
- utils
- modelconverter
- modelgenerator/internal
- test
- library-tests
- annotations
- dataflow/taintsources
- query-tests/security/CWE-643
- stubs/jwtk-jjwt-0.11.2/io/jsonwebtoken
- utils/modelgenerator/dataflow
- misc
- bazel
- codegen
- lib
- templates
- test
- suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- concepts
- dataflow/new/internal
- frameworks
- security/dataflow
- src
- Security/CWE-020-ExternalAPIs
- Variables
- change-notes/released
- experimental
- Security/CWE-074/paramiko
- semmle/python
- external
- test
- experimental
- dataflow
- TestUtil
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage
- exceptions
- fieldflow
- global-flow
- match
- module-initialization
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests/CallGraph
- meta
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-074/paramiko
- CWE-079
- CWE-113
- CWE-1236
- CWE-208/TimingAttackAgainstSensitiveInfo
- CWE-327-UnsafeUsageOfClientSideEncryptionVersion
- CWE-522
- CWE-614
- CWE-943
- library-tests
- ApiGraphs
- py2
- py3
- frameworks/django-orm
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-079-ReflectedXss
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-285-PamAuthorization
- CWE-327-WeakSensitiveDataHashing
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-918-ServerSideRequestForgery
- ql/extractor/src
- ruby/ql
- lib
- change-notes
- released
- codeql/ruby
- dataflow/internal
- filters
- frameworks
- data/internal
- security
- src
- change-notes/released
- experimental/template-injection/examples
- queries/meta/internal
- test
- library-tests/frameworks/sqlite3
- query-tests/experimental/TemplateInjection
- swift
- downgrades/ba4171b90d0665b40e9e203bac9e3d4a0b2d03ec
- extractor
- infra
- file
- invocation
- remapping
- translators
- trap
- integration-tests
- linux-only/RegexLiteralExpr
- posix-only
- cross-references
- deduplication
- hello-world
- linkage-awareness
- logging
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- type
- frameworks
- StandardLibrary
- Xml
- generated
- decl
- expr
- printast
- security
- upgrades/f937d9e63094280b7ec0ef26c70310daad5c1f79
- src/queries/Security
- CWE-135
- CWE-943
- test
- extractor-tests
- expressions
- generated
- decl
- Accessor
- CapturedDecl
- ConcreteVarDecl
- Deinitializer
- Initializer
- NamedFunction
- ParamDecl
- expr
- ExplicitClosureExpr
- InitializerRefCallExpr
- LazyInitializationExpr
- OtherInitializerRefExpr
- RebindSelfInInitializerExpr
- type/DynamicSelfType
- types
- library-tests
- ast
- dataflow/dataflow
- elements
- decl
- abstractfunctiondecl
- function
- expr/methodlookup
- query-tests/Security
- CWE-022
- CWE-321
- CWE-757
- third_party
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,190 files changed
+82241
-62536
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
3 |
| - | |
| 3 | + | |
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
|
Lines changed: 46 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + |
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
43 |
| - | |
44 | 43 |
| |
45 | 44 |
| |
46 | 45 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 |
| |
2 | 6 |
| |
3 | 7 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
0 commit comments