File tree
1,861 files changed
+34926
-255116
lines changed- .github
- workflows
- config
- cpp
- downgrades
- ql
- lib
- change-notes/released
- semmle/code/cpp
- controlflow
- dataflow
- internal
- exprs
- ir
- dataflow
- internal
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- internal
- models
- implementations
- interfaces
- security
- flowafterfree
- valuenumbering
- src
- Critical
- Security/CWE
- CWE-022
- CWE-497
- change-notes/released
- experimental/Security/CWE
- CWE-125
- CWE-416
- test
- experimental
- library-tests/rangeanalysis
- arraylengthanalysis
- signanalysis
- query-tests/Security/CWE
- CWE-078
- CWE-190/AllocMultiplicationOverflow
- CWE-193
- array-access
- constant-size
- CWE-359/semmle/tests
- CWE-416
- library-tests
- controlflow
- guards-ir
- guards
- dataflow
- dataflow-tests
- fields
- models-as-data
- parameters-without-defs
- source-sink-tests
- taint-tests
- fields/fields
- ir
- ir
- points_to
- ssa
- types
- __wchar_t
- wchar_t_typedef
- valuenumbering/GlobalValueNumbering
- variables/variables
- query-tests
- Critical
- GlobalUseBeforeInit
- MemoryFreed
- Likely Bugs/Format/NonConstantFormat
- Security/CWE
- CWE-022/semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-119
- SAMATE
- semmle/tests
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- consts
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- TaintedAllocationSize
- tainted
- CWE-193
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-497/semmle/tests
- CWE-611
- CWE-807/semmle/TaintedCondition
- CWE-843
- csharp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- SourceGenerators
- DotnetSourceGeneratorWrapper
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp/Extractor
- Semmle.Extraction.Tests
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms/standalone_resx
- posix-only
- standalone_dependencies_multi_project
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_versions
- d1
- d2
- lib
- change-notes/released
- ext
- generated
- semmle/code/csharp
- dataflow/internal
- exprs
- security/dataflow
- flowsinks
- flowsources
- src
- Likely Bugs
- Security Features
- CWE-016
- CWE-352
- Telemetry
- change-notes/released
- utils
- modeleditor
- modelgenerator/internal
- test
- experimental/Security Features/CWE-759
- library-tests
- dataflow
- async
- collections
- global
- library
- threat-models
- types
- frameworks/EntityFramework
- query-tests
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- CWE-838
- Telemetry/SupportedExternalApis
- utils
- modeleditor
- modelgenerator
- dataflow
- typebasedflow
- docs/codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- go
- docs/language/learn-ql/go
- extractor/project
- ql
- consistency-queries
- change-notes/released
- integration-tests/all-platforms/go
- bazel-sample-1/src
- bazel-sample-2/src
- go-mod-sample/src
- go-mod-without-version/src
- make-sample/src
- mixed-layout/src
- module
- workspace/subdir
- ninja-sample/src
- single-go-mod-and-go-files-not-under-it/src/subdir
- single-go-mod-in-root/src
- single-go-mod-not-in-root/src/subdir
- single-go-work-not-in-root/src/modules
- subdir1
- subdir2
- two-go-mods-nested-none-in-root/src/subdir0
- subdir1
- two-go-mods-nested-one-in-root/src
- two-go-mods-not-nested/src/subdir1
- two-go-mods-one-failure/src/subdir1
- lib
- change-notes/released
- semmle/go
- dataflow/internal
- frameworks
- stdlib
- security
- src
- Security
- CWE-020
- CWE-640
- change-notes/released
- experimental
- CWE-090
- CWE-203
- CWE-287
- CWE-369
- CWE-74
- CWE-79
- CWE-807
- CWE-840
- CWE-918
- CWE-942
- frameworks
- test
- experimental/frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- concepts/HTTP
- dataflow/DefaultTaintSanitizer
- frameworks
- AwsLambda
- ElazarlGoproxy
- Encoding
- Fasthttp
- Gin
- GoKit
- Macaron
- Mux
- Revel
- query-tests/Security
- CWE-020/IncompleteHostnameRegexp
- CWE-681
- javascript
- extractor
- src/com/semmle
- jcorn
- js/extractor
- tests
- flow/output/trap
- node
- input
- output/trap
- strictmode/output/trap
- test/com/semmle/js/extractor/test
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- counting
- evaluation
- extraction
- model
- src
- codeql-suites
- test
- endpoint_large_scale
- autogenerated
- NosqlAndSqlInjection
- typed
- untyped
- ShellCommandInjectionFromEnvironment
- CommandInjection
- IndirectCommandInjection
- SecondOrderCommandInjection
- ShellCommandInjectionFromEnvironment
- UnsafeShellCommandConstruction/lib
- subLib2
- subLib3
- subLib4
- subLib
- UselessUseOfCat
- TaintedPath
- XssThroughDom
- BadTagFilter
- DoubleEscaping
- IncompleteSanitization
- Xss
- DomBasedXss
- ExceptionXss
- ReflectedXss
- pages/api
- StoredXss
- UnsafeHtmlConstruction
- lib2
- src
- lib/src
- UnsafeJQueryPlugin
- XssThroughDom
- endpoint_unit_tests
- applications/examples/static/epydoc
- function_body_feature
- generic_feature_testing
- modeled_apis
- query_mappings
- lib
- change-notes/released
- semmle/javascript
- dataflow
- endpoints
- frameworks
- data
- internal
- security
- internal
- regexp
- src
- Security/CWE-020
- change-notes/released
- test
- ApiGraphs
- custom-use-steps
- reexport
- lib
- library-tests
- ModelGeneration
- aliases
- long-access-path
- reexport
- return-this
- root-function
- semi-internal-class
- subclass
- Modules
- frameworks/data
- java/ql
- automodel/src
- change-notes/released
- lib
- change-notes/released
- config
- semmle/code/java
- dataflow/internal
- os
- regex
- src
- change-notes/released
- test/library-tests/frameworks/guava/handwritten
- misc
- bazel
- registry
- codegen
- generators
- scripts
- suite-helpers
- change-notes/released
- python
- downgrades
- extractor/tsg-python/tsp
- ql
- examples/snippets
- lib
- analysis
- change-notes/released
- experimental/cryptography/modules/stdlib
- semmle/python
- dataflow
- new
- internal
- old
- frameworks
- data/internal
- objects
- pointsto
- regexp
- internal
- security
- dataflow
- internal
- types
- src
- Expressions
- Formatting
- Imports
- Security
- CVE-2018-1281
- CWE-020
- CWE-798
- Statements
- Variables
- change-notes/released
- experimental
- Security
- CWE-287-ConstantSecretKey
- CWE-287
- CWE-327/Azure
- CWE-348
- CWE-770
- semmle/python
- frameworks
- libraries
- security
- test
- 2
- extractor-tests
- ellipsis
- exec
- import_depth
- package
- multibyte
- normalise
- object_hash
- old_style_disequality
- syntax_error
- library-tests
- PointsTo/imports
- locations2.7plus
- locations
- general
- strings
- query-tests
- Statements
- Variables/undefined
- 3
- extractor-tests
- Kannada
- annotations
- async3.5
- async3.6
- decorators
- fstrings3.6
- fstrings3.8
- import_depth
- package
- matmult
- multibyte
- numbers
- positional_only
- tuple_unpacking
- unpacking
- walrus_operator
- library-tests
- PointsTo/attributes
- calls
- functions
- locations/general
- parameters
- query-tests
- Statements/iter
- Variables/undefined
- TestUtilities/dataflow
- experimental
- attrs
- dataflow
- basic
- coverage
- exceptions
- fieldflow
- match
- model-summaries
- summaries
- tainttracking/generator-flow
- import-resolution
- meta/debug
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-287-ConstantSecretKey
- CWE-409
- extractor-tests
- ast
- async
- basicblocks
- comment-on-decorator-line
- conflicts
- package
- mod
- deep_graph
- double-import
- pack
- inner
- exceptions
- exclude-subpath
- src
- pack
- test
- exo_path
- path1/package1
- path2/package2
- exports
- filter-option
- foo
- flags
- identical_contents
- folder1
- folder2
- ignore
- package
- imports
- just_folder
- test
- latin
- line_endings
- long_path
- long_string
- main
- match
- paths
- not_package
- package
- pruning
- script
- splitter-regression
- splitter
- string_concatenation
- syntax_error
- thrift
- unicode_decoding
- library-tests
- ApiGraphs/py3
- ControlFlow
- splitting
- successors
- truefalse
- PointsTo
- calls
- global
- local
- new
- dataflow
- basic
- callgraph_crosstalk
- calls
- consistency
- coverage-py2
- coverage-py3
- coverage
- def-use-flow
- enclosing-callable
- exceptions
- fieldflow
- global-flow
- import-star
- match
- method-calls
- model-summaries
- module-initialization
- path-graph
- pep_328
- package
- subpackage1
- subpackage2
- qll-private-imports
- regression
- sensitive-data
- strange-essaflow
- summaries-checks
- summaries
- extracted_package
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking-summaries
- typetracking_imports
- pkg
- typetracking
- use-use-flow
- variable-capture
- exprs/strings
- frameworks
- data
- django-orm
- CONSISTENCY
- stdlib-py3
- stdlib
- locations/implicit_concatenation
- parentheses
- taint/general
- query-tests
- Expressions
- Formatting
- Regex
- general
- strings
- Security
- CWE-020-IncompleteHostnameRegExp
- CWE-020-IncompleteUrlSubstringSanitization
- CWE-022-PathInjection
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-730-PolynomialReDoS
- CWE-798-HardcodedCredentials
- CWE-943-NoSqlInjection
- Variables/undefined
- ruby
- downgrades
- ql
- lib
- change-notes/released
- codeql/ruby
- dataflow/internal
- frameworks
- actiondispatch/internal
- core
- data/internal
- stdlib
- security
- internal
- src
- change-notes/released
- queries/security
- cwe-020
- cwe-078/examples
- test
- library-tests
- dataflow/summaries
- frameworks/json
- query-tests/security
- cwe-020/IncompleteHostnameRegExp
- cwe-022
- cwe-078/CommandInjection
- cwe-094/CodeInjection
- swift
- downgrades
- extractor
- logging
- ql
- lib
- change-notes/released
- codeql/swift
- dataflow
- internal
- security/internal
- src
- change-notes/released
- test/TestUtilities
- third_party
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,861 files changed
+34926
-255116
lines changedLines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
| 17 | + | |
| 18 | + | |
| 19 | + | |
17 | 20 |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + |
Lines changed: 0 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
67 | 67 |
| |
68 | 68 |
| |
69 | 69 |
| |
70 |
| - | |
71 |
| - | |
72 |
| - | |
73 |
| - | |
74 |
| - | |
75 | 70 |
| |
76 | 71 |
| |
77 | 72 |
| |
|
Lines changed: 1 addition & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
18 |
| - | |
| 18 | + | |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
| |||
46 | 46 |
| |
47 | 47 |
| |
48 | 48 |
| |
49 |
| - | |
50 |
| - | |
51 |
| - |
Lines changed: 28 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + |
Lines changed: 6 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
24 |
| - | |
| 23 | + | |
25 | 24 |
| |
26 | 25 |
| |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
27 | 31 |
| |
28 |
| - | |
29 |
| - | |
30 | 32 |
| |
31 | 33 |
| |
32 | 34 |
| |
|
Lines changed: 9 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + |
Lines changed: 0 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 | 15 |
| |
19 | 16 |
| |
20 | 17 |
| |
| |||
37 | 34 |
| |
38 | 35 |
| |
39 | 36 |
| |
40 |
| - | |
41 | 37 |
| |
42 |
| - | |
43 | 38 |
| |
44 | 39 |
| |
45 | 40 |
| |
|
Lines changed: 3 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
14 | 14 |
| |
15 | 15 |
| |
16 | 16 |
| |
17 |
| - | |
| 17 | + | |
18 | 18 |
| |
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
| 25 | + | |
| 26 | + | |
25 | 27 |
| |
26 | 28 |
| |
27 | 29 |
| |
|
Lines changed: 0 additions & 10 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 | 14 |
| |
25 | 15 |
| |
26 | 16 |
| |
|
0 commit comments