File tree
1,148 files changed
+119515
-11380
lines changed- cpp/ql
- lib
- change-notes/released
- semmle/code/cpp
- dataflow
- internal
- ir/dataflow/internal
- src
- Security/CWE/CWE-190
- change-notes/released
- test/query-tests/Security/CWE/CWE-190/semmle/TaintedAllocationSize
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- downgrades/15b989afd2bfc4743536fdb0958c1d8177a32600
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- SourceGenerators
- DotnetSourceGeneratorWrapper
- Semmle.Extraction.CSharp
- Entities
- Compilations
- PreprocessorDirectives
- Extractor
- Semmle.Extraction.Tests
- Semmle.Extraction
- Entities
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- autobuild
- binlog
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- msbuild
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_failed
- standalone_resx
- standalone_winforms
- standalone
- linux-only
- compiler_args
- standalone_dependencies_non_utf8_filename
- posix-only
- diag_autobuild_script
- diag_multiple_scripts
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- standalone_dependencies_executing_runtime
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- standalone_dependencies_nuget_no_sources
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows-only
- diag_autobuild_script
- diag_multiple_scripts
- standalone_dependencies
- lib
- change-notes/released
- ext
- generated
- semmle/code/csharp
- dataflow/internal
- exprs
- security/dataflow/flowsources
- upgrades/fd04e45710e1988076801608abffdfa013b680fc
- src
- Documentation
- Telemetry
- change-notes/released
- utils/modelgenerator/internal
- test
- TestUtilities
- experimental/Security Features/CWE-759
- library-tests
- dataflow
- async
- collections
- constructors
- external-models
- fields
- global
- library
- operators
- patterns
- threat-models
- tuples
- typeflow-dispatch
- types
- frameworks/EntityFramework
- query-tests
- Documentation
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- CWE-838
- utils/modelgenerator/dataflow
- docs/codeql
- codeql-language-guides
- reusables
- go
- documentation/library-coverage
- extractor
- integration-tests-lib
- ql
- consistency-queries
- change-notes/released
- integration-tests
- all-platforms/go
- bazel-sample-1
- bazel-sample-2
- diagnostics
- build-constraints-exclude-all-go-files
- go-files-found-not-processed
- invalid-toolchain-version
- newer-go-version-needed
- no-go-files-found
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- unsupported-relative-path
- extract-vendor
- go-get-without-modules-sample
- go-mod-sample
- go-mod-without-version
- go-version-bump
- make-sample
- mixed-layout
- ninja-sample
- resolve-build-environment/newer-go-needed
- single-go-mod-and-go-files-not-under-it
- single-go-mod-in-root
- single-go-mod-not-in-root
- single-go-work-not-in-root
- two-go-mods-nested-none-in-root
- two-go-mods-nested-one-in-root
- two-go-mods-not-nested
- two-go-mods-one-failure
- linux-only/go
- dep-sample
- glide-sample
- lib
- change-notes/released
- ext
- semmle/go
- concepts
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- Security/CWE-322
- change-notes/released
- experimental
- CWE-918
- frameworks
- test
- TestUtilities
- experimental/CWE-321-V2
- vendor
- library-tests/semmle/go
- concepts/Regexp
- dataflow
- DefaultTaintSanitizer
- ExternalValueFlow
- flowsources/local
- environment
- vendor
- github.com
- caarlos0/env
- gobuffalo/envy
- hashicorp/go-envparse
- joho/godotenv
- kelseyhightower/envconfig
- file
- frameworks
- Afero
- vendor
- BeegoOrm
- Beego
- Echo
- Encoding
- Gin
- Gorestful
- Revel
- SQL
- query-tests
- InconsistentCode/UnhandledCloseWritableHandle
- Security
- CWE-020/IncompleteHostnameRegexp
- CWE-022
- CWE-078
- CWE-190
- CWE-347
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-643
- javascript
- extractor
- src/com/semmle/jcorn
- tests/flow
- input
- output/trap
- ql
- lib
- change-notes/released
- semmle/javascript
- frameworks
- data/internal
- security/dataflow
- src
- change-notes/released
- test
- library-tests/Modules
- query-tests/Security
- CWE-022/TaintedPath
- CWE-079/DomBasedXss
- CWE-730
- CWE-798
- __tests__
- java
- documentation/library-coverage
- kotlin-extractor/dev
- ql
- automodel/src
- change-notes/released
- integration-tests
- all-platforms
- java
- buildless-gradle-classifiers
- gradle/wrapper
- src/main/java/com/fractestexample
- buildless-maven-executable-war
- src
- main
- java/com/example
- resources
- test/java/com/example
- kotlin
- annotation-id-consistency
- compiler_arguments
- gradle/wrapper
- default-parameter-mad-flow
- diagnostics/kotlin-version-too-new
- enabling
- enhanced-nullability
- external-property-overloads
- extractor_crash
- code
- extractor_information_kotlin1
- extractor_information_kotlin2
- file_classes
- gradle_groovy_app
- gradle/wrapper
- gradle_kotlinx_serialization
- gradle/wrapper
- java-interface-redeclares-tostring
- java_modifiers
- jvmoverloads-external-class
- kotlin-interface-inherited-default
- kotlin_compiler_java_source
- kotlin_file_import
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- kotlin_kfunction
- gradle/wrapper
- kotlinc_multi
- logs
- nested_generic_types
- nullability-annotations
- path_transformer
- private_property_accessors
- raw_generic_types
- repeatable-annotations
- trap_compression
- linux-only/kotlin
- custom_plugin
- use_java_library
- posix-only/kotlin
- generic-extension-property
- java_kotlin_extraction_orders
- kotlin_double_interception
- code
- module_mangled_names
- needless-java-wildcards
- lib
- change-notes/released
- ext/experimental
- semmle/code/java
- dataflow
- internal
- security/internal
- src
- Telemetry
- change-notes/released
- experimental/Security/CWE
- CWE-078
- CWE-347
- test-kotlin1
- TestUtilities
- library-tests/dataflow/summaries
- test-kotlin2
- TestUtilities
- library-tests/dataflow/summaries
- test
- TestUtilities
- experimental
- query-tests/security
- CWE-347
- CWE-625
- stubs
- auth0-java-jwt-4.4.0/com
- auth0/jwt
- algorithms
- exceptions
- interfaces
- github/luben/zstd
- org-apache-shiro-authc-2.0.1/org/apache/shiro/authc
- ext/TestModels
- library-tests
- dataflow
- callctx
- capture
- collections
- flowfeature
- fluent-methods
- stream-collect
- stream-read
- subpaths
- synth-global
- taint-format
- taint-gson
- taint-jackson
- threat-models
- typeflow-dispatch
- frameworks
- android
- asynctask
- content-provider-summaries
- flow-steps
- intent
- notification
- uri
- widget
- apache-ant
- apache-collections
- apache-commons-compress
- apache-commons-lang3
- gson
- guava/generated
- cache
- collect
- hudson
- jackson
- javax-json
- jdk
- java.io
- java.net
- java.nio.file
- json-java
- netty/generated
- play
- spring
- beans
- cache
- componentscan
- WEB-INF
- com/semmle
- d
- e
- f
- g
- h
- context
- data
- http
- ui
- util
- validation
- webmultipart
- webutil
- stapler
- stream
- thymeleaf
- logging
- optional
- paths
- regex
- scanner
- query-tests/DeadCode/camel
- com/semmle/camel
- javadsl
- stubs
- apache-camel-4.0.6
- org/apache/camel
- builder
- impl
- model
- springframework-5.3.8/org/springframework
- beans
- factory
- config
- support
- context/annotation
- core
- type
- utils/modelgenerator/dataflow
- p
- misc
- bazel/internal
- zipmerge
- suite-helpers
- change-notes/released
- python
- extractor
- ql
- lib
- change-notes/released
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- src
- Security
- CWE-020
- CWE-614
- examples
- change-notes/released
- experimental
- Security/CWE-614
- semmle/python
- frameworks
- test
- experimental
- meta
- query-tests/Security/CWE-614
- library-tests/frameworks
- aiohttp
- django-v2-v3
- fastapi
- flask
- pyramid
- rest_framework
- testapp
- tornado
- twisted
- query-tests/Security/CWE-614-InsecureCookie
- ruby/ql
- integration-tests
- all-platforms
- diagnostics
- syntax-error
- unknown-encoding
- lib
- change-notes/released
- codeql/ruby
- dataflow/internal
- frameworks/data/internal
- src
- change-notes/released
- queries/security/cwe-078
- test
- TestUtilities
- library-tests
- dataflow
- array-flow
- barrier-guards
- call-sensitivity
- erb
- flow-summaries
- global
- hash-flow
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- sinatra
- swift/ql
- integration-tests
- autobuilder/unsupported-os
- linux-only
- RegexLiteralExpr
- autobuilder/unsupported-os
- osx-only
- autobuilder
- failure
- no-build-system
- no-swift-with-spm
- no-swift
- no-xcode-with-spm
- only-tests-with-spm
- only-tests
- xcode-fails-spm-works
- canonical-case
- hello-xcode
- posix-only
- cross-references
- deduplication
- frontend-invocations
- hello-world
- linkage-awareness
- partial-modules
- symlinks
- lib
- change-notes/released
- codeql/swift
- dataflow
- internal
- security
- src
- change-notes/released
- test/query-tests/Security
- CWE-311
- CWE-321
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,148 files changed
+119515
-11380
lines changedLines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
| 27 | + | |
27 | 28 |
| |
28 | 29 |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
| 11 | + |
Lines changed: 17 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + | |
3 | 3 |
| |
| 4 | + | |
4 | 5 |
| |
5 | 6 |
| |
6 | 7 |
| |
| |||
30 | 31 |
| |
31 | 32 |
| |
32 | 33 |
| |
33 |
| - | |
| 34 | + | |
| 35 | + | |
34 | 36 |
| |
35 | 37 |
| |
| 38 | + | |
36 | 39 |
| |
37 |
| - | |
| 40 | + | |
38 | 41 |
| |
39 | 42 |
| |
40 | 43 |
| |
41 | 44 |
| |
42 | 45 |
| |
43 | 46 |
| |
44 | 47 |
| |
45 |
| - | |
46 |
| - | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
47 | 58 |
| |
48 | 59 |
| |
49 | 60 |
| |
50 | 61 |
| |
51 | 62 |
| |
52 | 63 |
| |
53 |
| - | |
| 64 | + | |
54 | 65 |
| |
55 | 66 |
| |
56 | 67 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 |
| |
2 | 6 |
| |
3 | 7 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + | |
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
|
Lines changed: 0 additions & 18 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
953 | 953 |
| |
954 | 954 |
| |
955 | 955 |
| |
956 |
| - | |
957 |
| - | |
958 |
| - | |
959 |
| - | |
960 |
| - | |
961 |
| - | |
962 |
| - | |
963 |
| - | |
964 |
| - | |
965 |
| - | |
966 |
| - | |
967 |
| - | |
968 |
| - | |
969 |
| - | |
970 |
| - | |
971 |
| - | |
972 |
| - | |
973 |
| - |
Lines changed: 0 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
290 | 290 |
| |
291 | 291 |
| |
292 | 292 |
| |
293 |
| - | |
294 |
| - | |
295 |
| - | |
296 |
| - | |
297 |
| - | |
298 |
| - | |
299 |
| - | |
300 |
| - | |
301 | 293 |
| |
302 | 294 |
| |
303 | 295 |
| |
|
Lines changed: 0 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
290 | 290 |
| |
291 | 291 |
| |
292 | 292 |
| |
293 |
| - | |
294 |
| - | |
295 |
| - | |
296 |
| - | |
297 |
| - | |
298 |
| - | |
299 |
| - | |
300 |
| - | |
301 | 293 |
| |
302 | 294 |
| |
303 | 295 |
| |
|
0 commit comments