File tree
6,198 files changed
+282486
-114343
lines changed- .devcontainer
- .github
- codeql
- workflows
- .vscode
- actions/ql
- lib
- change-notes/released
- codeql
- actions
- Violations Of Best Practices
- ast/internal
- config
- controlflow
- internal
- dataflow
- internal
- ideContextual
- security
- files
- ext
- config
- generated
- composite-actions
- reusable-workflows
- manual
- ide-contextual-queries
- src
- Debug
- Models
- Security
- CWE-074
- CWE-077
- CWE-078
- CWE-088
- CWE-094
- CWE-1395
- CWE-200
- CWE-275
- CWE-284
- CWE-285
- CWE-312
- CWE-349
- CWE-367
- CWE-571
- CWE-829
- CWE-918
- Violations Of Best Practice/CodeQL
- change-notes/released
- codeql-suites
- test
- library-tests
- .github/workflows
- query-tests
- Models
- .github/workflows
- action1
- Placeholder
- .github/workflows
- Security
- CWE-074
- .github/workflows
- CWE-077
- .github
- actions
- download-artifact-2
- download-artifact
- workflows
- CWE-078
- .github
- actions/run-airbyte-ci
- workflows
- CWE-088
- .github/workflows
- CWE-094
- .github
- actions
- action1
- action2
- action3
- action4
- action5
- action6
- action7
- external
- TestOrg/TestRepo/.github/actions/clone-repo
- ultralytics/actions
- workflows
- external/TestOrg/TestRepo/.github/workflows
- CWE-1395
- .github/workflows
- CWE-200
- .github/workflows
- CWE-275
- .github/workflows
- CWE-284
- .github/workflows
- CWE-285
- .github/workflows
- CWE-312
- .github/workflows
- CWE-349
- .github/workflows
- CWE-367
- .github/workflows
- CWE-571
- .github/workflows
- CWE-829
- .github
- actions
- dangerous-git-checkout
- download-artifact-2
- download-artifact
- workflows
- external/TestOrg/TestRepo/.github/workflows
- CWE-918
- .github/workflows
- SyntaxError
- .github/workflows
- Violations Of Best Practice/CodeQL
- .github/workflows
- config
- cpp
- downgrades
- 1a4bbe5ded083b9de87911c155fc99ca22ecb0ce
- 1aa71a4a687fc93f807d4dfeeef70feceeced242
- 4813509d85b45ae17421c036905199f7324cf228
- 7eeff19bf7c89a350d3e43516a33c98a270cb057
- a01d8f91b8d49259e509b574962dec90719f69a6
- c3881af7e5b247d126aea68a1901b4497adf3d83
- d6a03a00b9824f27241b58b8e18208f31c03904a
- dd32242a870867a532bb0b2a88a6a917a5b4c26f
- f0156f5f88ab5967c79162012c20f30600ca5ebf
- f786eb3f5dfddb0ac914ab09551bf1c5c64b47c0
- ql
- lib
- change-notes/released
- ext
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- new
- exprs
- internal
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- gvn
- internal
- raw
- gvn
- internal
- unaliased_ssa
- gvn
- models
- implementations
- interfaces
- rangeanalysis
- new/internal/semantic
- analysis
- stmts
- upgrades
- 1a4bbe5ded083b9de87911c155fc99ca22ecb0ce
- 4813509d85b45ae17421c036905199f7324cf228
- 7eeff19bf7c89a350d3e43516a33c98a270cb057
- a01d8f91b8d49259e509b574962dec90719f69a6
- c3881af7e5b247d126aea68a1901b4497adf3d83
- d6a03a00b9824f27241b58b8e18208f31c03904a
- dd32242a870867a532bb0b2a88a6a917a5b4c26f
- e51fad7a2436caefab0c6bd52f05e28e7cce4d92
- f0156f5f88ab5967c79162012c20f30600ca5ebf
- f786eb3f5dfddb0ac914ab09551bf1c5c64b47c0
- utils/test
- dataflow
- internal
- src
- Architecture/Refactoring Opportunities
- Best Practices
- Unused Entities
- Critical
- Likely Bugs
- Arithmetic
- Format
- Leap Year
- examples
- Likely Typos
- Memory Management
- Underspecified Functions
- Microsoft
- Likely Bugs
- Conversion
- Drivers
- SizeOfMisuse
- Security
- Cryptography
- examples
- BannedModesCAPI
- BannedModesCNG
- WeakEncryption
- MemoryAccess/EnumIndex
- Protocols
- examples
- HardCodedSecurityProtocol
- UseOfDeprecatedSecurityProtocol
- Security/CWE
- CWE-078
- CWE-120
- CWE-570
- CWE-732
- change-notes/released
- experimental/Best Practices
- jsf/4.13 Functions
- test
- examples/expressions
- experimental
- library-tests/rangeanalysis
- rangeanalysis
- signanalysis
- query-tests
- Best Practices/GuardedFree
- Security/CWE
- CWE-193/constant-size
- CWE-409/DecompressionBombs
- library-tests
- arguments
- blocks
- capture
- cpp
- c
- deduplication
- builtins/type_traits
- clang_builtin_macros
- complex_numbers
- constants/addresses
- consteval_if
- constexpr_if
- controlflow
- guards-ir
- guards
- conversions
- cpp11_g
- dataflow
- asExpr
- dataflow-tests
- external-models
- fields
- ir-barrier-guards
- models-as-data
- parameters-without-defs
- smart-pointers-taint
- source-sink-tests
- taint-tests
- declaration
- fold
- functionpointerish
- functions/functions
- ir
- ir
- modulus-analysis
- points_to
- range-analysis
- sign-analysis
- types
- preprocessor/preprocessor
- proxy_class
- rangeanalysis/SimpleRangeAnalysis
- rvalueCast
- specifiers2
- structs/compatible_c
- syntax-zoo
- type_sizes
- types/datasizeof
- udl
- unspecified_type/types
- vector_types
- query-tests
- Best Practices
- GuardedFree
- Unused Entities/UnusedStaticFunctions
- Critical
- MissingCheckScanf
- SizeCheck
- Likely Bugs
- Format
- WrongNumberOfFormatArguments
- WrongTypeFormatArguments
- Buildless
- Microsoft_no_wchar
- Leap Year
- Adding365DaysPerYear
- AntiPattern5InvalidLeapYearCheck
- LeapYearConditionalLogic
- UncheckedLeapYearAfterYearModification
- UnsafeArrayForDaysOfYear
- Likely Typos/ExprHasNoEffect/CMakeFiles/CMakeScratch/TryCompile-abcdef
- Memory Management/ReturnStackAllocatedMemory
- Underspecified Functions
- Security/CWE
- CWE-022/semmle/tests
- CWE-119/semmle/tests
- CWE-120/semmle/tests
- CWE-193
- jsf/4.13 Functions/AV Rule 114
- csharp
- .config
- .vscode
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- SourceGenerators/DotnetSourceGeneratorWrapper
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp
- CodeAnalysisExtensions
- Entities
- Base
- Expressions
- Patterns
- Types
- Extractor
- Trap
- Semmle.Extraction.Tests
- Semmle.Util.Tests
- Semmle.Util
- Logging
- Testrunner
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- examples/snippets
- integration-tests
- all-platforms
- blazor_net_8
- BlazorTest
- Components
- Layout
- Pages
- Properties
- wwwroot
- bootstrap
- blazor
- BlazorTest
- Components
- Layout
- Pages
- Properties
- wwwroot
- bootstrap
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- dotnet_build
- posix/standalone_dependencies_executing_runtime
- lib
- change-notes/released
- experimental/code/csharp/Cryptography
- ext
- generated
- semmle/code/csharp
- commons
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- dispatch
- exprs
- frameworks
- system
- collections
- security
- dataflow
- xml
- telemetry
- utils/test
- internal
- src
- Bad Practices
- Likely Bugs
- Dynamic
- Telemetry
- change-notes/released
- experimental/dataflow/flowsources
- meta/frameworks
- utils/modeleditor
- test
- TestUtilities/inline-tests
- experimental/Security Features/CWE-759
- library-tests
- arguments
- assemblies
- async
- conversion
- boxing
- operator
- reftype
- csharp11
- csharp7.2
- csharp9
- dataflow
- async
- barrier-guards
- collections
- constructors
- external-models
- fields
- flowsources/stored
- database/dapper
- file
- global
- implicittostring
- library
- operators
- patterns
- threat-models
- tuples
- typeflow-dispatch
- types
- dispatch
- frameworks
- EntityFramework
- format
- generics
- implements
- implicittostring
- iterators
- methods
- parameters
- security/dataflow/flowsources
- statements
- strings
- tuples
- typeparameterconstraints
- unification
- query-tests
- Bad Practices/VirtualCallInConstructorOrDestructor
- Nullness
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- CWE-838
- Telemetry/DatabaseQuality
- Useless Code
- RedundantToStringCall
- UnusedLabel
- resources/stubs
- utils
- inline-tests
- queries
- modeleditor
- modelgenerator
- dataflow
- typebasedflow
- scripts
- docs/codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- ql-language-reference
- reusables
- go
- actions/test
- documentation/library-coverage
- extractor
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes/released
- ext
- semmle/go
- dataflow
- internal
- tainttracking1
- tainttracking2
- frameworks
- stdlib
- security
- utils/test
- internal
- src
- Security/CWE-640
- change-notes/released
- experimental
- CWE-090
- CWE-1004
- CWE-327
- CWE-74
- CWE-807
- CWE-918
- test
- experimental
- CWE-090
- CWE-203
- CWE-287
- CWE-369
- CWE-522-DecompressionBombs
- CWE-74
- CWE-79
- CWE-918
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- Function
- Types
- pkg1
- pkg2
- aliases
- DataflowFields
- InterfaceImpls
- concepts
- HTTP
- LoggerCall
- dataflow
- ArrayConversion
- ChannelField
- ExternalFlowInheritance
- vendor/github.com/nonexistent/test
- ExternalFlowVarArgs
- ExternalTaintFlow
- vendor/github.com/nonexistent/test
- ExternalValueFlow
- vendor/github.com/nonexistent/test
- GenericFunctionsAndTypes
- GlobalVariableSideEffects
- GuardingFunctions
- HiddenNodes
- ListOfConstantsSanitizerGuards
- MapReadsAndStores
- PromotedFields
- PromotedMethods
- SliceExpressions
- Switch
- TypeAssertions
- VarArgsWithFunctionModels
- VarArgs
- flowsources/local
- commandargs
- database
- vendor
- github.com
- astaxie/beego/orm
- beego/beego/v2/client/orm
- jmoiron/sqlx
- gorm.io/gorm
- environment
- file
- stdin
- frameworks
- Afero
- AwsLambda
- BeegoOrm
- Beego
- Chi
- CouchbaseV1
- Echo
- ElazarlGoproxy
- EvanphxJsonPatch
- Fasthttp
- Fiber
- Gin
- GoKit
- GoMicro
- Iris
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- K8sIoClientGo
- Macaron
- NoSQL
- Protobuf
- Revel
- SQL
- Gorm
- Sqlx
- bun
- gogf
- gorqlite
- vendor
- github.com/rqlite/gorqlite
- vendor/github.com/Masterminds/squirrel
- Spew
- StdlibTaintFlow
- vendor
- Twirp
- XNetHtml
- Yaml
- Zap
- gqlgen
- query-tests
- InconsistentCode/UnhandledCloseWritableHandle
- Security
- CWE-020/IncompleteHostnameRegexp
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-117
- vendor
- github.com/sirupsen/logrus
- CWE-190
- CWE-312
- CWE-327
- CWE-338/InsecureRandomness
- CWE-347
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- CWE-681
- CWE-770
- CWE-918
- java
- kotlin-extractor
- src/main/java/com/semmle/util
- process
- trap/pathtransformers
- ql
- automodel
- src
- change-notes
- test
- AutomodelApplicationModeExtraction
- hudson
- AutomodelFrameworkModeExtraction
- com/github/codeql/test
- java
- io
- nio/file
- change-notes
- consistency-queries
- integration-tests
- java
- android-8-sample
- android-sample-kotlin-build-script-no-wrapper
- android-sample-kotlin-build-script
- android-sample-no-wrapper
- android-sample-old-style-kotlin-build-script-no-wrapper
- android-sample-old-style-kotlin-build-script
- android-sample-old-style-no-wrapper
- android-sample-old-style
- android-sample
- buildless-erroneous
- buildless-gradle-classifiers
- buildless-gradle-timeout
- buildless-gradle
- buildless-maven-executable-war
- buildless-maven-existing-settings-xml
- buildless-maven-multimodule
- buildless-maven-timeout
- buildless-maven
- buildless-proxy-gradle
- buildless-proxy-maven
- buildless-sibling-projects
- buildless
- ecj-sample-noexit
- ecj-sample
- gradle-sample-kotlin-script
- gradle-sample
- javac-tool-custom-file
- maven-enforcer
- maven-sample-extract-properties
- maven-sample-large-xml-files
- maven-sample-small-xml-files
- maven-sample-xml-mode-all
- maven-sample-xml-mode-byname
- maven-sample-xml-mode-disabled
- maven-sample-xml-mode-smart
- maven-sample
- maven-wrapper-script-only
- maven-wrapper-source-only
- maven-wrapper
- multi-release-jar-java11
- multi-release-jar-java17
- partial-gradle-sample-without-gradle
- partial-gradle-sample
- spring-boot-sample
- kotlin/all-platforms/default-parameter-mad-flow
- lib
- change-notes/released
- semmle/code/java
- controlflow
- dataflow
- internal
- rangeanalysis
- tainttracking1
- tainttracking2
- tainttracking3
- dispatch
- frameworks
- spring
- metrics
- security
- utils/test
- internal
- src
- Likely Bugs
- Comparison
- Concurrency
- Serialization
- Termination
- Security/CWE
- CWE-327
- CWE-833
- Violations of Best Practice/Declarations
- change-notes/released
- experimental
- Security/CWE
- CWE-094
- CWE-208
- CWE-625
- semmle/code/java/security
- utils/flowtestcasegenerator
- test-kotlin1/library-tests
- controlflow
- basic
- dominance
- paths
- dataflow/summaries
- test-kotlin2/library-tests
- controlflow
- basic
- dominance
- paths
- dataflow/summaries
- test
- experimental/query-tests/security
- CWE-020
- CWE-022
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- NotConstantTimeCheckOnSignature
- TimingAttackAgainstSignagure
- CWE-299
- CWE-327
- CWE-346
- CWE-347
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-502
- CWE-522-DecompressionBombs
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- ext/TestModels
- library-tests
- Encryption
- controlflow
- basic
- dominance
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
6,198 files changed
+282486
-114343
lines changedLines changed: 8 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
27 | 35 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
| 2 | + | |
2 | 3 |
| |
3 | 4 |
| |
4 | 5 |
| |
|
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
86 | 86 |
| |
87 | 87 |
| |
88 | 88 |
| |
89 |
| - | |
| 89 | + | |
| 90 | + |
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
12 |
| - | |
13 |
| - | |
| 12 | + |
Lines changed: 2 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
30 | 30 |
| |
31 | 31 |
| |
32 | 32 |
| |
33 |
| - | |
| 33 | + | |
| 34 | + | |
34 | 35 |
| |
35 | 36 |
| |
36 | 37 |
| |
|
Lines changed: 7 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
10 | 15 |
| |
11 | 16 |
| |
12 | 17 |
| |
| |||
33 | 38 |
| |
34 | 39 |
| |
35 | 40 |
| |
36 |
| - | |
| 41 | + | |
37 | 42 |
| |
38 | 43 |
| |
39 | 44 |
| |
40 | 45 |
| |
41 |
| - | |
| 46 | + |
Lines changed: 3 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
22 |
| - | |
| 22 | + | |
23 | 23 |
| |
24 | 24 |
| |
25 | 25 |
| |
| |||
38 | 38 |
| |
39 | 39 |
| |
40 | 40 |
| |
41 |
| - | |
42 |
| - | |
| 41 | + | |
43 | 42 |
| |
44 |
| - | |
45 | 43 |
| |
46 |
| - | |
| 44 | + | |
47 | 45 |
| |
48 | 46 |
| |
49 | 47 |
| |
|
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
8 | 9 |
| |
9 | 10 |
| |
| 11 | + | |
10 | 12 |
| |
11 | 13 |
| |
12 | 14 |
| |
13 | 15 |
| |
14 | 16 |
| |
15 | 17 |
| |
16 | 18 |
| |
| 19 | + | |
17 | 20 |
| |
18 | 21 |
| |
19 | 22 |
| |
| 23 | + | |
20 | 24 |
| |
21 | 25 |
| |
22 | 26 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
40 | 40 |
| |
41 | 41 |
| |
42 | 42 |
| |
43 |
| - | |
| 43 | + | |
44 | 44 |
| |
45 | 45 |
| |
46 | 46 |
| |
|
0 commit comments