File tree
904 files changed
+53374
-50522
lines changed- .github
- workflows
- config
- cpp
- autobuilder/Semmle.Autobuild.Cpp
- ql
- lib
- change-notes/released
- semmle/code/cpp
- controlflow
- dataflow/internal
- tainttracking1
- tainttracking2
- ir
- dataflow/internal
- implementation/raw/internal
- internal
- models
- implementations
- interfaces
- src
- Likely Bugs/Format
- change-notes/released
- test
- experimental/query-tests/Security/CWE/CWE-193/array-access
- include
- library-tests
- arguments
- dataflow
- dataflow-tests
- fields
- taint-tests
- ir
- ir
- points_to
- special_members/generated_copy
- specifiers2
- syntax-zoo
- query-tests
- Likely Bugs/Format/NonConstantFormat
- Security/CWE
- CWE-078/semmle/ExecTainted
- CWE-119
- SAMATE
- semmle/tests
- CWE-134/semmle
- argv
- consts
- globalVars
- CWE-311/semmle/tests
- CWE-611
- successor-tests/staticlocals/no_dynamic_init
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- downgrades
- 21ede72308c41493f19b37720d8259d5eb307f12
- fd04e45710e1988076801608abffdfa013b680fc
- extractor
- Semmle.Extraction.CIL.Driver
- Semmle.Extraction.CIL
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.DependencyStubGenerator
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Semmle.Extraction.CSharp
- Entities
- Statements
- Extractor
- Semmle.Extraction.Tests
- Semmle.Extraction
- Extractor
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- dotnet_build
- dotnet_run
- standalone_dependencies_net48
- standalone
- linux-only/standalone_dependencies_non_utf8_filename
- posix-only
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_no_sources
- standalone_dependencies_nuget
- standalone_dependencies
- windows-only/standalone_dependencies
- lib
- change-notes/released
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- dispatch
- exprs
- frameworks
- system/diagnostics
- security
- auth
- dataflow
- flowsources
- upgrades
- 21ede72308c41493f19b37720d8259d5eb307f12
- c9ee11bd1ee96e925a35cedff000be924634447f
- src
- Dead Code
- Security Features
- CWE-089
- CWE-091
- CWE-114
- CWE-134
- CWE-502
- change-notes/released
- experimental
- CWE-099
- CWE-918
- test
- experimental/Security Features
- CWE-759
- backdoor
- library-tests
- attributes
- cil/dataflow
- constructors
- controlflow
- graph
- splits
- csharp7
- csharp8
- csharp9
- dataflow
- async
- call-sensitivity
- collections
- constructors
- defuse
- external-models
- fields
- global
- local
- operators
- ssa
- threat-models
- tuples
- typeflow-dispatch
- types
- expressions
- exprorstmtparent
- frameworks/EntityFramework
- goto
- nullable
- parameters
- standalone
- controlflow
- errorrecovery
- statements
- structuralcomparison
- query-tests
- Likely Bugs/UnsafeYearConstruction
- Nullness
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsecureSQLConnection
- CWE-338
- CWE-601/UrlRedirect
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- CWE-838
- tools
- docs/codeql
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview/codeql-changelog
- images/codeql-for-visual-studio-code
- reusables
- go
- documentation/library-coverage
- extractor
- autobuilder
- cli/go-autobuilder
- diagnostics
- project
- toolchain
- util
- ql
- consistency-queries
- change-notes/released
- integration-tests/all-platforms/go
- diagnostics
- go-files-found-not-processed
- unsupported-relative-path
- go-mod-without-version
- src
- subdir
- mixed-layout
- src
- module
- stray-files
- workspace
- subdir
- single-go-mod-and-go-files-not-under-it
- single-go-mod-in-root
- single-go-mod-not-in-root
- single-go-work-not-in-root
- two-go-mods-nested-none-in-root
- two-go-mods-nested-one-in-root
- two-go-mods-not-nested
- two-go-mods-one-failure
- src
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- lib
- change-notes/released
- semmle/go/dataflow/internal
- src
- change-notes/released
- experimental/CWE-525
- examples
- test
- experimental/CWE-525
- vendor
- github.com
- go-chi/chi/v5
- middleware
- gofiber/fiber/v2
- julienschmidt/httprouter
- library-tests/semmle/go/dataflow/MapReadsAndStores
- javascript
- downgrades
- externs
- extractor
- lib/typescript
- tests
- test/com/semmle/js/extractor/test
- ql
- lib
- change-notes/released
- semmle/javascript/endpoints
- src
- change-notes/released
- test
- library-tests/EndpointNaming
- pack10
- pack11
- pack12
- pack1
- pack2
- pack3
- pack4
- pack5/src
- pack6
- pack7
- pack8
- pack9
- query-tests/Security/CWE-400/ReDoS
- java
- documentation/library-coverage
- integration-tests-lib
- kotlin-extractor
- src/main/kotlin/utils/versions/v_2_0_0-Beta4
- ql
- automodel/src
- change-notes/released
- integration-tests/all-platforms
- java
- buildless-erroneous
- maven-wrapper-script-only
- .mvn/wrapper
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-wrapper-source-only
- .mvn/wrapper
- src
- main
- java/com/example
- resources
- test/java/com/example
- maven-wrapper
- .mvn/wrapper
- src
- main
- java/com/example
- resources
- test/java/com/example
- kotlin
- extractor_information_kotlin1
- extractor_information_kotlin2
- lib
- change-notes/released
- ext
- semmle/code/java
- dataflow
- internal
- security
- src
- Likely Bugs/Likely Typos
- Security/CWE
- CWE-200
- CWE-287
- Telemetry
- change-notes/released
- test-kotlin1/library-tests
- compilation-units
- enum
- java-kotlin-collection-type-generic-methods
- reflection
- test-kotlin2/library-tests
- exprs
- interface-delegate
- ministdlib
- multiple_files
- operator-overloads
- reflection
- test
- ext/TopJdkApis
- library-tests
- errorexpr
- errortype
- properties
- unknown-method-reference-lhs
- query-tests
- Metrics/GeneratedVsManualCoverage/TopJdkApisTest
- security
- CWE-287
- InsecureKeys
- Test1
- Test2
- InsecureLocalAuth
- CWE-312/android/CleartextStorage
- CWE-532
- stubs/google-android-9.0.0/android/security/keystore
- utils/modelgenerator/dataflow
- misc
- bazel
- cmake
- semmle_code_stub
- codegen
- suite-helpers
- change-notes/released
- python/ql
- consistency-queries
- lib
- analysis
- change-notes/released
- semmle/python
- dataflow/new/internal
- src
- Security/CWE-943
- change-notes/released
- test/experimental/dataflow
- coverage
- fieldflow
- ql
- buramu
- extractor
- ql/src/codeql
- ruby
- downgrades
- extractor
- ql
- lib
- change-notes/released
- codeql
- ruby
- dataflow/internal
- frameworks
- actiondispatch/internal
- core
- ide-contextual-queries
- src
- change-notes/released
- experimental/cwe-502
- examples
- test
- library-tests
- controlflow/graph
- dataflow
- array-flow
- flow-summaries
- global
- hash-flow
- local
- params
- summaries
- frameworks
- action_controller
- active_record
- active_support
- core
- sinatra
- query-tests
- experimental
- LdapInjection
- cwe-502
- security
- cwe-079
- app
- controllers/foo
- views/foo/bars
- cwe-089
- cwe-094/UnsafeCodeConstruction
- cwe-312
- cwe-502/unsafe-deserialization
- cwe-506
- tools
- swift
- extractor
- config
- remapping
- logging/tests/assertion-diagnostics
- ql
- lib
- change-notes/released
- codeql/swift
- controlflow/internal
- elements
- decl
- src
- change-notes/released
- test/library-tests/controlflow/graph
- third_party
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
904 files changed
+53374
-50522
lines changedLines changed: 8 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
2 | 10 |
| |
3 | 11 |
| |
4 | 12 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + |
Lines changed: 4 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
74 | 74 |
| |
75 | 75 |
| |
76 | 76 |
| |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
28 | 28 |
| |
29 | 29 |
| |
30 | 30 |
| |
31 |
| - | |
| 31 | + | |
32 | 32 |
| |
33 | 33 |
| |
34 | 34 |
| |
|
Lines changed: 8 additions & 65 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
51 | 51 |
| |
52 | 52 |
| |
53 | 53 |
| |
54 |
| - | |
55 |
| - | |
56 |
| - | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
57 | 59 |
| |
58 | 60 |
| |
59 | 61 |
| |
| |||
82 | 84 |
| |
83 | 85 |
| |
84 | 86 |
| |
85 |
| - | |
86 |
| - | |
87 |
| - | |
88 |
| - | |
89 |
| - | |
90 |
| - | |
91 |
| - | |
92 |
| - | |
93 |
| - | |
94 |
| - | |
| 87 | + | |
| 88 | + | |
95 | 89 |
| |
96 | 90 |
| |
97 | 91 |
| |
| |||
123 | 117 |
| |
124 | 118 |
| |
125 | 119 |
| |
126 |
| - | |
| 120 | + | |
127 | 121 |
| |
128 | 122 |
| |
129 | 123 |
| |
| |||
235 | 229 |
| |
236 | 230 |
| |
237 | 231 |
| |
238 |
| - | |
239 |
| - | |
240 |
| - | |
241 |
| - | |
242 |
| - | |
243 |
| - | |
244 |
| - | |
245 |
| - | |
246 |
| - | |
247 |
| - | |
248 |
| - | |
249 |
| - | |
250 |
| - | |
251 |
| - | |
252 |
| - | |
253 |
| - | |
254 |
| - | |
255 |
| - | |
256 |
| - | |
257 |
| - | |
258 |
| - | |
259 |
| - | |
260 |
| - | |
261 |
| - | |
262 |
| - | |
263 |
| - | |
264 |
| - | |
265 |
| - | |
266 |
| - | |
267 |
| - | |
268 |
| - | |
269 |
| - | |
270 |
| - | |
271 |
| - | |
272 |
| - | |
273 |
| - | |
274 |
| - | |
275 |
| - | |
276 |
| - | |
277 |
| - | |
278 |
| - | |
279 |
| - | |
280 |
| - | |
281 |
| - | |
282 |
| - | |
283 |
| - | |
284 |
| - | |
285 |
| - | |
286 |
| - | |
287 |
| - | |
288 |
| - |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
39 | 39 |
| |
40 | 40 |
| |
41 | 41 |
| |
| 42 | + | |
| 43 | + | |
| 44 | + | |
42 | 45 |
| |
43 | 46 |
| |
44 | 47 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
| 28 | + | |
28 | 29 |
| |
29 | 30 |
| |
30 | 31 |
| |
|
Lines changed: 53 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + |
Lines changed: 2 additions & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
4 |
| - | |
5 |
| - | |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
| 1 | + | |
| 2 | + |
0 commit comments