File tree
2,224 files changed
+78348
-29407
lines changed- .github
- workflows
- config
- cpp/ql
- lib
- change-notes
- released
- semmle/code/cpp
- controlflow
- internal
- dataflow/internal
- ir
- dataflow/internal
- ssa0
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- models/implementations
- rangeanalysis
- new/internal/semantic
- src
- Security/CWE
- CWE-020
- ir
- CWE-119
- change-notes/released
- experimental/Security/CWE
- CWE-190
- CWE-193
- external
- test
- experimental/query-tests/Security/CWE
- CWE-190/IfStatementAdditionOverflow
- CWE-193
- constant-size
- pointer-deref
- library-tests
- dataflow
- dataflow-tests
- fields
- taint-tests
- ir/range-analysis
- query-tests/Security/CWE/CWE-119/semmle/tests
- csharp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Expressions
- Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms/cshtml
- Views/Home
- posix-only
- dotnet_test_mstest
- dotnet_test
- lib
- change-notes
- released
- ext
- semmle/code
- asp
- cil
- csharp
- commons
- dataflow
- internal
- frameworks
- security/dataflow
- src
- Bad Practices/Implementation Hiding
- Complexity
- Security Features/CWE-022
- change-notes
- released
- experimental/ir/implementation
- internal
- raw
- internal
- desugar/internal
- unaliased_ssa
- internal
- test
- TestUtilities
- experimental/CWE-918
- library-tests
- dataflow
- collections
- delegates
- external-models
- fields
- global
- library
- operators
- patterns
- tuples
- frameworks/EntityFramework
- parameters
- query-tests
- API Abuse
- CallToGCCollect
- CallToObsoleteMethod
- ClassDoesNotImplementEquals
- ClassImplementsICloneable
- DisposeNotCalledOnException
- FormatInvalid
- InconsistentEqualsGetHashCode
- IncorrectCompareToSignature
- IncorrectEqualsSignature
- MissingDisposeCall
- MissingDisposeMethod
- NoDisposeCallOnLocalIDisposable
- NonOverridingMethod
- NullArgumentToEquals
- UncheckedReturnValue
- AlertSuppression
- Bad Practices/Implementation Hiding/ExposeRepresentation
- Security Features
- CWE-011
- CWE-016
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-119
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-248/MissingASPNETGlobalErrorHandler
- WebConfigOffButGlobal
- WebConfigOff
- CWE-312
- CWE-327/InsecureSQLConnection
- CWE-338
- CWE-352
- global
- missing
- CWE-359
- CWE-384
- CWE-451/MissingXFrameOptions
- CodeAddedHeader
- NoHeader
- WebConfigAddedHeader
- CWE-502
- DeserializedDelegate
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- UnsafeDeserialization
- CWE-539/PersistentCookie
- CWE-548
- CWE-601/UrlRedirect
- CWE-614/RequireSSL
- AddedInCode
- AddedInForms
- HttpCookiesCorrect
- RequireSSLMissing
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- resources
- assemblies
- stubs
- tools
- docs/codeql
- codeql-for-visual-studio-code
- codeql-language-guides
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- go
- extractor/cli/go-autobuilder
- ql
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- security
- src
- RedundantCode
- Security
- CWE-022
- CWE-117
- change-notes
- released
- test
- TestUtilities
- example-tests/snippets
- experimental
- CWE-134
- CWE-918
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- Function
- Types
- concepts
- HTTP
- LoggerCall
- dataflow
- ArrayConversion
- ExternalFlowVarArgs
- ExternalFlow
- vendor/github.com/nonexistent/test
- FlowSteps
- GenericFunctionsAndTypes
- GuardingFunctions
- ListOfConstantsSanitizerGuards
- PromotedFields
- PromotedMethods
- TypeAssertions
- VarArgsWithFunctionModels
- VarArgs
- frameworks
- Beego
- CouchbaseV1
- ElazarlGoproxy
- EvanphxJsonPatch
- GoKit
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- K8sIoClientGo
- NoSQL
- Revel
- SQL
- StdlibTaintFlow
- TaintSteps
- Yaml
- Zap
- query-tests/Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-117
- CWE-327
- CWE-338/InsecureRandomness
- CWE-352
- CWE-681
- javascript
- extractor
- lib/typescript
- src
- src/com/semmle
- js/extractor
- ts/extractor
- ql
- experimental/adaptivethreatmodeling/lib/experimental/adaptivethreatmodeling
- lib
- Expressions
- change-notes
- released
- semmle/javascript
- dataflow
- dependencies
- frameworks
- data/internal
- sequelize
- internal
- security
- dataflow
- src
- Declarations
- Performance
- Security
- CWE-022
- CWE-089
- examples
- CWE-094/examples
- CWE-798
- examples
- change-notes
- released
- experimental/heuristics/ql/src/Security/CWE-089
- test
- library-tests
- DataExtensions
- GlobalAccessPaths
- JSX
- frameworks/ReactJS
- query-tests
- RegExp/RegExpAlwaysMatches
- Security
- CWE-020/MissingRegExpAnchor
- CWE-089
- typed
- untyped
- CWE-400/ReDoS
- CWE-730
- tutorials/Validating RAML-based APIs
- java
- documentation/library-coverage
- downgrades/ecfcf050952e54b1155fc89525db84af6ad34aaf
- kotlin-explorer
- src/main/kotlin
- kotlin-extractor
- src/main
- java/com/semmle/util/files
- kotlin
- utils
- versions
- v_1_4_32
- v_1_8_0
- ql
- integration-tests/all-platforms/kotlin
- default-parameter-mad-flow
- diagnostics/kotlin-version-too-new
- lib
- change-notes
- released
- config
- ext
- generated
- semmle/code
- java
- controlflow/internal
- dataflow
- internal
- deadcode
- frameworks
- android
- google
- hudson
- jackson
- javaee
- ejb
- jsf
- spring
- stapler
- struts
- security
- xml
- upgrades/7cbc85b1f3ecda39661ad4806dedbd0973d2c4c0
- src
- Metrics/Summaries
- Security/CWE
- CWE-022
- CWE-730
- Telemetry
- Violations of Best Practice/Implementation Hiding
- change-notes
- released
- experimental
- Security/CWE
- CWE-073
- CWE-089
- CWE-200
- CWE-552
- semmle/code/xml
- semmle/code/xml
- utils
- flowtestcasegenerator
- modelgenerator/internal
- stub-generator
- test
- TestUtilities
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-200
- CWE-470
- CWE-552
- CWE-598
- CWE-755
- ext/TestModels
- kotlin/library-tests
- classes
- dataflow
- notnullexpr
- summaries
- whenexpr
- library-tests
- dataflow
- callback-dispatch
- callctx
- collections
- entrypoint-types
- external-models
- fluent-methods
- local-additional-taint
- state
- stream-collect
- synth-global
- taint-format
- taint-gson
- taint-jackson
- taintsources
- dispatch
- frameworks
- JaxWs
- android
- asynctask
- content-provider-summaries
- content-provider
- external-storage
- flow-steps
- intent
- notification
- slice
- sources
- taint-database
- uri
- widget
- apache-ant
- apache-collections
- apache-commons-compress
- apache-commons-lang3
- apache-http
- gson
- guava
- generated
- cache
- collect
- handwritten
- hudson
- jackson
- javax-json
- jdk
- java.io
- java.net
- java.nio.file
- jms
- json-java
- netty
- generated
- manual
- okhttp
- play
- mad
- rabbitmq
- ratpack
- retrofit
- spring
- beans
- cache
- context
- controller
- data
- http
- ui
- util
- validation
- webmultipart
- webutil
- stapler
- stream
- thymeleaf
- logging
- neutrals/neutralsinks
- optional
- pathsanitizer
- paths
- regex
- scanner
- xml
- query-tests
- ExposeRepresentation
- Metrics/GeneratedVsManualCoverage/TopJdkApisTest
- Telemetry/SupportedExternalSinks
- security
- CWE-023/semmle/tests
- CWE-074
- CWE-078
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- CWE-094
- CWE-117
- CWE-1204
- CWE-266
- CWE-273
- CWE-295
- AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- Test5
- ImproperWebVeiwCertificateValidation
- InsecureTrustManager
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-326
- CWE-347
- CWE-441
- CWE-470
- CWE-489
- debuggable-attribute
- webview-debugging
- CWE-502
- CWE-522
- CWE-524
- CWE-532
- CWE-611
- CWE-643
- CWE-730
- CWE-749
- CWE-780
- CWE-798/semmle/tests
- CWE-807/semmle/tests
- CWE-917
- CWE-918
- mad
- CWE-925
- CWE-926
- incomplete_provider_permissions
- CWE-927
- CWE-940
- stubs
- apache-http-5/org/apache/hc/client5/http/protocol
- gson-2.8.6/com/google/gson
- internal
- reflect
- stream
- javax-annotation-api-1.3.2/javax/annotation
- jenkins/hudson
- model
- playframework-2.6.x/play
- api/mvc
- libs/ws
- mvc
- serialkiller-4.0.0/org/nibblesec/tools
- stapler-1.263/org/kohsuke/stapler
- utils/modelgenerator/dataflow
- misc
- bazel/cmake
- codegen
- generators
- lib
- loaders
- templates
- test
- suite-helpers
- change-notes/released
- python
- ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- frameworks
- data/internal
- pointsto
- security
- dataflow
- flow
- injection
- types
- web
- bottle
- cherrypy
- client
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- src
- Expressions
- Security
- CWE-020-ExternalAPIs
- CWE-502
- CWE-730
- CWE-798
- Statements
- change-notes
- released
- experimental
- Security
- CWE-022
- CWE-074/paramiko
- semmle/python
- security
- injection
- test
- 2/query-tests
- Expressions
- Imports/syntax_error
- 3
- library-tests/taint
- strings
- unpacking
- query-tests/Imports/syntax_error
- experimental
- dataflow
- TestUtil
- basic
- calls
- coverage
- exceptions
- fieldflow
- global-flow
- match
- model-summaries
- module-initialization
- regression
- sensitive-data
- summaries
- tainttracking
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- generator-flow
- unwanted-global-flow
- typetracking-summaries
- typetracking_imports
- typetracking
- variable-capture
- import-resolution
- library-tests
- CallGraph-implicit-init
- CallGraph-imports
- CallGraph
- meta
- debug
- inline-taint-test-demo
- query-tests/Security
- CWE-022-TarSlip
- CWE-022-UnsafeUnpacking
- CWE-1236
- library-tests
- ApiGraphs/py2
- InlineExpectationsTest/missing-relevant-tag
- essa/ssa-compute
- examples/custom-sanitizer
- frameworks
- aioch
- aiohttp
- aiomysql
- aiopg
- aiosqlite
- asyncpg
- cassandra-driver
- clickhouse_driver
- cryptodome
- cryptography
- crypto
- cx_Oracle
- dill
- django-orm
- django-v1
- django-v2-v3
- django
- fabric
- fastapi
- flask_admin
- flask_sqlalchemy
- flask
- httpx
- idna
- internal-ql-helpers
- invoke
- jmespath
- libtaxii
- lxml
- markupsafe
- multidict
- mysql-connector-python
- mysqldb
- oracledb
- peewee
- phoenixdb
- pycurl
- pymssql
- pymysql
- pyodbc
- requests
- rest_framework
- rsa
- ruamel.yaml
- simplejson
- sqlalchemy
- stdlib-py2
- stdlib-py3
- stdlib
- toml
- tornado
- twisted
- ujson
- urllib3
- xmltodict
- yaml
- yarl
- regex
- security
- command-execution
- fabric-v1-execute
- sensitive
- taint
- collections
- config
- example
- exception_traceback
- flowpath_regression
- general
- namedtuple
- strings
- unpacking
- web
- bottle
- cherrypy
- client
- requests
- six
- stdlib
- django
- falcon
- flask
- pyramid
- stdlib
- tornado
- turbogears
- twisted
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-079-ReflectedXss
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-285-PamAuthorization
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-798-HardcodedCredentials
- Statements/general
- tools/recorded-call-graph-metrics/ql/lib
- ql
- buramu
- extractor
- ql
- src
- codeql_ql
- ast
- internal
- style
- queries
- performance
- style
- test
- dataflow/getAStringValue
- queries
- performance/AbstractClassImport
- style
- DeadCode
- FieldOnlyUsedInCharPred
- MissingOverride
- ruby
- extractor
- ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- ast
- controlflow
- dataflow/internal
- frameworks
- actioncontroller
- actiondispatch/internal
- core
- data/internal
- rack/internal
- regexp/internal
- security
- typetracking
- internal
- ide-contextual-queries
- src
- change-notes
- released
- experimental/cwe-022-zipslip
- queries/security
- cwe-1333
- cwe-502
- cwe-829
- test
- TestUtilities
- library-tests
- concepts
- dataflow
- api-graphs
- array-flow
- barrier-guards
- call-sensitivity
- flow-summaries
- global
- hash-flow
- local
- params
- pathname-flow
- ssa-flow
- string-flow
- summaries
- type-tracker
- frameworks
- action_controller
- action_dispatch
- app/controllers
- action_mailer
- active_support
- arel
- json
- mysql2
- pathname
- rack
- sequel
- sinatra
- query-tests
- experimental/improper-memoization
- security
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-1333-polynomial-redos
- cwe-300
- cwe-502/unsafe-deserialization
- cwe-829
- swift
- actions
- build-and-test
- run-integration-tests
- downgrades
- 147e087e57e51b2eb41e75c9c97380d0e6c20ecb
- 44e36e15e90bc1535964d9b86b3cd06a8b0d26e3
- extractor
- infra
- file
- remapping
- translators
- trap
- logging
- tests/assertion-diagnostics
- ql
- lib
- change-notes
- released
- codeql/swift
- dataflow
- internal
- elements
- decl
- expr
- pattern
- stmt
- frameworks/StandardLibrary
- generated
- decl
- expr
- pattern
- stmt
- type
- regex
- internal
- security
- internal
- upgrades
- 44e36e15e90bc1535964d9b86b3cd06a8b0d26e3
- ba4171b90d0665b40e9e203bac9e3d4a0b2d03ec
- src
- change-notes
- released
- diagnostics
- queries
- Security/CWE-312
- Summary
- test
- extractor-tests
- errors
- generated
- decl
- CapturedDecl
- NamedFunction
- expr/MethodLookupExpr
- CONSISTENCY
- run_under
- updates
- library-tests
- ast
- controlflow/graph
- dataflow/dataflow
- elements
- decl/enumdecl
- CONSISTENCY
- expr/methodlookup
- regex
- test_fragment_licenses
- query-tests/Security
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-135
- CWE-311
- CWE-321
- CWE-328
- CWE-760
- third_party
- swift-llvm-support
- patches
- tools
- autobuilder-diagnostics
- diagnostics
- test/qltest
- xcode-autobuilder
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,224 files changed
+78348
-29407
lines changedLines changed: 7 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
2 | 8 |
| |
3 | 9 |
|
Lines changed: 1 addition & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
| 14 | + | |
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
24 | 23 |
| |
25 | 24 |
| |
26 | 25 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
| 13 | + | |
13 | 14 |
| |
14 | 15 |
| |
15 | 16 |
| |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
16 | 16 |
| |
17 | 17 |
| |
18 | 18 |
| |
| 19 | + | |
19 | 20 |
| |
20 | 21 |
| |
21 | 22 |
| |
| |||
30 | 31 |
| |
31 | 32 |
| |
32 | 33 |
| |
| 34 | + | |
33 | 35 |
| |
34 | 36 |
| |
35 | 37 |
| |
|
Lines changed: 0 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
8 | 8 |
| |
9 | 9 |
| |
10 | 10 |
| |
11 |
| - | |
12 | 11 |
| |
13 | 12 |
| |
14 | 13 |
| |
|
Lines changed: 7 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
511 | 511 |
| |
512 | 512 |
| |
513 | 513 |
| |
514 |
| - | |
| 514 | + | |
| 515 | + | |
515 | 516 |
| |
516 | 517 |
| |
517 | 518 |
| |
| |||
522 | 523 |
| |
523 | 524 |
| |
524 | 525 |
| |
| 526 | + | |
| 527 | + | |
| 528 | + | |
| 529 | + | |
525 | 530 |
| |
526 | 531 |
| |
527 | 532 |
| |
| |||
598 | 603 |
| |
599 | 604 |
| |
600 | 605 |
| |
601 |
| - | |
| 606 | + |
Lines changed: 24 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
1 | 25 |
| |
2 | 26 |
| |
3 | 27 |
| |
|
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 4 deletions
This file was deleted.
0 commit comments