File tree
1,057 files changed
+21488
-15528
lines changed- .github/workflows
- cpp
- downgrades
- ql
- lib
- change-notes/released
- ext
- semmle/code/cpp
- controlflow
- dataflow
- internal
- ir
- dataflow/internal
- implementation/raw/internal
- src
- Likely Bugs/Memory Management
- Security/CWE/CWE-676
- change-notes/released
- test
- library-tests
- controlflow
- guards-ir
- guards
- dataflow
- dataflow-tests
- external-models
- fields
- source-sink-tests
- ir/ir
- variables/variables
- query-tests/Security/CWE/CWE-676/semmle/PotentiallyDangerousFunction
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Properties
- Semmle.Extraction.CSharp.DependencyStubGenerator
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp.StubGenerator
- Properties
- Semmle.Extraction.CSharp.Util
- Semmle.Extraction.CSharp/Extractor
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util.Tests
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms/standalone_buildless_option
- posix-only/standalone_dependencies_nuget with_space
- lib
- change-notes/released
- ext
- generated
- semmle/code/csharp
- dataflow/internal
- frameworks/system
- security/dataflow
- flowsources
- src
- Security Features/CWE-327
- change-notes/released
- utils/modelgenerator/internal
- test
- experimental/Security Features/CWE-759
- library-tests
- dataflow
- async
- collections
- external-models
- global
- library
- threat-models
- frameworks/EntityFramework
- security/dataflow/flowsources
- query-tests/Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSS
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- CWE-838
- utils/modelgenerator/dataflow
- scripts
- tools
- docs/codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- reusables
- go
- actions/test
- codeql-tools
- extractor-smoke-test
- extractor
- autobuilder
- cli/go-autobuilder
- project
- toolchain
- trap
- util
- ql
- consistency-queries
- change-notes/released
- integration-tests
- lib
- change-notes/released
- ext
- semmle/go
- dataflow
- internal
- frameworks/stdlib
- security
- src
- change-notes/released
- experimental/frameworks
- test
- experimental
- CWE-522-DecompressionBombs
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- concepts/LoggerCall
- dataflow
- ArrayConversion
- ChannelField
- ExternalTaintFlow
- vendor/github.com/nonexistent/test
- ExternalValueFlow
- vendor/github.com/nonexistent/test
- GenericFunctionsAndTypes
- GlobalVariableSideEffects
- GuardingFunctions
- HiddenNodes
- ListOfConstantsSanitizerGuards
- MapReadsAndStores
- PromotedFields
- PromotedMethods
- SliceExpressions
- Switch
- TypeAssertions
- VarArgsWithFunctionModels
- VarArgs
- frameworks
- Afero
- AwsLambda
- CouchbaseV1
- Echo
- ElazarlGoproxy
- Encoding
- EvanphxJsonPatch
- Fasthttp
- Fiber
- GoKit
- GoMicro
- Gorestful
- Iris
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- K8sIoClientGo
- Macaron
- Mux
- NoSQL
- Protobuf
- SQL
- Spew
- StdlibTaintFlow
- SystemCommandExecutors
- TaintSteps
- Twirp
- Yaml
- Zap
- gqlgen
- query-tests/Security
- CWE-022
- CWE-117
- CWE-312
- CWE-601/OpenUrlRedirect
- CWE-681
- CWE-770
- javascript
- downgrades
- externs
- extractor
- lib/typescript
- src/com/semmle/js/extractor
- tests/xsaccess
- input
- output/trap
- test/com/semmle/js/extractor/test
- ql
- integration-tests
- lib
- change-notes/released
- semmle/javascript
- dataflow/internal
- frameworks/data/internal
- src
- change-notes/released
- test/library-tests/frameworks/data
- resources
- tools
- java
- documentation/library-coverage
- downgrades
- kotlin-extractor
- defaults
- deps
- dev
- src/main/java/com/semmle/extractor/java
- ql
- automodel/src
- change-notes/released
- integration-tests
- all-platforms
- java
- android-sample-kotlin-build-script-no-wrapper
- android-sample-kotlin-build-script
- android-sample-no-wrapper
- android-sample-old-style-kotlin-build-script-no-wrapper
- android-sample-old-style-kotlin-build-script
- android-sample-old-style-no-wrapper
- android-sample-old-style
- android-sample
- ant-sample
- buildless-gradle-timeout
- ecj-sample-noexit
- ecj-sample
- gradle-sample-kotlin-script
- gradle-sample
- java-web-jsp
- maven-sample-extract-properties
- maven-sample-large-xml-files
- maven-sample-small-xml-files
- maven-sample-xml-mode-all
- maven-sample-xml-mode-byname
- maven-sample-xml-mode-disabled
- maven-sample-xml-mode-smart
- partial-gradle-sample-without-gradle
- partial-gradle-sample
- kotlin
- annotation-id-consistency
- default-parameter-mad-flow
- enhanced-nullability
- external-property-overloads
- extractor_information_kotlin1
- file_classes
- java-interface-redeclares-tostring
- java_modifiers
- jvmoverloads-external-class
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- nested_generic_types
- nullability-annotations
- path_transformer
- private_property_accessors
- linux-only/kotlin/custom_plugin
- plugin
- posix-only/kotlin
- generic-extension-property
- module_mangled_names
- lib
- change-notes/released
- ext
- semmle/code/java
- dataflow
- security
- src
- change-notes/released
- test-kotlin1/library-tests
- classes
- comments
- controlflow/basic
- dataflow/foreach
- exprs
- extensions
- generated-throws
- generic-inner-classes
- generic-instance-methods
- generics
- java-kotlin-collection-type-generic-methods
- jvmoverloads-annotation
- jvmoverloads_flow
- literals
- methods
- parameter-defaults
- private-anonymous-types
- reflection
- stmts
- trap
- vararg
- test-kotlin2
- TestUtilities
- library-tests
- arrays
- comments
- compilation-units
- enum
- exprs
- generated-throws
- java-kotlin-collection-type-generic-methods
- reflection
- test
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208/TimingAttackAgainstSignagure
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-759
- library-tests
- dataflow/threat-models
- dispatch
- frameworks/JaxWs
- query-tests/security
- CWE-022/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests/TempDirLocalInformationDisclosure
- CWE-297
- CWE-311/CWE-319
- CWE-327/semmle/tests
- CWE-352
- CWE-601/semmle/tests
- CWE-681/semmle/tests
- CWE-807/semmle/tests
- stubs/springframework-5.3.8/org/springframework/security/config/web/server
- misc
- bazel
- cmake
- internal
- zipmerge
- test-files
- registry/modules/rules_kotlin
- 1.9.4-codeql.1
- patches
- codegen/loaders
- ripunzip
- suite-helpers
- change-notes/released
- python
- extractor
- ql
- lib
- change-notes/released
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- security/dataflow
- src
- Security/CWE-601
- examples
- change-notes/released
- tools
- ql
- extractor/src
- ruby
- extractor
- src
- ql
- consistency-queries
- integration-tests
- lib
- change-notes/released
- codeql/ruby
- dataflow/internal
- frameworks/data/internal
- src
- change-notes/released
- test
- library-tests
- ast
- calls
- dataflow
- flow-summaries
- summaries
- frameworks/action_view/app/views/foo/bars
- query-tests
- diagnostics/CONSISTENCY
- security
- cwe-078/CommandInjection
- cwe-300
- tools
- swift
- actions
- build-and-test
- run-integration-tests
- run-ql-tests
- extractor
- ql
- integration-tests
- lib
- change-notes/released
- codeql/swift/dataflow
- src
- change-notes/released
- third_party
- resource-dir
- swift-llvm-support
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,057 files changed
+21488
-15528
lines changedLines changed: 5 additions & 4 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 |
| - | |
| 13 | + | |
| 14 | + | |
17 | 15 |
| |
18 | 16 |
| |
19 | 17 |
| |
20 | 18 |
| |
21 | 19 |
| |
| 20 | + | |
| 21 | + | |
| 22 | + | |
22 | 23 |
| |
23 | 24 |
| |
24 | 25 |
| |
|
Lines changed: 22 additions & 15 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
50 | 50 |
| |
51 | 51 |
| |
52 | 52 |
| |
53 |
| - | |
54 |
| - | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
55 | 56 |
| |
56 | 57 |
| |
57 |
| - | |
58 |
| - | |
| 58 | + | |
| 59 | + | |
59 | 60 |
| |
60 |
| - | |
| 61 | + | |
61 | 62 |
| |
62 |
| - | |
| 63 | + | |
63 | 64 |
| |
64 | 65 |
| |
65 | 66 |
| |
66 | 67 |
| |
67 | 68 |
| |
68 |
| - | |
| 69 | + | |
69 | 70 |
| |
70 | 71 |
| |
71 |
| - | |
| 72 | + | |
72 | 73 |
| |
73 | 74 |
| |
74 |
| - | |
75 |
| - | |
| 75 | + | |
| 76 | + | |
76 | 77 |
| |
77 | 78 |
| |
78 |
| - | |
79 |
| - | |
80 |
| - | |
81 |
| - | |
82 |
| - | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
65 | 65 |
| |
66 | 66 |
| |
67 | 67 |
| |
68 |
| - | |
| 68 | + | |
69 | 69 |
| |
70 | 70 |
| |
71 | 71 |
| |
| |||
101 | 101 |
| |
102 | 102 |
| |
103 | 103 |
| |
104 |
| - | |
| 104 | + | |
105 | 105 |
| |
106 | 106 |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
7 | 7 |
| |
8 | 8 |
| |
9 | 9 |
| |
| 10 | + | |
| 11 | + | |
| 12 | + | |
10 | 13 |
| |
11 | 14 |
| |
12 | 15 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| 18 | + | |
| 19 | + | |
| 20 | + | |
18 | 21 |
| |
19 | 22 |
| |
20 | 23 |
| |
|
Lines changed: 28 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + |
Lines changed: 5 additions & 5 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
49 | 49 |
| |
50 | 50 |
| |
51 | 51 |
| |
52 |
| - | |
| 52 | + | |
53 | 53 |
| |
54 |
| - | |
| 54 | + | |
55 | 55 |
| |
56 | 56 |
| |
57 | 57 |
| |
58 |
| - | |
| 58 | + | |
59 | 59 |
| |
60 | 60 |
| |
61 | 61 |
| |
62 | 62 |
| |
63 |
| - | |
| 63 | + | |
64 | 64 |
| |
65 |
| - | |
| 65 | + | |
66 | 66 |
| |
67 | 67 |
| |
68 | 68 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
53 | 53 |
| |
54 | 54 |
| |
55 | 55 |
| |
56 |
| - | |
57 |
| - | |
| 56 | + | |
| 57 | + | |
58 | 58 |
| |
59 | 59 |
| |
60 | 60 |
| |
|
Lines changed: 6 additions & 7 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
49 | 49 |
| |
50 | 50 |
| |
51 | 51 |
| |
52 |
| - | |
| 52 | + | |
53 | 53 |
| |
54 | 54 |
| |
55 | 55 |
| |
56 |
| - | |
| 56 | + | |
57 | 57 |
| |
58 | 58 |
| |
59 | 59 |
| |
60 |
| - | |
| 60 | + | |
61 | 61 |
| |
62 | 62 |
| |
63 | 63 |
| |
64 | 64 |
| |
65 | 65 |
| |
66 | 66 |
| |
67 | 67 |
| |
68 |
| - | |
| 68 | + | |
69 | 69 |
| |
70 | 70 |
| |
71 | 71 |
| |
| |||
100 | 100 |
| |
101 | 101 |
| |
102 | 102 |
| |
103 |
| - | |
| 103 | + | |
104 | 104 |
| |
105 | 105 |
| |
106 | 106 |
| |
107 | 107 |
| |
108 | 108 |
| |
109 | 109 |
| |
110 | 110 |
| |
111 |
| - | |
112 |
| - | |
| 111 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
44 | 44 |
| |
45 | 45 |
| |
46 | 46 |
| |
47 |
| - | |
| 47 | + | |
48 | 48 |
| |
49 | 49 |
| |
50 | 50 |
| |
|
0 commit comments