File tree
2,961 files changed
+168030
-64719
lines changed- .github/workflows
- actions
- extractor
- tools
- ql
- integration-tests/query-suite
- lib
- change-notes/released
- codeql
- actions
- ast/internal
- controlflow
- internal
- dataflow
- security
- src
- Diagnostics
- Security
- CWE-077
- CWE-094
- CWE-349
- CWE-829
- change-notes/released
- experimental/Security
- CWE-078
- CWE-088
- CWE-829
- config
- cpp
- downgrades/c16b29b27f71247023321cc0d0360998b318837c
- ql
- integration-tests/query-suite
- lib
- change-notes
- released
- experimental
- cryptography
- modules
- utils/OpenSSL
- quantum
- OpenSSL
- AlgorithmInstances
- AlgorithmValueConsumers
- Operations
- semmle/code/cpp/rangeanalysis
- ext
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn/internal
- raw
- gvn/internal
- internal
- unaliased_ssa
- gvn/internal
- internal
- models/interfaces
- rangeanalysis/new/internal/semantic
- security
- boostorg/asio
- stmts
- upgrades/5340d6d5f428557632b1a50113e406430f29ef7d
- src
- Best Practices
- Magic Constants
- Critical
- Likely Bugs
- Arithmetic
- Format
- Leap Year
- Memory Management
- Protocols
- Underspecified Functions
- Metrics/Internal
- Security/CWE
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-120
- CWE-129
- CWE-170
- CWE-190
- CWE-290
- CWE-295
- CWE-311
- CWE-313
- CWE-319
- CWE-326
- CWE-367
- CWE-416
- CWE-428
- CWE-457
- CWE-468
- CWE-570
- CWE-732
- CWE-807
- CWE-843
- change-notes/released
- experimental
- Likely Bugs
- Security/CWE
- CWE-1126
- CWE-125
- CWE-193
- CWE-243
- CWE-401
- CWE-409
- CWE-416
- external
- jsf/4.10 Classes
- test
- examples/docs-examples/analyzing-data-flow-in-cpp
- experimental/library-tests
- quantum
- rangeanalysis/rangeanalysis
- library-tests
- controlflow
- guards-ir
- guards
- dataflow
- dataflow-tests
- dispatch
- external-models
- fields
- ir-barrier-guards
- models-as-data
- taint-tests
- files
- functions/routinetype
- ir
- ir
- range-analysis
- macros/arguments
- permissive
- preprocessor/preprocessor
- syntax-zoo
- typedefs
- types
- __wchar_t
- cstd_types
- integral_types_ms
- wchar_t_typedef
- valuenumbering/GlobalValueNumbering
- variables/variables
- query-tests
- Best Practices/SloppyGlobal
- Critical/MissingCheckScanf
- Likely Bugs/Memory Management/StrncpyFlippedArgs
- Security/CWE
- CWE-119/semmle/tests
- CWE-134/semmle/globalVars
- CWE-295
- CWE-313
- CWE-457/semmle/tests
- CWE-497/semmle/tests
- CWE-611
- csharp
- actions/create-extractor-pack
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp
- Entities
- Base
- Locations
- PreprocessorDirectives
- Types
- Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- integration-tests
- all-platforms
- autobuild
- binlog_multiple
- binlog
- blazor_build_mode_none/BlazorTest
- blazor
- BlazorTest
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_resx
- standalone_winforms
- standalone
- linux
- compiler_args
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- query-suite
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- proj
- standalone_dependencies_nuget_config_error
- proj
- standalone_dependencies_nuget_config_fallback
- proj
- standalone_dependencies_nuget_no_sources/proj
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows/standalone_dependencies
- lib
- change-notes
- released
- ext
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- dispatch
- security/dataflow
- serialization
- src
- API Abuse
- ASP
- Bad Practices
- Comments
- Control-Flow
- Declarations
- Implementation Hiding
- Magic Constants
- Naming Conventions
- Concurrency
- Documentation
- Language Abuse
- Likely Bugs
- Dynamic
- LeapYear
- Statements
- Linq
- Security Features
- CWE-090
- CWE-384
- CWE-798
- Telemetry
- Useless code
- change-notes/released
- experimental/Security Features/CWE-759
- test
- library-tests
- assignables
- controlflow/graph
- csharp8
- dataflow
- call-sensitivity
- external-models
- library
- ssa
- threat-models
- frameworks/microsoft/aspnetcore/blazor
- goto
- locations
- tainttracking/collections
- query-tests
- Nullness
- Security Features
- CWE-502/UnsafeDeserializationUntrustedInput
- CWE-611
- resources/stubs
- scripts
- stubs
- docs
- codeql
- _static
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview/codeql-changelog
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- go
- actions/test
- extractor
- autobuilder
- cli
- go-autobuilder
- go-extractor
- util
- old-change-notes
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes
- released
- ext
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-295
- CWE-322
- CWE-327
- CWE-352
- CWE-601
- CWE-681
- change-notes/released
- experimental
- CWE-1004
- CWE-807
- CWE-840
- CWE-918
- IntegerOverflow
- test
- example-tests/snippets
- experimental
- CWE-1004
- CWE-321-V2
- CWE-522-DecompressionBombs
- CWE-74
- CWE-918
- library-tests/semmle/go
- dataflow
- ChannelField
- DefaultTaintSanitizer
- ExternalTaintFlow
- ExternalValueFlow
- FlowSteps
- FunctionInputsAndOutputs
- PostUpdateNodes
- PromotedFields
- ReadsAndWrites
- flowsources/local/database
- frameworks
- BeegoOrm
- Beego
- Echo
- Email
- Encoding
- Fasthttp
- Gin
- GoMicro
- Gorestful
- Revel
- StdlibTaintFlow
- TaintSteps
- Twirp
- WebSocket
- XNetHtml
- Yaml
- security/SafeUrlFlow
- query-tests
- InconsistentCode/MistypedExponentiation
- Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- CWE-209
- CWE-295/DisabledCertificateCheck
- CWE-312
- CWE-338/InsecureRandomness
- CWE-601/OpenUrlRedirect
- CWE-640
- CWE-918
- javascript
- documentation
- downgrades
- 76a926a00d5f3bc199c203a1437796fd7b2835ba
- 80b2bc24189307c5fd178dc2da95b45bcdb117f7
- extractor
- lib/typescript
- src
- src/com/semmle
- jcorn
- flow
- js
- ast
- extractor
- ts/extractor
- ql
- integration-tests/query-suite
- lib
- change-notes/released
- ext
- semmle/javascript
- dataflow
- internal
- frameworks
- AngularJS
- data/internal
- internal
- flow_summaries
- security
- dataflow
- upgrades
- 76a926a00d5f3bc199c203a1437796fd7b2835ba
- ccefb5e2d49318eea4aeafd4c6ae2af9f94ac72a
- src
- Comments
- DOM
- Declarations
- LanguageFeatures
- Performance
- RegExp
- Security
- CWE-116
- CWE-942
- examples
- Statements
- change-notes/released
- experimental/Security
- CWE-918
- CWE-942
- test
- experimental
- FormParsers
- Security
- CWE-094-dataURL
- CWE-099
- EnvValueAndKeyInjection
- EnvValueInjection
- CWE-347
- localsource
- remotesource
- CWE-918
- CWE-942
- library-tests
- CallGraphs/FullTest
- DataFlow
- DefUse
- FlowSummary
- GlobalAccessPaths
- Portals
- src
- bluebird
- cyclic
- m1
- m2
- m3
- m4
- m5
- SSA
- GetRhsNode
- SSADefinition
- StringConcatenation
- TripleDot
- TypeScript
- ImportDefer
- RegressionTests
- EmptyName
- SemicolonInName
- frameworks
- AsyncPackage
- Electron
- Express
- src
- ReactJS
- koa
- xUnit
- query-tests
- LanguageFeatures/LengthComparisonOffByOne
- Security
- CWE-020/UntrustedDataToExternalAPI
- CWE-022
- TaintedPath
- ZipSlip
- CWE-073
- CWE-078
- CommandInjection
- IndirectCommandInjection
- SecondOrderCommandInjection
- UnsafeShellCommandConstruction
- CWE-079
- DomBasedXssWithResponseThreat
- DomBasedXss
- ExceptionXss
- ReflectedXss
- StoredXss
- UnsafeHtmlConstruction
- UnsafeJQueryPlugin
- XssThroughDom
- CWE-089
- local-threat-source
- typed
- untyped
- CWE-094
- CodeInjection
- UnsafeDynamicMethodAccess
- CWE-116/IncompleteSanitization
- CWE-117
- CWE-200
- CWE-312
- CWE-327
- CWE-338
- CWE-346
- CWE-377
- CWE-400
- ReDoS
- RemotePropertyInjection
- RemovePropertyInjection
- CWE-506
- CWE-522-DecompressionBombs
- CWE-601
- ClientSideUrlRedirect
- ServerSideUrlRedirect
- CWE-611
- CWE-643
- CWE-730
- Threat-models-disabled
- Threat-models-enabled
- CWE-754
- CWE-770/ResourceExhaustion
- CWE-776
- CWE-798
- CWE-807
- CWE-829
- CWE-843
- CWE-915
- PrototypePollutingAssignment
- PrototypePollutingFunction
- PrototypePollutingMergeCall
- CWE-918
- CWE-942
- tutorials/Analyzing data flow in JavaScript/Local data flow
- resources
- java
- documentation/library-coverage
- downgrades/9f6026c400996c13842974b24f076a486ad1f69c
- ql
- integration-tests/java
- android-sample-kotlin-build-script-no-wrapper
- android-sample-no-wrapper
- android-sample-old-style-kotlin-build-script-no-wrapper
- android-sample-old-style-no-wrapper
- buildless-dependency-different-repository
- buildless-erroneous
- evaluation-to-constant-errortype
- maven_3_fetch_maven_4_wrapper
- app
- .mvn/wrapper
- src/main/java/testmaven
- query-suite
- lib
- change-notes
- released
- config
- experimental/quantum
- ext
- semmle/code
- configfiles
- java
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- dispatch
- internal
- frameworks
- android
- javaee/ejb
- regex
- security
- xml
- upgrades/1b8f5f4c747e4249f4731796ccaa0661c7434d8a
- src
- Advisory
- Declarations
- Documentation
- Java Objects
- Naming
- Statements
- Types
- DeadCode
- Language Abuse
- Likely Bugs
- Arithmetic
- Cloning
- Collections
- Comparison
- Concurrency
- Finalization
- Frameworks
- JUnit
- Swing
- Likely Typos
- Reflection
- Serialization
- Statements
- Termination
- Security/CWE/CWE-200/SpringBootActuatorsConfig
- Telemetry
- Violations of Best Practice
- Dead Code
- Implementation Hiding
- Magic Constants
- Naming Conventions
- Testing
- Undesirable Calls
- change-notes/released
- experimental
- Security/CWE/CWE-016
- quantum
- Analysis
- Examples
- utils/flowtestcasegenerator
- test-kotlin1/library-tests
- java-kotlin-collection-type-generic-methods
- reflection
- test-kotlin2/library-tests
- java-kotlin-collection-type-generic-methods
- reflection
- test
- experimental
- library-tests/quantum
- jca
- query-tests
- quantum/NonceReuse
- security/CWE-016
- library-tests
- compact-source-files
- dataflow
- kdf
- scoped-values
- flexible-constructors
- guards
- module-import-declarations
- query-tests
- CallsToSystemExit
- ExcessivePublicMethodMocking
- Nullness
- StartInConstructor
- VisibleForTestingAbuse
- packageone
- packagetwo
- security/CWE-200/semmle/tests/SpringBootActuatorsConfig
- Version1.0.x-1.4.x
- bad
- default
- false
- good
- Version1.5.x
- bad
- good
- Version2.x
- bad
- expose
- exposure-include
- all-exposed
- some-exposed
- good
- Version3.x
- bad
- all-exposed
- some-exposed
- good
- stubs
- junit-4.13
- org/junit
- function
- mockito-5.14/org/mockito
- internal
- creation
- handler
- progress
- util
- invocation
- mock
- plugins
- stubbing
- misc
- bazel
- 3rdparty
- py_deps
- tree_sitter_extractors_deps
- registry/modules/rules_dotnet
- 0.19.2-codeql.1
- patches
- scripts
- suite-helpers
- change-notes/released
- python
- extractor
- semmle
- tests/parser
- tsg-python
- src
- tsp
- ql
- integration-tests/query-suite
- lib
- analysis
- change-notes/released
- experimental/cryptography
- modules
- stdlib
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- objects
- regexp
- internal
- types
- src
- Classes
- CallsToInitDel
- examples
- Comparisons
- examples
- SubclassShadowing
- examples
- Exceptions
- Expressions
- Functions
- examples
- Imports
- Resources
- Security/CWE-327
- Statements
- Variables
- change-notes/released
- experimental/Security
- CWE-022bis
- CWE-208/TimingAttackAgainstHash
- meta/ClassHierarchy
- test
- 2/query-tests/Classes/equals-hash
- 3/query-tests/Classes
- equals-hash
- equals-ne
- experimental/query-tests/Security/CWE-208/TimingAttackAgainstHash
- library-tests
- dataflow
- fieldflow
- global-flow
- typetracking
- frameworks
- lxml
- psycopg2
- regex
- query-tests
- Classes
- equals-attr
- equals-hash
- equals-not-equals
- incomplete-ordering
- missing-del
- missing-init
- multiple
- multiple-del
- multiple-init
- subclass-shadowing
- Exceptions/general
- Expressions/Regex
- Functions
- IncorrectRaiseInSpecialMethod
- general
- overriding
- Resources/FileNotAlwaysClosed
- Security
- CWE-022-PathInjection
- CWE-776-XmlBomb
- analysis/jump_to_defn
- ql/ql
- src/codeql_ql/style
- test/queries
- performance/VarUnusedInDisjunct
- style
- Misspelling
- UseInstanceofExtension
- UseSetLiteral
- ruby
- extractor
- ql
- consistency-queries
- lib
- change-notes/released
- codeql/ruby
- controlflow
- internal
- dataflow/internal
- frameworks
- core
- data/internal
- http_clients
- regexp/internal
- security
- regexp
- utils/test
- src
- change-notes/released
- experimental/insecure-randomness/examples
- queries/performance
- test
- library-tests
- controlflow/graph
- dataflow/barrier-guards
- frameworks
- grape
- CONSISTENCY
- http_clients
- query-tests
- experimental/InsecureRandomness
- security/cwe-915
- rust
- ast-generator
- src
- downgrades
- b41e55c0dba14a139d01dbee713aca5efe5b818a
- dfade44a27bd44db996ae8c5095a11effc883aba
- extractor
- macros
- src
- generated
- translate
- ql
- integration-tests
- hello-project
- hello-workspace
- exe/src
- lib/src
- a_module
- qltest
- query-suite
- lib
- change-notes
- released
- codeql/rust
- controlflow
- internal
- generated
- dataflow
- internal
- elements
- internal
- generated
- frameworks
- asyncstd
- rustcrypto
- stdlib
- tokio
- internal
- security
- ext/generated
- upgrades
- 319c933d9615ccf40f363548cafd51d08c74a534
- b41e55c0dba14a139d01dbee713aca5efe5b818a
- utils/test
- src
- change-notes
- released
- queries
- diagnostics
- security
- CWE-117
- CWE-312
- CWE-319
- CWE-614
- CWE-696
- CWE-798
- CWE-918
- summary
- telemetry
- unusedentities
- test
- extractor-tests
- canonical_path_disabled
- canonical_path
- generated
- AsmExpr
- AssocTypeArg
- ClosureBinder
- ClosureExpr
- Const
- DynTraitTypeRepr
- Enum
- ExternBlock
- ExternCrate
- ForBinder
- ForTypeRepr
- Function
- ImplTraitTypeRepr
- Impl
- MacroBlockExpr
- MacroCall
- MacroDef
- MacroItems
- MacroRules
- MethodCallExpr
- Module
- NeverTypeRepr
- Path
- Static
- StmtList
- StructExpr
- StructPat
- Struct
- TraitAlias
- Trait
- TupleExpr
- TupleStructPat
- TypeAlias
- TypeBoundList
- TypeBound
- Union
- Use
- Variant
- WherePred
- macro-expansion
- CONSISTENCY
- library-tests
- controlflow-unstable
- controlflow
- dataflow
- closures
- global
- lambdas
- local
- CONSISTENCY
- models
- CONSISTENCY
- sources
- CONSISTENCY
- strings
- definitions
- elements
- operations
- stmtlist
- frameworks
- postgres
- CONSISTENCY
- rusqlite
- path-resolution
- CONSISTENCY
- my2
- my3
- my
- my4/my5
- sensitivedata
- type-inference
- CONSISTENCY
- variables
- CONSISTENCY
- query-tests
- diagnostics
- CONSISTENCY
- security
- CWE-020
- CWE-022
- src
- CWE-089
- CONSISTENCY
- CWE-117
- CONSISTENCY
- CWE-311
- CWE-312
- CONSISTENCY
- CWE-319
- CWE-327
- CONSISTENCY
- CWE-614
- CWE-696
- CONSISTENCY
- CWE-770/CONSISTENCY
- CWE-798
- CONSISTENCY
- CWE-825
- CONSISTENCY
- CWE-918
- CONSISTENCY
- unusedentities
- CONSISTENCY
- utils-tests/modelgenerator
- schema
- swift
- ql
- lib
- change-notes/released
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements/decl/internal
- security
- src
- change-notes/released
- third_party/resources
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,961 files changed
+168030
-64719
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
33 | 36 | | |
34 | 37 | | |
35 | 38 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
| 40 | + | |
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
25 | | - | |
| 25 | + | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
0 commit comments