File tree
2,354 files changed
+172133
-111742
lines changed- .github
- ISSUE_TEMPLATE
- actions
- cache-query-compilation
- fetch-codeql
- incremental-cache
- workflows
- .vscode
- config
- atm/ml-powered-queries-repo
- models
- cpp
- autobuilder
- Semmle.Autobuild.Cpp.Tests
- Semmle.Autobuild.Cpp
- ql
- examples
- lib
- change-notes
- released
- experimental/semmle/code/cpp/ir/dataflow/internal
- semmle/code/cpp
- dataflow/internal
- ir/dataflow
- internal
- models/implementations
- security
- valuenumbering
- src
- Likely Bugs
- Format
- Memory Management
- OO
- Metrics/Dependencies
- change-notes/released
- jsf
- 4.09 Style
- 4.10 Classes
- test
- experimental/query-tests/Security/CWE/CWE-193/pointer-deref
- library-tests
- dataflow
- dataflow-tests
- fields
- taint-tests
- syntax-zoo
- valuenumbering/GlobalValueNumbering
- query-tests
- Critical/UnsafeUseOfThis
- Likely Bugs
- Format/WrongNumberOfFormatArguments
- Memory Management/ReturnStackAllocatedMemory
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-120/semmle/tests
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- TaintedAllocationSize
- tainted
- CWE-290/semmle/AuthenticationBypass
- CWE-807/semmle/TaintedCondition
- jsf/4.10 Classes/AV Rule 76
- csharp
- actions/create-extractor-pack
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CIL
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util.Tests
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- test
- consistency-queries
- examples
- integration-tests/posix-only
- dotnet_test
- inherit-env-vars
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- generated
- semmle/code
- cil/internal
- csharp
- controlflow/internal
- dataflow
- internal
- frameworks
- generated/dotnet
- microsoft
- extensions
- system
- collections
- componentmodel
- data
- io
- net
- runtime
- security
- cryptography
- text
- threading
- web/ui
- xml
- security/dataflow
- flowsinks
- flowsources
- src
- Bad Practices/Magic Constants
- Metrics/Summaries
- Security Features
- CWE-114
- CWE-321
- Telemetry
- change-notes/released
- meta/frameworks
- utils
- model-generator
- internal
- modelconverter
- modelgenerator/internal
- test
- experimental/Security Features/backdoor
- library-tests
- assemblies
- controlflow/graph
- csharp7
- csharp9
- dataflow
- external-models
- ext
- fields
- library
- local
- ssa-large
- ssa
- query-tests
- Bad Practices/Control-Flow/ConstantCondition
- Security Features
- CWE-114/AssemblyPathInjection
- CWE-321/HardcodedSymmetricEncryptionKey
- Telemetry
- LibraryUsage
- SupportedExternalSinks
- SupportedExternalSources
- scripts
- docs
- codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- codeql-overview
- ql-language-reference
- ql-training
- query-help
- reusables
- support
- reusables
- writing-codeql-queries
- go
- extractor/trap
- ql
- examples
- snippets
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- tainttracking1
- tainttracking2
- security
- src
- Metrics
- Security
- CWE-020
- CWE-190
- CWE-322
- CWE-327
- CWE-338
- CWE-352
- CWE-601
- change-notes
- released
- experimental
- CWE-400
- CWE-942
- InconsistentCode
- Unsafe
- test
- experimental/CWE-918
- library-tests/semmle/go
- dataflow/ExternalFlow
- frameworks
- BeegoOrm
- Beego
- Chi
- Echo
- Revel
- StdlibTaintFlow
- XNetHtml
- query-tests/Security
- CWE-022
- CWE-079
- CWE-312
- CWE-327
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- javascript
- downgrades/4d00210ca570d55c4833af11d3372b774dbc63f2
- extractor
- lib/typescript
- src
- src/com/semmle
- js
- ast
- extractor
- ts
- ast
- extractor
- tests
- ts
- input
- output/trap
- vue
- input
- output/trap
- yaml/output/trap
- ql
- examples
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- counting
- extraction
- model
- src
- test
- endpoint_large_scale
- endpoint_unit_tests
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- frameworks
- data/internal
- security
- dataflow
- internal
- regexp
- upgrades/c0664d5721c90dd32a5b167efea24f9cc6f57cfb
- src
- Declarations
- Security/CWE-078
- examples
- change-notes
- released
- experimental/Security/CWE-340
- test
- experimental/PoI
- library-tests
- DataFlow
- ESLint
- TypeScript/Types
- YAML
- frameworks
- Nest
- hapi
- src
- query-tests/Security
- CWE-078
- CommandInjection
- IndirectCommandInjection
- SecondOrderCommandInjection
- ShellCommandInjectionFromEnvironment
- UnsafeShellCommandConstruction
- lib
- subLib2
- subLib3
- subLib4
- subLib
- UselessUseOfCat
- lib/subLib
- CWE-079
- ExceptionXss
- ReflectedXss
- StoredXss
- UnsafeHtmlConstruction
- UnsafeJQueryPlugin
- XssThroughDom
- CWE-089/untyped
- CWE-094
- CodeInjection
- lib
- ExpressionInjection
- .github/workflows
- CWE-116/IncompleteSanitization
- CWE-312
- CWE-400/ReDoS
- lib
- CWE-915/PrototypePollutingAssignment
- sublib
- tutorials/Validating RAML-based APIs
- java
- documentation/library-coverage
- downgrades/44d61b266bebf261cb027872646262e645efa059
- kotlin-extractor
- src/main/kotlin
- comments
- utils
- versions
- v_1_4_32
- v_1_5_20
- v_1_7_20
- ql
- consistency-queries
- examples
- integration-tests
- all-platforms/kotlin
- compiler_arguments
- app
- src/main/kotlin/testProject
- default-parameter-mad-flow
- ext
- enabling
- enhanced-nullability
- external-property-overloads
- gradle_kotlinx_serialization
- java-interface-redeclares-tostring
- jvmoverloads-external-class
- kotlin-interface-inherited-default
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- nested_generic_types
- linux-only/kotlin/custom_plugin
- plugin
- posix-only/kotlin
- compiler_arguments
- default-parameter-mad-flow
- generic-extension-property
- lib
- change-notes
- released
- config
- ext
- experimental
- generated
- semmle/code
- java
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- apache
- guava
- jackson
- javaee/jsf
- kotlin
- ratpack
- spring
- regex
- security
- regexp
- xml
- upgrades/709f1d1fd04ffd9bbcf242f17b120f8a389949bd
- src
- Advisory
- Naming
- Statements
- Architecture/Dependencies
- DeadCode
- Likely Bugs
- Comparison
- Resource Leaks
- Serialization
- Statements
- Metrics/Summaries
- Security/CWE
- CWE-020
- CWE-326
- CWE-524
- CWE-730
- CWE-829
- Telemetry
- Violations of Best Practice
- Boolean Logic
- Dead Code
- Magic Constants
- Naming Conventions
- legacy
- change-notes
- released
- experimental/Security/CWE
- CWE-020
- CWE-073
- CWE-089
- CWE-200
- CWE-299
- CWE-321
- CWE-326
- CWE-400
- CWE-552
- CWE-625
- CWE-730
- utils
- flowtestcasegenerator
- model-generator
- internal
- modelconverter
- modelgenerator/internal
- stub-generator
- test
- experimental/query-tests/security
- CWE-089/src/main
- CWE-326
- CWE-730
- ext
- kotlin
- library-tests
- annotation_classes
- annotations/jvmName
- arrays-with-variances
- arrays
- call-int-to-char
- classes
- collection-literals
- comments
- controlflow
- basic
- dominance
- data-classes
- dataflow
- extensionMethod
- foreach
- func
- notnullexpr
- summaries
- whenexpr
- exprs_typeaccess
- exprs
- CONSISTENCY
- extensions
- fake_overrides
- all_kotlin
- kotlin_calling_java
- generic-inner-classes
- generic-instance-methods
- generics-location
- generics
- inherited-callee
- inherited-collection-implementation
- inherited-default-value
- internal-constructor-called-from-java
- internal-public-alias
- java-lang-number-conversions
- java-map-methods
- java_and_kotlin_internal
- java_and_kotlin
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmoverloads_generics
- jvmstatic-annotation
- lateinit
- literals
- maps-iterator-overloads
- methods
- modifiers
- multiple_files
- operator-overloads
- parameter-defaults
- reflection
- special-method-getters
- static-method-calls
- stmts
- super-method-calls
- this
- trap
- vararg
- variables
- query-tests
- AutoBoxing
- CloseReader
- CloseWriter
- ConfusingMethodSignature
- ConfusingOverloading
- DeadCode
- EmptyBlock
- MissingInstanceofInEquals
- MutualDependency
- NamingConventionsRefTypes
- NonSerializableField
- NonSerializableInnerClass
- OneStatementPerLine
- ReturnValueIgnored
- SimplifyBoolExpr
- UnderscoreIdentifier
- UnreadLocal
- UselessParameter
- WhitespaceContradictsPrecedence
- library-tests
- dataflow
- callback-dispatch
- collections
- external-models
- synth-global
- frameworks
- android
- content-provider-summaries
- intent
- notification
- apache-collections
- guava/generated/collect
- stream
- multiply-bounded-wildcards
- optional
- paths
- regex/parser
- wildcards-and-captured-types
- query-tests/security
- CWE-326
- CWE-524
- res/layout
- CWE-730
- CWE-829/semmle/tests
- CWE-927
- stubs/google-android-9.0.0/android/app
- utils
- flowtestcasegenerator
- model-generator
- dataflow
- p
- typebasedflow
- p
- misc
- bazel
- scripts/models-as-data
- suite-helpers
- change-notes/released
- python/ql
- consistency-queries
- examples
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- frameworks
- internal
- security
- dataflow
- internal
- regexp
- src
- Expressions
- Imports
- Security
- CWE-020
- CWE-116
- CWE-730
- change-notes
- released
- test
- experimental
- dataflow
- TestUtil
- basic
- calls
- consistency
- coverage
- enclosing-callable
- fieldflow
- global-flow
- match
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- unwanted-global-flow
- typetracking_imports/pkg
- typetracking
- variable-capture
- import-resolution
- attr_clash
- namespace_package
- package
- subpackage
- library-tests
- CallGraph-implicit-init
- foo_explicit/bar
- foo/bar
- CallGraph-xfail
- CallGraph
- code
- library-tests
- ApiGraphs/py3
- frameworks/django-orm
- query-tests
- Expressions/super
- Security
- CWE-020-ExternalAPIs
- CWE-312-CleartextLogging
- CWE-730-PolynomialReDoS
- CWE-730-ReDoS
- ql
- node-types/src
- ql
- consistency-queries
- examples
- src
- codeql_ql
- ast
- dependency
- performance
- codeql
- queries
- explore
- performance
- style
- summary
- test
- callgraph/packs/src
- printAst
- queries/style/NonDocBlock
- ruby
- actions/create-extractor-pack
- downgrades/1199e154f5e9b3560297633c6ebb4dfe0b191ae4
- node-types/src
- ql
- consistency-queries
- examples
- lib
- change-notes
- released
- codeql
- ruby
- ast
- controlflow
- internal
- dataflow
- internal
- frameworks
- core
- stdlib
- regexp
- internal
- security
- internal
- regexp
- src
- change-notes
- released
- experimental/weak-params
- queries
- security
- cwe-020
- cwe-078
- examples
- cwe-089
- cwe-116
- cwe-1333
- cwe-209
- examples
- cwe-327
- summary
- test
- library-tests
- controlflow/graph
- dataflow
- array-flow
- barrier-guards
- global
- hash-flow
- helpers
- local
- params
- ssa-flow
- string-flow
- summaries
- type-tracker
- frameworks
- action_cable
- action_controller
- controllers
- foo
- users
- active_storage
- active_support
- arel
- variables
- query-tests/security
- cwe-078
- CommandInjection
- UnsafeShellCommandConstruction
- impl
- sub
- cwe-079
- app/views/foo/stores
- cwe-089
- cwe-117
- app/controllers
- cwe-1333-exponential-redos
- cwe-134
- cwe-209
- cwe-327
- swift
- actions
- build-and-test
- database-upgrade-scripts
- run-integration-tests
- run-ql-tests
- codegen
- generators
- lib
- schema
- templates
- test
- downgrades
- abbb8c9e8408841c2bc12e3deb2305f062f5399e
- initial
- extractor
- infra
- invocation
- print_unextracted
- remapping
- translators
- trap
- visitors
- integration-tests
- posix-only
- cross-references
- frontend-invocations
- hello-world
- partial-modules
- ql
- lib
- codeql/swift
- controlflow/internal
- dataflow
- internal
- elements
- decl
- expr
- type
- frameworks
- StandardLibrary
- generated
- decl
- expr
- stmt
- type
- printast
- security
- upgrades
- ceca289a0ff56bcc88f72ad78a8fbff1d850922f
- initial
- src
- diagnostics/internal
- queries
- Security
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-135
- CWE-259
- CWE-311
- CWE-611
- CWE-760
- CWE-916
- Summary
- ide-contextual-queries
- test
- extractor-tests
- errors
- expressions
- generated
- Diagnostics
- decl
- ConcreteVarDecl
- IfConfigDecl
- MissingMemberDecl
- ModuleDecl
- OpaqueTypeDecl
- ParamDecl
- PoundDiagnosticDecl
- expr
- AppliedPropertyWrapperExpr
- ArrowExpr
- AwaitExpr
- BridgeToObjCExpr
- CodeCompletionExpr
- DotSelfExpr
- DynamicLookupExpr
- DynamicMemberRefExpr
- DynamicSubscriptExpr
- EditorPlaceholderExpr
- IdentityExpr
- ObjectLiteralExpr
- OverloadedDeclRefExpr
- PackExpr
- ParenExpr
- PostfixUnaryExpr
- PropertyWrapperValuePlaceholderExpr
- stmt
- FailStmt
- PoundAssertStmt
- type
- ErrorType
- NestedArchetypeType
- OpaqueTypeArchetypeType
- PackExpansionType
- PackType
- ParameterizedProtocolType
- PlaceholderType
- SequenceArchetypeType
- SilBlockStorageType
- SilBoxType
- SilFunctionType
- SilTokenType
- TypeVariableType
- run_under
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- flowsources
- taint
- elements/expr/bitwiseopration
- query-tests/Security
- CWE-094
- CWE-1204
- CWE-259
- CWE-311
- CWE-611
- CWE-760
- CWE-916
- third_party/swift-llvm-support/patches
- tools
- test/qltest
- expected_failure_codes
- extractor_env
- unexpected_return_code
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,354 files changed
+172133
-111742
lines changedLines changed: 0 additions & 24 deletions
This file was deleted.
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
10 | 10 |
| |
11 | 11 |
| |
12 | 12 |
| |
13 |
| - | |
| 13 | + | |
14 | 14 |
|
Lines changed: 36 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + |
Lines changed: 36 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + |
Lines changed: 11 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 | 2 |
| |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
3 | 10 |
| |
4 | 11 |
| |
5 | 12 |
| |
6 | 13 |
| |
7 | 14 |
| |
| 15 | + | |
| 16 | + | |
| 17 | + | |
8 | 18 |
| |
9 | 19 |
| |
10 |
| - | |
| 20 | + | |
11 | 21 |
| |
12 | 22 |
| |
13 |
| - | |
14 |
| - | |
|
Lines changed: 44 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
51 | 51 |
| |
52 | 52 |
| |
53 | 53 |
| |
| 54 | + | |
| 55 | + | |
| 56 | + |
Lines changed: 0 additions & 13 deletions
This file was deleted.
Lines changed: 93 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + |
Lines changed: 12 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + |
Lines changed: 39 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + |
0 commit comments