File tree
968 files changed
+88914
-94404
lines changed- .github
- actions/fetch-codeql
- workflows
- config
- cpp
- downgrades
- 23f7cbb88a4eb29f30c3490363dc201bc054c5ff
- 34549c3b0937002f11037d01822ebe99442c1402
- ql
- lib
- change-notes
- released
- semmle/code/cpp
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow
- internal
- implementation/raw/internal
- models/implementations
- rangeanalysis
- security
- upgrades
- 19e31bf071f588bb7efd1e4d5a185ce4f6fbbd84
- 23f7cbb88a4eb29f30c3490363dc201bc054c5ff
- src
- Likely Bugs
- Likely Typos
- Memory Management
- Metrics/Internal
- Security/CWE
- CWE-253
- CWE-428
- CWE-704
- CWE-732
- change-notes
- released
- experimental/Security/CWE
- CWE-125
- CWE-273
- test
- experimental/query-tests/Security/CWE/CWE-125/semmle/tests
- library-tests
- builtins
- edg
- type_traits
- constants/strlen
- dataflow
- dataflow-tests
- taint-tests
- ir/ir
- templates/CPP-203
- vector_types
- query-tests
- Likely Bugs/Memory Management
- ReturnStackAllocatedMemory
- StrncpyFlippedArgs
- Security/CWE
- CWE-134/semmle/globalVars
- CWE-497/semmle/tests
- CWE-611
- csharp
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp/Extractor
- Semmle.Extraction.Tests
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- lib
- change-notes/released
- semmle/code/csharp
- controlflow/internal
- dataflow
- internal
- frameworks
- generated/dotnet
- microsoft/extensions
- system
- collections
- io
- security
- threading
- security
- cryptography
- dataflow
- flowsources
- src
- Telemetry
- change-notes
- released
- test
- experimental/Security Features
- CWE-1004
- CookieHttpOnlyFalseAspNetCore
- CookieBuilder
- NoPolicy
- UseCookiePolicyCallback
- CookieWithoutHttpOnlyAspNetCore
- NoPolicy
- UseCookiePolicyAlways
- UseCookiePolicyCallback
- UseCookiePolicyNone
- CWE-614
- RequireSSLAspNetCore
- NoPolicy
- UseCookiePolicyAlways
- UseCookiePolicyCallback
- UseCookiePolicyNone
- RequireSSLFalseAspNetCore
- CookieBuilder
- NoPolicy
- UseCookiePolicyCallback
- library-tests
- dataflow
- fields
- flowsources/aspremote
- library
- frameworks/ServiceStack
- query-tests/Security Features
- CWE-079/XSS
- CWE-089
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- CWE-601/UrlRedirect
- resources/stubs
- Microsoft.Extensions.Primitives/6.0.0
- Microsoft.NETCore.Platforms/5.0.0
- Microsoft.Win32.SystemEvents/5.0.0
- Newtonsoft.Json/13.0.1
- ServiceStack.Client
- 5.11.0
- 6.2.0
- ServiceStack.Common
- 5.11.0
- 6.2.0
- ServiceStack.Interfaces/6.2.0
- ServiceStack.OrmLite.SqlServer/6.2.0
- ServiceStack.OrmLite/6.2.0
- ServiceStack.Redis/5.11.0
- ServiceStack.Text/6.2.0
- ServiceStack/6.2.0
- System.Data.SqlClient/4.8.2
- System.Drawing.Common/5.0.2
- System.Security.AccessControl/4.7.0
- _frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- tools
- docs/codeql/codeql-cli
- go/ql
- lib
- change-notes/released
- semmle/go
- dataflow
- internal
- frameworks/stdlib
- security
- src
- RedundantCode
- change-notes
- released
- experimental/CWE-807
- javascript
- extractor/src/com/semmle/js/extractor
- trapcache
- ql
- experimental/adaptivethreatmodeling
- modelbuilding/extraction
- test/endpoint_large_scale
- lib
- change-notes/released
- semmle/javascript
- dataflow
- internal
- frameworks
- AngularJS
- src
- Declarations
- Expressions
- Security/CWE-200
- change-notes/released
- test
- library-tests
- Arrays
- RecursionPrevention
- query-tests/Performance/ReDoS
- lib/subLib5
- java
- documentation/library-coverage
- kotlin-extractor/src/main/kotlin
- utils/versions
- v_1_4_32
- v_1_5_0
- v_1_5_10
- v_1_5_21
- v_1_5_31
- v_1_6_10
- v_1_6_20
- v_1_7_0
- ql
- consistency-queries
- lib
- change-notes
- released
- semmle/code/java
- dataflow/internal
- dispatch
- frameworks
- android
- guava
- spring
- regex
- security
- src
- Likely Bugs
- Collections
- Comparison
- Security/CWE
- CWE-022
- CWE-295
- Telemetry
- Violations of Best Practice/Naming Conventions
- change-notes
- released
- test
- TestUtilities
- experimental/query-tests/security/CWE-200
- kotlin/library-tests
- exprs
- generic-instance-methods
- reflection
- underscore-parameters
- library-tests
- dataflow
- collections
- modulus-analysis
- range-analysis
- frameworks/android/asynctask
- literals
- booleanLiterals
- charLiterals
- doubleLiterals
- floatLiterals
- integerLiterals
- literals-numeric
- longLiterals
- nullLiterals
- stringLiterals
- printAst
- ssa
- types/sealed-classes
- wildcard-substitution
- xml
- query-tests/security
- CWE-022/semmle/tests
- CWE-295/ImproperWebVeiwCertificateValidation
- stubs
- apache-commons-io-2.6/org/apache/commons/io/output
- google-android-9.0.0/android
- app
- assist
- content
- media
- net/http
- os
- print
- text
- transition
- view
- accessibility
- textclassifier
- webkit
- widget
- window
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow
- new/internal
- old
- essa
- frameworks/internal
- pointsto
- src
- Security/CWE-020-ExternalAPIs
- change-notes/released
- test
- experimental/dataflow
- tainttracking
- commonSanitizer
- customSanitizer
- typetracking
- library-tests/ApiGraphs/py3
- query-tests/Security/CWE-022-TarSlip
- ql/ql
- src
- codeql_ql
- ast
- internal
- style
- queries
- performance
- style
- test/queries/style/Misspelling
- ruby/ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- controlflow
- dataflow/internal
- frameworks
- core
- data/internal
- src
- change-notes
- released
- test/library-tests
- ast
- concepts
- app/controllers
- dataflow
- hash-flow
- params
- summaries
- frameworks
- action_dispatch
- active_record
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- visitors
- integration-tests
- posix-only
- cross-references
- partial-modules
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- expr
- typerepr
- generated
- type
- src/queries/Security
- CWE-079
- CWE-135
- test
- TestUtilities
- extractor-tests
- comments
- generated
- Comment
- decl
- ConcreteVarDecl
- ModuleDecl
- ParamDecl
- type/ModuleType
- library-tests
- controlflow/graph
- dataflow
- dataflow
- taint
- query-tests/Security
- CWE-079
- CWE-135
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
968 files changed
+88914
-94404
lines changedLines changed: 4 additions & 14 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 | 6 |
| |
17 | 7 |
| |
18 | 8 |
| |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
23 | 13 |
| |
24 | 14 |
|
Lines changed: 6 additions & 10 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
8 | 9 |
| |
9 | 10 |
| |
10 | 11 |
| |
| |||
14 | 15 |
| |
15 | 16 |
| |
16 | 17 |
| |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 | 18 |
| |
26 | 19 |
| |
27 | 20 |
| |
28 | 21 |
| |
| 22 | + | |
| 23 | + | |
| 24 | + | |
29 | 25 |
| |
30 | 26 |
| |
31 | 27 |
| |
| |||
34 | 30 |
| |
35 | 31 |
| |
36 | 32 |
| |
37 |
| - | |
| 33 | + | |
38 | 34 |
| |
39 | 35 |
| |
40 | 36 |
| |
41 | 37 |
| |
42 | 38 |
| |
43 | 39 |
| |
44 | 40 |
| |
45 |
| - | |
| 41 | + | |
46 | 42 |
| |
47 | 43 |
| |
48 | 44 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
| 15 | + | |
15 | 16 |
| |
16 | 17 |
| |
17 | 18 |
| |
|
Lines changed: 80 additions & 83 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
3 | 3 |
| |
4 | 4 |
| |
5 | 5 |
| |
6 |
| - | |
7 |
| - | |
8 |
| - | |
9 |
| - | |
10 |
| - | |
11 |
| - | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
12 | 14 |
| |
13 |
| - | |
14 |
| - | |
| 15 | + | |
| 16 | + | |
15 | 17 |
| |
16 | 18 |
| |
17 |
| - | |
| 19 | + | |
18 | 20 |
| |
19 | 21 |
| |
20 | 22 |
| |
| |||
23 | 25 |
| |
24 | 26 |
| |
25 | 27 |
| |
26 |
| - | |
27 |
| - | |
28 |
| - | |
29 |
| - | |
30 |
| - | |
31 |
| - | |
32 |
| - | |
33 |
| - | |
34 |
| - | |
35 |
| - | |
36 |
| - | |
37 |
| - | |
38 |
| - | |
39 |
| - | |
40 |
| - | |
41 |
| - | |
42 |
| - | |
43 |
| - | |
44 |
| - | |
45 |
| - | |
46 |
| - | |
47 |
| - | |
48 |
| - | |
49 |
| - | |
50 |
| - | |
51 |
| - | |
52 |
| - | |
53 |
| - | |
54 |
| - | |
55 |
| - | |
56 |
| - | |
57 |
| - | |
58 |
| - | |
59 |
| - | |
60 |
| - | |
61 |
| - | |
62 |
| - | |
63 |
| - | |
64 |
| - | |
65 |
| - | |
66 |
| - | |
67 |
| - | |
68 |
| - | |
69 |
| - | |
70 |
| - | |
71 |
| - | |
72 |
| - | |
73 |
| - | |
74 |
| - | |
75 |
| - | |
76 |
| - | |
77 |
| - | |
78 |
| - | |
79 |
| - | |
80 |
| - | |
81 |
| - | |
82 |
| - | |
83 |
| - | |
84 |
| - | |
85 |
| - | |
86 |
| - | |
87 |
| - | |
88 |
| - | |
89 |
| - | |
90 |
| - | |
91 |
| - | |
92 |
| - | |
93 |
| - | |
94 |
| - | |
95 |
| - | |
96 |
| - | |
97 |
| - | |
98 |
| - | |
99 |
| - | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + |
Lines changed: 23 additions & 32 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
8 |
| - | |
9 | 8 |
| |
10 | 9 |
| |
11 | 10 |
| |
12 |
| - | |
13 |
| - | |
14 |
| - | |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
26 |
| - | |
27 |
| - | |
28 |
| - | |
29 |
| - | |
30 |
| - | |
31 |
| - | |
32 |
| - | |
33 |
| - | |
34 |
| - | |
35 |
| - | |
36 |
| - | |
37 |
| - | |
38 |
| - | |
39 |
| - | |
40 |
| - | |
41 |
| - | |
42 |
| - | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + |
Lines changed: 23 additions & 29 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
12 | 12 |
| |
13 | 13 |
| |
14 | 14 |
| |
15 |
| - | |
16 |
| - | |
17 |
| - | |
18 |
| - | |
19 |
| - | |
20 |
| - | |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
26 |
| - | |
27 |
| - | |
28 |
| - | |
29 |
| - | |
30 |
| - | |
31 |
| - | |
32 |
| - | |
33 |
| - | |
34 |
| - | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
35 | 33 |
| |
36 |
| - | |
37 |
| - | |
38 |
| - | |
39 |
| - | |
40 |
| - | |
41 |
| - | |
42 |
| - | |
43 |
| - | |
44 |
| - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + |
0 commit comments