File tree
2,360 files changed
+189944
-57709
lines changed- .github
- workflows
- config
- cpp
- downgrades
- 34549c3b0937002f11037d01822ebe99442c1402
- 73af5058c6899dcdb05754c27ca966aeb3a68c94
- f96ad9b2da43bbc9e55a72a165febd270ae07981
- ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp/semantic
- analysis
- semmle/code/cpp
- controlflow
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- internal
- raw
- internal
- unaliased_ssa
- internal
- models
- implementations
- interfaces
- security
- upgrades
- 23f7cbb88a4eb29f30c3490363dc201bc054c5ff
- 34549c3b0937002f11037d01822ebe99442c1402
- 73af5058c6899dcdb05754c27ca966aeb3a68c94
- src
- Best Practices
- Likely Errors
- Documentation
- Likely Bugs
- Arithmetic
- Likely Typos
- Memory Management
- OO
- Metrics/Internal
- Security/CWE
- CWE-020
- ir
- CWE-078
- CWE-295
- CWE-311
- CWE-497
- change-notes
- released
- experimental/Security/CWE
- CWE-125
- CWE-190
- jsf/4.10 Classes
- test
- TestUtilities
- dataflow
- library-tests
- constants/strlen
- dataflow/DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- globals
- files
- ir
- ir
- range-analysis
- syntax-zoo
- query-tests
- Best Practices/Likely Errors/EmptyBlock
- Documentation/CommentedOutCode
- Likely Bugs/Arithmetic
- BitwiseSignCheck
- FloatComparison
- csharp
- documentation/library-coverage
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- lib
- change-notes
- released
- semmle/code
- asp
- cil
- internal
- csharp
- controlflow/internal
- pressa
- dataflow
- internal
- basessa
- exprs
- frameworks
- generated/dotnet
- microsoft
- extensions
- system
- collections
- componentmodel
- data
- io
- net
- runtime
- security
- cryptography
- text
- threading
- web/ui
- xml
- security/dataflow
- flowsources
- src
- Bad Practices
- Comments
- Naming Conventions
- Concurrency
- Configuration
- Likely Bugs
- Collections
- Statements
- Security Features
- CWE-011
- CWE-016
- CWE-548
- CWE-614
- CWE-730
- Stubs
- Telemetry
- Useless code
- change-notes
- released
- experimental
- Security Features
- CWE-1004
- CWE-614
- ir/implementation
- internal
- raw
- internal
- desugar/internal
- unaliased_ssa
- internal
- utils/model-generator
- internal
- test
- TestUtilities
- library-tests
- csharp9
- dataflow
- external-models
- flowsources/aspremote
- library
- ssa-large
- ssa
- frameworks/EntityFramework
- query-tests
- Bad Practices/Comments/TodoComments
- EmptyBlock
- Likely Bugs
- BadCheckOdd
- Collections/ContainerLengthCmpOffByOne
- RandomUsedOnce
- RecursiveEquals
- UncheckedCastInEquals
- ReadOnlyContainer
- Security Features
- CWE-079/XSS
- CWE-089
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- CWE-730/RegexInjection
- Stubs
- All
- Minimal
- Telemetry/LibraryUsage
- UseBraces
- Useless Code/RedundantToStringCall
- resources/stubs
- Newtonsoft.Json/13.0.1
- Stub.System.Data.SQLite.Core.NetStandard/1.0.116
- System.Data.SQLite.Core/1.0.116
- System.Data.SQLite.EF6/1.0.116
- System.Data.SQLite/1.0.116
- _frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- utils/model-generator
- tools
- docs/codeql/support/reusables
- go
- codeql-tools
- extractor/srcarchive
- ql
- lib
- change-notes
- released
- semmle/go
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- Security
- CWE-020
- CWE-022
- CWE-209
- CWE-352
- CWE-643
- change-notes
- released
- experimental
- CWE-285
- CWE-79
- CWE-807
- InconsistentCode
- test
- TestUtilities
- experimental
- CWE-79
- CWE-942
- library-tests/semmle/go
- dataflow
- ChannelField
- ExternalFlow
- FlowSteps
- frameworks
- Beego
- NoSQL
- Revel
- examples/booking/app/controllers
- SQL
- StdlibTaintFlow
- WebSocket
- query-tests/Security
- CWE-022
- CWE-209
- CWE-643
- vendor
- golang.org/x
- mod
- modfile
- module
- semver
- sys
- execabs
- tools
- go
- gcexportdata
- internal
- gcimporter
- pkgbits
- packages
- internal
- gocommand
- packagesinternal
- typeparams
- typesinternal
- xerrors
- internal
- javascript
- extractor
- src/com/semmle
- jcorn
- js/extractor
- tests/esnext
- input
- output/trap
- ql
- experimental/adaptivethreatmodeling
- lib
- modelbuilding/evaluation
- src
- test/endpoint_large_scale
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- frameworks
- security
- dataflow
- internal
- performance
- regexp
- src
- Declarations
- Expressions
- LanguageFeatures
- Metrics
- Performance
- Security
- CWE-020
- CWE-022
- CWE-078
- CWE-116
- CWE-134
- CWE-178
- CWE-338
- CWE-643
- Statements
- change-notes
- released
- test
- library-tests
- DataFlow
- InterProceduralFlow
- NPM/src
- TaintTracking
- TypeTracking
- XML
- frameworks
- Collections
- HTTP-heuristics
- Testing/customised
- query-tests
- Declarations/UnusedParameter
- Expressions/BitwiseSignCheck
- Performance/ReDoS
- Security
- CWE-020/SuspiciousRegexpRange
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-116/IncompleteSanitization
- CWE-134
- CWE-178
- CWE-338
- CWE-400/ReDoS
- lib
- moduleLib
- otherLib
- js/src
- subLib4
- subLib5
- sublib
- regexplib
- CWE-643
- CWE-915
- PrototypePollutingAssignment
- PrototypePollutingFunction
- Statements/NestedLoopsSameVariable
- java
- documentation/library-coverage
- downgrades
- ecb42310286011ada450ff65b9b417509863549f
- initial
- kotlin-extractor
- src/main/kotlin
- utils
- versions
- v_1_4_32
- v_1_5_0
- v_1_5_10
- v_1_5_20
- v_1_5_21
- v_1_5_31
- v_1_6_0
- v_1_6_10
- v_1_6_20
- v_1_7_0
- v_1_7_20-Beta
- ql
- consistency-queries
- integration-tests
- linux-only/kotlin/custom_plugin
- posix-only/kotlin/trap_compression
- lib
- change-notes
- released
- config
- semmle/code
- java
- dataflow
- internal
- deadcode
- dispatch
- frameworks
- android
- apache
- camel
- guava
- gwt
- j2objc
- javaee
- ejb
- jsf
- spring
- struts
- metrics
- regex
- security
- performance
- regexp
- xml
- upgrades
- 37f33da42d2cffa6ad8b26feaa6beed1c5ce3149
- 57c55f404a5954f0e738febf590ad5d49dd67b08
- 81ccfabe82e696953268e784979262e56871ce86
- 89a76edebff191538968a6b25d22ada661ffa59a
- b9225587bc0a643ae484ec215b9a6f19d17d0fc2
- cf58c7d9b1fa1eae9cdc20ce8f157c140ac0c3de
- src
- DeadCode
- Likely Bugs
- Comparison
- Serialization
- Metrics/Files
- Security/CWE
- CWE-020
- CWE-023
- CWE-089
- CWE-113
- CWE-1204
- CWE-200
- CWE-319
- CWE-489
- CWE-611
- CWE-681
- CWE-730
- CWE-780
- CWE-798
- CWE-926
- Telemetry
- Violations of Best Practice
- Comments
- Dead Code
- Implementation Hiding
- legacy
- change-notes
- released
- experimental
- Security/CWE
- CWE-089
- CWE-1204
- CWE-297
- CWE-327
- CWE-522
- CWE-552
- CWE-555
- CWE-611
- CWE-730
- semmle/code/xml
- external
- semmle/code/xml
- utils/model-generator
- internal
- test
- TestUtilities
- experimental/query-tests/security
- CWE-078
- CWE-094
- CWE-200
- CWE-555
- CWE-730
- CWE-755
- kotlin/library-tests
- comments
- data-classes
- fake_overrides/kotlin_calling_java
- reflection
- library-tests
- dataflow
- external-models
- local-additional-taint
- modulus-analysis
- range-analysis
- frameworks
- android
- fragments
- sources
- spring/webutil
- gwt
- j2objc
- literals
- booleanLiterals
- charLiterals
- doubleLiterals
- floatLiterals
- integerLiterals
- literals-numeric
- longLiterals
- nullLiterals
- stringLiterals
- paths
- printAst
- ssa
- types/sealed-classes
- xml
- query-tests
- MissingInstanceofInEquals
- StaticArray
- UnreadLocal
- dead-code/UselessParameter
- security
- CWE-020
- CWE-023/semmle/tests
- CWE-1204
- CWE-266
- CWE-470
- CWE-489
- TestFalse
- TestNotSet
- Testbuild
- CWE-502
- CWE-611
- CWE-730
- CWE-749
- CWE-780
- CWE-798/semmle/tests
- CWE-926
- TestApplicationPermission
- Testbuild
- stubs
- apache-commons-net-3.8.0/org/apache/commons/net
- ftp
- apache-mina-sshd-2.8.0/org
- apache/sshd
- agent
- common
- client
- auth
- hostbased
- keyboard
- password
- pubkey
- channel
- config
- hosts
- keys
- future
- keyverifier
- session
- forward
- simple
- common
- auth
- channel
- throttle
- cipher
- compression
- config/keys
- digest
- file
- forward
- future
- helpers
- io
- kex
- extension
- keyprovider
- mac
- random
- session
- helpers
- signature
- util
- buffer
- keys
- closeable
- io/functors
- logging
- net
- threads
- server
- forward
- x11
- slf4j
- ganymed-ssh-2-260/ch/ethz/ssh2
- google-android-9.0.0/androidx
- core
- app
- content
- view
- fragment/app
- lifecycle
- loader/app
- savedstate
- j2ssh-1.5.5/com/sshtools/j2ssh/authentication
- jsch-0.1.55/com/jcraft/jsch
- mongodbClient/com/mongodb
- annotations
- lang
- sshj-0.33.0
- com/hierynomus/sshj/common
- net/schmizz/sshj
- common
- connection/channel/direct
- transport
- userauth
- trilead-ssh2-212/com/trilead/ssh2
- utils/model-generator
- misc/scripts/models-as-data
- python
- ql
- lib
- change-notes
- released
- semmle/python
- dataflow
- new
- internal
- old
- essa
- frameworks
- internal
- pointsto
- security
- internal
- performance
- regexp
- strings
- types
- xml
- src
- Exceptions
- Lexical
- Resources
- Security
- CWE-020-ExternalAPIs
- CWE-020
- CWE-022
- CWE-078
- CWE-209
- CWE-295
- CWE-327
- CWE-502
- CWE-643
- CWE-730
- Statements
- Variables
- change-notes
- released
- experimental
- Security
- CWE-091
- CWE-348
- semmle/python
- frameworks
- security
- injection
- test
- TestUtilities
- experimental/query-tests/Security/CWE-091
- library-tests
- PointsTo/new
- formatting
- jump_to_defn
- query-tests
- Exceptions/general
- Lexical/commented_out_code
- Security
- CWE-020-SuspiciousRegexpRange
- CWE-022-PathInjection
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-209-StackTraceExposure
- CWE-502-UnsafeDeserialization
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-ReDoS
- Statements/unreachable
- Variables
- unused_local_nonlocal
- unused
- tools/recorded-call-graph-metrics/ql/lib
- ql
- extractor
- src
- generator
- src
- ql
- src
- codeql_ql
- ast
- internal
- style
- queries
- diagnostics
- style
- docs
- test
- TestUtilities
- callgraph
- modules
- printAst
- queries/style
- Misspelling
- RedundantOverride
- scripts
- ruby/ql
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow/internal
- dataflow/internal
- frameworks
- core
- data/internal
- regexp
- security
- internal
- performance
- regexp
- src
- change-notes
- released
- queries
- security
- cwe-020
- cwe-022
- cwe-079
- cwe-094
- cwe-116
- cwe-117
- examples
- cwe-1333
- cwe-352
- cwe-611
- variables
- test
- TestUtilities
- library-tests
- ast
- dataflow
- params
- type-tracker
- frameworks
- app/controllers/foo
- security
- query-tests/security
- cwe-020/SuspiciousRegexpRange
- cwe-022
- cwe-079
- cwe-094
- cwe-116/IncompleteMultiCharacterSanitization
- cwe-117
- app/controllers
- cwe-1333-exponential-redos
- cwe-611
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- visitors
- integration-tests/posix-only/cross-references
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- pattern
- stmt
- typerepr
- type
- generated
- decl
- expr
- pattern
- stmt
- type
- src/queries/Security
- CWE-079
- CWE-135
- test
- TestUtilities
- extractor-tests
- declarations
- expressions
- generated
- decl
- AccessorDecl
- AssociatedTypeDecl
- ClassDecl
- ConcreteFuncDecl
- ConcreteVarDecl
- EnumDecl
- IfConfigDecl
- ImportDecl
- ModuleDecl
- ParamDecl
- expr
- ConstructorRefCallExpr
- DotSyntaxCallExpr
- EnumIsCaseExpr
- MethodRefExpr
- patterns
- statements
- types
- library-tests
- controlflow/graph
- dataflow
- dataflow
- taint
- elements/expr
- arithmeticoperation
- logicaloperation
- parent
- query-tests/Security
- CWE-079
- CWE-135
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,360 files changed
+189944
-57709
lines changedLines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
42 | 42 |
| |
43 | 43 |
| |
44 | 44 |
| |
| 45 | + |
Lines changed: 6 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
| 14 | + | |
15 | 15 |
| |
16 | 16 |
| |
17 |
| - | |
| 17 | + | |
18 | 18 |
| |
19 | 19 |
| |
20 | 20 |
| |
| |||
57 | 57 |
| |
58 | 58 |
| |
59 | 59 |
| |
60 |
| - | |
| 60 | + | |
61 | 61 |
| |
62 | 62 |
| |
63 |
| - | |
| 63 | + | |
64 | 64 |
| |
65 | 65 |
| |
66 | 66 |
| |
| |||
87 | 87 |
| |
88 | 88 |
| |
89 | 89 |
| |
90 |
| - | |
| 90 | + | |
91 | 91 |
| |
92 | 92 |
| |
93 |
| - | |
| 93 | + | |
94 | 94 |
| |
95 | 95 |
| |
96 | 96 |
| |
|
Lines changed: 46 additions & 71 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
17 | 17 |
| |
18 | 18 |
| |
19 | 19 |
| |
20 |
| - | |
| 20 | + | |
21 | 21 |
| |
22 | 22 |
| |
23 | 23 |
| |
| |||
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
30 | 36 |
| |
| 37 | + | |
31 | 38 |
| |
32 | 39 |
| |
33 | 40 |
| |
34 |
| - | |
35 |
| - | |
| 41 | + | |
| 42 | + | |
36 | 43 |
| |
37 |
| - | |
| 44 | + | |
38 | 45 |
| |
39 | 46 |
| |
40 |
| - | |
41 |
| - | |
42 |
| - | |
| 47 | + | |
| 48 | + | |
43 | 49 |
| |
44 | 50 |
| |
45 |
| - | |
46 |
| - | |
47 |
| - | |
48 |
| - | |
49 |
| - | |
50 |
| - | |
51 |
| - | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
52 | 58 |
| |
53 | 59 |
| |
| 60 | + | |
54 | 61 |
| |
55 | 62 |
| |
56 | 63 |
| |
| |||
61 | 68 |
| |
62 | 69 |
| |
63 | 70 |
| |
64 |
| - | |
| 71 | + | |
65 | 72 |
| |
66 | 73 |
| |
67 | 74 |
| |
| |||
70 | 77 |
| |
71 | 78 |
| |
72 | 79 |
| |
73 |
| - | |
| 80 | + | |
74 | 81 |
| |
75 | 82 |
| |
76 |
| - | |
| 83 | + | |
77 | 84 |
| |
78 | 85 |
| |
79 |
| - | |
| 86 | + | |
80 | 87 |
| |
81 | 88 |
| |
82 |
| - | |
| 89 | + | |
83 | 90 |
| |
84 | 91 |
| |
85 |
| - | |
| 92 | + | |
86 | 93 |
| |
87 |
| - | |
88 |
| - | |
89 |
| - | |
90 |
| - | |
91 |
| - | |
92 |
| - | |
93 |
| - | |
94 |
| - | |
95 |
| - | |
96 | 94 |
| |
97 | 95 |
| |
98 |
| - | |
99 |
| - | |
100 |
| - | |
101 |
| - | |
102 |
| - | |
103 |
| - | |
104 |
| - | |
105 |
| - | |
106 |
| - | |
107 |
| - | |
108 |
| - | |
109 |
| - | |
110 |
| - | |
111 |
| - | |
112 |
| - | |
113 |
| - | |
114 |
| - | |
115 |
| - | |
116 |
| - | |
117 |
| - | |
118 |
| - | |
119 |
| - | |
120 |
| - | |
121 |
| - | |
122 |
| - | |
123 |
| - | |
124 |
| - | |
125 |
| - | |
126 |
| - | |
127 |
| - | |
128 |
| - | |
129 |
| - | |
130 |
| - | |
131 |
| - | |
132 |
| - | |
133 |
| - | |
| 96 | + | |
| 97 | + | |
134 | 98 |
| |
135 |
| - | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
136 | 105 |
| |
137 |
| - | |
138 | 106 |
| |
| 107 | + | |
| 108 | + | |
139 | 109 |
| |
140 | 110 |
| |
141 | 111 |
| |
| |||
149 | 119 |
| |
150 | 120 |
| |
151 | 121 |
| |
152 |
| - | |
153 |
| - | |
| 122 | + | |
| 123 | + | |
154 | 124 |
| |
155 | 125 |
| |
156 | 126 |
| |
157 | 127 |
| |
158 | 128 |
| |
159 |
| - | |
| 129 | + | |
160 | 130 |
| |
161 | 131 |
| |
162 | 132 |
| |
163 | 133 |
| |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
164 | 139 |
| |
165 | 140 |
| |
166 |
| - | |
| 141 | + | |
167 | 142 |
| |
168 | 143 |
| |
169 | 144 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
28 |
| - | |
| 28 | + | |
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
|
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 |
| - | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
| |||
44 | 44 |
| |
45 | 45 |
| |
46 | 46 |
| |
47 |
| - | |
| 47 | + | |
48 | 48 |
| |
49 | 49 |
| |
50 | 50 |
| |
|
Lines changed: 27 additions & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
485 | 485 |
| |
486 | 486 |
| |
487 | 487 |
| |
488 |
| - | |
489 |
| - | |
490 |
| - | |
491 |
| - | |
| 488 | + | |
| 489 | + | |
| 490 | + | |
| 491 | + | |
492 | 492 |
| |
493 | 493 |
| |
494 |
| - | |
495 |
| - | |
496 |
| - | |
497 |
| - | |
| 494 | + | |
| 495 | + | |
| 496 | + | |
| 497 | + | |
498 | 498 |
| |
499 | 499 |
| |
500 |
| - | |
501 |
| - | |
502 |
| - | |
503 |
| - | |
| 500 | + | |
| 501 | + | |
| 502 | + | |
| 503 | + | |
| 504 | + | |
| 505 | + | |
| 506 | + | |
| 507 | + | |
| 508 | + | |
504 | 509 |
| |
505 | 510 |
| |
506 | 511 |
| |
507 | 512 |
| |
508 | 513 |
| |
509 | 514 |
| |
| 515 | + | |
| 516 | + | |
| 517 | + | |
| 518 | + | |
| 519 | + | |
| 520 | + | |
510 | 521 |
| |
511 | 522 |
| |
512 | 523 |
| |
| |||
586 | 597 |
| |
587 | 598 |
| |
588 | 599 |
| |
| 600 | + | |
| 601 | + | |
| 602 | + | |
| 603 | + | |
589 | 604 |
| |
590 | 605 |
|
Lines changed: 17 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + |
0 commit comments