File tree
1,402 files changed
+85084
-53848
lines changed- .devcontainer/swift
- .github/workflows
- config
- cpp/ql
- lib
- change-notes
- released
- semmle/code/cpp
- dataflow/internal
- tainttracking1
- tainttracking2
- internal
- ir/dataflow/internal
- tainttracking1
- tainttracking2
- tainttracking3
- src
- change-notes/released
- experimental/Security/CWE/CWE-670
- test
- TestUtilities
- experimental/query-tests/Security/CWE/CWE-670/semmle/tests
- library-tests
- dataflow/dataflow-tests
- declarationEntry/declarationEntry
- ir/ir
- lambdas/captures
- variables/global
- csharp
- extractor/Semmle.Extraction.CSharp
- Entities
- Statements
- Populators
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- lib
- change-notes
- released
- semmle/code/csharp
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- frameworks
- generated/dotnet
- microsoft
- extensions
- system
- collections
- componentmodel
- data
- io
- net
- runtime
- security
- cryptography
- text
- threading
- web/ui
- xml
- security/dataflow
- flowsinks
- flowsources
- src
- Diagnostics
- Telemetry
- change-notes
- released
- experimental/CWE-918
- utils/model-generator
- internal
- test
- TestUtilities
- library-tests
- csharp9-standalone
- dataflow
- external-models
- flowsources/aspremote
- library
- frameworks/EntityFramework
- query-tests/Security Features/CWE-079/XSS
- resources/stubs
- utils/model-generator
- docs/codeql/codeql-language-guides
- go
- codeql-tools
- extractor/cli/go-autobuilder
- ql
- lib
- change-notes
- released
- semmle/go
- dataflow
- barrierguardutil
- internal
- tainttracking1
- tainttracking2
- security
- src
- InconsistentCode
- Security/CWE-326
- change-notes/released
- experimental
- CWE-321
- CWE-369
- CWE-918
- test
- TestUtilities
- library-tests/semmle/go/dataflow/GuardingFunctions
- javascript
- downgrades
- c0664d5721c90dd32a5b167efea24f9cc6f57cfb
- initial
- extractor
- lib/typescript/src
- src/com/semmle
- js/extractor
- ts
- ast
- extractor
- ql
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- heuristics
- security
- dataflow
- internal
- upgrades/c1ee5346e068f6e0b687e75b4ba3f04a7382f4c4
- src
- Declarations
- change-notes/released
- meta
- alerts
- analysis-quality
- test
- library-tests/TypeTracking
- query-tests/Security/CWE-079/UnsafeHtmlConstruction
- java
- kotlin-extractor
- src/main/kotlin
- utils
- versions
- v_1_7_0-RC
- v_1_7_0
- ql
- consistency-queries
- integration-tests
- linux-only/kotlin
- custom_plugin
- plugin
- resources/META-INF/services
- use_java_library
- javasrc/extlib
- posix-only/kotlin
- enabling
- extractor_crash
- code
- gradle_groovy_app
- app
- src/main/kotlin/testProject
- gradle_kotlinx_serialization
- app
- src/main/kotlin/testProject
- java_kotlin_extraction_orders
- kotlin_compiler_java_source
- kotlin_file_import
- libsrc
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- kotlinc_multi
- logs
- nested_generic_types
- libsrc/extlib
- raw_generic_types
- libsrc/extlib
- lib
- change-notes
- released
- config
- semmle/code/java
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- frameworks
- android
- apache
- guava
- jackson
- javaee/jsf
- ratpack
- spring
- regex
- security
- upgrades
- 57c55f404a5954f0e738febf590ad5d49dd67b08
- b9225587bc0a643ae484ec215b9a6f19d17d0fc2
- src
- Likely Bugs
- Cloning
- Likely Typos
- Serialization
- Security/CWE
- CWE-022
- CWE-117
- Telemetry
- Violations of Best Practice/Naming Conventions
- change-notes
- released
- experimental
- Security/CWE
- CWE-020
- CWE-073
- CWE-200
- CWE-321
- CWE-400
- CWE-470
- CWE-552
- CWE-601
- semmle/code/java
- utils
- flowtestcasegenerator
- model-generator
- internal
- test
- TestUtilities
- kotlin/library-tests
- arrays-with-variances
- dataflow
- notnullexpr
- whenexpr
- enum
- exprs
- java-kotlin-collection-type-generic-methods
- java-lang-number-conversions
- java-list-kotlin-user
- lazy-val-multiple-constructors
- maps-iterator-overloads
- methods
- reflection
- stmts
- library-tests
- dataflow
- callback-dispatch
- collections
- external-models
- frameworks
- android
- content-provider
- flow-steps
- intent
- notification
- slice
- uri
- widget
- apache-collections
- guava/generated
- cache
- collect
- jackson
- javax-json
- json-java
- okhttp
- spring
- beans
- cache
- ui
- util
- webmultipart
- webutil
- stream
- logging
- optional
- regex
- query-tests
- NonSerializableField
- security
- CWE-094
- CWE-312
- utils/model-generator
- misc/suite-helpers
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- frameworks
- Stdlib
- security
- dataflow
- internal
- src
- Security
- CWE-295
- CWE-732
- analysis
- change-notes
- released
- experimental/semmle/python/security
- dataflow
- injection
- test
- TestUtilities
- experimental
- dataflow
- sensitive-data
- tainttracking
- commonSanitizer
- customSanitizer
- meta
- debug
- library-tests/frameworks
- aiohttp
- asyncpg
- httpx
- requests
- stdlib-py2
- stdlib
- urllib3
- query-tests
- Security
- CWE-295-RequestWithoutValidation
- CWE-732-WeakFilePermissions
- analysis/suppression
- ql
- extractor
- generator
- ql
- src
- codeql_ql
- ast
- internal
- style
- codeql
- files
- ide-contextual-queries
- queries
- diagnostics
- performance
- test
- TestUtilities
- callgraph
- queries/performance/VarUnusedInDisjunct
- ruby
- downgrades/4ba51641799d2aaa315c7323931e2dd2a94c9f9d
- extractor
- generator
- ql
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- dataflow
- internal
- tainttracking1
- tainttrackingforlibraries
- frameworks
- core
- internal
- data
- internal
- http_clients
- stdlib
- security
- internal
- performance
- upgrades/1199e154f5e9b3560297633c6ebb4dfe0b191ae4
- src
- change-notes
- released
- experimental
- decompression-api
- examples
- improper-memoization
- queries/security
- cwe-078
- cwe-089
- test
- TestUtilities
- library-tests
- ast/erb
- concepts
- app/controllers
- dataflow
- api-graphs
- barrier-guards
- hash-flow
- summaries
- frameworks
- action_cable
- active_support
- app/controllers/foo
- archive
- files
- railties
- stdlib
- query-tests
- experimental/improper-memoization
- security
- cwe-022
- cwe-601
- decompression-api
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- trap
- visitors
- integration-tests
- cross-references
- Sources/cross-references
- frontend-invocations
- hello-world
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- elements
- decl
- expr
- type
- frameworks/StandardLibrary
- generated
- decl
- expr
- type
- src/queries
- Security/CWE-135
- test
- extractor-tests
- declarations
- expressions
- files
- generated
- File
- decl
- AccessorDecl
- AssociatedTypeDecl
- ClassDecl
- ConcreteFuncDecl
- ConcreteVarDecl
- ConstructorDecl
- DestructorDecl
- EnumCaseDecl
- EnumDecl
- EnumElementDecl
- ExtensionDecl
- GenericTypeParamDecl
- IfConfigDecl
- ImportDecl
- InfixOperatorDecl
- MissingMemberDecl
- ModuleDecl
- OpaqueTypeDecl
- ParamDecl
- PatternBindingDecl
- PostfixOperatorDecl
- PoundDiagnosticDecl
- PrecedenceGroupDecl
- PrefixOperatorDecl
- ProtocolDecl
- StructDecl
- SubscriptDecl
- TopLevelCodeDecl
- TypeAliasDecl
- expr
- AnyHashableErasureExpr
- AppliedPropertyWrapperExpr
- ArchetypeToSuperExpr
- Argument
- ArrayExpr
- ArrayToPointerExpr
- ArrowExpr
- AssignExpr
- AutoClosureExpr
- AwaitExpr
- BinaryExpr
- BindOptionalExpr
- BooleanLiteralExpr
- BridgeToObjCExpr
- CallExpr
- CaptureListExpr
- ClassMetatypeToObjectExpr
- ClosureExpr
- CodeCompletionExpr
- CoerceExpr
- CollectionUpcastConversionExpr
- ConditionalCheckedCastExpr
- ConstructorRefCallExpr
- CovariantFunctionConversionExpr
- CovariantReturnConversionExpr
- DeclRefExpr
- DefaultArgumentExpr
- DerivedToBaseExpr
- DestructureTupleExpr
- DictionaryExpr
- DifferentiableFunctionExpr
- DifferentiableFunctionExtractOriginalExpr
- DiscardAssignmentExpr
- DotSelfExpr
- DotSyntaxBaseIgnoredExpr
- DotSyntaxCallExpr
- DynamicMemberRefExpr
- DynamicSubscriptExpr
- DynamicTypeExpr
- EditorPlaceholderExpr
- EnumIsCaseExpr
- ErasureExpr
- ExistentialMetatypeToObjectExpr
- FloatLiteralExpr
- ForceTryExpr
- ForceValueExpr
- ForcedCheckedCastExpr
- ForeignObjectConversionExpr
- FunctionConversionExpr
- IfExpr
- InOutExpr
- InOutToPointerExpr
- InjectIntoOptionalExpr
- IntegerLiteralExpr
- InterpolatedStringLiteralExpr
- IsExpr
- KeyPathApplicationExpr
- KeyPathDotExpr
- KeyPathExpr
- LazyInitializerExpr
- LinearFunctionExpr
- LinearFunctionExtractOriginalExpr
- LinearToDifferentiableFunctionExpr
- LoadExpr
- MagicIdentifierLiteralExpr
- MakeTemporarilyEscapableExpr
- MemberRefExpr
- MetatypeConversionExpr
- NilLiteralExpr
- ObjectLiteralExpr
- OneWayExpr
- OpaqueValueExpr
- OpenExistentialExpr
- OptionalEvaluationExpr
- OptionalTryExpr
- OtherConstructorDeclRefExpr
- OverloadedDeclRefExpr
- ParenExpr
- PointerToPointerExpr
- PostfixUnaryExpr
- PrefixUnaryExpr
- PropertyWrapperValuePlaceholderExpr
- ProtocolMetatypeToObjectExpr
- RebindSelfInConstructorExpr
- RegexLiteralExpr
- StringLiteralExpr
- StringToPointerExpr
- SubscriptExpr
- SuperRefExpr
- TapExpr
- TryExpr
- TupleElementExpr
- TupleExpr
- TypeExpr
- UnderlyingToOpaqueExpr
- UnevaluatedInstanceExpr
- UnresolvedDotExpr
- UnresolvedMemberChainResultExpr
- UnresolvedTypeConversionExpr
- VarargExpansionExpr
- pattern
- AnyPattern
- BindingPattern
- BoolPattern
- EnumElementPattern
- ExprPattern
- IsPattern
- NamedPattern
- OptionalSomePattern
- ParenPattern
- TuplePattern
- TypedPattern
- stmt
- BraceStmt
- BreakStmt
- CaseLabelItem
- CaseStmt
- ConditionElement
- ContinueStmt
- DeferStmt
- DoCatchStmt
- DoStmt
- FailStmt
- FallthroughStmt
- ForEachStmt
- GuardStmt
- IfStmt
- PoundAssertStmt
- RepeatWhileStmt
- ReturnStmt
- StmtCondition
- SwitchStmt
- ThrowStmt
- WhileStmt
- YieldStmt
- typerepr
- ArrayTypeRepr
- AttributedTypeRepr
- CompileTimeConstTypeRepr
- CompositionTypeRepr
- CompoundIdentTypeRepr
- DictionaryTypeRepr
- ErrorTypeRepr
- ExistentialTypeRepr
- FixedTypeRepr
- FunctionTypeRepr
- GenericIdentTypeRepr
- ImplicitlyUnwrappedOptionalTypeRepr
- InOutTypeRepr
- IsolatedTypeRepr
- MetatypeTypeRepr
- NamedOpaqueReturnTypeRepr
- OpaqueReturnTypeRepr
- OptionalTypeRepr
- OwnedTypeRepr
- PlaceholderTypeRepr
- ProtocolTypeRepr
- SilBoxTypeRepr
- SimpleIdentTypeRepr
- TupleTypeRepr
- type
- ArraySliceType
- BoundGenericClassType
- BoundGenericEnumType
- BoundGenericStructType
- BuiltinBridgeObjectType
- BuiltinDefaultActorStorageType
- BuiltinExecutorType
- BuiltinFloatType
- BuiltinIntegerLiteralType
- BuiltinIntegerType
- BuiltinJobType
- BuiltinNativeObjectType
- BuiltinRawPointerType
- BuiltinRawUnsafeContinuationType
- BuiltinUnsafeValueBufferType
- BuiltinVectorType
- ClassType
- DependentMemberType
- DictionaryType
- DynamicSelfType
- EnumType
- ErrorType
- ExistentialMetatypeType
- ExistentialType
- FunctionType
- GenericFunctionType
- GenericTypeParamType
- InOutType
- LValueType
- MetatypeType
- ModuleType
- NestedArchetypeType
- OpaqueTypeArchetypeType
- OpenedArchetypeType
- OptionalType
- ParenType
- PlaceholderType
- PrimaryArchetypeType
- ProtocolCompositionType
- ProtocolType
- SequenceArchetypeType
- SilBlockStorageType
- SilBoxType
- SilFunctionType
- SilTokenType
- StructType
- TupleType
- TypeAliasType
- TypeVariableType
- UnboundGenericType
- UnmanagedStorageType
- UnownedStorageType
- UnresolvedType
- VariadicSequenceType
- WeakStorageType
- statements
- types
- library-tests
- controlflow/graph
- dataflow/dataflow
- parent
- query-tests/Security/CWE-135
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,402 files changed
+85084
-53848
lines changedLines changed: 9 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + |
Lines changed: 25 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + |
Lines changed: 22 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + |
Lines changed: 20 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + |
Lines changed: 13 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + |
Lines changed: 12 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
18 | 23 |
| |
19 | 24 |
| |
20 | 25 |
| |
21 |
| - | |
22 |
| - | |
23 |
| - | |
24 |
| - | |
25 |
| - | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
26 | 30 |
| |
27 | 31 |
| |
28 |
| - | |
| 32 | + | |
29 | 33 |
| |
30 | 34 |
| |
31 |
| - | |
32 |
| - | |
| 35 | + | |
| 36 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
58 | 58 |
| |
59 | 59 |
| |
60 | 60 |
| |
| 61 | + | |
| 62 | + | |
| 63 | + |
Lines changed: 7 additions & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
15 | 15 |
| |
16 | 16 |
| |
17 | 17 |
| |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
18 | 24 |
| |
19 | 25 |
| |
20 | 26 |
| |
| |||
40 | 46 |
| |
41 | 47 |
| |
42 | 48 |
| |
43 |
| - | |
| 49 | + | |
44 | 50 |
| |
45 | 51 |
| |
46 | 52 |
| |
|
Lines changed: 4 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
75 | 75 |
| |
76 | 76 |
| |
77 | 77 |
| |
78 |
| - | |
| 78 | + | |
| 79 | + | |
79 | 80 |
| |
80 | 81 |
| |
81 | 82 |
| |
| |||
527 | 528 |
| |
528 | 529 |
| |
529 | 530 |
| |
530 |
| - | |
| 531 | + | |
| 532 | + | |
531 | 533 |
| |
532 | 534 |
| |
533 | 535 |
| |
|
Lines changed: 6 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
1 | 7 |
| |
2 | 8 |
| |
3 | 9 |
| |
|
0 commit comments