File tree
1,184 files changed
+51275
-13549
lines changed- .github/workflows
- config
- cpp
- change-notes
- ql
- lib
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- tainttracking1
- tainttracking2
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- raw
- unaliased_ssa
- internal
- models
- implementations
- interfaces
- rangeanalysis
- security
- src
- Critical
- Diagnostics
- Documentation
- Likely Bugs
- Arithmetic
- Memory Management
- Metrics/Internal
- Security/CWE
- CWE-078
- CWE-170
- CWE-311
- CWE-468
- CWE-570
- experimental/Security/CWE/CWE-1041
- external
- jsf/4.10 Classes
- test
- TestUtilities
- experimental/query-tests/Security/CWE/CWE-1041/semmle/tests
- include
- library-tests/dataflow/taint-tests
- query-tests
- Critical/OverflowStatic
- Likely Bugs/Memory Management/ImproperNullTermination
- Security/CWE
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-119/semmle/tests
- CWE-311/semmle/tests
- CWE-367/semmle
- upgrades
- 7806a11dd7ab6611c4245b2e96b8ed13cb5c6056
- csharp
- change-notes
- extractor/Semmle.Extraction.CSharp
- Extractor
- Populators
- ql
- examples
- lib
- semmle/code
- asp
- cil
- csharp
- commons
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- dispatch
- exprs
- frameworks
- microsoft
- system
- collections
- data
- text
- web
- security
- cryptography
- dataflow
- flowsources
- xml
- dotnet
- src
- Bad Practices/Control-Flow
- Dead Code
- Diagnostics
- Stubs
- experimental/ir
- implementation
- raw
- internal
- unaliased_ssa
- internal
- internal
- rangeanalysis
- test
- TestUtilities
- library-tests
- assignables
- cil/consistency
- dataflow
- external-models
- fields
- query-tests
- Bad Practices/Control-Flow/ConstantCondition
- Dead Code/DeadStoreOfLocal
- upgrades
- docs/codeql
- codeql-cli
- codeql-language-guides
- ql-language-reference
- ql-training
- cpp
- java
- slide-snippets
- reusables
- support
- javascript/ql
- examples
- lib
- Declarations
- Expressions
- LanguageFeatures
- semmle/javascript
- dataflow
- filters
- frameworks
- security
- performance
- src
- Comments
- Declarations
- Expressions
- LanguageFeatures
- Security
- CWE-020
- CWE-078
- CWE-094
- CWE-134
- CWE-730
- CWE-834
- CWE-912
- experimental/poi
- external
- filters
- test
- library-tests/PackageExports
- query-tests/Performance/ReDoS
- testUtilities
- java
- change-notes
- documentation/library-coverage
- ql
- examples
- lib
- semmle/code
- java
- dataflow
- internal
- rangeanalysis
- tainttracking1
- tainttracking2
- frameworks
- android
- apache
- gigaspaces
- google
- javaee/ejb
- spring
- security
- xml
- src
- Advisory/Documentation
- Likely Bugs
- Collections
- Comparison
- Concurrency
- Reflection
- Serialization
- Performance
- Security/CWE
- CWE-074
- CWE-094
- CWE-297
- CWE-502
- CWE-798
- Violations of Best Practice/Naming Conventions
- experimental/Security/CWE
- CWE-074
- CWE-094
- CWE-200
- CWE-297
- CWE-502
- utils
- flowtestcasegenerator
- stub-generator
- test
- TestUtilities
- experimental/query-tests/security
- CWE-074
- CWE-094
- CWE-200
- CWE-297
- CWE-755
- library-tests
- dataflow
- callback-dispatch
- taintsources
- frameworks
- android
- content-provider
- flow-steps
- intent
- apache-collections
- stream
- literals
- booleanLiterals
- charLiterals
- doubleLiterals
- floatLiterals
- integerLiterals
- literals-numeric
- literals
- longLiterals
- nullLiterals
- stringLiterals
- optional
- query-tests/security
- CWE-074
- CWE-079/semmle/tests
- CWE-094
- CWE-297
- CWE-502
- CWE-798/semmle/tests
- stubs
- Saxon-HE-9.9.1-7/net/sf/saxon
- lib
- om
- s9api
- android
- android
- accounts
- content
- pm
- res
- loader
- database
- sqlite
- graphics
- drawable
- text
- hardware
- icu/util
- net
- os
- util
- view
- org/xmlpull/v1
- apache-commons-collections4-4.4/org/apache/commons/collections4
- bag
- bidimap
- collection
- iterators
- keyvalue
- list
- map
- multimap
- multiset
- properties
- queue
- set
- splitmap
- trie
- azure-sdk-for-java/com/azure
- core/credential
- identity
- security/keyvault/secrets
- models
- google-android-9.0.0
- androidx/annotation
- android
- accounts
- annotation
- app
- content
- pm
- res
- database
- sqlite
- graphics
- drawable
- text
- hardware
- icu/util
- net
- os
- util
- view
- org/xmlpull/v1
- gson-2.8.6/com/google/gson
- reflect
- stream
- typeadapters
- jakarta-mail-2.0.1/jakarta/mail
- shiro-core-1.4.0/org/apache/shiro
- codec
- crypto
- mgt
- web/mgt
- springframework-5.3.8/org/springframework/expression
- common
- spel/standard
- python
- change-notes
- ql
- lib
- semmle/python
- concepts
- dataflow
- new/internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- old
- essa
- frameworks
- objects
- pointsto
- security
- dataflow
- injection
- performance
- templates
- types
- web
- xml
- src
- Functions
- Lexical
- Metrics/Internal
- Security
- CWE-730
- CWE-798
- analysis
- experimental
- Security
- CWE-117
- CWE-348
- semmle/python
- frameworks
- security/injection
- external
- test
- TestUtilities
- experimental
- dataflow
- coverage
- fieldflow
- module-initialization
- strange-essaflow
- typetracking
- meta
- query-tests/Security
- CWE-117
- CWE-348
- CWE-730
- library-tests
- PointsTo
- customise
- new
- frameworks
- cryptodome
- crypto
- dill
- stdlib
- taint/extensions
- query-tests/Security
- CWE-327-WeakSensitiveDataHashing
- CWE-730-RegexInjection
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,184 files changed
+51275
-13549
lines changedLines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
| 9 | + | |
| 10 | + | |
9 | 11 |
| |
10 | 12 |
| |
11 | 13 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
24 | 24 |
| |
25 | 25 |
| |
26 | 26 |
| |
| 27 | + | |
| 28 | + | |
| 29 | + |
Lines changed: 2 additions & 2 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
7 |
| - | |
8 |
| - | |
| 7 | + | |
| 8 | + | |
9 | 9 |
| |
10 | 10 |
| |
11 | 11 |
| |
|
Lines changed: 9 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
373 | 373 |
| |
374 | 374 |
| |
375 | 375 |
| |
| 376 | + | |
376 | 377 |
| |
377 | 378 |
| |
378 | 379 |
| |
| |||
478 | 479 |
| |
479 | 480 |
| |
480 | 481 |
| |
| 482 | + | |
| 483 | + | |
| 484 | + | |
| 485 | + | |
| 486 | + | |
| 487 | + | |
| 488 | + | |
| 489 | + | |
481 | 490 |
| |
482 | 491 |
|
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 2 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + |
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + |
Lines changed: 2 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
275 | 275 |
| |
276 | 276 |
| |
277 | 277 |
| |
278 |
| - | |
279 |
| - | |
280 |
| - | |
| 278 | + | |
| 279 | + | |
281 | 280 |
| |
282 | 281 |
| |
283 | 282 |
| |
|
0 commit comments