File tree
803 files changed
+75677
-50804
lines changed- .github/workflows
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- ir/dataflow/internal
- semantic
- semmle/code/cpp
- commons
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa/internal
- raw/internal
- unaliased_ssa/internal
- src
- Architecture
- General Namespace-Level Information
- Refactoring Opportunities
- Best Practices
- Likely Errors
- Magic Constants
- Unused Entities
- Critical
- Diagnostics
- Likely Bugs
- Arithmetic
- Conversion
- Format
- Leap Year
- Memory Management
- OO
- Protocols
- Security/CWE
- CWE-022
- CWE-078
- CWE-089
- CWE-114
- CWE-129
- CWE-134
- CWE-170
- CWE-190
- CWE-253
- CWE-311
- CWE-313
- CWE-319
- CWE-457
- CWE-468
- CWE-676
- CWE-732
- CWE-807
- change-notes
- released
- experimental
- Best Practices
- Likely Bugs
- Security/CWE
- CWE-020
- CWE-1041
- CWE-120
- CWE-193
- CWE-359
- CWE-401
- CWE-670
- CWE-691
- CWE-754
- CWE-783
- CWE-787
- CWE-788
- jsf
- 4.06 Pre-Processing Directives
- 4.09 Style
- 4.10 Classes
- 4.11 Namespaces
- 4.13 Functions
- 4.15 Declarations and Definitions
- 4.21 Operators
- 4.22 Pointers and References
- 4.23 Type Conversions
- 4.25 Expressions
- test
- experimental/query-tests/Security/CWE
- CWE-020
- NoCheckBeforeUnsafePutUser
- semmle/tests
- CWE-1041/semmle/tests
- CWE-119
- CWE-193
- array-access
- pointer-deref
- CWE-359/semmle/tests
- CWE-401/semmle/tests
- CWE-670/semmle/tests
- CWE-691/semmle/tests
- CWE-754/semmle/tests
- CWE-783/semmle/tests
- CWE-788/semmle/tests
- semmle/tests
- library-tests
- dataflow
- dataflow-tests
- fields
- syntax-zoo
- query-tests
- Architecture/Refactoring Opportunities/ComplexFunctions
- Best Practices
- Likely Errors/Slicing
- Unused Entities
- UnusedLocals
- UnusedStaticVariables
- Critical
- FileClosed
- MemoryFreed
- MissingCheckScanf
- NewFree
- UnsafeUseOfThis
- Likely Bugs
- Arithmetic/BadAdditionOverflowCheck
- Conversion
- CastArrayPointerArithmetic
- ImplicitDowncastFromBitfield
- LossyFunctionResultCast
- Format/WrongTypeFormatArguments
- Linux_mixed_byte_wprintf
- Linux_mixed_word_size
- Linux_signed_chars
- Linux_two_byte_wprintf
- Linux_unsigned_chars
- Microsoft_no_wchar
- Microsoft
- Leap Year/Adding365DaysPerYear
- Memory Management
- ImproperNullTermination
- NtohlArrayNoBound
- UsingExpiredStackAddress
- Protocols
- RedundantNullCheckSimple
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- ArithmeticWithExtremeValues
- TaintedAllocationSize
- tainted
- CWE-197/SAMATE/IntegerOverflowTainted
- CWE-242/semmle/tests
- CWE-253
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests
- CWE-457/semmle/tests
- CWE-468/semmle/IncorrectPointerScaling
- CWE-676/semmle/PotentiallyDangerousFunction
- CWE-732
- CWE-772
- SAMATE
- semmle
- tests-file
- tests-memory
- CWE-807/semmle/TaintedCondition
- jsf/4.09 Style/AV Rule 53 54
- csharp/ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests/all-platforms/dotnet_run
- lib
- change-notes
- released
- semmle/code/csharp
- dataflow
- internal
- frameworks/microsoft
- security
- cryptography
- src
- change-notes
- released
- experimental/ir/implementation/unaliased_ssa/internal
- meta/frameworks
- test
- library-tests/frameworks/microsoft
- query-tests/Security Features/CWE-117
- docs
- codeql
- codeql-cli
- support/reusables
- ql-libraries/dataflow
- go/ql
- lib
- change-notes
- released
- src
- Diagnostics
- change-notes
- released
- javascript
- documentation
- extractor
- src/com/semmle
- jcorn
- flow
- js
- extractor
- parser
- tests/mozilla/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib/experimental/adaptivethreatmodeling
- test
- endpoint_large_scale
- endpoint_unit_tests
- generic_feature_testing
- lib
- change-notes
- released
- semmle/javascript/frameworks
- data/internal
- minimongo
- mongodb
- mssql
- mysql
- pg
- sequelize
- spanner
- sqlite3
- src
- change-notes
- released
- experimental/Summaries
- test
- ApiGraphs/typed
- library-tests
- Security/heuristics
- frameworks/SQL
- query-tests
- LanguageFeatures/SyntaxError
- Security
- CWE-089/untyped
- Summaries
- java
- kotlin-extractor
- src/main
- java/com/semmle/extractor/java
- kotlin
- comments
- utils/versions
- v_1_4_32
- v_1_5_20
- v_1_6_0
- v_1_7_0
- ql
- integration-tests/posix-only/kotlin/gradle_kotlinx_serialization
- lib
- change-notes
- released
- semmle/code/java
- dataflow
- internal
- frameworks/android
- regex
- security
- regexp
- src
- Advisory/Documentation
- Security/CWE/CWE-489
- Violations of Best Practice/Naming Conventions
- change-notes
- released
- experimental
- Security/CWE/CWE-552
- semmle/code/java/frameworks
- test
- experimental/query-tests/security
- CWE-200
- CWE-552
- kotlin/library-tests
- annotation-accessor-result-type
- classes
- comments
- exprs_typeaccess
- exprs
- methods
- library-tests
- dataflow/taintsources
- frameworks/android
- intent
- taint-database
- widget
- query-tests
- Javadoc
- security/CWE-489
- debuggable-attribute
- TestFalse
- TestNotSet
- Testbuild
- webview-debugging
- stubs
- android
- android
- accounts
- app
- content
- pm
- res
- loader
- database
- sqlite
- graphics
- drawable
- text
- hardware
- icu/util
- net
- os
- util
- view
- webkit
- com/android/internal
- org/xmlpull/v1
- google-android-9.0.0/android/app
- springframework-5.3.8/org/springframework/core/io
- misc/suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- src
- change-notes
- released
- test
- experimental/dataflow
- basic
- calls
- consistency
- coverage
- fieldflow
- global-flow
- match
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests
- ApiGraphs/py3
- frameworks
- django-orm
- flask
- query-tests/Security
- CWE-209-StackTraceExposure
- CWE-730-ReDoS
- ql/ql/src
- codeql_ql
- ast/internal
- style
- codeql
- queries
- diagnostics
- style
- ruby/ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- ast
- dataflow
- internal
- experimental
- frameworks
- core
- data/internal
- regexp
- src
- change-notes
- released
- test/library-tests
- dataflow
- array-flow
- call-sensitivity
- global
- summaries
- experimental
- frameworks
- active_record
- active_storage
- modules
- swift/ql
- lib/codeql/swift/dataflow/internal
- src/queries/Security
- CWE-135
- CWE-311
- test
- library-tests/dataflow/taint
- query-tests/Security
- CWE-079
- CWE-135
- CWE-311
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
803 files changed
+75677
-50804
lines changedLines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
43 | 43 |
| |
44 | 44 |
| |
45 | 45 |
| |
46 |
| - | |
| 46 | + | |
47 | 47 |
| |
48 | 48 |
| |
49 | 49 |
| |
|
Lines changed: 15 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
1 | 16 |
| |
2 | 17 |
| |
3 | 18 |
| |
|
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 5 deletions
This file was deleted.
Lines changed: 13 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 |
| - | |
2 |
| - | |
3 |
| - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
4 | 10 |
| |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
1 | 1 |
| |
2 |
| - | |
| 2 | + |
Lines changed: 127 additions & 12 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
20 | 20 |
| |
21 | 21 |
| |
22 | 22 |
| |
23 |
| - | |
| 23 | + | |
| 24 | + | |
24 | 25 |
| |
25 | 26 |
| |
26 | 27 |
| |
| |||
49 | 50 |
| |
50 | 51 |
| |
51 | 52 |
| |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
52 | 136 |
| |
53 | 137 |
| |
54 | 138 |
| |
| |||
63 | 147 |
| |
64 | 148 |
| |
65 | 149 |
| |
66 |
| - | |
| 150 | + | |
67 | 151 |
| |
68 | 152 |
| |
69 | 153 |
| |
70 |
| - | |
| 154 | + | |
71 | 155 |
| |
72 | 156 |
| |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
73 | 172 |
| |
74 | 173 |
| |
75 | 174 |
| |
76 | 175 |
| |
77 | 176 |
| |
78 |
| - | |
79 |
| - | |
80 |
| - | |
81 |
| - | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
82 | 181 |
| |
83 | 182 |
| |
84 | 183 |
| |
85 |
| - | |
86 |
| - | |
87 |
| - | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
88 | 188 |
| |
89 | 189 |
| |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
90 | 205 |
| |
91 | 206 |
| |
92 | 207 |
| |
93 | 208 |
| |
94 | 209 |
| |
95 | 210 |
| |
96 | 211 |
| |
97 |
| - | |
| 212 | + | |
98 | 213 |
| |
99 | 214 |
| |
100 | 215 |
| |
| |||
157 | 272 |
| |
158 | 273 |
| |
159 | 274 |
| |
160 |
| - | |
| 275 | + | |
161 | 276 |
| |
162 | 277 |
| |
163 | 278 |
| |
|
Lines changed: 7 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
558 | 558 |
| |
559 | 559 |
| |
560 | 560 |
| |
| 561 | + | |
| 562 | + | |
| 563 | + | |
561 | 564 |
| |
562 | 565 |
| |
563 | 566 |
| |
564 | 567 |
| |
565 | 568 |
| |
566 | 569 |
| |
567 |
| - | |
| 570 | + | |
568 | 571 |
| |
569 | 572 |
| |
570 | 573 |
| |
| |||
598 | 601 |
| |
599 | 602 |
| |
600 | 603 |
| |
601 |
| - | |
602 |
| - | |
603 | 604 |
| |
604 | 605 |
| |
605 |
| - | |
606 |
| - | |
607 |
| - | |
| 606 | + | |
608 | 607 |
| |
609 | 608 |
| |
610 | 609 |
| |
| |||
613 | 612 |
| |
614 | 613 |
| |
615 | 614 |
| |
616 |
| - | |
| 615 | + | |
617 | 616 |
| |
618 | 617 |
| |
619 | 618 |
| |
| |||
753 | 752 |
| |
754 | 753 |
| |
755 | 754 |
| |
756 |
| - | |
| 755 | + | |
757 | 756 |
| |
758 | 757 |
| |
759 | 758 |
| |
|
Lines changed: 7 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
558 | 558 |
| |
559 | 559 |
| |
560 | 560 |
| |
| 561 | + | |
| 562 | + | |
| 563 | + | |
561 | 564 |
| |
562 | 565 |
| |
563 | 566 |
| |
564 | 567 |
| |
565 | 568 |
| |
566 | 569 |
| |
567 |
| - | |
| 570 | + | |
568 | 571 |
| |
569 | 572 |
| |
570 | 573 |
| |
| |||
598 | 601 |
| |
599 | 602 |
| |
600 | 603 |
| |
601 |
| - | |
602 |
| - | |
603 | 604 |
| |
604 | 605 |
| |
605 |
| - | |
606 |
| - | |
607 |
| - | |
| 606 | + | |
608 | 607 |
| |
609 | 608 |
| |
610 | 609 |
| |
| |||
613 | 612 |
| |
614 | 613 |
| |
615 | 614 |
| |
616 |
| - | |
| 615 | + | |
617 | 616 |
| |
618 | 617 |
| |
619 | 618 |
| |
| |||
753 | 752 |
| |
754 | 753 |
| |
755 | 754 |
| |
756 |
| - | |
| 755 | + | |
757 | 756 |
| |
758 | 757 |
| |
759 | 758 |
| |
|
0 commit comments