File tree
1,425 files changed
+125558
-17640
lines changed- .github
- workflows
- config
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp/semantic/analysis
- semmle/code/cpp
- commons
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa/internal
- internal
- unaliased_ssa/internal
- valuenumbering
- src
- Architecture/Refactoring Opportunities
- Best Practices
- Likely Errors
- Critical
- Documentation
- Likely Bugs
- Arithmetic
- Likely Typos
- Microsoft
- Security/CWE
- CWE-020
- ir
- CWE-295
- CWE-311
- CWE-457
- CWE-497
- CWE-611
- change-notes
- released
- jsf/3.02 Code Size and Complexity
- test
- TestUtilities/dataflow
- library-tests
- dataflow/DefaultTaintTracking
- annotate_path_to_sink
- annotate_sinks_only
- globals
- files
- pod
- sal
- query-tests
- Best Practices/Likely Errors/EmptyBlock
- Critical/MissingCheckScanf
- Documentation/CommentedOutCode
- Likely Bugs/Arithmetic
- BitwiseSignCheck
- FloatComparison
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- documentation/library-coverage
- downgrades/4ac7d8bcac6f664b1e83c858aa71f8dc761cc603
- extractor
- Semmle.Extraction.CSharp.Driver
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.Tests
- Semmle.Extraction
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- lib
- change-notes
- released
- experimental/code/csharp/Cryptography
- semmle/code
- asp
- cil
- internal
- csharp
- controlflow
- internal
- pressa
- dataflow
- internal
- basessa
- frameworks
- generated/dotnet
- microsoft
- security/dataflow
- flowsinks
- flowsources
- upgrades/a696c8bae067f69ab3208e98ce35f4fdf7efb68b
- src
- Bad Practices
- Comments
- Naming Conventions
- Concurrency
- Configuration
- Likely Bugs
- Collections
- Statements
- Security Features
- CWE-011
- CWE-016
- CWE-548
- CWE-614
- CWE-730
- Stubs
- Telemetry
- Useless code
- change-notes
- released
- experimental
- Security Features
- CWE-1004
- CWE-614
- ir/implementation
- internal
- raw/internal
- unaliased_ssa/internal
- utils/model-generator
- internal
- test
- library-tests
- dataflow
- external-models
- library
- ssa
- frameworks/EntityFramework
- query-tests
- Bad Practices/Comments/TodoComments
- EmptyBlock
- Likely Bugs
- BadCheckOdd
- Collections/ContainerLengthCmpOffByOne
- RandomUsedOnce
- RecursiveEquals
- UncheckedCastInEquals
- ReadOnlyContainer
- Security Features/CWE-730/RegexInjection
- Telemetry/LibraryUsage
- UseBraces
- Useless Code/RedundantToStringCall
- utils/model-generator
- tools
- linux64
- osx64
- win64
- docs/codeql
- codeql-overview
- ql-language-reference
- support/reusables
- go
- codeql-tools
- extractor/srcarchive
- ql
- lib
- change-notes
- released
- semmle/go
- dataflow
- frameworks
- stdlib
- security
- src
- RedundantCode
- Security
- CWE-020
- CWE-022
- CWE-209
- CWE-322
- CWE-352
- CWE-643
- change-notes
- released
- experimental
- CWE-285
- CWE-79
- test
- experimental
- CWE-79
- CWE-942
- library-tests/semmle/go
- dataflow
- ExternalFlow
- FlowSteps
- frameworks
- Beego
- NoSQL
- Revel
- examples/booking/app/controllers
- SQL
- StdlibTaintFlow
- query-tests/Security
- CWE-022
- CWE-209
- CWE-643
- vendor
- golang.org/x
- mod
- modfile
- module
- semver
- sys
- execabs
- tools
- go
- gcexportdata
- internal
- gcimporter
- pkgbits
- packages
- internal
- gocommand
- packagesinternal
- typeparams
- typesinternal
- xerrors
- internal
- javascript
- extractor
- lib/typescript
- src
- src/com/semmle
- js/extractor
- ts/extractor
- ql
- experimental/adaptivethreatmodeling
- lib
- modelbuilding
- evaluation
- extraction
- src
- test
- endpoint_large_scale
- modeled_apis
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- dependencies
- frameworks
- data/internal
- linters
- security
- dataflow
- regexp
- src
- Declarations
- Expressions
- Security
- CWE-022
- CWE-078
- CWE-134
- CWE-178
- CWE-338
- CWE-643
- CWE-830
- Statements
- change-notes
- released
- experimental/Security/CWE-094
- test
- library-tests
- DataFlow
- InterProceduralFlow
- TaintTracking
- TypeScript/Types
- XML
- YAML
- frameworks
- Collections
- GWT
- HTTP-heuristics
- NodeJSLib
- data
- query-tests
- Declarations/UnusedParameter
- Expressions/BitwiseSignCheck
- Security
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- lib/subLib4
- CWE-134
- CWE-178
- CWE-338
- CWE-400/ReDoS
- lib
- CWE-643
- CWE-915/PrototypePollutingAssignment
- Statements/NestedLoopsSameVariable
- tutorials/Validating RAML-based APIs
- java
- documentation/library-coverage
- downgrades
- ecb42310286011ada450ff65b9b417509863549f
- initial
- kotlin-extractor
- src/main/kotlin
- comments
- utils
- ql
- consistency-queries
- integration-tests
- linux-only/kotlin/custom_plugin
- posix-only/kotlin/trap_compression
- lib
- change-notes
- released
- config
- semmle/code
- java
- dataflow
- internal
- deadcode
- dispatch
- internal
- frameworks
- android
- apache
- camel
- gwt
- j2objc
- javaee
- ejb
- jsf
- spring
- struts
- metrics
- security
- regexp
- xml
- upgrades
- 37f33da42d2cffa6ad8b26feaa6beed1c5ce3149
- 57c55f404a5954f0e738febf590ad5d49dd67b08
- 81ccfabe82e696953268e784979262e56871ce86
- 89a76edebff191538968a6b25d22ada661ffa59a
- b9225587bc0a643ae484ec215b9a6f19d17d0fc2
- cf58c7d9b1fa1eae9cdc20ce8f157c140ac0c3de
- src
- DeadCode
- Frameworks/JavaEE/EJB
- Likely Bugs
- Comparison
- Serialization
- Security/CWE
- CWE-089
- CWE-113
- CWE-319
- CWE-611
- CWE-730
- CWE-780
- CWE-798
- CWE-926
- Telemetry
- Violations of Best Practice
- Comments
- Dead Code
- Exception Handling
- Implementation Hiding
- legacy
- change-notes
- released
- experimental
- Security/CWE
- CWE-089
- CWE-297
- CWE-326
- CWE-327
- CWE-522
- CWE-552
- CWE-555
- CWE-601
- CWE-611
- CWE-625
- CWE-730
- CWE-755
- semmle/code
- java/security
- xml
- external
- semmle/code/xml
- utils/model-generator
- internal
- test
- TestUtilities
- experimental/query-tests/security
- CWE-078
- CWE-094
- CWE-200
- CWE-555
- CWE-625
- CWE-730
- CWE-755
- kotlin/library-tests
- arrays
- comments
- data-classes
- java_and_kotlin_internal
- operator-overloads
- library-tests
- dataflow
- external-models
- taint
- frameworks
- android
- fragments
- sources
- spring/data
- gwt
- j2objc
- paths
- xml
- query-tests
- MissingInstanceofInEquals
- StaticArray
- UnreadLocal
- dead-code/UselessParameter
- security
- CWE-089/semmle/examples
- CWE-113/semmle/tests
- CWE-266
- CWE-470
- CWE-502
- CWE-601/semmle/tests
- CWE-611
- CWE-749
- CWE-780
- CWE-798/semmle/tests
- CWE-926
- TestApplicationPermission
- Testbuild
- stubs
- apache-commons-net-3.8.0/org/apache/commons/net
- ftp
- apache-mina-sshd-2.8.0/org
- apache/sshd
- agent
- common
- client
- auth
- hostbased
- keyboard
- password
- pubkey
- channel
- config
- hosts
- keys
- future
- keyverifier
- session
- forward
- simple
- common
- auth
- channel
- throttle
- cipher
- compression
- config/keys
- digest
- file
- forward
- future
- helpers
- io
- kex
- extension
- keyprovider
- mac
- random
- session
- helpers
- signature
- util
- buffer
- keys
- closeable
- io/functors
- logging
- net
- threads
- server
- forward
- x11
- slf4j
- ganymed-ssh-2-260/ch/ethz/ssh2
- google-android-9.0.0/androidx
- core
- app
- content
- view
- fragment/app
- lifecycle
- loader/app
- savedstate
- j2ssh-1.5.5/com/sshtools/j2ssh/authentication
- jsch-0.1.55/com/jcraft/jsch
- mongodbClient/com/mongodb
- annotations
- lang
- sshj-0.33.0
- com/hierynomus/sshj/common
- net/schmizz/sshj
- common
- connection/channel/direct
- transport
- userauth
- trilead-ssh2-212/com/trilead/ssh2
- utils/model-generator
- misc/scripts/models-as-data
- python
- ql
- lib
- change-notes
- released
- semmle/python
- dataflow
- new
- old
- frameworks
- data/internal
- security
- regexp
- strings
- xml
- src
- Exceptions
- Functions
- Lexical
- Resources
- Security
- CWE-020-ExternalAPIs
- CWE-022
- CWE-078
- CWE-090
- CWE-094
- CWE-117
- CWE-209
- CWE-295
- CWE-312
- CWE-327
- CWE-502
- CWE-601
- CWE-611
- CWE-643
- CWE-730
- CWE-776
- Statements
- Variables
- change-notes
- released
- experimental
- Security/CWE-091
- semmle/python
- frameworks
- libraries
- security
- injection
- test
- experimental
- dataflow
- TestUtil
- coverage
- fieldflow
- match
- strange-pointsto-interaction-investigation
- test-1-normal
- test-2-without-splitting
- test-3-max-import-depth-0
- test-4-max-import-depth-100
- test-5-max-import-depth-3
- test-6-max-import-depth-2
- query-tests/Security/CWE-091
- library-tests
- PointsTo/new
- formatting
- frameworks/django-orm
- jump_to_defn
- query-tests
- Exceptions/general
- Functions
- ModificationOfParameterWithDefault
- general
- Lexical/commented_out_code
- Security
- CWE-022-TarSlip
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-312-CleartextLogging
- CWE-312-CleartextStorage-py3
- CWE-312-CleartextStorage
- CWE-327-WeakSensitiveDataHashing
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- Statements/unreachable
- Variables
- unused_local_nonlocal
- unused
- tools/recorded-call-graph-metrics/ql/lib
- ql/ql
- src
- codeql_ql
- ast
- internal
- style
- queries/style
- test/queries/style/Misspelling
- ruby/ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow/internal
- dataflow
- internal
- frameworks
- data/internal
- security
- regexp
- src
- change-notes
- released
- queries
- security
- cwe-022
- cwe-079
- cwe-094
- cwe-352
- cwe-506
- examples
- cwe-611
- variables
- test
- library-tests
- modules
- security
- query-tests/security
- cwe-020/SuspiciousRegexpRange
- cwe-022
- cwe-079
- cwe-094
- cwe-506
- cwe-611
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- visitors
- integration-tests
- osx-only/frontend-invocations
- posix-only
- cross-references
- frontend-invocations
- partial-modules
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- generated
- decl
- expr
- printast
- security
- src/queries
- Security/CWE-311
- ide-contextual-queries
- test
- extractor-tests
- declarations
- expressions
- generated
- decl
- AccessorDecl
- AssociatedTypeDecl
- ClassDecl
- ConcreteFuncDecl
- ConcreteVarDecl
- EnumDecl
- IfConfigDecl
- ImportDecl
- ModuleDecl
- ParamDecl
- expr
- ConstructorRefCallExpr
- DotSyntaxCallExpr
- EnumIsCaseExpr
- MethodRefExpr
- type
- BuiltinType
- ModuleType
- types
- library-tests
- ast
- controlflow/graph
- dataflow
- dataflow
- taint
- parent
- query-tests/Security
- CWE-079
- CWE-135
- CWE-311
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,425 files changed
+125558
-17640
lines changedLines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
42 | 42 |
| |
43 | 43 |
| |
44 | 44 |
| |
| 45 | + |
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
56 | 56 |
| |
57 | 57 |
| |
58 | 58 |
| |
59 |
| - | |
| 59 | + | |
60 | 60 |
| |
61 | 61 |
| |
62 | 62 |
|
Lines changed: 6 additions & 6 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
11 | 11 |
| |
12 | 12 |
| |
13 | 13 |
| |
14 |
| - | |
| 14 | + | |
15 | 15 |
| |
16 | 16 |
| |
17 |
| - | |
| 17 | + | |
18 | 18 |
| |
19 | 19 |
| |
20 | 20 |
| |
| |||
57 | 57 |
| |
58 | 58 |
| |
59 | 59 |
| |
60 |
| - | |
| 60 | + | |
61 | 61 |
| |
62 | 62 |
| |
63 |
| - | |
| 63 | + | |
64 | 64 |
| |
65 | 65 |
| |
66 | 66 |
| |
| |||
87 | 87 |
| |
88 | 88 |
| |
89 | 89 |
| |
90 |
| - | |
| 90 | + | |
91 | 91 |
| |
92 | 92 |
| |
93 |
| - | |
| 93 | + | |
94 | 94 |
| |
95 | 95 |
| |
96 | 96 |
| |
|
Lines changed: 58 additions & 78 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
8 | 15 |
| |
9 | 16 |
| |
10 | 17 |
| |
| |||
17 | 24 |
| |
18 | 25 |
| |
19 | 26 |
| |
20 |
| - | |
| 27 | + | |
21 | 28 |
| |
22 | 29 |
| |
23 | 30 |
| |
| |||
27 | 34 |
| |
28 | 35 |
| |
29 | 36 |
| |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
30 | 43 |
| |
| 44 | + | |
31 | 45 |
| |
32 | 46 |
| |
33 | 47 |
| |
34 |
| - | |
35 |
| - | |
| 48 | + | |
| 49 | + | |
36 | 50 |
| |
37 |
| - | |
| 51 | + | |
38 | 52 |
| |
39 | 53 |
| |
40 |
| - | |
41 |
| - | |
42 |
| - | |
43 |
| - | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
44 | 62 |
| |
45 | 63 |
| |
46 |
| - | |
47 |
| - | |
48 |
| - | |
49 |
| - | |
50 |
| - | |
51 |
| - | |
52 | 64 |
| |
53 | 65 |
| |
54 | 66 |
| |
| 67 | + | |
55 | 68 |
| |
56 | 69 |
| |
57 | 70 |
| |
| |||
62 | 75 |
| |
63 | 76 |
| |
64 | 77 |
| |
65 |
| - | |
| 78 | + | |
66 | 79 |
| |
67 | 80 |
| |
68 | 81 |
| |
| |||
71 | 84 |
| |
72 | 85 |
| |
73 | 86 |
| |
74 |
| - | |
| 87 | + | |
75 | 88 |
| |
76 | 89 |
| |
77 |
| - | |
| 90 | + | |
78 | 91 |
| |
79 | 92 |
| |
80 |
| - | |
| 93 | + | |
81 | 94 |
| |
82 | 95 |
| |
83 |
| - | |
| 96 | + | |
84 | 97 |
| |
85 | 98 |
| |
86 |
| - | |
| 99 | + | |
87 | 100 |
| |
88 |
| - | |
89 |
| - | |
90 |
| - | |
91 |
| - | |
92 |
| - | |
93 |
| - | |
94 |
| - | |
95 |
| - | |
96 |
| - | |
97 | 101 |
| |
98 | 102 |
| |
99 |
| - | |
100 |
| - | |
101 |
| - | |
102 |
| - | |
103 |
| - | |
104 |
| - | |
105 |
| - | |
106 |
| - | |
107 |
| - | |
108 |
| - | |
109 |
| - | |
110 |
| - | |
111 |
| - | |
112 |
| - | |
113 |
| - | |
114 |
| - | |
115 |
| - | |
116 |
| - | |
117 |
| - | |
118 |
| - | |
119 |
| - | |
120 |
| - | |
121 |
| - | |
122 |
| - | |
123 |
| - | |
124 |
| - | |
125 |
| - | |
126 |
| - | |
127 |
| - | |
128 |
| - | |
129 |
| - | |
130 |
| - | |
131 |
| - | |
132 |
| - | |
133 |
| - | |
134 |
| - | |
135 |
| - | |
| 103 | + | |
| 104 | + | |
136 | 105 |
| |
137 |
| - | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
138 | 112 |
| |
139 |
| - | |
140 | 113 |
| |
| 114 | + | |
| 115 | + | |
141 | 116 |
| |
142 | 117 |
| |
143 |
| - | |
| 118 | + | |
144 | 119 |
| |
145 | 120 |
| |
146 | 121 |
| |
147 | 122 |
| |
148 | 123 |
| |
149 | 124 |
| |
150 | 125 |
| |
151 |
| - | |
152 |
| - | |
| 126 | + | |
| 127 | + | |
153 | 128 |
| |
154 |
| - | |
155 |
| - | |
| 129 | + | |
| 130 | + | |
156 | 131 |
| |
157 | 132 |
| |
158 |
| - | |
| 133 | + | |
159 | 134 |
| |
160 | 135 |
| |
161 |
| - | |
| 136 | + | |
162 | 137 |
| |
163 | 138 |
| |
164 | 139 |
| |
165 | 140 |
| |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
166 | 146 |
| |
167 | 147 |
| |
168 |
| - | |
169 |
| - | |
| 148 | + | |
| 149 | + | |
170 | 150 |
| |
171 | 151 |
| |
172 | 152 |
| |
173 | 153 |
| |
174 | 154 |
| |
175 |
| - | |
| 155 | + | |
176 | 156 |
| |
177 | 157 |
| |
178 | 158 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
25 | 25 |
| |
26 | 26 |
| |
27 | 27 |
| |
28 |
| - | |
| 28 | + | |
29 | 29 |
| |
30 | 30 |
| |
31 | 31 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 |
| - | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
|
Lines changed: 5 additions & 8 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
463 | 463 |
| |
464 | 464 |
| |
465 | 465 |
| |
466 |
| - | |
467 |
| - | |
468 |
| - | |
469 | 466 |
| |
470 | 467 |
| |
471 | 468 |
| |
| |||
585 | 582 |
| |
586 | 583 |
| |
587 | 584 |
| |
588 |
| - | |
| 585 | + | |
589 | 586 |
| |
590 | 587 |
| |
591 | 588 |
| |
592 |
| - | |
| 589 | + | |
593 | 590 |
| |
594 | 591 |
| |
595 | 592 |
| |
596 |
| - | |
| 593 | + | |
597 | 594 |
| |
598 | 595 |
| |
599 | 596 |
| |
600 |
| - | |
| 597 | + | |
601 | 598 |
| |
602 | 599 |
| |
603 | 600 |
| |
604 | 601 |
| |
605 | 602 |
| |
606 |
| - | |
| 603 | + |
Lines changed: 16 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
1 | 17 |
| |
2 | 18 |
| |
3 | 19 |
| |
|
Lines changed: 0 additions & 4 deletions
This file was deleted.
Lines changed: 0 additions & 6 deletions
This file was deleted.
0 commit comments