File tree
1,296 files changed
+64672
-9544
lines changed- .github
- workflows
- config
- cpp/ql
- lib
- change-notes
- semmle/code/cpp
- commons
- dataflow/internal
- exprs
- ir
- dataflow/internal
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- internal
- src/experimental/Security/CWE/CWE-020
- test
- TestUtilities
- experimental/query-tests/Security/CWE/CWE-020/NoCheckBeforeUnsafePutUser
- library-tests
- controlflow/dereferenced
- dataflow/dataflow-tests
- ir
- ir
- ssa
- lambdas/captures
- syntax-zoo
- valuenumbering/GlobalValueNumbering
- variables/global
- csharp
- documentation/library-coverage
- extractor/Semmle.Extraction.CSharp
- Entities
- Statements
- Populators
- ql
- lib/semmle/code/csharp
- dataflow
- internal
- frameworks
- generated/dotnet
- security/dataflow/flowsources
- src
- Diagnostics
- Security Features/CWE-209
- change-notes
- experimental/ir
- implementation
- internal
- raw
- internal
- unaliased_ssa
- internal
- utils/model-generator
- test
- TestUtilities
- experimental/ir/ir
- library-tests
- csharp7
- csharp9-standalone
- dataflow
- flowsources/aspremote
- library
- query-tests/Security Features
- CWE-020
- CWE-022/TaintedPath
- CWE-078
- CWE-079
- StoredXSS
- XSS
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-117
- CWE-134
- CWE-209
- CWE-601/UrlRedirect
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-807
- resources/stubs
- docs/codeql
- codeql-cli
- codeql-for-visual-studio-code
- codeql-language-guides
- support/reusables
- go
- codeql-tools
- extractor/cli/go-autobuilder
- ql
- lib/semmle/go
- dataflow/internal
- src/experimental
- CWE-285
- CWE-321
- test
- TestUtilities
- experimental
- CWE-285
- vendor
- github.com/msteinert/pam
- CWE-321
- vendor
- github.com
- appleboy/gin-jwt/v2
- cristalhq/jwt/v3
- gin-gonic/gin
- go-kit/kit/auth/jwt
- golang-jwt/jwt/v4
- lestrrat/go-jwx/jwk
- square/go-jose/v3
- gopkg.in/square/go-jose.v2
- frameworks
- CleverGo
- Fiber
- library-tests/semmle/go
- Function
- Types
- concepts
- HTTP
- LoggerCall
- dataflow
- ExternalFlowVarArgs
- GuardingFunctions
- ListOfConstantsSanitizerGuards
- PromotedFields
- PromotedMethods
- TypeAssertions
- VarArgsWithFunctionModels
- VarArgs
- frameworks
- CouchbaseV1
- ElazarlGoproxy
- EvanphxJsonPatch
- GoKit
- K8sIoApiCoreV1
- K8sIoApimachineryPkgRuntime
- K8sIoClientGo
- NoSQL
- Revel
- SQL
- StdlibTaintFlow
- Yaml
- Zap
- javascript
- extractor
- lib/typescript
- src
- src/com/semmle
- js
- dependencies
- extractor
- ts
- ast
- extractor
- tests/ts/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib
- experimental/adaptivethreatmodeling
- modelbuilding
- counting
- model
- src
- test
- lib
- Expressions
- change-notes
- semmle/javascript
- dataflow
- internal
- frameworks
- data
- internal
- heuristics
- internal
- security
- dataflow
- internal
- performance
- upgrades/c1ee5346e068f6e0b687e75b4ba3f04a7382f4c4
- src
- Declarations
- Performance
- Security
- CWE-020
- CWE-295
- CWE-352
- CWE-598
- CWE-915
- change-notes
- meta
- ApiGraphs
- alerts
- analysis-quality
- test
- ApiGraphs
- call-nodes
- custom-entry-point
- typed
- library-tests
- AMD
- Arrays
- Routing
- TaintBarriers
- TaintTracking
- TypeScript
- RegressionTests
- ExportBaseResolution
- ImportDtsFile
- Types
- TypeTracking
- frameworks
- Express
- data
- query-tests
- Declarations
- UnusedProperty
- UnusedVariable
- Expressions/ExprHasNoEffect
- Security
- CWE-598
- CWE-601/ServerSideUrlRedirect
- CWE-770/ResourceExhaustion
- CWE-843
- CWE-915/PrototypePollutingFunction
- java
- documentation/library-coverage
- kotlin-extractor
- src/main
- java/com/semmle/extractor/java
- kotlin
- utils
- ql
- lib/semmle/code/java
- dataflow
- internal
- frameworks
- apache
- security/performance
- src
- Likely Bugs
- Cloning
- Likely Typos
- Serialization
- Security/CWE/CWE-022
- utils/model-generator
- internal
- test
- TestUtilities
- kotlin/library-tests
- android_function_return_types
- clashing-extension-fields
- enum
- exprs
- function-n
- java-kotlin-collection-type-generic-methods
- java-lang-number-conversions
- java-list-kotlin-user
- kotlin-java-map-entries
- maps-iterator-overloads
- multiple_extensions
- reflection
- query-tests/NonSerializableField
- python/ql
- lib/semmle/python
- concepts
- internal
- dataflow/new/internal
- filters
- frameworks
- Stdlib
- data
- internal
- internal
- security
- dataflow
- performance
- src
- Security
- CWE-295
- CWE-327
- CWE-732
- analysis
- change-notes
- experimental
- Security
- CWE-079
- CWE-1236
- semmle/python
- frameworks
- libraries
- security
- dataflow
- injection
- test
- TestUtilities
- experimental
- dataflow/basic
- meta
- query-tests/Security
- CWE-079
- CWE-1236
- library-tests
- filters/tests
- frameworks
- aiohttp
- asyncpg
- cryptodome
- cryptography
- crypto
- data
- django-v2-v3
- httpx
- requests
- stdlib-py2
- stdlib
- urllib3
- query-tests
- Security
- CWE-295-RequestWithoutValidation
- CWE-327-BrokenCryptoAlgorithm
- CWE-732-WeakFilePermissions
- Statements/asserts
- analysis/suppression
- ql
- extractor
- generator
- ql
- src
- codeql_ql
- ast
- internal
- style
- codeql
- files
- ide-contextual-queries
- queries
- diagnostics
- performance
- test
- TestUtilities
- callgraph
- queries/performance/VarUnusedInDisjunct
- ruby
- downgrades/4ba51641799d2aaa315c7323931e2dd2a94c9f9d
- extractor
- generator
- ql
- consistency-queries
- lib
- change-notes/released
- codeql/ruby
- ast
- internal
- dataflow/internal
- experimental
- frameworks
- core
- data/internal
- stdlib
- internal
- security
- internal
- performance
- upgrades/1199e154f5e9b3560297633c6ebb4dfe0b191ae4
- src
- change-notes
- experimental
- decompression-api
- examples
- improper-memoization
- queries/security
- cwe-116
- cwe-327
- test
- TestUtilities
- library-tests
- ast/erb
- concepts
- dataflow
- global
- hash-flow
- params
- summaries
- type-tracker
- experimental
- frameworks
- active_support
- archive
- stdlib
- query-tests
- experimental/improper-memoization
- security
- cwe-022
- cwe-078
- cwe-327
- decompression-api
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- trap
- visitors
- integration-tests
- cross-references
- Sources/cross-references
- hello-world
- Sources/hello-world
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- elements
- decl
- expr
- pattern
- stmt
- typerepr
- type
- generated
- decl
- expr
- stmt
- type
- src
- codeql-suites
- queries
- test
- extractor-tests
- declarations
- expressions
- files
- generated
- File
- decl
- AccessorDecl
- AssociatedTypeDecl
- ClassDecl
- ConcreteFuncDecl
- ConcreteVarDecl
- ConstructorDecl
- DestructorDecl
- EnumCaseDecl
- EnumDecl
- EnumElementDecl
- ExtensionDecl
- GenericTypeParamDecl
- IfConfigDecl
- ImportDecl
- InfixOperatorDecl
- MissingMemberDecl
- ModuleDecl
- OpaqueTypeDecl
- ParamDecl
- PatternBindingDecl
- PostfixOperatorDecl
- PoundDiagnosticDecl
- PrecedenceGroupDecl
- PrefixOperatorDecl
- ProtocolDecl
- StructDecl
- SubscriptDecl
- TopLevelCodeDecl
- TypeAliasDecl
- expr
- AnyHashableErasureExpr
- AppliedPropertyWrapperExpr
- ArchetypeToSuperExpr
- Argument
- ArrayExpr
- ArrayToPointerExpr
- ArrowExpr
- AssignExpr
- AutoClosureExpr
- AwaitExpr
- BinaryExpr
- BindOptionalExpr
- BooleanLiteralExpr
- BridgeFromObjCExpr
- BridgeToObjCExpr
- CallExpr
- CaptureListExpr
- ClassMetatypeToObjectExpr
- ClosureExpr
- CodeCompletionExpr
- CoerceExpr
- CollectionUpcastConversionExpr
- ConditionalBridgeFromObjCExpr
- ConditionalCheckedCastExpr
- ConstructorRefCallExpr
- CovariantFunctionConversionExpr
- CovariantReturnConversionExpr
- DeclRefExpr
- DefaultArgumentExpr
- DerivedToBaseExpr
- DestructureTupleExpr
- DictionaryExpr
- DifferentiableFunctionExpr
- DifferentiableFunctionExtractOriginalExpr
- DiscardAssignmentExpr
- DotSelfExpr
- DotSyntaxBaseIgnoredExpr
- DotSyntaxCallExpr
- DynamicMemberRefExpr
- DynamicSubscriptExpr
- DynamicTypeExpr
- EditorPlaceholderExpr
- EnumIsCaseExpr
- ErasureExpr
- ErrorExpr
- ExistentialMetatypeToObjectExpr
- FloatLiteralExpr
- ForceTryExpr
- ForceValueExpr
- ForcedCheckedCastExpr
- ForeignObjectConversionExpr
- FunctionConversionExpr
- IfExpr
- InOutExpr
- InOutToPointerExpr
- InjectIntoOptionalExpr
- IntegerLiteralExpr
- InterpolatedStringLiteralExpr
- IsExpr
- KeyPathApplicationExpr
- KeyPathDotExpr
- KeyPathExpr
- LazyInitializerExpr
- LinearFunctionExpr
- LinearFunctionExtractOriginalExpr
- LinearToDifferentiableFunctionExpr
- LoadExpr
- MagicIdentifierLiteralExpr
- MakeTemporarilyEscapableExpr
- MemberRefExpr
- MetatypeConversionExpr
- NilLiteralExpr
- ObjCSelectorExpr
- ObjectLiteralExpr
- OneWayExpr
- OpaqueValueExpr
- OpenExistentialExpr
- OptionalEvaluationExpr
- OptionalTryExpr
- OtherConstructorDeclRefExpr
- OverloadedDeclRefExpr
- ParenExpr
- PointerToPointerExpr
- PostfixUnaryExpr
- PrefixUnaryExpr
- PropertyWrapperValuePlaceholderExpr
- ProtocolMetatypeToObjectExpr
- RebindSelfInConstructorExpr
- RegexLiteralExpr
- SequenceExpr
- StringLiteralExpr
- StringToPointerExpr
- SubscriptExpr
- SuperRefExpr
- TapExpr
- TryExpr
- TupleElementExpr
- TupleExpr
- TypeExpr
- UnderlyingToOpaqueExpr
- UnevaluatedInstanceExpr
- UnresolvedDeclRefExpr
- UnresolvedDotExpr
- UnresolvedMemberChainResultExpr
- UnresolvedMemberExpr
- UnresolvedPatternExpr
- UnresolvedSpecializeExpr
- UnresolvedTypeConversionExpr
- VarargExpansionExpr
- pattern
- AnyPattern
- BindingPattern
- BoolPattern
- EnumElementPattern
- ExprPattern
- IsPattern
- NamedPattern
- OptionalSomePattern
- ParenPattern
- TuplePattern
- TypedPattern
- stmt
- BraceStmt
- BreakStmt
- CaseLabelItem
- CaseStmt
- ConditionElement
- ContinueStmt
- DeferStmt
- DoCatchStmt
- DoStmt
- FailStmt
- FallthroughStmt
- ForEachStmt
- GuardStmt
- IfStmt
- PoundAssertStmt
- RepeatWhileStmt
- ReturnStmt
- StmtCondition
- SwitchStmt
- ThrowStmt
- WhileStmt
- YieldStmt
- typerepr
- ArrayTypeRepr
- AttributedTypeRepr
- CompileTimeConstTypeRepr
- CompositionTypeRepr
- CompoundIdentTypeRepr
- DictionaryTypeRepr
- ErrorTypeRepr
- ExistentialTypeRepr
- FixedTypeRepr
- FunctionTypeRepr
- GenericIdentTypeRepr
- ImplicitlyUnwrappedOptionalTypeRepr
- InOutTypeRepr
- IsolatedTypeRepr
- MetatypeTypeRepr
- NamedOpaqueReturnTypeRepr
- OpaqueReturnTypeRepr
- OptionalTypeRepr
- OwnedTypeRepr
- PlaceholderTypeRepr
- ProtocolTypeRepr
- SilBoxTypeRepr
- SimpleIdentTypeRepr
- TupleTypeRepr
- type
- ArraySliceType
- BoundGenericClassType
- BoundGenericEnumType
- BoundGenericStructType
- BuiltinBridgeObjectType
- BuiltinDefaultActorStorageType
- BuiltinExecutorType
- BuiltinFloatType
- BuiltinIntegerLiteralType
- BuiltinIntegerType
- BuiltinJobType
- BuiltinNativeObjectType
- BuiltinRawPointerType
- BuiltinRawUnsafeContinuationType
- BuiltinUnsafeValueBufferType
- BuiltinVectorType
- ClassType
- DependentMemberType
- DictionaryType
- DynamicSelfType
- EnumType
- ErrorType
- ExistentialMetatypeType
- ExistentialType
- FunctionType
- GenericFunctionType
- GenericTypeParamType
- InOutType
- LValueType
- MetatypeType
- ModuleType
- NestedArchetypeType
- OpaqueTypeArchetypeType
- OpenedArchetypeType
- OptionalType
- ParenType
- PlaceholderType
- PrimaryArchetypeType
- ProtocolCompositionType
- ProtocolType
- SequenceArchetypeType
- SilBlockStorageType
- SilBoxType
- SilFunctionType
- SilTokenType
- StructType
- TupleType
- TypeAliasType
- TypeVariableType
- UnboundGenericType
- UnmanagedStorageType
- UnownedStorageType
- UnresolvedType
- VariadicSequenceType
- WeakStorageType
- patterns
- statements
- types
- library-tests
- controlflow/graph
- dataflow/dataflow
- parent
- tools
- prebuilt
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,296 files changed
+64672
-9544
lines changedLines changed: 0 additions & 30 deletions
This file was deleted.
Lines changed: 12 additions & 3 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
6 | 6 |
| |
7 | 7 |
| |
8 | 8 |
| |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
9 | 13 |
| |
10 |
| - | |
| 14 | + | |
11 | 15 |
| |
12 | 16 |
| |
13 | 17 |
| |
14 | 18 |
| |
15 | 19 |
| |
16 | 20 |
| |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
17 | 26 |
| |
18 | 27 |
| |
19 | 28 |
| |
20 | 29 |
| |
21 | 30 |
| |
22 | 31 |
| |
23 | 32 |
| |
24 |
| - | |
| 33 | + | |
25 | 34 |
| |
26 | 35 |
| |
27 | 36 |
| |
| |||
31 | 40 |
| |
32 | 41 |
| |
33 | 42 |
| |
34 |
| - | |
| 43 | + | |
35 | 44 |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
41 | 41 |
| |
42 | 42 |
| |
43 | 43 |
| |
44 |
| - | |
| 44 | + | |
45 | 45 |
| |
46 | 46 |
| |
47 | 47 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 |
| - | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
19 | 19 |
| |
20 | 20 |
| |
21 | 21 |
| |
22 |
| - | |
| 22 | + | |
23 | 23 |
| |
24 | 24 |
| |
25 | 25 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
22 | 22 |
| |
23 | 23 |
| |
24 | 24 |
| |
25 |
| - | |
| 25 | + | |
26 | 26 |
| |
27 | 27 |
| |
28 | 28 |
| |
|
Lines changed: 1 addition & 1 deletion
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
23 | 23 |
| |
24 | 24 |
| |
25 | 25 |
| |
26 |
| - | |
| 26 | + | |
27 | 27 |
| |
28 | 28 |
| |
29 | 29 |
| |
|
Lines changed: 1 addition & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + | |
7 | 8 |
| |
8 | 9 |
| |
9 | 10 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
5 | 5 |
| |
6 | 6 |
| |
7 | 7 |
| |
| 8 | + | |
8 | 9 |
| |
9 | 10 |
| |
10 | 11 |
| |
11 | 12 |
| |
12 | 13 |
| |
13 | 14 |
| |
14 | 15 |
| |
| 16 | + | |
| 17 | + | |
15 | 18 |
| |
16 | 19 |
| |
17 | 20 |
| |
|
Lines changed: 3 additions & 0 deletions
Original file line number | Diff line number | Diff line change | |
---|---|---|---|
| |||
4 | 4 |
| |
5 | 5 |
| |
6 | 6 |
| |
| 7 | + | |
| 8 | + | |
| 9 | + | |
7 | 10 |
| |
8 | 11 |
| |
9 | 12 |
| |
|
0 commit comments