Commit 7ddfa80
File tree
5,416 files changed
+483334
-196104
lines changed- .github
- instructions
- workflows
- actions/ql
- examples
- snippets
- lib
- change-notes
- released
- codeql/actions
- ast/internal
- security
- src
- Models
- Security
- CWE-094
- CWE-275
- change-notes/released
- experimental/Security
- CWE-200
- CWE-829
- test
- library-tests
- basic
- .github/workflows
- very-long-expression
- .github/workflows
- query-tests/Security
- CWE-094
- .github/workflows
- CWE-200
- config
- cpp
- downgrades
- 1402ab319d20cdc9289deb7bfc1c70f36be44d44
- 1a6854060d5d3ada16c580a29f8c5ce21f3367f8
- 2121ffec11fac265524955fee1775217364d4ca4
- 83100310bf73eefc37c1d8d0ac98b2ca3019c7b6
- 9439176c1d1312787926458dd54d65a849069118
- a42ce5fc943254097f85471b94ae2247e819104a
- d2d611b3fdcc7c4fe370f0d115200a3aa6ad5837
- ql
- lib
- change-notes
- released
- experimental
- quantum
- OpenSSL
- AlgorithmInstances
- AlgorithmValueConsumers
- Operations
- semmle/code/cpp/rangeanalysis
- ext
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- exprs
- internal
- ir
- dataflow/internal
- implementation
- aliased_ssa
- raw
- internal
- unaliased_ssa
- models/implementations
- rangeanalysis
- new/internal/semantic
- stmts
- upgrades
- 1402ab319d20cdc9289deb7bfc1c70f36be44d44
- 1a6854060d5d3ada16c580a29f8c5ce21f3367f8
- 2121ffec11fac265524955fee1775217364d4ca4
- 83100310bf73eefc37c1d8d0ac98b2ca3019c7b6
- a42ce5fc943254097f85471b94ae2247e819104a
- c16b29b27f71247023321cc0d0360998b318837c
- d2d611b3fdcc7c4fe370f0d115200a3aa6ad5837
- src
- Critical
- Likely Bugs
- Arithmetic
- Format
- Memory Management
- Security/CWE
- CWE-020
- ir
- CWE-078
- CWE-089
- CWE-120
- CWE-129
- CWE-190
- CWE-290
- CWE-295
- CWE-311
- CWE-313
- CWE-319
- CWE-327
- CWE-367
- change-notes/released
- experimental/Security/CWE
- CWE-078
- CWE-125
- CWE-190
- CWE-193
- CWE-200
- CWE-243
- CWE-266
- CWE-377
- CWE-401
- CWE-409
- CWE-476
- CWE-670
- jsf/lib/section_4_21_Operators
- utils/modelgenerator
- internal
- test
- examples/docs-examples/analyzing-data-flow-in-cpp
- experimental/library-tests
- quantum
- rangeanalysis/rangeanalysis
- library-tests
- attributes/deprecated_with_msg
- builtins
- type_traits
- types
- constants/addresses
- controlflow
- guards-ir
- guards
- dataflow
- asDefinition
- dataflow-tests
- external-models
- fields
- ir-barrier-guards
- taint-tests
- files
- friends/loop
- functions/routinetype
- ir
- ir
- range-analysis
- literals/literals
- preprocessor/preprocessor
- rangeanalysis/SimpleRangeAnalysis
- scopes/parents
- subscript_operator
- templates
- isfromtemplateinstantiation
- type_instantiations
- variables
- type_sizes
- typedefs
- types
- __wchar_t
- cstd_types
- integral_types_ms
- sizeof
- wchar_t_typedef
- unspecified_type/types
- variables/variables
- vector_types
- query-tests
- Best Practices
- SloppyGlobal
- Unused Entities/UnusedLocals
- Critical
- MissingCheckScanf
- UnsafeUseOfThis
- Likely Bugs/Arithmetic/PointlessComparison
- Security/CWE/CWE-119/semmle/tests
- csharp
- .config
- .vscode
- actions/create-extractor-pack
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.CSharp
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- downgrades
- 605f85053409cd72b4904df3f198ddc8324f3a83
- 68b5aec54e50fe7e375df3777b756a746ca3a37c
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.DependencyStubGenerator
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Base
- Compilations
- Locations
- PreprocessorDirectives
- Types
- Extractor
- Populators
- Trap
- Semmle.Extraction.Tests
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- autobuild_slnx
- proj1
- proj2
- autobuild
- binlog_multiple
- a
- b
- binlog
- a
- b
- blazor_build_mode_none
- BlazorTest
- blazor_net_8
- blazor
- BlazorTest
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_10
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_dependency_dir
- proj
- standalone_failed
- standalone_resx
- standalone_slnx
- mylib
- proj
- standalone_winforms
- standalone
- linux
- compiler_args
- diag_nuget_config_casing
- sub-project
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- query-suite
- standalone_dependencies_executing_runtime
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- proj
- standalone_dependencies_nuget_config_error
- proj
- standalone_dependencies_nuget_config_fallback
- proj
- standalone_dependencies_nuget_no_sources/proj
- standalone_dependencies_nuget_versions
- d1
- d2
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows/standalone_dependencies
- lib
- change-notes
- released
- ext
- generated
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- frameworks
- internal
- security
- auth
- dataflow
- flowsinks
- upgrades
- 605f85053409cd72b4904df3f198ddc8324f3a83
- 66044cfa5bbf2ecfabd06ead25e91db2bdd79764
- src
- Bad Practices
- Control-Flow
- Declarations
- CSI
- Likely Bugs/Collections
- Security Features
- CWE-1004
- CWE-327
- CWE-352
- CWE-451
- CWE-502
- CWE-614
- change-notes/released
- experimental
- CWE-918
- Security Features
- CWE-1004
- CWE-327/Azure
- CWE-614
- dataflow/flowsources
- utils
- modelconverter
- modelgenerator
- internal
- test
- experimental/Security Features
- CWE-1004
- CookieHttpOnlyFalseAspNetCore
- CookieBuilder
- NoPolicy
- UseCookiePolicyCallback
- CookieHttpOnlyFalseSystemWeb
- CookieWithoutHttpOnlyAspNetCore
- NoPolicy
- UseCookiePolicyAlways
- UseCookiePolicyCallback
- UseCookiePolicyNone
- CookieWithoutHttpOnlySystemWeb
- ConfigEmpty
- ConfigFalse
- HttpCookiesTrue
- CWE-614
- RequireSSLAspNetCore
- NoPolicy
- UseCookiePolicyAlways
- UseCookiePolicyCallback
- UseCookiePolicyNone
- RequireSSLFalseAspNetCore
- CookieBuilder
- NoPolicy
- UseCookiePolicyCallback
- RequireSSLFalseSystemWeb
- RequireSSLSystemWeb
- ConfigEmpty
- ConfigFalse
- FormsTrue
- HttpCookiesTrue
- library-tests
- arguments
- assemblies
- assignables
- assignments
- attributes
- comments
- constructors
- controlflow
- graph
- CONSISTENCY
- guards
- splits
- CONSISTENCY
- conversion
- operator
- span
- csharp10
- csharp11
- csharp6
- csharp7.1
- csharp7.2
- csharp7.3
- csharp7
- csharp8
- csharp9-standalone
- csharp9
- dataflow
- barrier-guards
- call-sensitivity
- callablereturnsarg
- collections
- constructors
- defuse
- external-models
- fields
- flowsources/stored/database/dapper
- global
- implicittostring
- library
- local
- modulusanalysis
- nullness
- signanalysis
- ssa
- tuples
- definitions
- delegates
- dynamic
- enums
- events
- exceptions
- expressions
- extension-method-call
- fields
- frameworks
- Aws
- JsonNET
- NHibernate
- ServiceStack
- generics
- goto
- implicittostring
- indexers
- initializers
- linq
- locations
- members
- methods
- nameof
- namespaces
- nestedtypes
- nullable
- obinit
- operators
- overlay
- base
- overlay
- partial
- properties
- security/dataflow/flowsources
- standalone
- brokentypes
- controlflow
- errorrecovery
- externalLocationSink
- statements
- stringinterpolation
- structuralcomparison
- types
- unsafe
- query-tests
- API Abuse/FormatInvalid
- Bad Practices
- Control-Flow/ConstantCondition
- Path Combine
- Dead Code/DeadStoreOfLocal
- Nullness
- Security Features
- CWE-089-2
- CWE-089
- CWE-1004/HttpOnlyCookie
- AspNetCore
- CookieBuilder
- NoPolicy
- PolicyAlways
- PolicyCallback
- PolicyNone
- SystemWeb
- HttpOnlyCookiesFalse
- HttpOnlyCookiesTrue
- CWE-352/missing-aspnetcore
- CWE-451/MissingXFrameOptions/WebConfigAddedHeaderInLocation
- CWE-502/UnsafeDeserializationUntrustedInputNewtonsoftJson
- CWE-611
- CWE-614/InsecureCookie
- AspNetCore
- CookieBuilder
- NoPolicy
- PolicyAlways
- PolicyCallback
- PolicyNone
- SystemWeb
- RequireSSLFalse
- RequireSSLTrue
- FormsTrue
- HttpCookiesTrue
- CWE-639/MVCTests
- standalone/Bad Practices/Control-Flow/ConstantCondition
- resources/stubs
- Amazon.Lambda.APIGatewayEvents/2.7.3
- Amazon.Lambda.Core/2.8.0
- Antlr3.Runtime/3.5.1
- Azure.Core
- 1.38.0
- 1.47.1
- Azure.Identity
- 1.11.4
- 1.14.2
- Dapper/2.1.66
- EntityFramework/6.5.1
- Iesi.Collections
- 4.0.4
- 4.1.1
- Microsoft.Bcl.AsyncInterfaces/8.0.0
- Microsoft.Bcl.Cryptography/9.0.4
- Microsoft.CSharp/4.7.0
- Microsoft.Data.SqlClient.SNI.runtime/6.0.2
- Microsoft.Data.SqlClient
- 6.0.2
- 6.1.3
- Microsoft.Extensions.Caching.Abstractions/9.0.4
- Microsoft.Extensions.Caching.Memory/9.0.4
- Microsoft.Extensions.Configuration.Abstractions/10.0.0
- Microsoft.Extensions.Configuration.Binder
- 10.0.0
- 8.0.0
- Microsoft.Extensions.Configuration
- 10.0.0
- 8.0.0
- Microsoft.Extensions.DependencyInjection.Abstractions
- 10.0.0
- 8.0.0
- 9.0.4
- Microsoft.Extensions.DependencyInjection/10.0.0
- Microsoft.Extensions.Diagnostics.Abstractions
- 10.0.0
- 8.0.0
- Microsoft.Extensions.Diagnostics
- 10.0.0
- 8.0.0
- Microsoft.Extensions.Http
- 10.0.0
- 8.0.0
- Microsoft.Extensions.Logging.Abstractions
- 10.0.0
- 8.0.0
- 9.0.4
- Microsoft.Extensions.Logging
- 10.0.0
- 8.0.0
- Microsoft.Extensions.Options.ConfigurationExtensions
- 10.0.0
- 8.0.0
- Microsoft.Extensions.Options
- 10.0.0
- 8.0.0
- 9.0.4
- Microsoft.Extensions.Primitives
- 10.0.0
- 8.0.0
- 9.0.4
- Microsoft.Identity.Client.Extensions.Msal/4.73.1
- Microsoft.Identity.Client/4.73.1
- Microsoft.IdentityModel.Abstractions/7.7.1
- Microsoft.IdentityModel.JsonWebTokens/7.7.1
- Microsoft.IdentityModel.Logging/7.7.1
- Microsoft.IdentityModel.Protocols.OpenIdConnect/7.7.1
- Microsoft.IdentityModel.Protocols/7.7.1
- Microsoft.IdentityModel.Tokens/7.7.1
- Microsoft.NETCore.Platforms/1.0.1
- Microsoft.NETCore.Targets/1.0.1
- Microsoft.SqlServer.Server/1.0.0
- Microsoft.Win32.Primitives
- 4.0.1
- 4.3.0
- Microsoft.Win32.SystemEvents/10.0.1
- NETStandard.Library
- 1.6.0
- 1.6.1
- NHibernate/5.6.0
- Newtonsoft.Json/13.0.4
- Remotion.Linq.EagerFetching/2.2.0
- Remotion.Linq/2.2.0
- ServiceStack.Client
- 10.0.4
- 8.5.2
- ServiceStack.Common
- 10.0.4
- 8.5.2
- ServiceStack.Interfaces/10.0.4
- ServiceStack.OrmLite.SqlServer
- 10.0.4
- 8.5.2
- ServiceStack.OrmLite
- 10.0.4
- 8.5.2
- ServiceStack.Text
- 10.0.4
- 8.5.2
- ServiceStack
- 10.0.4
- 8.5.2
- Stub.System.Data.SQLite.Core.NetStandard/1.0.119
- System.AppContext/4.1.0
- System.Buffers
- 4.0.0
- 4.3.0
- System.ClientModel
- 1.0.0
- 1.5.1
- System.CodeDom/6.0.0
- System.Collections.Concurrent
- 4.0.12
- 4.3.0
- System.Collections.NonGeneric/4.3.0
- System.Collections
- 4.0.11
- 4.3.0
- System.ComponentModel.Annotations/5.0.0
- System.ComponentModel.Primitives/4.3.0
- System.ComponentModel/4.3.0
- System.Configuration.ConfigurationManager
- 10.0.1
- 9.0.1
- 9.0.4
- System.Console
- 4.0.0
- 4.3.0
- System.Data.OleDb
- 10.0.1
- 9.0.1
- System.Data.SQLite.Core/1.0.119
- System.Data.SQLite.EF6/1.0.119
- System.Data.SQLite
- 1.0.119
- 2.0.2
- System.Data.SqlClient/4.9.0
- System.Diagnostics.Debug
- 4.0.11
- 4.3.0
- System.Diagnostics.DiagnosticSource
- 6.0.1
- 8.0.0
- System.Diagnostics.EventLog
- 10.0.1
- 9.0.1
- 9.0.4
- System.Diagnostics.PerformanceCounter/10.0.1
- System.Diagnostics.Tools
- 4.0.1
- 4.3.0
- System.Diagnostics.Tracing
- 4.1.0
- 4.3.0
- System.Drawing.Common/10.0.1
- System.Dynamic.Runtime/4.3.0
- System.Globalization.Calendars
- 4.0.1
- 4.3.0
- System.Globalization.Extensions
- 4.0.1
- 4.3.0
- System.Globalization
- 4.0.11
- 4.3.0
- System.IO.Compression.ZipFile
- 4.0.1
- 4.3.0
- System.IO.Compression
- 4.1.0
- 4.3.0
- System.IO.FileSystem.Primitives/4.0.1
- System.IO.FileSystem
- 4.0.1
- 4.3.0
- System.IO
- 4.1.0
- 4.3.0
- System.IdentityModel.Tokens.Jwt/7.7.1
- System.Linq.Expressions
- 4.1.0
- 4.3.0
- System.Linq.Queryable/4.0.1
- System.Linq
- 4.1.0
- 4.3.0
- System.Memory.Data
- 1.0.2
- 8.0.1
- System.Memory
- 4.5.4
- 4.5.5
- 4.6.0
- System.Net.Http
- 4.1.0
- 4.3.0
- System.Net.Primitives
- 4.0.11
- 4.3.0
- System.Net.Sockets
- 4.1.0
- 4.3.0
- System.Numerics.Vectors/4.5.0
- System.ObjectModel
- 4.0.12
- 4.3.0
- System.Reflection.Emit.ILGeneration
- 4.0.1
- 4.3.0
- System.Reflection.Emit.Lightweight
- 4.0.1
- 4.7.0
- System.Reflection.Emit
- 4.0.1
- 4.7.0
- System.Reflection.Extensions
- 4.0.1
- 4.3.0
- System.Reflection.Primitives
- 4.0.1
- 4.3.0
- System.Reflection.TypeExtensions
- 4.1.0
- 4.7.0
- System.Reflection
- 4.1.0
- 4.3.0
- System.Resources.ResourceManager
- 4.0.1
- 4.3.0
- System.Runtime.CompilerServices.Unsafe/6.0.0
- System.Runtime.Extensions
- 4.1.0
- 4.3.0
- System.Runtime.Handles
- 4.0.1
- 4.3.0
- System.Runtime.InteropServices.RuntimeInformation
- 4.0.0
- 4.3.0
- System.Runtime.InteropServices
- 4.1.0
- 4.3.0
- System.Runtime.Numerics
- 4.0.1
- 4.3.0
- System.Runtime.Serialization.Formatters/4.3.0
- System.Runtime.Serialization.Primitives/4.3.0
- System.Runtime/4.1.0
- System.Security.Cryptography.Algorithms
- 4.2.0
- 4.3.0
- System.Security.Cryptography.Cng
- 4.2.0
- 4.3.0
- System.Security.Cryptography.Csp
- 4.0.0
- 4.3.0
- System.Security.Cryptography.Encoding
- 4.0.0
- 4.3.0
- System.Security.Cryptography.OpenSsl
- 4.0.0
- 4.3.0
- System.Security.Cryptography.Pkcs/9.0.4
- System.Security.Cryptography.Primitives
- 4.0.0
- 4.3.0
- System.Security.Cryptography.ProtectedData
- 10.0.1
- 9.0.1
- 9.0.4
- System.Security.Cryptography.X509Certificates
- 4.1.0
- 4.3.0
- System.Security.Permissions
- 10.0.1
- 9.0.1
- System.Text.Encoding.Extensions
- 4.0.11
- 4.3.0
- System.Text.Encodings.Web/4.7.2
- System.Text.Encoding
- 4.0.11
- 4.3.0
- System.Text.Json/9.0.5
- System.Text.RegularExpressions
- 4.1.0
- 4.3.0
- System.Threading.Tasks.Extensions
- 4.0.0
- 4.3.0
- 4.5.4
- System.Threading.Tasks
- 4.0.11
- 4.3.0
- System.Threading.Timer
- 4.0.1
- 4.3.0
- System.Threading
- 4.0.11
- 4.3.0
- System.Windows.Extensions/10.0.1
- System.Xml.ReaderWriter
- 4.0.11
- 4.3.0
- System.Xml.XDocument
- 4.0.11
- 4.3.0
- _frameworks
- Microsoft.AspNetCore.App
- Microsoft.NETCore.App
- runtime.debian.8-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.fedora.23-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.fedora.24-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.native.System.IO.Compression/4.1.0
- runtime.native.System.Net.Http/4.0.1
- runtime.native.System.Security.Cryptography.Apple/4.3.0
- runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.native.System.Security.Cryptography/4.0.0
- runtime.native.System/4.0.0
- runtime.opensuse.13.2-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.opensuse.42.1-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.Apple/4.3.0
- runtime.osx.10.10-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.rhel.7-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.14.04-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.16.04-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.ubuntu.16.10-x64.runtime.native.System.Security.Cryptography.OpenSsl/4.3.0
- runtime.win-arm64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x64.runtime.native.System.Data.SqlClient.sni/4.4.0
- runtime.win-x86.runtime.native.System.Data.SqlClient.sni/4.4.0
- utils/modeleditor
- scripts
- stubs
- tools
- docs/codeql
- _static
- codeql-language-guides
- codeql-overview
- codeql-changelog
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- writing-codeql-queries
- go
- codeql-tools
- downgrades/b1341734d6870b105e5c9d168ce7dec25d7f72d0
- extractor
- cli
- go-autobuilder
- go-extractor
- dbscheme
- diagnostics
- srcarchive
- trap
- util
- ql
- consistency-queries
- change-notes/released
- integration-tests
- diagnostics
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- query-suite
- lib
- change-notes
- released
- ext
- semmle/go
- concepts
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- internal
- security
- upgrades/b3da71c3ac204b557c86e9d9c26012360bdbdccb
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-020
- CWE-1004
- examples
- CWE-209
- CWE-295
- CWE-322
- CWE-326
- CWE-327
- examples
- CWE-352
- CWE-601
- CWE-614
- examples
- CWE-681
- CWE-918
- change-notes/released
- experimental
- CWE-1004
- CWE-285
- CWE-287
- CWE-321-V2
- CWE-327
- examples
- CWE-369
- CWE-918
- frameworks
- test
- consistency
- example-tests/snippets
- experimental
- CWE-1004
- vendor
- github.com/gorilla/sessions
- CWE-203/CONSISTENCY
- CWE-287/CONSISTENCY
- CWE-321-V2
- CONSISTENCY
- CWE-369/CONSISTENCY
- CWE-522-DecompressionBombs
- CONSISTENCY
- CWE-74
- CWE-807/CONSISTENCY
- CWE-840/CONSISTENCY
- CWE-918
- CONSISTENCY
- CWE-942/CONSISTENCY
- Unsafe/CONSISTENCY
- frameworks/CleverGo/CONSISTENCY
- library-tests/semmle/go
- Types/CONSISTENCY
- concepts/HTTP/CONSISTENCY
- dataflow
- ChannelField
- DefaultTaintSanitizer
- CONSISTENCY
- ExternalTaintFlow
- CONSISTENCY
- ExternalValueFlow
- CONSISTENCY
- FlowSteps
- FunctionInputsAndOutputs
- GlobalValueNumbering/CONSISTENCY
- GlobalVariableSideEffects
- CONSISTENCY
- PostUpdateNodes
- CONSISTENCY
- PromotedFields
- ReadsAndWrites
- SSA/CONSISTENCY
- ThreatModels/CONSISTENCY
- flowsources/local/database
- frameworks
- Afero/CONSISTENCY
- BeegoOrm
- CONSISTENCY
- Beego
- CONSISTENCY
- Chi/CONSISTENCY
- Echo
- CONSISTENCY
- Email
- Encoding
- Fasthttp
- CONSISTENCY
- Gin
- CONSISTENCY
- GoMicro
- CONSISTENCY
- Gorestful
- Protobuf/CONSISTENCY
- Revel
- CONSISTENCY
- SystemCommandExecutors/CONSISTENCY
- TaintSteps
- CONSISTENCY
- Twirp
- CONSISTENCY
- WebSocket
- CONSISTENCY
- XNetHtml
- CONSISTENCY
- Yaml
- security/SafeUrlFlow
- query-tests
- RedundantCode/DeadStoreOfLocal/CONSISTENCY
- Security
- CWE-020
- IncompleteHostnameRegexp/CONSISTENCY
- MissingRegexpAnchor/CONSISTENCY
- CWE-022
- CONSISTENCY
- CWE-078
- CONSISTENCY
- CWE-079
- CONSISTENCY
- CWE-089
- CONSISTENCY
- CWE-1004
- vendor
- github.com/gin-gonic/gin
- binding
- CWE-117/CONSISTENCY
- CWE-190
- CONSISTENCY
- CWE-209
- CWE-295/DisabledCertificateCheck
- CWE-312
- CONSISTENCY
- CWE-327
- CONSISTENCY
- vendor
- golang.org/x/crypto
- md4
- ripemd160
- CWE-338/InsecureRandomness
- CWE-347/CONSISTENCY
- CWE-601
- BadRedirectCheck/CONSISTENCY
- OpenUrlRedirect
- CONSISTENCY
- CWE-614
- vendor
- github.com/gin-gonic/gin
- binding
- CWE-640
- CONSISTENCY
- CWE-643/CONSISTENCY
- CWE-770/CONSISTENCY
- CWE-918
- CONSISTENCY
- java
- documentation/library-coverage
- kotlin-extractor
- deps
- dev
- src/main/kotlin
- utils
- versions
- v_1_6_0
- v_1_6_20
- v_1_7_0
- v_1_7_20
- v_1_8_0
- v_1_9_0-Beta
- ql
- integration-tests
- java
- buildless-dependency-different-repository
- buildless-paths
- include
- exclude
- sibling
- lambda-expression-buildless-recovery
- maven-add-exports-module-flags
- src/main/java/com/example
- maven-execution-specific-java-version
- src
- main/java/com/example
- test/java/com/example
- maven-java16-with-higher-jdk
- src/main/java/com/example
- maven-java8-java11-dependency
- src
- main/java/com/example
- test/java/com/example
- maven-multimodule-test-java-version
- main-module
- src/main/java/com/example
- test-module
- src/main/java/com/example/tests
- maven-wrapper-missing-properties
- src/main/java/com/example
- maven_3_fetch_maven_4_wrapper
- app
- .mvn/wrapper
- src/main/java/testmaven
- query-suite
- kotlin
- all-platforms
- compiler_arguments/app
- diagnostics/kotlin-version-too-new
- gradle_groovy_app/app
- gradle_kotlinx_serialization
- app
- java_modifiers
- jvmoverloads-external-class
- kotlin_java_static_fields
- kotlin_kfunction/app
- nullability-annotations
- recursive_interfaces
- somepkg
- posix/module_mangled_names
- lib
- change-notes
- released
- experimental/quantum
- ext
- semmle/code
- java
- controlflow
- dataflow
- internal
- rangeanalysis
- dispatch
- frameworks
- android
- google
- hudson
- jackson
- javaee/ejb
- owasp
- spring
- struts
- internal
- regex
- security
- regexp
- xml
- src
- Likely Bugs
- Arithmetic
- Collections
- Comparison
- Concurrency
- Likely Typos
- Termination
- Metrics/Summaries
- Security/CWE
- CWE-020
- CWE-1004
- CWE-200
- CWE-327
- CWE-614
- Violations of Best Practice/Dead Code
- change-notes
- released
- experimental
- Security/CWE
- CWE-1004
- CWE-295
- CWE-327/Azure
- CWE-346
- CWE-347
- CWE-470
- CWE-502
- quantum
- Analysis
- Examples
- semmle/code/java/security
- meta/ssa
- utils
- modelconverter
- modelgenerator
- internal
- test-kotlin1/library-tests
- data-classes
- methods
- ministdlib
- parameter-defaults
- test-kotlin2/library-tests
- annotation_classes
- annotations/jvmName
- classes
- comments
- companion_objects
- data-classes
- exprs
- generic-instance-methods
- generic-selective-extraction
- inherited-default-value
- interface-delegate
- internal-constructor-called-from-java
- internal-public-alias
- java_and_kotlin_internal
- java_and_kotlin
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmoverloads_generics
- jvmstatic-annotation
- lateinit
- methods-mixed-java-and-kotlin
- methods
- modifiers
- nested_types
- parameter-defaults
- private-anonymous-types
- properties
- stmts
- vararg
- test
- experimental
- library-tests/quantum
- jca
- query-tests
- quantum/examples
- BadMacUse
- InsecureOrUnknownNonceSource
- NonceReuse
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- security
- CWE-1004
- CWE-601
- library-tests
- dataflow
- capture
- collections
- entrypoint-types
- modulus-analysis
- range-analysis
- ssa
- taintsources
- frameworks
- android/taint-database
- apache-collections
- apache-commons-fileupload-1.4
- apache-commons-lang3
- json-java
- netty/generated
- spring
- beans
- http
- util
- websocket
- webutil
- optional
- scanner
- ssa-large
- ssa
- typeflow
- query-tests
- Escaping
- Nullness
- SafePublication
- StartInConstructor
- ThreadSafe
- examples
- UnreleasedLock
- security
- CWE-089/semmle/examples
- CWE-1004
- CWE-532
- CWE-798/semmle/tests
- CWE-918
- stubs
- apache-commons-fileupload-1.4/org/apache/commons/fileupload
- servlet
- util
- couchbaseClient/com/couchbase/client
- core/env
- java
- analytics
- kv
- query
- jakarta.servlet-api-6.0.0/jakarta/servlet
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
5,416 files changed
+483334
-196104
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
82 | 82 | | |
83 | 83 | | |
84 | 84 | | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | 85 | | |
89 | 86 | | |
90 | 87 | | |
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
40 | 40 | | |
41 | 41 | | |
42 | 42 | | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
22 | 50 | | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
23 | 55 | | |
24 | 56 | | |
25 | 57 | | |
| |||
31 | 63 | | |
32 | 64 | | |
33 | 65 | | |
34 | | - | |
| 66 | + | |
35 | 67 | | |
36 | | - | |
| 68 | + | |
37 | 69 | | |
38 | 70 | | |
39 | 71 | | |
40 | 72 | | |
41 | | - | |
| 73 | + | |
42 | 74 | | |
43 | 75 | | |
44 | 76 | | |
45 | 77 | | |
46 | | - | |
| 78 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
| |||
0 commit comments