Commit 803e9fc
File tree
2,302 files changed
+170712
-65658
lines changed- .github
- instructions
- workflows
- actions/ql
- lib
- change-notes/released
- codeql/actions/security
- src
- Models
- change-notes/released
- experimental/Security/CWE-829
- config
- cpp
- downgrades
- 1a6854060d5d3ada16c580a29f8c5ce21f3367f8
- 2121ffec11fac265524955fee1775217364d4ca4
- a42ce5fc943254097f85471b94ae2247e819104a
- ql
- lib
- change-notes
- released
- experimental/quantum/OpenSSL/AlgorithmInstances
- ext
- semmle/code/cpp
- controlflow
- dataflow
- exprs
- ir/dataflow/internal
- models/implementations
- rangeanalysis
- upgrades
- 1a6854060d5d3ada16c580a29f8c5ce21f3367f8
- 2121ffec11fac265524955fee1775217364d4ca4
- c16b29b27f71247023321cc0d0360998b318837c
- src
- Critical
- Likely Bugs/Format
- Security/CWE
- CWE-078
- CWE-089
- CWE-120
- CWE-190
- CWE-290
- CWE-311
- CWE-313
- CWE-319
- CWE-327
- change-notes/released
- experimental/Security/CWE
- CWE-078
- CWE-125
- CWE-190
- CWE-193
- CWE-200
- CWE-243
- CWE-266
- CWE-377
- CWE-409
- CWE-476
- CWE-670
- utils/modelgenerator
- internal
- test/library-tests
- attributes/deprecated_with_msg
- controlflow/guards
- dataflow
- external-models
- fields
- taint-tests
- rangeanalysis/SimpleRangeAnalysis
- types/sizeof
- variables/variables
- csharp
- autobuilder/Semmle.Autobuild.CSharp
- downgrades
- 605f85053409cd72b4904df3f198ddc8324f3a83
- 68b5aec54e50fe7e375df3777b756a746ca3a37c
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.Standalone
- Semmle.Extraction.CSharp
- Entities
- Compilations
- Locations
- PreprocessorDirectives
- Types
- Extractor
- Populators
- Semmle.Extraction.Tests
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- dotnet_10
- standalone_dependency_dir
- proj
- linux/compiler_args
- posix
- query-suite
- standalone_dependencies_executing_runtime
- lib
- change-notes
- released
- ext
- semmle/code/csharp
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- internal
- security
- auth
- dataflow
- upgrades
- 605f85053409cd72b4904df3f198ddc8324f3a83
- 66044cfa5bbf2ecfabd06ead25e91db2bdd79764
- src
- Bad Practices/Control-Flow
- CSI
- Likely Bugs/Collections
- Security Features
- CWE-1004
- CWE-327
- CWE-451
- CWE-614
- change-notes/released
- experimental
- CWE-918
- Security Features
- CWE-1004
- CWE-327/Azure
- CWE-614
- utils
- modelconverter
- modelgenerator
- test
- experimental/Security Features
- CWE-1004
- CookieHttpOnlyFalseAspNetCore
- CookieBuilder
- NoPolicy
- UseCookiePolicyCallback
- CookieHttpOnlyFalseSystemWeb
- CookieWithoutHttpOnlyAspNetCore
- NoPolicy
- UseCookiePolicyAlways
- UseCookiePolicyCallback
- UseCookiePolicyNone
- CookieWithoutHttpOnlySystemWeb
- ConfigEmpty
- ConfigFalse
- HttpCookiesTrue
- CWE-614
- RequireSSLAspNetCore
- NoPolicy
- UseCookiePolicyAlways
- UseCookiePolicyCallback
- UseCookiePolicyNone
- RequireSSLFalseAspNetCore
- CookieBuilder
- NoPolicy
- UseCookiePolicyCallback
- RequireSSLFalseSystemWeb
- RequireSSLSystemWeb
- ConfigEmpty
- ConfigFalse
- FormsTrue
- HttpCookiesTrue
- library-tests
- assignables
- controlflow
- graph
- CONSISTENCY
- guards
- splits
- CONSISTENCY
- csharp11
- csharp8
- dataflow
- barrier-guards
- call-sensitivity
- callablereturnsarg
- global
- library
- local
- modulusanalysis
- signanalysis
- ssa
- definitions
- exceptions
- methods
- overlay
- base
- overlay
- statements
- query-tests
- API Abuse/FormatInvalid
- Bad Practices/Control-Flow/ConstantCondition
- Dead Code/DeadStoreOfLocal
- Nullness
- Security Features
- CWE-1004/HttpOnlyCookie
- AspNetCore
- CookieBuilder
- NoPolicy
- PolicyAlways
- PolicyCallback
- PolicyNone
- SystemWeb
- HttpOnlyCookiesFalse
- HttpOnlyCookiesTrue
- CWE-451/MissingXFrameOptions/WebConfigAddedHeaderInLocation
- CWE-614/InsecureCookie
- AspNetCore
- CookieBuilder
- NoPolicy
- PolicyAlways
- PolicyCallback
- PolicyNone
- SystemWeb
- RequireSSLFalse
- RequireSSLTrue
- FormsTrue
- HttpCookiesTrue
- standalone/Bad Practices/Control-Flow/ConstantCondition
- tools
- docs/codeql
- codeql-language-guides
- codeql-overview
- codeql-changelog
- reusables
- go
- downgrades/b1341734d6870b105e5c9d168ce7dec25d7f72d0
- extractor
- cli
- go-autobuilder
- go-extractor
- dbscheme
- srcarchive
- trap
- util
- ql
- consistency-queries
- change-notes/released
- integration-tests/query-suite
- lib
- change-notes/released
- semmle/go
- concepts
- frameworks
- stdlib
- security
- upgrades/b3da71c3ac204b557c86e9d9c26012360bdbdccb
- src
- InconsistentCode
- Security
- CWE-1004
- examples
- CWE-326
- CWE-327
- examples
- CWE-614
- examples
- change-notes
- released
- experimental
- CWE-1004
- CWE-327
- examples
- CWE-369
- CWE-918
- test
- experimental/CWE-1004
- vendor
- github.com/gorilla/sessions
- query-tests/Security
- CWE-1004
- vendor
- github.com/gin-gonic/gin
- binding
- CWE-327
- vendor
- golang.org/x/crypto
- md4
- ripemd160
- CWE-614
- vendor
- github.com/gin-gonic/gin
- binding
- javascript
- extractor/src/com/semmle
- jcorn
- flow
- js
- ast
- jsdoc
- regexp
- extractor
- ql
- integration-tests
- diagnostics/syntax-error
- query-suite
- lib
- Expressions
- LanguageFeatures
- change-notes/released
- semmle/javascript
- dataflow
- internal
- frameworks
- AngularJS
- data
- internal
- internal
- flow_summaries
- security
- dataflow
- regexp
- utils/test
- src
- Expressions
- LanguageFeatures
- Security
- CWE-020
- CWE-079
- CWE-327
- change-notes
- released
- experimental/Security/CWE-918
- test
- library-tests
- AMD
- CustomAbstractValueDefinitions
- FlowCustomisation
- ModuleImportNodes
- RecursionPrevention
- frameworks/data
- query-tests/Security
- CWE-079/ReflectedXss
- app/pages
- CWE-312
- java
- kotlin-extractor/src/main/kotlin
- utils
- ql
- integration-tests
- java
- maven-add-exports-module-flags
- src/main/java/com/example
- maven-execution-specific-java-version
- src
- main/java/com/example
- test/java/com/example
- maven-java16-with-higher-jdk
- src/main/java/com/example
- maven-java8-java11-dependency
- src
- main/java/com/example
- test/java/com/example
- maven-multimodule-test-java-version
- main-module
- src/main/java/com/example
- test-module
- src/main/java/com/example/tests
- maven-wrapper-missing-properties
- src/main/java/com/example
- query-suite
- kotlin/all-platforms/recursive_interfaces
- somepkg
- lib
- change-notes
- released
- experimental/quantum
- semmle/code/java
- controlflow
- dataflow
- internal
- rangeanalysis
- dispatch
- frameworks
- android
- security
- src
- Likely Bugs
- Collections
- Comparison
- Concurrency
- Likely Typos
- Termination
- Security/CWE
- CWE-020
- CWE-1004
- CWE-327
- CWE-614
- Violations of Best Practice/Dead Code
- change-notes
- released
- experimental
- Security/CWE
- CWE-327/Azure
- CWE-470
- CWE-502
- quantum
- Analysis
- Examples
- meta/ssa
- utils
- modelconverter
- modelgenerator
- internal
- test-kotlin2/library-tests/nested_types
- test
- experimental
- library-tests/quantum
- query-tests
- quantum
- NonceReuse
- examples
- BadMacUse
- InsecureOrUnknownNonceSource
- NonceReuse
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- security/CWE-1004
- library-tests
- dataflow
- modulus-analysis
- range-analysis
- ssa-large
- ssa
- query-tests
- Escaping
- Nullness
- SafePublication
- ThreadSafe
- examples
- security
- CWE-1004
- CWE-532
- CWE-918
- misc
- bazel
- 3rdparty
- py_deps
- tree_sitter_extractors_deps
- codegen/templates
- ripunzip
- scripts
- suite-helpers
- change-notes/released
- python
- downgrades
- 6a1f497168da2f43828161d3c86db7d4c94c2b53
- acf8d3b08ae3cfac8833d16efbfa5a10fef86819
- extractor
- semmle
- tests
- ql
- consistency-queries
- examples/snippets
- integration-tests/query-suite
- lib
- analysis
- change-notes/released
- semmle/python
- dataflow
- new
- old
- dependencies
- frameworks/data/internal
- internal
- objects
- security/dataflow
- types
- values
- upgrades
- 5af903da088e3746aa283700a43a779302453523
- 6a1f497168da2f43828161d3c86db7d4c94c2b53
- src
- Classes
- Exceptions
- Expressions
- Formatting
- Functions
- Imports
- Security
- CWE-020
- CWE-1004
- examples
- CWE-1275
- examples
- CWE-327
- CWE-614
- examples
- Statements
- Testing
- Variables
- analysis
- change-notes/released
- experimental
- Security
- CWE-094
- CWE-327/Azure
- CWE-346
- cryptography/example_alerts
- semmle/python/security
- test
- 2/library-tests
- PointsTo
- class_properties
- imports2
- imports
- origin_uniqueness
- six
- 3/library-tests
- PointsTo
- attributes
- class_properties
- imports
- typehints
- six
- extractor-tests
- exports
- overlay
- basic-full-eval
- lib
- basic-overlay-eval
- orig_src
- lib
- library-tests
- PointsTo
- absent
- calls
- comparisons
- decorators
- general
- guarded
- import_star
- indexing
- inheritance
- new
- properties
- regressions
- missing
- if-urlsplit-access
- re-compile
- uncalled-function
- wrong/classmethod
- super
- objects
- taint/extensions
- query-tests/Security
- CWE-1004-NonHttpOnlyCookie
- CWE-1275-SameSiteNoneCookie
- CWE-614-InsecureCookie
- ql/ql/src/queries
- performance
- style
- docs
- ruby/ql
- lib
- change-notes/released
- codeql/ruby
- frameworks/data/internal
- security/regexp
- src
- change-notes/released
- experimental
- manually-check-http-verb
- weak-params
- queries
- security
- cwe-020
- cwe-327
- cwe-352
- cwe-732
- variables
- utils/modeleditor
- test/library-tests/security
- rust
- ast-generator/src
- downgrades/30a0713e5bf69c60d003e4994e5abd1c78a36826
- extractor/src
- generated
- translate
- ql
- examples
- snippets
- integration-tests
- hello-workspace
- exe/src
- lib/src
- query-suite
- lib
- change-notes
- released
- codeql
- files
- rust
- controlflow/internal
- dataflow
- internal
- elements
- internal
- generated
- frameworks
- asyncstd
- rustcrypto
- stdlib
- tokio
- internal
- typeinference
- security
- regex
- upgrades/dfade44a27bd44db996ae8c5095a11effc883aba
- utils/test
- src
- change-notes
- released
- queries
- security
- CWE-295
- CWE-312
- CWE-327
- CWE-614
- CWE-825
- summary
- telemetry
- unusedentities
- utils/modelgenerator
- internal
- test
- extractor-tests
- File
- CONSISTENCY
- bad_cargo
- src
- nested
- generated
- ClosureExpr
- Function
- MatchArm
- RetTypeRepr
- UseBoundGenericArgs
- literal
- macro-expansion
- macro-in-library
- library-tests
- const_access
- dataflow
- barrier
- global
- CONSISTENCY
- local
- CONSISTENCY
- models/CONSISTENCY
- sources
- CONSISTENCY
- database
- CONSISTENCY
- env
- file
- net
- CONSISTENCY
- stdin
- web_frameworks
- CONSISTENCY
- strings
- CONSISTENCY
- elements
- builtintypes
- enum
- frameworks/postgres/CONSISTENCY
- path-resolution
- CONSISTENCY
- sensitivedata
- CONSISTENCY
- type-inference
- CONSISTENCY
- invalid
- loop
- variables
- query-tests
- diagnostics
- security
- CWE-020
- CWE-089
- CONSISTENCY
- CWE-117
- CWE-295
- CWE-312
- CONSISTENCY
- CWE-327
- BrokenCryptoAlgorithm
- CONSISTENCY
- WeakSensitiveDataHashing
- CWE-614
- CWE-696/CONSISTENCY
- CWE-770
- CWE-825
- CONSISTENCY
- CWE-918
- CONSISTENCY
- unusedentities
- schema
- tools/builtins
- swift
- downgrades
- 33e5e5e03bd3f98322f4c67aefa81015be832b88
- b7006eaacb007a06251596835506185619b86e98
- extractor
- infra
- mangler
- translators
- ql
- integration-tests
- autobuilder/xcode-fails-spm-works
- posix/deduplication
- lib
- change-notes/released
- codeql/swift
- elements
- decl
- internal
- expr
- internal
- internal
- type
- internal
- generated
- decl
- expr
- type
- security
- upgrades
- 987ab0bc0911f8c88449210e21d2ee80ebcb488a
- b7006eaacb007a06251596835506185619b86e98
- src
- change-notes/released
- test
- extractor-tests
- declarations
- expressions
- generated
- AvailabilitySpec
- KeyPathComponent
- decl
- Accessor
- CapturedDecl
- ConcreteVarDecl
- MacroDecl
- ParamDecl
- PoundDiagnosticDecl
- UsingDecl
- expr
- AppliedPropertyWrapperExpr
- IdentityExpr
- MethodLookupExpr
- type
- ExistentialArchetypeType
- InlineArrayType
- library-tests
- ast
- controlflow/graph
- dataflow/dataflow
- elements
- KeyPathComponent
- expr/methodlookup
- type/nominaltype
- query-tests/Diagnostics
- third_party/resources
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,302 files changed
+170712
-65658
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
82 | 82 | | |
83 | 83 | | |
84 | 84 | | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | 85 | | |
89 | 86 | | |
90 | 87 | | |
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
9 | | - | |
| 8 | + | |
| 9 | + | |
10 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
11 | 16 | | |
12 | 17 | | |
| 18 | + | |
13 | 19 | | |
| 20 | + | |
14 | 21 | | |
15 | 22 | | |
| 23 | + | |
16 | 24 | | |
| 25 | + | |
17 | 26 | | |
18 | 27 | | |
| 28 | + | |
19 | 29 | | |
20 | | - | |
| 30 | + | |
21 | 31 | | |
22 | 32 | | |
23 | 33 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
13 | | - | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
23 | | - | |
| 22 | + | |
| 23 | + | |
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | 30 | | |
31 | | - | |
| 31 | + | |
32 | 32 | | |
33 | 33 | | |
34 | 34 | | |
| |||
269 | 269 | | |
270 | 270 | | |
271 | 271 | | |
272 | | - | |
| 272 | + | |
273 | 273 | | |
274 | | - | |
275 | | - | |
276 | | - | |
277 | | - | |
278 | | - | |
279 | | - | |
280 | | - | |
281 | | - | |
282 | | - | |
283 | | - | |
284 | | - | |
285 | | - | |
286 | | - | |
287 | | - | |
288 | | - | |
289 | | - | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
290 | 282 | | |
291 | 283 | | |
292 | 284 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
1 | 9 | | |
2 | 10 | | |
3 | 11 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
0 commit comments