Commit cf7091a
File tree
454 files changed
+20773
-21177
lines changed- cpp/ql
- lib/semmle/code/cpp/ir/dataflow/internal
- test
- experimental/query-tests/Security/CWE
- CWE-078
- CWE-190/AllocMultiplicationOverflow
- CWE-193
- array-access
- constant-size
- CWE-359/semmle/tests
- library-tests/dataflow
- dataflow-tests
- fields
- query-tests
- Critical/MemoryFreed
- Likely Bugs/Conversion/CastArrayPointerArithmetic
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-079/semmle/CgiXss
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-119
- SAMATE
- semmle/tests
- CWE-120/semmle/tests
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- TaintedAllocationSize
- tainted
- CWE-193
- CWE-290/semmle/AuthenticationBypass
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests/UseAfterFree
- CWE-497
- SAMATE
- semmle/tests
- CWE-611
- CWE-807/semmle/TaintedCondition
- csharp
- extractor/Semmle.Extraction.CSharp/Entities
- PreprocessorDirectives
- ql
- consistency-queries
- lib/semmle/code/csharp
- dataflow/internal
- security/dataflow
- src/experimental/Security Features/backdoor
- test
- experimental
- CWE-918
- Security Features
- CWE-759
- backdoor
- library-tests
- cil/dataflow
- csharp7
- dataflow
- async
- call-sensitivity
- collections
- delegates
- external-models
- fields
- global
- operators
- threat-models
- tuples
- typeflow-dispatch
- types
- frameworks/EntityFramework
- query-tests
- API Abuse/FormatInvalid
- Likely Bugs/UnsafeYearConstruction
- Security Features
- CWE-020
- CWE-022
- TaintedPath
- ZipSlip
- CWE-078
- CWE-079
- StoredXSS
- XSSAsp
- XSSRazorPages
- Generated
- XSS
- XssPageModels
- CWE-089
- CWE-090
- CWE-091/XMLInjection
- CWE-094
- CWE-099
- CWE-112
- CWE-114/AssemblyPathInjection
- CWE-117
- CWE-134
- CWE-201/ExposureInTransmittedData
- CWE-209
- CWE-321/HardcodedSymmetricEncryptionKey
- CWE-327
- DontInstallRootCert
- InsecureSQLConnection
- CWE-338
- CWE-502
- UnsafeDeserializationUntrustedInputNewtonsoftJson
- UnsafeDeserializationUntrustedInput
- CWE-601/UrlRedirect
- CWE-611
- CWE-643
- CWE-730
- ReDoSGlobalTimeout
- ReDoS
- RegexInjection
- CWE-798
- CWE-807
- CWE-838
- go/ql/test
- experimental
- CWE-090
- CWE-1004
- CWE-203
- CWE-287
- CWE-321-V2
- CWE-321
- CWE-347
- CWE-369
- CWE-74
- CWE-79
- CWE-918
- Unsafe
- library-tests/semmle/go
- dataflow
- ChannelField
- DefaultTaintSanitizer
- HiddenNodes
- frameworks
- BeegoOrm
- Beego
- Chi
- Echo
- Encoding
- Gin
- GoMicro
- Gorestful
- Revel
- Twirp
- XNetHtml
- query-tests
- InconsistentCode/UnhandledCloseWritableHandle
- Security
- CWE-020/IncompleteHostnameRegexp
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- CWE-209
- CWE-312
- CWE-322
- CWE-326
- CWE-327
- CWE-338/InsecureRandomness
- CWE-352
- CWE-601
- BadRedirectCheck
- OpenUrlRedirect
- CWE-640
- CWE-643
- CWE-918
- java
- documentation/library-coverage
- ql
- integration-tests/all-platforms/kotlin/kotlin_java_static_fields
- lib
- change-notes
- ext
- semmle/code/java
- dataflow/internal
- security
- src
- Security/CWE
- CWE-022
- CWE-200
- change-notes
- experimental/Security/CWE/CWE-073
- test
- experimental/query-tests/security
- CWE-020
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-1004
- CWE-200
- CWE-208
- NotConstantTimeCheckOnSignature
- TimingAttackAgainstSignagure
- CWE-299
- CWE-327
- CWE-346
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-502
- CWE-552
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-755
- CWE-759
- library-tests
- dataflow
- call-sensitivity
- threat-models
- frameworks/JaxWs
- neutrals/neutralsinks
- pathcreation
- query-tests
- Telemetry/SupportedExternalSinks
- security
- CWE-022/semmle/tests
- mad
- CWE-078
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests/TempDirLocalInformationDisclosure
- CWE-297
- CWE-311/CWE-319
- CWE-327/semmle/tests
- CWE-601/semmle/tests
- CWE-681/semmle/tests
- CWE-807/semmle/tests
- utils/modeleditor
- python/ql
- lib/semmle/python/dataflow/new/internal
- test
- experimental
- dataflow/summaries
- query-tests/Security
- CWE-022-TarSlip
- CWE-022-UnsafeUnpacking
- CWE-074-TemplateInjection
- CWE-074-paramiko
- CWE-079
- CWE-091-XsltInjection
- CWE-113
- CWE-1236
- CWE-176
- CWE-208
- TimingAttackAgainstHash
- TimingAttackAgainstSensitiveInfo
- CWE-287-ConstantSecretKey
- CWE-327-UnsafeUsageOfClientSideEncryptionVersion
- CWE-348
- CWE-522
- CWE-614
- library-tests/frameworks
- django-orm
- modeling-example
- query-tests
- Functions/ModificationOfParameterWithDefault
- Security
- CWE-020-ExternalAPIs
- CWE-022-PathInjection
- CWE-022-TarSlip
- CWE-078-CommandInjection-py2
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- CWE-079-ReflectedXss
- CWE-089-SqlInjection
- CWE-090-LdapInjection
- CWE-094-CodeInjection
- CWE-117-LogInjection
- CWE-209-StackTraceExposure
- CWE-285-PamAuthorization
- CWE-312-CleartextLogging
- CWE-312-CleartextStorage-py3
- CWE-312-CleartextStorage
- CWE-327-WeakSensitiveDataHashing
- CWE-502-UnsafeDeserialization
- CWE-601-UrlRedirect
- CWE-611-Xxe
- CWE-643-XPathInjection
- CWE-730-PolynomialReDoS
- CWE-730-RegexInjection
- CWE-776-XmlBomb
- CWE-798-HardcodedCredentials
- CWE-918-ServerSideRequestForgery
- CWE-943-NoSqlInjection
- ql
- buramu
- ruby/ql
- lib/codeql/ruby/dataflow/internal
- test
- library-tests
- dataflow
- array-flow
- call-sensitivity
- erb
- flow-summaries
- global
- hash-flow
- local
- params
- ssa-flow
- string-flow
- summaries
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- sinatra
- variables
- query-tests
- experimental
- ImproperLdapAuth
- LdapInjection
- TemplateInjection
- XPathInjection
- cwe-022-ZipSlip
- cwe-176
- manually-check-http-verb
- weak-params
- security
- cwe-020/MissingFullAnchor
- cwe-022
- cwe-078
- CommandInjection
- KernelOpen
- UnsafeShellCommandConstruction
- cwe-079
- cwe-089
- cwe-094
- CodeInjection
- UnsafeCodeConstruction
- cwe-117
- cwe-1333-polynomial-redos
- cwe-1333-regexp-injection
- cwe-134
- cwe-209
- cwe-312
- cwe-502
- oj-global-options
- ox-global-options
- unsafe-deserialization
- cwe-506
- cwe-601
- cwe-611
- libxml-backend
- xxe
- cwe-732
- cwe-798
- cwe-807-user-controlled-bypass
- cwe-829
- cwe-912
- cwe-918
- decompression-api
- swift/ql/test
- library-tests/dataflow
- dataflow
- taint/core
- query-tests/Security
- CWE-078
- CWE-079
- CWE-089
- CWE-094
- CWE-1204
- CWE-134
- CWE-135
- CWE-259
- CWE-311
- CWE-312
- CWE-321
- CWE-327
- CWE-328
- CWE-730
- CWE-757
- CWE-760
- CWE-916
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
454 files changed
+20773
-21177
lines changedLines changed: 17 additions & 10 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
709 | 709 | | |
710 | 710 | | |
711 | 711 | | |
712 | | - | |
| 712 | + | |
713 | 713 | | |
714 | 714 | | |
715 | 715 | | |
| |||
740 | 740 | | |
741 | 741 | | |
742 | 742 | | |
743 | | - | |
| 743 | + | |
744 | 744 | | |
745 | 745 | | |
746 | 746 | | |
| |||
943 | 943 | | |
944 | 944 | | |
945 | 945 | | |
946 | | - | |
947 | | - | |
948 | | - | |
949 | | - | |
| 946 | + | |
| 947 | + | |
| 948 | + | |
| 949 | + | |
| 950 | + | |
| 951 | + | |
| 952 | + | |
950 | 953 | | |
951 | 954 | | |
952 | 955 | | |
| |||
996 | 999 | | |
997 | 1000 | | |
998 | 1001 | | |
| 1002 | + | |
| 1003 | + | |
999 | 1004 | | |
1000 | 1005 | | |
1001 | 1006 | | |
1002 | 1007 | | |
1003 | 1008 | | |
1004 | | - | |
| 1009 | + | |
1005 | 1010 | | |
1006 | 1011 | | |
1007 | 1012 | | |
| |||
1038 | 1043 | | |
1039 | 1044 | | |
1040 | 1045 | | |
| 1046 | + | |
| 1047 | + | |
1041 | 1048 | | |
1042 | 1049 | | |
1043 | 1050 | | |
1044 | 1051 | | |
1045 | 1052 | | |
1046 | | - | |
| 1053 | + | |
1047 | 1054 | | |
1048 | 1055 | | |
1049 | 1056 | | |
| |||
1136 | 1143 | | |
1137 | 1144 | | |
1138 | 1145 | | |
1139 | | - | |
| 1146 | + | |
1140 | 1147 | | |
1141 | 1148 | | |
1142 | 1149 | | |
| |||
1789 | 1796 | | |
1790 | 1797 | | |
1791 | 1798 | | |
1792 | | - | |
| 1799 | + | |
1793 | 1800 | | |
1794 | 1801 | | |
1795 | 1802 | | |
| |||
Lines changed: 8 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
507 | 507 | | |
508 | 508 | | |
509 | 509 | | |
510 | | - | |
| 510 | + | |
511 | 511 | | |
512 | 512 | | |
513 | 513 | | |
514 | 514 | | |
515 | 515 | | |
516 | | - | |
| 516 | + | |
517 | 517 | | |
518 | 518 | | |
519 | 519 | | |
| |||
530 | 530 | | |
531 | 531 | | |
532 | 532 | | |
533 | | - | |
| 533 | + | |
534 | 534 | | |
535 | 535 | | |
536 | 536 | | |
| |||
543 | 543 | | |
544 | 544 | | |
545 | 545 | | |
546 | | - | |
| 546 | + | |
547 | 547 | | |
548 | 548 | | |
549 | 549 | | |
| |||
558 | 558 | | |
559 | 559 | | |
560 | 560 | | |
561 | | - | |
| 561 | + | |
562 | 562 | | |
563 | 563 | | |
564 | 564 | | |
| |||
571 | 571 | | |
572 | 572 | | |
573 | 573 | | |
574 | | - | |
| 574 | + | |
575 | 575 | | |
576 | 576 | | |
577 | 577 | | |
| |||
590 | 590 | | |
591 | 591 | | |
592 | 592 | | |
593 | | - | |
| 593 | + | |
594 | 594 | | |
595 | 595 | | |
596 | 596 | | |
| |||
610 | 610 | | |
611 | 611 | | |
612 | 612 | | |
613 | | - | |
| 613 | + | |
614 | 614 | | |
615 | 615 | | |
616 | 616 | | |
| |||
Lines changed: 17 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
548 | 548 | | |
549 | 549 | | |
550 | 550 | | |
| 551 | + | |
| 552 | + | |
| 553 | + | |
| 554 | + | |
| 555 | + | |
551 | 556 | | |
552 | 557 | | |
553 | 558 | | |
| |||
591 | 596 | | |
592 | 597 | | |
593 | 598 | | |
594 | | - | |
595 | | - | |
| 599 | + | |
| 600 | + | |
596 | 601 | | |
597 | 602 | | |
598 | 603 | | |
| 604 | + | |
| 605 | + | |
| 606 | + | |
| 607 | + | |
| 608 | + | |
599 | 609 | | |
600 | 610 | | |
601 | 611 | | |
| |||
1115 | 1125 | | |
1116 | 1126 | | |
1117 | 1127 | | |
| 1128 | + | |
| 1129 | + | |
| 1130 | + | |
| 1131 | + | |
| 1132 | + | |
1118 | 1133 | | |
1119 | 1134 | | |
1120 | 1135 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
| |||
Lines changed: 3 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
4 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| |||
Lines changed: 39 additions & 39 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
4 | | - | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| |||
0 commit comments