Commit f89b321
File tree
2,041 files changed
+145334
-121977
lines changed- .devcontainer/swift
- .github
- actions/fetch-codeql
- workflows
- config
- cpp
- downgrades/23f7cbb88a4eb29f30c3490363dc201bc054c5ff
- ql
- lib
- change-notes
- released
- semmle/code/cpp
- controlflow
- dataflow/internal
- tainttracking1
- tainttracking2
- exprs
- internal
- ir
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- implementation
- aliased_ssa
- internal
- raw
- internal
- unaliased_ssa
- internal
- upgrades/19e31bf071f588bb7efd1e4d5a185ce4f6fbbd84
- src
- Likely Bugs
- Conversion
- Likely Typos
- Memory Management
- Security/CWE
- CWE-078
- CWE-253
- CWE-428
- CWE-704
- CWE-732
- change-notes/released
- experimental/Security/CWE
- CWE-273
- CWE-670
- test
- TestUtilities
- experimental/query-tests/Security/CWE/CWE-670/semmle/tests
- library-tests
- builtins
- edg
- type_traits
- controlflow/nullness
- dataflow
- dataflow-tests
- taint-tests
- declarationEntry/declarationEntry
- ir
- ir
- ssa
- syntax-zoo
- templates/CPP-203
- valuenumbering/GlobalValueNumbering
- variables/global
- vector_types
- query-tests
- Likely Bugs
- Conversion/LossyFunctionResultCast
- Memory Management/ReturnStackAllocatedMemory
- Security/CWE
- CWE-134/semmle/globalVars
- CWE-497/semmle/tests
- CWE-611
- csharp
- extractor
- Semmle.Extraction.CSharp
- Entities
- Statements
- Extractor
- Populators
- Semmle.Extraction.Tests
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- lib
- change-notes/released
- semmle/code/csharp
- controlflow/internal
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- tainttracking5
- frameworks
- generated/dotnet
- microsoft
- extensions
- system
- collections
- componentmodel
- data
- io
- net
- runtime
- security
- cryptography
- text
- threading
- web/ui
- xml
- security/dataflow
- flowsinks
- flowsources
- src
- Diagnostics
- Telemetry
- change-notes/released
- experimental
- CWE-918
- Security Features/CWE-327/Azure
- ir
- implementation
- internal
- raw
- internal
- unaliased_ssa
- internal
- utils/model-generator
- internal
- test
- TestUtilities
- experimental/ir/ir
- library-tests
- csharp9-standalone
- dataflow
- external-models
- flowsources/aspremote
- library
- frameworks/EntityFramework
- query-tests/Security Features/CWE-079/XSS
- resources/stubs
- utils/model-generator
- tools
- docs/codeql
- codeql-cli
- codeql-language-guides
- codeql-overview
- query-help
- reusables
- support/reusables
- go
- codeql-tools
- extractor/cli/go-autobuilder
- ql
- lib
- change-notes/released
- semmle/go
- dataflow
- barrierguardutil
- internal
- tainttracking1
- tainttracking2
- security
- src
- InconsistentCode
- Security/CWE-326
- change-notes
- released
- experimental
- CWE-321
- CWE-369
- CWE-918
- test
- TestUtilities
- library-tests/semmle/go/dataflow/GuardingFunctions
- javascript
- downgrades
- c0664d5721c90dd32a5b167efea24f9cc6f57cfb
- initial
- externs/nodejs
- extractor
- lib/typescript/src
- src/com/semmle
- js/extractor
- ts
- ast
- extractor
- ql
- examples/queries/dataflow/TemplateInjection
- lib
- Declarations
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- frameworks
- AngularJS
- heuristics
- security
- dataflow
- internal
- upgrades/c1ee5346e068f6e0b687e75b4ba3f04a7382f4c4
- src
- Declarations
- Expressions
- LanguageFeatures
- Metrics
- NodeJS
- RegExp
- Security
- CWE-020
- CWE-094
- CWE-178
- examples
- CWE-200
- CWE-384
- change-notes/released
- external
- meta
- alerts
- analysis-quality
- test
- library-tests/TypeTracking
- query-tests/Security
- CWE-022/TaintedPath
- CWE-079
- DomBasedXss
- UnsafeHtmlConstruction
- CWE-094/CodeInjection
- lib
- CWE-178
- java
- documentation/library-coverage
- kotlin-extractor
- src/main/kotlin
- comments
- utils
- versions
- v_1_4_32
- v_1_5_0
- v_1_5_10
- v_1_5_21
- v_1_5_31
- v_1_6_10
- v_1_6_20
- v_1_7_0-RC
- v_1_7_0
- ql
- consistency-queries
- integration-tests
- linux-only/kotlin
- custom_plugin
- plugin
- resources/META-INF/services
- use_java_library
- javasrc/extlib
- posix-only/kotlin
- enabling
- extractor_crash
- code
- gradle_groovy_app
- app
- src/main/kotlin/testProject
- gradle_kotlinx_serialization
- app
- src/main/kotlin/testProject
- java_kotlin_extraction_orders
- kotlin_compiler_java_source
- kotlin_file_import
- libsrc
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- kotlinc_multi
- logs
- module_mangled_names
- nested_generic_types
- libsrc/extlib
- private_property_accessors
- raw_generic_types
- libsrc/extlib
- lib
- change-notes/released
- config
- semmle/code
- java
- dataflow
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- dispatch
- frameworks
- android
- apache
- guava
- jackson
- javaee/jsf
- ratpack
- spring
- regex
- security
- upgrades
- 57c55f404a5954f0e738febf590ad5d49dd67b08
- b9225587bc0a643ae484ec215b9a6f19d17d0fc2
- cf58c7d9b1fa1eae9cdc20ce8f157c140ac0c3de
- src
- Likely Bugs
- Cloning
- Collections
- Comparison
- Likely Typos
- Serialization
- Security/CWE
- CWE-022
- CWE-117
- CWE-295
- CWE-925
- Telemetry
- Violations of Best Practice/Naming Conventions
- change-notes
- released
- experimental
- Security/CWE
- CWE-020
- CWE-073
- CWE-200
- CWE-321
- CWE-327/Azure
- CWE-400
- CWE-470
- CWE-552
- CWE-601
- semmle/code/java
- utils
- flowtestcasegenerator
- model-generator
- internal
- test
- TestUtilities
- kotlin/library-tests
- arrays-with-variances
- classes
- data-classes
- dataflow
- notnullexpr
- whenexpr
- exprs_typeaccess
- exprs
- for-array-iterators
- generic-instance-methods
- generics
- internal-public-alias
- java-kotlin-collection-type-generic-methods
- jvmstatic-annotation
- lazy-val-multiple-constructors
- maps-iterator-overloads
- methods
- modifiers
- properties
- reflection
- stmts
- string-charat
- super-method-calls
- library-tests
- dataflow
- callback-dispatch
- collections
- external-models
- frameworks
- android
- content-provider
- external-storage
- flow-steps
- intent
- notification
- slice
- uri
- widget
- apache-collections
- guava/generated
- cache
- collect
- jackson
- javax-json
- json-java
- okhttp
- spring
- beans
- cache
- ui
- util
- webmultipart
- webutil
- stream
- logging
- optional
- regex
- scanner
- types/cycles
- wildcard-substitution
- xml
- query-tests
- NonSerializableField
- security
- CWE-022/semmle/tests
- CWE-094
- CWE-295/ImproperWebVeiwCertificateValidation
- CWE-312
- CWE-749
- CWE-925
- stubs
- apache-commons-io-2.6/org/apache/commons/io/output
- google-android-9.0.0/android
- app
- assist
- content
- media
- net/http
- os
- print
- text
- transition
- view
- accessibility
- textclassifier
- webkit
- widget
- window
- utils/model-generator
- misc/suite-helpers
- python/ql
- lib
- analysis
- change-notes/released
- semmle/python
- dataflow/new
- internal
- tainttracking1
- tainttracking2
- tainttracking3
- tainttracking4
- filters
- frameworks
- data
- internal
- internal
- pointsto
- security
- dataflow
- internal
- src
- Security
- CWE-020
- CWE-022
- CWE-079
- CWE-285
- CWE-295
- CWE-327
- CWE-732
- analysis
- change-notes
- released
- experimental
- Security/CWE-327/Azure
- semmle/python
- frameworks
- security
- dataflow
- injection
- test
- TestUtilities
- experimental
- dataflow
- sensitive-data
- tainttracking
- commonSanitizer
- customSanitizer
- typetracking
- meta
- debug
- library-tests
- ApiGraphs/py2
- frameworks
- asyncpg
- data
- stdlib
- query-tests
- Security/CWE-022-TarSlip
- analysis/suppression
- ql
- autobuilder/src
- extractor
- src
- generator
- ql
- src
- codeql_ql
- ast
- internal
- dataflow
- style
- codeql
- files
- ide-contextual-queries
- queries
- bugs
- diagnostics
- performance
- reports
- style
- test
- TestUtilities
- callgraph
- printAst
- queries/style
- AcronymsShouldBeCamelCase
- DeadCode
- MissingOverride
- MissingParameterInQlDoc
- Misspelling
- RedundantCast
- type
- scripts
- ruby
- autobuilder/src
- downgrades/4ba51641799d2aaa315c7323931e2dd2a94c9f9d
- extractor
- src
- generator
- ql
- lib
- change-notes
- released
- codeql/ruby
- ast
- internal
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- tainttrackingforlibraries
- frameworks
- core
- internal
- data
- internal
- http_clients
- stdlib
- security
- internal
- performance
- ide-contextual-queries
- upgrades/1199e154f5e9b3560297633c6ebb4dfe0b191ae4
- src
- change-notes
- released
- experimental
- decompression-api
- examples
- improper-memoization
- manually-check-http-verb
- weak-params
- queries/security
- cwe-020
- cwe-078
- cwe-089
- test
- TestUtilities
- library-tests
- ast
- constants
- erb
- misc
- concepts
- app/controllers
- dataflow
- api-graphs
- barrier-guards
- hash-flow
- pathname-flow
- summaries
- frameworks
- action_cable
- action_dispatch
- active_record
- active_support
- app/controllers/foo
- archive
- arel
- files
- pathname
- railties
- stdlib
- query-tests
- experimental
- improper-memoization
- manually-check-http-verb
- weak-params
- security
- cwe-022
- cwe-089
- cwe-601
- decompression-api
- swift
- codegen
- generators
- lib
- templates
- test
- extractor
- infra
- trap
- visitors
- integration-tests
- osx-only/frontend-invocations
- posix-only
- cross-references
- Sources/cross-references
- hello-world
- Sources/hello-world
- partial-modules
- A
- Sources/A
- B
- Sources/B
- Sources/partial-modules
- ql
- lib
- codeql/swift
- controlflow
- internal
- dataflow
- internal
- tainttracking1
- elements
- decl
- expr
- typerepr
- type
- frameworks/StandardLibrary
- generated
- decl
- expr
- pattern
- typerepr
- type
- src/queries/Security
- CWE-079
- CWE-135
- test
- TestUtilities
- extractor-tests
- comments
- declarations
- expressions
- generated
- Comment
- File
- decl
- ConcreteFuncDecl
- ConcreteVarDecl
- EnumDecl
- IfConfigClause
- IfConfigDecl
- ImportDecl
- ModuleDecl
- ParamDecl
- expr
- BridgeFromObjCExpr
- BridgeToObjCExpr
- ConditionalBridgeFromObjCExpr
- DotSelfExpr
- DotSyntaxCallExpr
- EnumIsCaseExpr
- ErrorExpr
- ObjCSelectorExpr
- SequenceExpr
- UnresolvedDeclRefExpr
- UnresolvedMemberExpr
- UnresolvedPatternExpr
- UnresolvedSpecializeExpr
- typerepr
- ArrayTypeRepr
- AttributedTypeRepr
- CompileTimeConstTypeRepr
- CompositionTypeRepr
- CompoundIdentTypeRepr
- DictionaryTypeRepr
- ErrorTypeRepr
- ExistentialTypeRepr
- FixedTypeRepr
- FunctionTypeRepr
- GenericIdentTypeRepr
- ImplicitlyUnwrappedOptionalTypeRepr
- InOutTypeRepr
- IsolatedTypeRepr
- MetatypeTypeRepr
- NamedOpaqueReturnTypeRepr
- OpaqueReturnTypeRepr
- OptionalTypeRepr
- OwnedTypeRepr
- PlaceholderTypeRepr
- ProtocolTypeRepr
- SilBoxTypeRepr
- SimpleIdentTypeRepr
- TupleTypeRepr
- type
- BuiltinBridgeObjectType
- BuiltinDefaultActorStorageType
- BuiltinExecutorType
- BuiltinFloatType
- BuiltinIntegerLiteralType
- BuiltinIntegerType
- BuiltinJobType
- BuiltinNativeObjectType
- BuiltinRawPointerType
- BuiltinRawUnsafeContinuationType
- BuiltinType
- BuiltinUnsafeValueBufferType
- BuiltinVectorType
- DynamicSelfType
- ExistentialType
- InOutType
- ModuleType
- NestedArchetypeType
- OpenedArchetypeType
- PrimaryArchetypeType
- ProtocolCompositionType
- TypeRepr
- UnmanagedStorageType
- UnownedStorageType
- VariadicSequenceType
- WeakStorageType
- statements
- types
- library-tests
- controlflow/graph
- dataflow
- dataflow
- taint
- elements/expr
- arithmeticoperation
- logicaloperation
- parent
- query-tests/Security
- CWE-079
- CWE-135
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
2,041 files changed
+145334
-121977
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | 6 | | |
17 | 7 | | |
18 | 8 | | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
23 | 13 | | |
24 | 14 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10 | 10 | | |
11 | 11 | | |
12 | 12 | | |
| 13 | + | |
13 | 14 | | |
14 | 15 | | |
15 | 16 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
8 | 9 | | |
9 | 10 | | |
10 | 11 | | |
| |||
14 | 15 | | |
15 | 16 | | |
16 | 17 | | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
22 | | - | |
23 | | - | |
24 | | - | |
25 | 18 | | |
26 | 19 | | |
27 | 20 | | |
28 | 21 | | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
29 | 25 | | |
30 | 26 | | |
31 | 27 | | |
| |||
34 | 30 | | |
35 | 31 | | |
36 | 32 | | |
37 | | - | |
| 33 | + | |
38 | 34 | | |
39 | 35 | | |
40 | 36 | | |
41 | 37 | | |
42 | 38 | | |
43 | 39 | | |
44 | 40 | | |
45 | | - | |
| 41 | + | |
46 | 42 | | |
47 | 43 | | |
48 | 44 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| 15 | + | |
15 | 16 | | |
16 | 17 | | |
17 | 18 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
8 | | - | |
9 | | - | |
10 | | - | |
11 | | - | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
12 | 14 | | |
13 | | - | |
14 | | - | |
| 15 | + | |
| 16 | + | |
15 | 17 | | |
16 | 18 | | |
17 | | - | |
| 19 | + | |
18 | 20 | | |
19 | 21 | | |
20 | 22 | | |
| |||
23 | 25 | | |
24 | 26 | | |
25 | 27 | | |
26 | | - | |
27 | | - | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
32 | | - | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
37 | | - | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
56 | | - | |
57 | | - | |
58 | | - | |
59 | | - | |
60 | | - | |
61 | | - | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | | - | |
67 | | - | |
68 | | - | |
69 | | - | |
70 | | - | |
71 | | - | |
72 | | - | |
73 | | - | |
74 | | - | |
75 | | - | |
76 | | - | |
77 | | - | |
78 | | - | |
79 | | - | |
80 | | - | |
81 | | - | |
82 | | - | |
83 | | - | |
84 | | - | |
85 | | - | |
86 | | - | |
87 | | - | |
88 | | - | |
89 | | - | |
90 | | - | |
91 | | - | |
92 | | - | |
93 | | - | |
94 | | - | |
95 | | - | |
96 | | - | |
97 | | - | |
98 | | - | |
99 | | - | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
0 commit comments