Commit 20546fe
authored
File tree
- .github
- instructions
- workflows
- actions
- extractor
- tools
- ql
- integration-tests/query-suite
- lib
- change-notes/released
- codeql
- actions
- ast/internal
- controlflow
- dataflow
- security
- src
- Diagnostics
- Models
- Security/CWE-829
- change-notes/released
- experimental/Security
- CWE-200
- CWE-829
- test/query-tests/Security/CWE-200
- config
- cpp/ql
- integration-tests/query-suite
- lib
- change-notes
- released
- experimental
- cryptography
- modules
- utils/OpenSSL
- quantum
- OpenSSL
- AlgorithmInstances
- AlgorithmValueConsumers
- Operations
- semmle/code/cpp/rangeanalysis
- semmle/code/cpp
- commons
- controlflow
- internal
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa
- gvn/internal
- raw
- gvn/internal
- internal
- unaliased_ssa
- gvn/internal
- internal
- models/interfaces
- rangeanalysis
- new/internal/semantic
- security
- boostorg/asio
- src
- Best Practices/Magic Constants
- Critical
- Likely Bugs
- Arithmetic
- Format
- Leap Year
- Memory Management
- Protocols
- Underspecified Functions
- Metrics/Internal
- Security/CWE
- CWE-078
- CWE-089
- CWE-120
- CWE-129
- CWE-190
- CWE-290
- CWE-295
- CWE-311
- CWE-313
- CWE-319
- CWE-327
- CWE-367
- CWE-457
- CWE-468
- CWE-570
- change-notes/released
- experimental
- Likely Bugs
- Security/CWE
- CWE-078
- CWE-1126
- CWE-125
- CWE-193
- CWE-243
- CWE-401
- CWE-409
- CWE-416
- external
- jsf/4.10 Classes
- test
- examples/docs-examples/analyzing-data-flow-in-cpp
- experimental/library-tests
- quantum
- rangeanalysis/rangeanalysis
- library-tests
- controlflow
- guards-ir
- guards
- dataflow
- dataflow-tests
- fields
- ir-barrier-guards
- models-as-data
- files
- functions/routinetype
- ir/range-analysis
- permissive
- preprocessor/preprocessor
- rangeanalysis/SimpleRangeAnalysis
- syntax-zoo
- typedefs
- types
- __wchar_t
- cstd_types
- integral_types_ms
- wchar_t_typedef
- variables/variables
- query-tests
- Critical/MissingCheckScanf
- Security/CWE/CWE-457/semmle/tests
- csharp
- actions/create-extractor-pack
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp
- Entities
- Base
- Locations
- PreprocessorDirectives
- Types
- Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- all-platforms
- autobuild
- binlog_multiple
- binlog
- blazor_build_mode_none/BlazorTest
- blazor
- BlazorTest
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_resx
- standalone_winforms
- standalone
- linux
- compiler_args
- dotnet_10_rc2
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- query-suite
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- proj
- standalone_dependencies_nuget_config_error
- proj
- standalone_dependencies_nuget_config_fallback
- proj
- standalone_dependencies_nuget_no_sources/proj
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows
- dotnet_10_rc2
- standalone_dependencies
- lib
- change-notes
- released
- ext
- semmle/code/csharp
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- security/dataflow
- src
- API Abuse
- ASP
- Bad Practices
- Comments
- Control-Flow
- Declarations
- Implementation Hiding
- Naming Conventions
- CSI
- Concurrency
- Documentation
- Language Abuse
- Likely Bugs
- Dynamic
- LeapYear
- Statements
- Linq
- Security Features
- CWE-327
- CWE-451
- Telemetry
- Useless code
- change-notes
- released
- experimental/CWE-918
- test
- library-tests
- assignables
- controlflow
- graph
- CONSISTENCY
- guards
- splits
- CONSISTENCY
- csharp7
- csharp8
- csharp9
- dataflow
- barrier-guards
- call-sensitivity
- callablereturnsarg
- global
- library
- local
- modulusanalysis
- signanalysis
- ssa
- exceptions
- expressions
- locations
- partial
- query-tests
- API Abuse/FormatInvalid
- Bad Practices/Control-Flow/ConstantCondition
- Dead Code/DeadStoreOfLocal
- Nullness
- Security Features
- CWE-451/MissingXFrameOptions/WebConfigAddedHeaderInLocation
- CWE-611
- standalone/Bad Practices/Control-Flow/ConstantCondition
- resources/stubs
- scripts
- stubs
- tools
- docs
- codeql
- codeql-language-guides
- codeql-overview
- codeql-changelog
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- writing-codeql-queries
- go
- extractor
- cli
- go-autobuilder
- go-extractor
- util
- old-change-notes
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes/released
- ext
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-295
- CWE-322
- CWE-326
- CWE-327
- CWE-352
- CWE-681
- change-notes/released
- experimental
- CWE-1004
- CWE-369
- CWE-918
- test
- example-tests/snippets
- experimental
- CWE-1004
- CWE-321-V2
- CWE-522-DecompressionBombs
- CWE-74
- CWE-918
- library-tests/semmle/go
- dataflow
- ChannelField
- DefaultTaintSanitizer
- ExternalTaintFlow
- ExternalValueFlow
- FlowSteps
- FunctionInputsAndOutputs
- PostUpdateNodes
- PromotedFields
- ReadsAndWrites
- flowsources/local/database
- frameworks
- BeegoOrm
- Beego
- Echo
- Email
- Encoding
- Fasthttp
- Gin
- GoMicro
- Gorestful
- Revel
- StdlibTaintFlow
- TaintSteps
- Twirp
- WebSocket
- XNetHtml
- Yaml
- security/SafeUrlFlow
- query-tests
- InconsistentCode/MistypedExponentiation
- Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- CWE-209
- CWE-295/DisabledCertificateCheck
- CWE-312
- CWE-338/InsecureRandomness
- CWE-601/OpenUrlRedirect
- CWE-640
- CWE-918
- javascript
- documentation
- downgrades/80b2bc24189307c5fd178dc2da95b45bcdb117f7
- extractor
- lib/typescript
- src
- src/com/semmle
- jcorn
- flow
- js
- ast
- extractor
- ts/extractor
- ql
- integration-tests
- diagnostics/syntax-error
- query-suite
- lib
- change-notes/released
- ext
- semmle/javascript
- dataflow
- internal
- frameworks
- AngularJS
- data/internal
- internal
- flow_summaries
- security
- dataflow
- regexp
- upgrades/76a926a00d5f3bc199c203a1437796fd7b2835ba
- src
- Comments
- DOM
- Declarations
- Expressions
- LanguageFeatures
- Performance
- RegExp
- Security
- CWE-116
- CWE-327
- CWE-942
- examples
- Statements
- change-notes/released
- experimental/Security
- CWE-918
- CWE-942
- test
- ApiGraphs/explicit-this
- experimental/Security/CWE-942
- library-tests
- DataFlow
- FlowSummary
- Portals
- src
- bluebird
- cyclic
- m1
- m2
- m3
- m4
- m5
- TripleDot
- TypeScript
- ImportDefer
- RegressionTests
- EmptyName
- SemicolonInName
- frameworks
- AsyncPackage
- Express
- src
- xUnit
- query-tests
- LanguageFeatures/LengthComparisonOffByOne
- Security
- CWE-078/CommandInjection
- CWE-079/DomBasedXss
- CWE-089/untyped
- CWE-094/CodeInjection
- CWE-312
- CWE-400
- RemotePropertyInjection
- RemovePropertyInjection
- CWE-942
- java
- documentation/library-coverage
- downgrades/9f6026c400996c13842974b24f076a486ad1f69c
- kotlin-extractor/src/main/kotlin
- utils
- ql
- integration-tests
- java
- buildless-dependency-different-repository
- buildless-erroneous
- evaluation-to-constant-errortype
- lambda-expression-buildless-recovery
- maven-wrapper-missing-properties
- src/main/java/com/example
- maven_3_fetch_maven_4_wrapper
- app
- .mvn/wrapper
- src/main/java/testmaven
- query-suite
- kotlin/all-platforms/recursive_interfaces
- somepkg
- lib
- change-notes/released
- config
- experimental/quantum
- ext
- semmle/code
- java
- controlflow
- internal
- dataflow
- internal
- dispatch
- internal
- frameworks
- android
- regex
- security
- xml
- upgrades/1b8f5f4c747e4249f4731796ccaa0661c7434d8a
- src
- Advisory
- Declarations
- Documentation
- Java Objects
- Naming
- Statements
- Types
- DeadCode
- Language Abuse
- Likely Bugs
- Arithmetic
- Cloning
- Collections
- Comparison
- Concurrency
- Finalization
- Frameworks
- JUnit
- Swing
- Likely Typos
- Reflection
- Serialization
- Statements
- Termination
- Security/CWE
- CWE-1004
- CWE-327
- Telemetry
- Violations of Best Practice
- Dead Code
- Implementation Hiding
- Naming Conventions
- Undesirable Calls
- change-notes
- released
- experimental
- Security/CWE/CWE-1004
- quantum
- Analysis
- Examples
- meta/ssa
- test-kotlin1/library-tests
- java-kotlin-collection-type-generic-methods
- reflection
- test-kotlin2/library-tests
- java-kotlin-collection-type-generic-methods
- nested_types
- reflection
- test
- experimental
- library-tests/quantum
- jca
- query-tests
- quantum/examples
- BadMacUse
- InsecureOrUnknownNonceSource
- NonceReuse
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- security/CWE-1004
- library-tests
- compact-source-files
- dataflow
- entrypoint-types
- kdf
- scoped-values
- flexible-constructors
- guards
- module-import-declarations
- query-tests
- Escaping
- Nullness
- SafePublication
- StartInConstructor
- ThreadSafe
- examples
- security
- CWE-1004
- CWE-918
- misc
- bazel
- 3rdparty
- py_deps
- tree_sitter_extractors_deps
- registry/modules/rules_dotnet
- 0.19.2-codeql.1
- patches
- scripts
- suite-helpers
- change-notes/released
- python
- downgrades
- 6a1f497168da2f43828161d3c86db7d4c94c2b53
- acf8d3b08ae3cfac8833d16efbfa5a10fef86819
- extractor
- semmle
- tests
- parser
- tsg-python
- src
- tsp
- ql
- consistency-queries
- integration-tests/query-suite
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- frameworks
- internal
- regexp
- internal
- security/dataflow
- upgrades
- 5af903da088e3746aa283700a43a779302453523
- 6a1f497168da2f43828161d3c86db7d4c94c2b53
- src
- Classes
- CallsToInitDel
- examples
- Exceptions
- Expressions
- Functions
- Imports
- Resources
- Security
- CWE-1004
- examples
- CWE-1275
- examples
- CWE-327
- CWE-614
- examples
- Statements
- Variables
- change-notes
- released
- experimental
- Security
- CWE-327/Azure
- CWE-346
- semmle/python/security
- meta/ClassHierarchy
- test
- extractor-tests/overlay
- basic-full-eval
- lib
- basic-overlay-eval
- orig_src
- lib
- library-tests
- dataflow
- fieldflow
- global-flow
- typetracking
- regex
- query-tests
- Classes
- missing-del
- missing-init
- multiple
- multiple-del
- multiple-init
- Exceptions/general
- Expressions/Regex
- Functions
- general
- overriding
- Resources/FileNotAlwaysClosed
- Security
- CWE-022-PathInjection
- CWE-1004-NonHttpOnlyCookie
- CWE-1275-SameSiteNoneCookie
- CWE-614-InsecureCookie
- ruby
- extractor
- ql
- lib
- change-notes/released
- codeql/ruby
- dataflow/internal
- frameworks
- core
- security/regexp
- src
- change-notes/released
- experimental
- insecure-randomness/examples
- manually-check-http-verb
- weak-params
- queries/security
- cwe-327
- cwe-352
- cwe-732
- test
- library-tests
- controlflow/graph
- frameworks/grape
- CONSISTENCY
- query-tests
- experimental/InsecureRandomness
- security/cwe-915
- rust
- ast-generator
- src
- downgrades/30a0713e5bf69c60d003e4994e5abd1c78a36826
- extractor
- macros
- src
- generated
- translate
- ql
- integration-tests
- hello-workspace
- exe/src
- lib/src
- a_module
- query-suite
- lib
- change-notes
- released
- codeql
- files
- rust
- controlflow
- internal
- dataflow
- internal
- elements
- internal
- generated
- frameworks
- rustcrypto
- stdlib
- internal
- typeinference
- security
- ext/generated
- upgrades/dfade44a27bd44db996ae8c5095a11effc883aba
- utils/test
- src
- change-notes
- released
- queries
- security
- CWE-319
- CWE-327
- CWE-614
- CWE-825
- CWE-918
- summary
- telemetry
- unusedentities
- test
- extractor-tests
- File
- CONSISTENCY
- bad_cargo
- src
- nested
- crate_graph
- generated
- AssocTypeArg
- ClosureExpr
- DynTraitTypeRepr
- Function
- ImplTraitTypeRepr
- MatchArm
- RetTypeRepr
- StmtList
- TraitAlias
- TypeBoundList
- UseBoundGenericArgs
- WherePred
- macro-expansion
- CONSISTENCY
- macro-in-library
- library-tests
- dataflow
- closures
- global
- CONSISTENCY
- lambdas
- local
- CONSISTENCY
- modeled
- models
- CONSISTENCY
- sources
- CONSISTENCY
- database
- CONSISTENCY
- env
- file
- net
- CONSISTENCY
- stdin
- CONSISTENCY
- web_frameworks
- CONSISTENCY
- strings
- CONSISTENCY
- definitions
- elements
- operations
- stmtlist
- frameworks/postgres/CONSISTENCY
- path-resolution
- CONSISTENCY
- my2
- my3
- my
- my4/my5
- sensitivedata/CONSISTENCY
- type-inference
- CONSISTENCY
- invalid
- loop
- variables
- CONSISTENCY
- query-tests
- diagnostics
- security
- CWE-020
- CWE-022
- CWE-089
- CONSISTENCY
- CWE-311
- CWE-312
- CONSISTENCY
- CWE-319
- CWE-327
- BrokenCryptoAlgorithm
- CONSISTENCY
- CONSISTENCY
- WeakSensitiveDataHashing
- CWE-328
- CWE-614
- CWE-696
- CONSISTENCY
- CWE-770
- CONSISTENCY
- CWE-798
- CONSISTENCY
- CWE-825
- CONSISTENCY
- CWE-918
- CONSISTENCY
- schema
- swift
- downgrades
- 33e5e5e03bd3f98322f4c67aefa81015be832b88
- b7006eaacb007a06251596835506185619b86e98
- extractor
- infra
- mangler
- translators
- ql
- integration-tests
- autobuilder/xcode-fails-spm-works
- posix/deduplication
- lib
- change-notes
- released
- codeql/swift
- dataflow/internal
- elements
- decl
- internal
- expr
- internal
- internal
- type
- internal
- generated
- decl
- expr
- type
- security
- upgrades
- 987ab0bc0911f8c88449210e21d2ee80ebcb488a
- b7006eaacb007a06251596835506185619b86e98
- src
- change-notes/released
- test
- extractor-tests
- declarations
- expressions
- generated
- AvailabilitySpec
- KeyPathComponent
- decl
- Accessor
- CapturedDecl
- ConcreteVarDecl
- MacroDecl
- ParamDecl
- PoundDiagnosticDecl
- UsingDecl
- expr
- AppliedPropertyWrapperExpr
- IdentityExpr
- MethodLookupExpr
- type
- ExistentialArchetypeType
- InlineArrayType
- OpenedArchetypeType
- library-tests
- ast
- controlflow/graph
- dataflow/dataflow
- elements
- KeyPathComponent
- expr/methodlookup
- type/nominaltype
- query-tests/Diagnostics
- third_party/resources
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
34 | 34 | | |
35 | 35 | | |
36 | 36 | | |
37 | | - | |
| 37 | + | |
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
54 | 54 | | |
55 | 55 | | |
56 | 56 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
35 | 35 | | |
36 | 36 | | |
37 | 37 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
76 | 76 | | |
77 | 77 | | |
78 | 78 | | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 | | |
2 | 6 | | |
3 | 7 | | |
| |||
7 | 11 | | |
8 | 12 | | |
9 | 13 | | |
| 14 | + | |
10 | 15 | | |
11 | 16 | | |
| 17 | + | |
12 | 18 | | |
13 | 19 | | |
14 | 20 | | |
| |||
25 | 31 | | |
26 | 32 | | |
27 | 33 | | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | 34 | | |
32 | 35 | | |
33 | 36 | | |
| |||
0 commit comments