Commit 8f6de12
File tree
803 files changed
+75677
-50804
lines changed- .github/workflows
- cpp/ql
- lib
- change-notes
- released
- experimental/semmle/code/cpp
- dataflow
- ir/dataflow/internal
- semantic
- semmle/code/cpp
- commons
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa/internal
- raw/internal
- unaliased_ssa/internal
- src
- Architecture
- General Namespace-Level Information
- Refactoring Opportunities
- Best Practices
- Likely Errors
- Magic Constants
- Unused Entities
- Critical
- Diagnostics
- Likely Bugs
- Arithmetic
- Conversion
- Format
- Leap Year
- Memory Management
- OO
- Protocols
- Security/CWE
- CWE-022
- CWE-078
- CWE-089
- CWE-114
- CWE-129
- CWE-134
- CWE-170
- CWE-190
- CWE-253
- CWE-311
- CWE-313
- CWE-319
- CWE-457
- CWE-468
- CWE-676
- CWE-732
- CWE-807
- change-notes
- released
- experimental
- Best Practices
- Likely Bugs
- Security/CWE
- CWE-020
- CWE-1041
- CWE-120
- CWE-193
- CWE-359
- CWE-401
- CWE-670
- CWE-691
- CWE-754
- CWE-783
- CWE-787
- CWE-788
- jsf
- 4.06 Pre-Processing Directives
- 4.09 Style
- 4.10 Classes
- 4.11 Namespaces
- 4.13 Functions
- 4.15 Declarations and Definitions
- 4.21 Operators
- 4.22 Pointers and References
- 4.23 Type Conversions
- 4.25 Expressions
- test
- experimental/query-tests/Security/CWE
- CWE-020
- NoCheckBeforeUnsafePutUser
- semmle/tests
- CWE-1041/semmle/tests
- CWE-119
- CWE-193
- array-access
- pointer-deref
- CWE-359/semmle/tests
- CWE-401/semmle/tests
- CWE-670/semmle/tests
- CWE-691/semmle/tests
- CWE-754/semmle/tests
- CWE-783/semmle/tests
- CWE-788/semmle/tests
- semmle/tests
- library-tests
- dataflow
- dataflow-tests
- fields
- syntax-zoo
- query-tests
- Architecture/Refactoring Opportunities/ComplexFunctions
- Best Practices
- Likely Errors/Slicing
- Unused Entities
- UnusedLocals
- UnusedStaticVariables
- Critical
- FileClosed
- MemoryFreed
- MissingCheckScanf
- NewFree
- UnsafeUseOfThis
- Likely Bugs
- Arithmetic/BadAdditionOverflowCheck
- Conversion
- CastArrayPointerArithmetic
- ImplicitDowncastFromBitfield
- LossyFunctionResultCast
- Format/WrongTypeFormatArguments
- Linux_mixed_byte_wprintf
- Linux_mixed_word_size
- Linux_signed_chars
- Linux_two_byte_wprintf
- Linux_unsigned_chars
- Microsoft_no_wchar
- Microsoft
- Leap Year/Adding365DaysPerYear
- Memory Management
- ImproperNullTermination
- NtohlArrayNoBound
- UsingExpiredStackAddress
- Protocols
- RedundantNullCheckSimple
- Security/CWE
- CWE-022
- SAMATE/TaintedPath
- semmle/tests
- CWE-078
- SAMATE/ExecTainted
- semmle/ExecTainted
- CWE-089/SqlTainted
- CWE-114
- SAMATE/UncontrolledProcessOperation
- semmle/UncontrolledProcessOperation
- CWE-129
- SAMATE/ImproperArrayIndexValidation
- semmle/ImproperArrayIndexValidation
- CWE-134
- SAMATE
- semmle
- argv
- funcs
- globalVars
- ifs
- CWE-190
- SAMATE
- semmle
- ArithmeticUncontrolled
- ArithmeticWithExtremeValues
- TaintedAllocationSize
- tainted
- CWE-197/SAMATE/IntegerOverflowTainted
- CWE-242/semmle/tests
- CWE-253
- CWE-311/semmle/tests
- CWE-319/UseOfHttp
- CWE-416/semmle/tests
- CWE-457/semmle/tests
- CWE-468/semmle/IncorrectPointerScaling
- CWE-676/semmle/PotentiallyDangerousFunction
- CWE-732
- CWE-772
- SAMATE
- semmle
- tests-file
- tests-memory
- CWE-807/semmle/TaintedCondition
- jsf/4.09 Style/AV Rule 53 54
- csharp/ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests/all-platforms/dotnet_run
- lib
- change-notes
- released
- semmle/code/csharp
- dataflow
- internal
- frameworks/microsoft
- security
- cryptography
- src
- change-notes
- released
- experimental/ir/implementation/unaliased_ssa/internal
- meta/frameworks
- test
- library-tests/frameworks/microsoft
- query-tests/Security Features/CWE-117
- docs
- codeql
- codeql-cli
- support/reusables
- ql-libraries/dataflow
- go/ql
- lib
- change-notes
- released
- src
- Diagnostics
- change-notes
- released
- javascript
- documentation
- extractor
- src/com/semmle
- jcorn
- flow
- js
- extractor
- parser
- tests/mozilla/output/trap
- ql
- experimental/adaptivethreatmodeling
- lib/experimental/adaptivethreatmodeling
- test
- endpoint_large_scale
- endpoint_unit_tests
- generic_feature_testing
- lib
- change-notes
- released
- semmle/javascript/frameworks
- data/internal
- minimongo
- mongodb
- mssql
- mysql
- pg
- sequelize
- spanner
- sqlite3
- src
- change-notes
- released
- experimental/Summaries
- test
- ApiGraphs/typed
- library-tests
- Security/heuristics
- frameworks/SQL
- query-tests
- LanguageFeatures/SyntaxError
- Security
- CWE-089/untyped
- Summaries
- java
- kotlin-extractor
- src/main
- java/com/semmle/extractor/java
- kotlin
- comments
- utils/versions
- v_1_4_32
- v_1_5_20
- v_1_6_0
- v_1_7_0
- ql
- integration-tests/posix-only/kotlin/gradle_kotlinx_serialization
- lib
- change-notes
- released
- semmle/code/java
- dataflow
- internal
- frameworks/android
- regex
- security
- regexp
- src
- Advisory/Documentation
- Security/CWE/CWE-489
- Violations of Best Practice/Naming Conventions
- change-notes
- released
- experimental
- Security/CWE/CWE-552
- semmle/code/java/frameworks
- test
- experimental/query-tests/security
- CWE-200
- CWE-552
- kotlin/library-tests
- annotation-accessor-result-type
- classes
- comments
- exprs_typeaccess
- exprs
- methods
- library-tests
- dataflow/taintsources
- frameworks/android
- intent
- taint-database
- widget
- query-tests
- Javadoc
- security/CWE-489
- debuggable-attribute
- TestFalse
- TestNotSet
- Testbuild
- webview-debugging
- stubs
- android
- android
- accounts
- app
- content
- pm
- res
- loader
- database
- sqlite
- graphics
- drawable
- text
- hardware
- icu/util
- net
- os
- util
- view
- webkit
- com/android/internal
- org/xmlpull/v1
- google-android-9.0.0/android/app
- springframework-5.3.8/org/springframework/core/io
- misc/suite-helpers
- change-notes/released
- python/ql
- lib
- change-notes
- released
- semmle/python
- dataflow/new/internal
- frameworks
- data/internal
- src
- change-notes
- released
- test
- experimental/dataflow
- basic
- calls
- consistency
- coverage
- fieldflow
- global-flow
- match
- pep_328
- regression
- strange-essaflow
- tainttracking
- basic
- commonSanitizer
- customSanitizer
- defaultAdditionalTaintStep-py3
- defaultAdditionalTaintStep
- unwanted-global-flow
- typetracking
- variable-capture
- library-tests
- ApiGraphs/py3
- frameworks
- django-orm
- flask
- query-tests/Security
- CWE-209-StackTraceExposure
- CWE-730-ReDoS
- ql/ql/src
- codeql_ql
- ast/internal
- style
- codeql
- queries
- diagnostics
- style
- ruby/ql
- consistency-queries
- lib
- change-notes
- released
- codeql/ruby
- ast
- dataflow
- internal
- experimental
- frameworks
- core
- data/internal
- regexp
- src
- change-notes
- released
- test/library-tests
- dataflow
- array-flow
- call-sensitivity
- global
- summaries
- experimental
- frameworks
- active_record
- active_storage
- modules
- swift/ql
- lib/codeql/swift/dataflow/internal
- src/queries/Security
- CWE-135
- CWE-311
- test
- library-tests/dataflow/taint
- query-tests/Security
- CWE-079
- CWE-135
- CWE-311
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
803 files changed
+75677
-50804
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
43 | 43 | | |
44 | 44 | | |
45 | 45 | | |
46 | | - | |
| 46 | + | |
47 | 47 | | |
48 | 48 | | |
49 | 49 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
1 | 16 | | |
2 | 17 | | |
3 | 18 | | |
| |||
Lines changed: 0 additions & 4 deletions
This file was deleted.
This file was deleted.
Lines changed: 13 additions & 3 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
2 | | - | |
3 | | - | |
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
4 | 10 | | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
Lines changed: 127 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
| 24 | + | |
24 | 25 | | |
25 | 26 | | |
26 | 27 | | |
| |||
49 | 50 | | |
50 | 51 | | |
51 | 52 | | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
52 | 136 | | |
53 | 137 | | |
54 | 138 | | |
| |||
63 | 147 | | |
64 | 148 | | |
65 | 149 | | |
66 | | - | |
| 150 | + | |
67 | 151 | | |
68 | 152 | | |
69 | 153 | | |
70 | | - | |
| 154 | + | |
71 | 155 | | |
72 | 156 | | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
73 | 172 | | |
74 | 173 | | |
75 | 174 | | |
76 | 175 | | |
77 | 176 | | |
78 | | - | |
79 | | - | |
80 | | - | |
81 | | - | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
82 | 181 | | |
83 | 182 | | |
84 | 183 | | |
85 | | - | |
86 | | - | |
87 | | - | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
88 | 188 | | |
89 | 189 | | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
90 | 205 | | |
91 | 206 | | |
92 | 207 | | |
93 | 208 | | |
94 | 209 | | |
95 | 210 | | |
96 | 211 | | |
97 | | - | |
| 212 | + | |
98 | 213 | | |
99 | 214 | | |
100 | 215 | | |
| |||
157 | 272 | | |
158 | 273 | | |
159 | 274 | | |
160 | | - | |
| 275 | + | |
161 | 276 | | |
162 | 277 | | |
163 | 278 | | |
| |||
Lines changed: 7 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
558 | 558 | | |
559 | 559 | | |
560 | 560 | | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
561 | 564 | | |
562 | 565 | | |
563 | 566 | | |
564 | 567 | | |
565 | 568 | | |
566 | 569 | | |
567 | | - | |
| 570 | + | |
568 | 571 | | |
569 | 572 | | |
570 | 573 | | |
| |||
598 | 601 | | |
599 | 602 | | |
600 | 603 | | |
601 | | - | |
602 | | - | |
603 | 604 | | |
604 | 605 | | |
605 | | - | |
606 | | - | |
607 | | - | |
| 606 | + | |
608 | 607 | | |
609 | 608 | | |
610 | 609 | | |
| |||
613 | 612 | | |
614 | 613 | | |
615 | 614 | | |
616 | | - | |
| 615 | + | |
617 | 616 | | |
618 | 617 | | |
619 | 618 | | |
| |||
753 | 752 | | |
754 | 753 | | |
755 | 754 | | |
756 | | - | |
| 755 | + | |
757 | 756 | | |
758 | 757 | | |
759 | 758 | | |
| |||
Lines changed: 7 additions & 8 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
558 | 558 | | |
559 | 559 | | |
560 | 560 | | |
| 561 | + | |
| 562 | + | |
| 563 | + | |
561 | 564 | | |
562 | 565 | | |
563 | 566 | | |
564 | 567 | | |
565 | 568 | | |
566 | 569 | | |
567 | | - | |
| 570 | + | |
568 | 571 | | |
569 | 572 | | |
570 | 573 | | |
| |||
598 | 601 | | |
599 | 602 | | |
600 | 603 | | |
601 | | - | |
602 | | - | |
603 | 604 | | |
604 | 605 | | |
605 | | - | |
606 | | - | |
607 | | - | |
| 606 | + | |
608 | 607 | | |
609 | 608 | | |
610 | 609 | | |
| |||
613 | 612 | | |
614 | 613 | | |
615 | 614 | | |
616 | | - | |
| 615 | + | |
617 | 616 | | |
618 | 617 | | |
619 | 618 | | |
| |||
753 | 752 | | |
754 | 753 | | |
755 | 754 | | |
756 | | - | |
| 755 | + | |
757 | 756 | | |
758 | 757 | | |
759 | 758 | | |
| |||
0 commit comments