File tree
1,670 files changed
+92304
-32969
lines changed- .github
- instructions
- actions/ql
- lib
- change-notes/released
- src
- change-notes/released
- experimental/Security/CWE-200
- test/query-tests/Security/CWE-200
- config
- cpp/ql
- lib
- change-notes
- released
- experimental
- quantum
- OpenSSL
- AlgorithmInstances
- AlgorithmValueConsumers
- Operations
- semmle/code/cpp/rangeanalysis
- semmle/code/cpp
- controlflow
- dataflow/internal
- ir
- dataflow/internal
- implementation
- aliased_ssa
- raw
- unaliased_ssa
- rangeanalysis
- new/internal/semantic
- src
- Likely Bugs/Memory Management
- Security/CWE
- CWE-129
- CWE-295
- CWE-327
- CWE-367
- change-notes/released
- experimental/Security/CWE/CWE-401
- test
- examples/docs-examples/analyzing-data-flow-in-cpp
- experimental/library-tests
- quantum
- rangeanalysis/rangeanalysis
- library-tests
- controlflow
- guards-ir
- guards
- dataflow
- dataflow-tests
- ir-barrier-guards
- files
- functions/routinetype
- ir/range-analysis
- permissive
- preprocessor/preprocessor
- rangeanalysis/SimpleRangeAnalysis
- typedefs
- types
- __wchar_t
- cstd_types
- integral_types_ms
- wchar_t_typedef
- variables/variables
- query-tests/Critical/MissingCheckScanf
- csharp
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp
- Entities
- Base
- Locations
- PreprocessorDirectives
- Types
- Extractor
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- integration-tests
- linux/dotnet_10_rc2
- windows/dotnet_10_rc2
- lib
- change-notes
- released
- ext
- semmle/code/csharp
- controlflow
- internal
- dataflow
- internal
- src
- Bad Practices/Control-Flow
- CSI
- change-notes
- released
- test
- library-tests
- assignables
- controlflow
- graph
- CONSISTENCY
- guards
- splits
- CONSISTENCY
- csharp7
- csharp8
- csharp9
- dataflow
- call-sensitivity
- global
- library
- local
- modulusanalysis
- signanalysis
- ssa
- exceptions
- expressions
- locations
- partial
- query-tests
- Bad Practices/Control-Flow/ConstantCondition
- Dead Code/DeadStoreOfLocal
- Nullness
- Security Features/CWE-611
- standalone/Bad Practices/Control-Flow/ConstantCondition
- resources/stubs
- tools
- docs/codeql
- codeql-language-guides
- codeql-overview
- codeql-changelog
- images/codeql-for-visual-studio-code
- ql-language-reference
- reusables
- writing-codeql-queries
- go
- extractor
- util
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes/released
- semmle/go
- controlflow
- dataflow
- internal
- frameworks
- stdlib
- security
- src
- InconsistentCode
- RedundantCode
- Security
- CWE-295
- CWE-322
- CWE-327
- CWE-352
- CWE-681
- change-notes/released
- experimental
- CWE-1004
- CWE-918
- test
- example-tests/snippets
- experimental
- CWE-1004
- CWE-321-V2
- CWE-522-DecompressionBombs
- CWE-74
- CWE-918
- library-tests/semmle/go
- dataflow
- ChannelField
- DefaultTaintSanitizer
- ExternalTaintFlow
- ExternalValueFlow
- FlowSteps
- FunctionInputsAndOutputs
- PostUpdateNodes
- PromotedFields
- ReadsAndWrites
- flowsources/local/database
- frameworks
- BeegoOrm
- Beego
- Echo
- Email
- Encoding
- Fasthttp
- Gin
- GoMicro
- Gorestful
- Revel
- TaintSteps
- Twirp
- WebSocket
- XNetHtml
- Yaml
- security/SafeUrlFlow
- query-tests
- InconsistentCode/MistypedExponentiation
- Security
- CWE-022
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- CWE-209
- CWE-295/DisabledCertificateCheck
- CWE-312
- CWE-338/InsecureRandomness
- CWE-601/OpenUrlRedirect
- CWE-640
- CWE-918
- javascript/ql
- integration-tests/query-suite
- lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- frameworks
- internal
- src
- Expressions
- LanguageFeatures
- Security/CWE-327
- change-notes/released
- test
- ApiGraphs/explicit-this
- library-tests/frameworks/Express
- src
- java/ql
- integration-tests/java
- buildless-dependency-different-repository
- evaluation-to-constant-errortype
- lambda-expression-buildless-recovery
- maven_3_fetch_maven_4_wrapper
- app
- .mvn/wrapper
- src/main/java/testmaven
- query-suite
- lib
- change-notes/released
- experimental/quantum
- semmle/code
- java
- controlflow
- dataflow
- internal
- security
- xml
- src
- Likely Bugs
- Arithmetic
- Concurrency
- Security/CWE
- CWE-1004
- CWE-327
- change-notes
- released
- experimental/quantum
- Analysis
- Examples
- test
- experimental
- library-tests/quantum
- jca
- query-tests
- quantum/examples
- BadMacUse
- InsecureOrUnknownNonceSource
- NonceReuse
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- security/CWE-1004
- library-tests/dataflow/entrypoint-types
- query-tests
- StartInConstructor
- security
- CWE-1004
- CWE-918
- misc
- bazel/3rdparty
- py_deps
- tree_sitter_extractors_deps
- scripts
- suite-helpers
- change-notes/released
- python
- downgrades
- 6a1f497168da2f43828161d3c86db7d4c94c2b53
- acf8d3b08ae3cfac8833d16efbfa5a10fef86819
- extractor
- semmle
- tests
- ql
- consistency-queries
- integration-tests/query-suite
- lib
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- internal
- regexp
- internal
- upgrades
- 5af903da088e3746aa283700a43a779302453523
- 6a1f497168da2f43828161d3c86db7d4c94c2b53
- src
- Classes/CallsToInitDel
- Security
- CWE-1004
- examples
- CWE-1275
- examples
- CWE-327
- CWE-614
- examples
- change-notes
- released
- test
- extractor-tests/overlay
- basic-full-eval
- lib
- basic-overlay-eval
- orig_src
- lib
- library-tests/regex
- query-tests
- Expressions/Regex
- Security
- CWE-1004-NonHttpOnlyCookie
- CWE-1275-SameSiteNoneCookie
- CWE-614-InsecureCookie
- ruby
- extractor
- ql
- lib
- change-notes/released
- codeql/ruby
- dataflow/internal
- frameworks
- core
- src
- change-notes/released
- queries/security/cwe-327
- test/library-tests/frameworks/grape
- CONSISTENCY
- rust
- ast-generator
- src
- downgrades/30a0713e5bf69c60d003e4994e5abd1c78a36826
- extractor
- macros
- src
- generated
- translate
- ql
- integration-tests
- hello-workspace
- exe/src
- lib/src
- a_module
- query-suite
- lib
- change-notes
- released
- codeql
- files
- rust
- controlflow/internal
- dataflow/internal
- elements
- internal
- generated
- frameworks
- rustcrypto
- stdlib
- internal
- typeinference
- security
- upgrades/dfade44a27bd44db996ae8c5095a11effc883aba
- utils/test
- src
- change-notes
- released
- queries
- security
- CWE-327
- CWE-614
- summary
- telemetry
- test
- extractor-tests
- File
- CONSISTENCY
- bad_cargo
- src
- nested
- crate_graph
- generated
- ClosureExpr
- Function
- StmtList
- macro-expansion
- CONSISTENCY
- macro-in-library
- library-tests
- dataflow
- closures
- global
- CONSISTENCY
- lambdas
- local
- CONSISTENCY
- modeled
- models
- CONSISTENCY
- sources
- CONSISTENCY
- database
- CONSISTENCY
- env
- file
- CONSISTENCY
- net
- CONSISTENCY
- stdin
- CONSISTENCY
- web_frameworks
- CONSISTENCY
- strings
- CONSISTENCY
- definitions
- elements
- operations
- stmtlist
- frameworks/postgres/CONSISTENCY
- path-resolution
- CONSISTENCY
- my2
- my3
- my
- my4/my5
- sensitivedata/CONSISTENCY
- type-inference
- CONSISTENCY
- invalid
- loop
- query-tests
- diagnostics
- security
- CWE-020
- CWE-022
- CWE-089
- CONSISTENCY
- CWE-311
- CWE-312
- CONSISTENCY
- CWE-319
- CWE-327
- BrokenCryptoAlgorithm
- CONSISTENCY
- CONSISTENCY
- WeakSensitiveDataHashing
- CWE-614
- CWE-696
- CONSISTENCY
- CWE-770
- CONSISTENCY
- CWE-798
- CONSISTENCY
- CWE-825
- CONSISTENCY
- CWE-918
- CONSISTENCY
- schema
- swift
- ql
- lib
- change-notes/released
- codeql/swift/dataflow/internal
- src
- change-notes/released
- tools
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
1,670 files changed
+92304
-32969
lines changedThis file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
76 | 76 | | |
77 | 77 | | |
78 | 78 | | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
1 | 5 | | |
2 | 6 | | |
3 | 7 | | |
| |||
7 | 11 | | |
8 | 12 | | |
9 | 13 | | |
| 14 | + | |
10 | 15 | | |
11 | 16 | | |
| 17 | + | |
12 | 18 | | |
13 | 19 | | |
14 | 20 | | |
| |||
25 | 31 | | |
26 | 32 | | |
27 | 33 | | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | 34 | | |
32 | 35 | | |
33 | 36 | | |
| |||
0 commit comments