Commit a367294
File tree
- .github
- workflows
- actions/ql
- lib
- change-notes/released
- ext/manual
- src
- Security
- CWE-275
- CWE-829
- change-notes/released
- test/query-tests/Security
- CWE-275/.github/workflows
- CWE-829
- config
- cpp
- downgrades/770002bb02322e04fa25345838ce6e82af285a0b
- ql
- integration-tests/query-suite
- lib
- change-notes
- released
- ext
- allocation
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- exprs
- internal
- ir
- dataflow
- internal
- implementation
- aliased_ssa
- raw
- internal
- unaliased_ssa
- models
- implementations
- interfaces
- rangeanalysis
- upgrades/7e7c2f55670f8123d514cf542ccb1938118ac561
- src
- Diagnostics
- Likely Bugs
- Arithmetic
- Format
- Leap Year
- Memory Management
- OO
- Underspecified Functions
- Security/CWE
- CWE-079
- CWE-134
- CWE-190
- CWE-468
- Telemetry
- change-notes/released
- utils/modelgenerator/internal
- test
- library-tests
- ctorinits
- dataflow
- dataflow-tests
- external-models
- fields
- ir-barrier-guards
- models-as-data
- taint-tests
- ir
- ir
- points_to
- range-analysis
- types
- rangeanalysis/SimpleRangeAnalysis
- syntax-zoo
- query-tests
- Likely Bugs
- Arithmetic/IntMultToLong
- Format/WrongTypeFormatArguments/Buildless
- Leap Year/UncheckedLeapYearAfterYearModification
- Likely Typos/ExprHasNoEffect
- autoconf
- meson-private/tmp_abc
- Memory Management/ReturnStackAllocatedMemory
- Security/CWE
- CWE-468/semmle/SuspiciousAddWithSizeof
- CWE-497/semmle/tests
- csharp
- documentation/library-coverage
- downgrades
- 19b8cc3e2dc768d4cbc03d6e3773b709bbebd036
- e73ca2c93df8aae162f1704edc4817a5cb330529
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp
- CodeAnalysisExtensions
- Entities
- Base
- Expressions
- ObjectCreation
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- examples/snippets
- integration-tests
- all-platforms
- autobuild_slnx
- autobuild
- binlog_multiple
- binlog
- blazor_build_mode_none
- BlazorTest
- blazor
- BlazorTest
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_10
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_dependency_dir/proj
- standalone_failed
- standalone_resx
- standalone_slnx
- standalone_winforms
- standalone
- linux
- compiler_args
- diag_nuget_config_casing
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- query-suite
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- standalone_dependencies_nuget_no_sources
- proj
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows/standalone_dependencies
- lib
- Linq
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- internal
- frameworks
- system
- runtime
- metrics
- security
- auth
- dataflow
- flowsources
- xml
- upgrades
- 178a7e6cf335486d33d4e49543148e3f57f04a9a
- e73ca2c93df8aae162f1704edc4817a5cb330529
- utils/test
- src
- Bad Practices/Control-Flow
- CSI
- Complexity
- Concurrency
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Statements
- Linq
- Performance
- Security Features
- CWE-079
- CWE-1004
- CWE-117
- CWE-119
- CWE-327
- CWE-384
- CWE-614
- Telemetry
- Useless code
- change-notes/released
- codeql-suites
- experimental
- CWE-918
- Security Features/CWE-759
- test
- library-tests
- arguments
- assignables
- assignments
- controlflow
- graph
- CONSISTENCY
- guards-large
- guards
- conversion/pointer
- csharp10
- csharp11
- csharp6
- csharp7
- csharp8
- dataflow
- call-sensitivity
- constructors
- defuse
- external-models
- fields
- flowsources
- aspremote
- remote
- library
- local
- methods
- modulusanalysis
- nullcoalescing
- operators
- signanalysis
- ssa-large
- ssa
- structs
- dispatch
- dynamic
- enums
- expressions
- goto
- linq
- obinit
- partial
- properties
- security/dataflow/flowsources
- standalone/controlflow
- structuralcomparison
- query-tests
- API Abuse
- ClassDoesNotImplementEquals
- IncorrectEqualsSignature
- Bad Practices/Control-Flow/ConstantCondition
- Concurrency/SynchSetUnsynchGet
- Dead Code/DeadStoreOfLocal
- Language Abuse/UselessNullCoalescingExpression
- Likely Bugs/ConstantComparison
- Linq/MissedSelectOpportunity
- Security Features
- CWE-1004/HttpOnlyCookie
- AspNetCore/NoPolicy
- SystemWeb/HttpOnlyCookiesFalse
- CWE-117
- CWE-614/InsecureCookie
- AspNetCore/NoPolicy
- SystemWeb/RequireSSLFalse
- Useless Code/RedundantToStringCall
- WriteOnlyContainer
- standalone/Bad Practices/Control-Flow/ConstantCondition
- resources/stubs
- utils/modelgenerator/dataflow
- docs
- codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- reusables
- ql-libraries/dataflow
- go
- extractor
- registries
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes
- released
- semmle/go
- concepts
- controlflow
- dataflow
- barrierguardutil
- internal
- dependencies
- frameworks
- stdlib
- utils/test/internal
- src
- RedundantCode
- Security
- CWE-079
- CWE-117
- CWE-327/examples
- change-notes/released
- experimental/CWE-203
- filters
- test/library-tests/semmle/go
- PrintAst
- dataflow
- ExternalFlowInheritance
- FlowSteps
- PromotedFields
- VarArgsWithFunctionModels
- flowsources/local
- file
- stdin
- frameworks/Macaron
- javascript
- downgrades/26a123164be893893e2aa0374d820785decf55af
- extractor
- src/com/semmle/js/extractor
- tests
- cfg/output/trap
- closure/output/trap
- comments/output/trap
- default-encoding/output/trap
- e4x/output/trap
- encoding/output/trap
- errors/output/trap
- es2015/output/trap
- es2016/output/trap
- es2017/output/trap
- es2018/output/trap
- es2019/output/trap
- es2021/output/trap
- es2024/output/trap
- esnext/output/trap
- exprs/output/trap
- extensions/output/trap
- externs/output/trap
- flow/output/trap
- functionbind/output/trap
- generatedcode/output/trap
- helloworld/output/trap
- html/output/trap
- jscript/output/trap
- jsx/output/trap
- keywords/output/trap
- moduleTypes1/output/trap
- moduleTypes2/output/trap
- moduleTypes3/output/trap
- mozilla/output/trap
- ng-templates/output/trap
- node/output/trap
- regexp/output/trap
- restprops/output/trap
- shebang/output/trap
- stmts/output/trap
- strictmode/output/trap
- ts/output/trap
- v8/output/trap
- variables/output/trap
- vue/output/trap
- test/com/semmle/js/extractor/test
- ql
- lib
- change-notes
- released
- semmle/javascript
- frameworks
- data
- internal
- security
- dataflow
- upgrades/578367e82a25a3e286aaf1238613db3717b67476
- src
- change-notes/released
- test
- library-tests
- TypeScript/Shebangs
- frameworks
- ReactJS
- WebSocket
- variables
- query-tests
- Declarations
- SuspiciousMethodNameDeclaration
- UniquePropertyNames
- Expressions
- DuplicateProperty
- ExprHasNoEffect
- Quality/UnhandledErrorInStreamPipeline
- Security
- CWE-022/TaintedPath
- CWE-078/CommandInjection
- CWE-770/MissingRateLimit
- CWE-918
- Statements/LoopIterationSkippedDueToShifting
- java
- downgrades/de4ded61c8ae83f829aedaf05be73307ba25ca40
- kotlin-extractor
- deps
- dev
- src/main/kotlin/utils
- ql
- consistency-queries
- integration-tests/kotlin/all-platforms
- annotation-id-consistency
- diagnostics/kotlin-version-too-new
- lib
- change-notes
- released
- config
- experimental/quantum
- ext
- semmle/code/java
- arithmetic
- controlflow
- dataflow
- internal
- rangeanalysis
- deadcode
- frameworks
- javaee
- ejb
- jsf
- spring
- metrics
- security
- regexp
- upgrades/9f6026c400996c13842974b24f076a486ad1f69c
- utils/test
- src
- Likely Bugs
- Arithmetic
- Comparison
- Frameworks/Swing
- Termination
- Security/CWE
- CWE-079
- CWE-1004
- CWE-117
- CWE-295
- CWE-319
- Violations of Best Practice
- Declarations
- legacy
- change-notes/released
- experimental
- Security/CWE
- CWE-094
- CWE-208
- CWE-327
- CWE-400
- CWE-489
- CWE-625
- CWE-652
- CWE-665
- quantum/Examples
- semmle/code/java/frameworks
- utils/modelgenerator/internal
- test-kotlin1/library-tests
- controlflow
- basic
- dominance
- exprs
- java-kotlin-collection-type-generic-methods
- test-kotlin2/library-tests
- controlflow
- basic
- dominance
- exprs
- java-kotlin-collection-type-generic-methods
- reflection
- test
- experimental/query-tests/quantum/examples
- BadMacUse
- InsecureOrUnknownNonceSource
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- ext/TestModels
- library-tests
- compact-source-files
- controlflow
- basic
- dominance
- dataflow
- capture
- entrypoint-types
- fluent-methods
- kdf
- scoped-values
- taint-jackson
- taintsources
- errorexpr
- flexible-constructors
- frameworks
- android
- intent
- slice
- taint-database
- apache-commons-lang3
- apache-http
- guava/handwritten
- javax-json
- jms
- lastaflute
- netty/manual
- rabbitmq
- ratpack/resources
- spring
- cache
- context
- controller
- data
- http
- ui
- util
- validation
- webmultipart
- websocket
- webutil
- guards12
- guards
- java7/MultiCatch
- module-import-declarations
- optional
- pattern-instanceof
- pattern-switch/cfg
- ssa
- successors
- CloseReaderTest
- LoopVarReadTest
- SaveFileTest
- SchackTest
- TestBreak
- TestContinue
- TestDeclarations
- TestFinallyBreakContinue
- TestFinally
- TestLoopBranch
- TestThrow2
- TestThrow
- TestTryCatch
- TestTryWithResources
- switch-default-impossible-dispatch
- query-tests
- Escaping
- Nullness
- SafePublication
- StringComparison
- ThreadSafe/examples
- UselessComparisonTest
- security
- CWE-022/semmle/tests
- CWE-023/semmle/tests
- CWE-078
- CWE-1004
- CWE-117
- CWE-1204
- CWE-190/semmle/tests
- CWE-200/semmle/tests
- SensitiveNotification
- SensitiveTextView
- CWE-287
- InsecureKeys/Test1
- InsecureLocalAuth
- CWE-295
- AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- ImproperWebVeiwCertificateValidation
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-327/semmle/tests
- CWE-524/res/layout
- CWE-532
- CWE-611
- CWE-676/semmle/tests
- CWE-749
- CWE-918
- CWE-927
- stubs
- javax-validation-constraints/javax/validation
- constraints
- woodstox-core-6.4.0
- com/ctc/wstx/stax
- org/codehaus/stax2
- misc
- bazel
- 3rdparty
- py_deps
- tree_sitter_extractors_deps
- cmake
- internal/zipmerge
- registry
- modules
- rules_dotnet/0.21.5-codeql.1
- rules_kotlin
- 2.2.0-codeql.1
- 2.2.2-codeql.1
- patches
- codegen
- templates
- suite-helpers
- change-notes/released
- python
- downgrades/eb5fc917c79bb23ce2de4a022f3e566d57a91be9
- extractor
- semmle
- python
- parser
- tests/parser
- tsg-python
- tsp
- src
- tree_sitter
- ql
- lib
- analysis
- change-notes
- released
- semmle/python
- dataflow/new
- internal
- essa
- frameworks
- data
- internal
- internal
- objects
- security/dataflow
- types
- upgrades/279cbb08d387ecd57ac177e87c94cfd5ca62f792
- src
- Classes
- CallsToInitDel
- Expressions
- Functions
- Imports
- Metrics
- History
- Security
- CVE-2018-1281
- CWE-079
- CWE-117
- Statements
- Summary
- Variables
- LoopVariableCapture
- analysis
- change-notes/released
- test
- 2/query-tests/Classes/new-style
- 3/extractor-tests
- lazy-imports
- unpacking-comprehensions
- experimental
- import-resolution-namespace-relative
- pkg
- sub
- import-resolution
- package/subpackage
- library-tests
- CallGraph-type-annotations
- CallGraph/code
- query-tests/Security
- CWE-022-UnsafeUnpacking
- CWE-1427-PromptInjection
- CWE-176
- library-tests
- ApiGraphs
- py2
- py3
- ControlFlow/general
- comprehensions
- dataflow
- basic
- calls-overload
- coverage-pep798
- coverage-py2
- coverage-py3
- coverage
- global-flow
- global-or-captured-vars
- match
- model-summaries
- module-initialization
- summaries
- tainttracking/customSanitizer
- typetracking-summaries
- typetracking
- variable-capture
- frameworks
- data
- django-orm/testapp
- django-v1
- django-v2-v3
- testapp
- testproj
- django
- fabric
- flask
- invoke
- mysql-connector-python
- mysqldb
- pandas
- paramiko
- pyramid
- rest_framework/testproj
- ruamel.yaml
- stdlib-py2
- stdlib-py3
- stdlib
- yaml
- regexparser
- regex
- query-tests
- Classes/should-be-context-manager
- Exceptions/general
- Functions
- ModificationOfParameterWithDefault
- general
- methodArgNames
- overriding
- Resources/FileNotAlwaysClosed
- Security
- CVE-2018-1281
- CWE-022-PathInjection
- CWE-078-CommandInjection
- CWE-078-UnsafeShellCommandConstruction
- src
- CWE-1004-NonHttpOnlyCookie
- CWE-1275-SameSiteNoneCookie
- CWE-209-StackTraceExposure
- CWE-614-InsecureCookie
- CWE-918-ServerSideRequestForgery
- CWE-943-NoSqlInjection
- Statements/general
- Variables/capture
- scripts
- ruby/ql
- docs
- lib
- change-notes
- released
- codeql/ruby
- ast/internal
- dataflow
- internal
- frameworks
- actioncontroller
- actiondispatch/internal
- core
- data/internal
- stdlib
- security
- src
- change-notes/released
- experimental/cwe-176/examples
- queries/security
- cwe-079
- cwe-117
- test
- library-tests
- ast
- control
- operations
- dataflow
- api-graphs
- flow-summaries
- local
- frameworks
- action_controller
- action_mailer
- active_support
- arel
- json
- mysql2
- sqlite3
- query-tests
- experimental
- cwe-176
- improper-memoization
- security
- cwe-094/CodeInjection
- cwe-300
- variables
- DeadStoreOfLocal
- UninitializedLocal
- rust
- ql
- lib
- change-notes
- released
- codeql
- files
- rust
- dataflow
- internal
- elements/internal
- frameworks
- stdlib
- internal
- typeinference
- security
- regex
- src
- change-notes/released
- queries
- security
- CWE-079
- CWE-117
- CWE-295
- CWE-825
- telemetry
- utils/modelgenerator/internal
- test
- library-tests
- dataflow
- barrier
- lambdas
- local
- models
- sources/net/CONSISTENCY
- taint
- path-resolution
- invalid
- type-inference
- CONSISTENCY
- query-tests/security
- CWE-117
- CONSISTENCY
- CWE-312
- CWE-327/BrokenCryptoAlgorithm
- CONSISTENCY
- CWE-770
- CWE-825
- utils-tests/modelgenerator
- tools/builtins
- swift
- downgrades
- 5738be6bb04742c424efdbf9f4de11f0b10fa37d
- ee3053b673c901a325b361b18c50b18342752bf8
- extractor
- infra
- mangler
- translators
- logging
- ql
- integration-tests/posix
- deduplication
- hello-world
- lib
- change-notes
- released
- codeql/swift
- dataflow
- internal
- elements/type
- internal
- frameworks/StandardLibrary
- generated
- type
- upgrades
- 33e5e5e03bd3f98322f4c67aefa81015be832b88
- ee3053b673c901a325b361b18c50b18342752bf8
- src
- change-notes/released
- diagnostics
- queries/Security/CWE-079
- test
- extractor-tests
- declarations
- errors
- generated
- decl
- CapturedDecl
- ConcreteVarDecl
- MacroDecl
- ParamDecl
- expr/ObjectLiteralExpr
- stmt/ForEachStmt
- type
- BuiltinFixedArrayType
- BuiltinType
- IntegerType
- library-tests
- ast
- controlflow/graph
- dataflow/taint/libraries
- query-tests/Diagnostics
- third_party
- resources
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
14 | 16 | | |
15 | 17 | | |
16 | 18 | | |
| |||
34 | 36 | | |
35 | 37 | | |
36 | 38 | | |
37 | | - | |
| 39 | + | |
38 | 40 | | |
39 | 41 | | |
40 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| 48 | + | |
| 49 | + | |
This file was deleted.
This file was deleted.
0 commit comments