Commit 36aa19b
authored
File tree
- .github
- workflows
- actions/ql
- lib
- change-notes/released
- ext/manual
- src
- Security
- CWE-275
- CWE-829
- change-notes/released
- test/query-tests/Security
- CWE-275/.github/workflows
- CWE-829
- config
- cpp
- downgrades
- 770002bb02322e04fa25345838ce6e82af285a0b
- 7e7c2f55670f8123d514cf542ccb1938118ac561
- ql
- integration-tests/query-suite
- lib
- change-notes
- released
- ext
- allocation
- generated/modelgenerator
- brotli
- curl
- glibc
- libidn2
- libssh2
- libuv
- nghttp2
- openssl
- sqlite
- zlib
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- exprs
- internal
- ir
- dataflow
- internal
- implementation
- aliased_ssa
- raw
- internal
- unaliased_ssa
- models
- implementations
- interfaces
- rangeanalysis
- stmts
- upgrades
- 7e7c2f55670f8123d514cf542ccb1938118ac561
- 9439176c1d1312787926458dd54d65a849069118
- src
- Diagnostics
- Likely Bugs
- Arithmetic
- Format
- Leap Year
- Memory Management
- OO
- Underspecified Functions
- Security/CWE
- CWE-079
- CWE-134
- CWE-190
- CWE-468
- Telemetry
- change-notes/released
- utils/modelgenerator/internal
- test
- library-tests
- builtins/complex
- controlflow
- guards-ir
- guards
- ctorinits
- dataflow
- dataflow-tests
- external-models
- fields
- ir-barrier-guards
- models-as-data
- source-sink-tests
- taint-tests
- ir
- ir
- points_to
- range-analysis
- types
- rangeanalysis/SimpleRangeAnalysis
- syntax-zoo
- query-tests
- Likely Bugs
- Arithmetic/IntMultToLong
- Format
- NonConstantFormat
- WrongTypeFormatArguments/Buildless
- Leap Year/UncheckedLeapYearAfterYearModification
- Likely Typos/ExprHasNoEffect
- autoconf
- meson-private/tmp_abc
- Memory Management/ReturnStackAllocatedMemory
- Underspecified Functions
- Security/CWE
- CWE-468/semmle/SuspiciousAddWithSizeof
- CWE-497/semmle/tests
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- downgrades
- 178a7e6cf335486d33d4e49543148e3f57f04a9a
- 19b8cc3e2dc768d4cbc03d6e3773b709bbebd036
- 3cabc77473cbbda95edebafea345c2e3fdfa12d9
- e73ca2c93df8aae162f1704edc4817a5cb330529
- ea7ad33252e550241975676f09fcc7b0a703deab
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.Util
- Semmle.Extraction.CSharp
- CodeAnalysisExtensions
- Entities
- Base
- Expressions
- ObjectCreation
- Types
- Kinds
- Trap
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- examples/snippets
- integration-tests
- all-platforms
- autobuild_slnx
- autobuild
- binlog_multiple
- binlog
- blazor_build_mode_none
- BlazorTest
- blazor
- BlazorTest
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_10
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_dependency_dir/proj
- standalone_failed
- standalone_resx
- standalone_slnx
- standalone_winforms
- standalone
- linux
- compiler_args
- diag_nuget_config_casing
- sub-project
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- query-suite
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_clear
- clear
- proj
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- standalone_dependencies_nuget_no_sources
- proj
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows/standalone_dependencies
- lib
- Linq
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- generated/modelgenerator
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- internal
- frameworks
- system
- runtime
- internal
- metrics
- security
- auth
- dataflow
- flowsources
- xml
- upgrades
- 178a7e6cf335486d33d4e49543148e3f57f04a9a
- 19b8cc3e2dc768d4cbc03d6e3773b709bbebd036
- 68b5aec54e50fe7e375df3777b756a746ca3a37c
- e73ca2c93df8aae162f1704edc4817a5cb330529
- ea7ad33252e550241975676f09fcc7b0a703deab
- utils/test
- src
- Bad Practices/Control-Flow
- CSI
- Complexity
- Concurrency
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Statements
- Linq
- Performance
- Security Features
- CWE-079
- CWE-1004
- CWE-117
- CWE-119
- CWE-327
- CWE-352
- CWE-384
- CWE-614
- Telemetry
- Useless code
- change-notes/released
- codeql-suites
- experimental
- CWE-918
- Security Features/CWE-759
- test
- library-tests
- arguments
- assignables
- assignments
- controlflow
- graph
- CONSISTENCY
- guards-large
- guards
- conversion/pointer
- csharp10
- csharp11
- csharp6
- csharp7
- csharp8
- dataflow
- call-sensitivity
- constructors
- defuse
- extensions
- external-models
- fields
- flowsources
- aspremote
- remote
- library
- local
- methods
- modulusanalysis
- nullcoalescing
- operators
- signanalysis
- ssa-large
- ssa
- structs
- dispatch
- dynamic
- enums
- expressions
- extension
- goto
- linq
- obinit
- operators
- parameters
- partial
- properties
- security/dataflow/flowsources
- standalone/controlflow
- structuralcomparison
- query-tests
- API Abuse
- ClassDoesNotImplementEquals
- IncorrectEqualsSignature
- Bad Practices/Control-Flow/ConstantCondition
- Concurrency/SynchSetUnsynchGet
- Dead Code/DeadStoreOfLocal
- Language Abuse/UselessNullCoalescingExpression
- Likely Bugs/ConstantComparison
- Linq/MissedSelectOpportunity
- Nullness
- Security Features
- CWE-1004/HttpOnlyCookie
- AspNetCore/NoPolicy
- SystemWeb/HttpOnlyCookiesFalse
- CWE-117
- CWE-352
- missing-aspnetcore
- missing
- CWE-614/InsecureCookie
- AspNetCore/NoPolicy
- SystemWeb/RequireSSLFalse
- CWE-639/MVCTests
- Useless Code/RedundantToStringCall
- WriteOnlyContainer
- standalone/Bad Practices/Control-Flow/ConstantCondition
- resources/stubs
- utils/modelgenerator/dataflow
- docs
- codeql
- codeql-language-guides
- codeql-overview/codeql-changelog
- reusables
- ql-libraries/dataflow
- go
- actions/test
- documentation/library-coverage
- extractor
- autobuilder
- diagnostics
- registries
- toolchain
- util
- ql
- consistency-queries
- change-notes/released
- lib
- change-notes
- released
- ext
- semmle/go
- concepts
- controlflow
- dataflow
- barrierguardutil
- internal
- dependencies
- frameworks
- stdlib
- utils/test/internal
- src
- RedundantCode
- Security
- CWE-020
- CWE-079
- CWE-117
- CWE-327/examples
- change-notes/released
- experimental/CWE-203
- filters
- test/library-tests/semmle/go
- PrintAst
- dataflow
- ExternalFlowInheritance
- ExternalTaintFlow
- ExternalValueFlow
- FlowSteps
- PromotedFields
- VarArgsWithFunctionModels
- flowsources/local
- file
- stdin
- frameworks
- Macaron
- StdlibTaintFlow
- javascript
- downgrades/26a123164be893893e2aa0374d820785decf55af
- extractor
- src/com/semmle/js/extractor
- tests
- cfg/output/trap
- closure/output/trap
- comments/output/trap
- default-encoding/output/trap
- e4x/output/trap
- encoding/output/trap
- errors/output/trap
- es2015/output/trap
- es2016/output/trap
- es2017/output/trap
- es2018/output/trap
- es2019/output/trap
- es2021/output/trap
- es2024/output/trap
- esnext/output/trap
- exprs/output/trap
- extensions/output/trap
- externs/output/trap
- flow/output/trap
- functionbind/output/trap
- generatedcode/output/trap
- helloworld/output/trap
- html/output/trap
- jscript/output/trap
- jsx/output/trap
- keywords/output/trap
- moduleTypes1/output/trap
- moduleTypes2/output/trap
- moduleTypes3/output/trap
- mozilla/output/trap
- ng-templates/output/trap
- node/output/trap
- regexp/output/trap
- restprops/output/trap
- shebang/output/trap
- stmts/output/trap
- strictmode/output/trap
- ts/output/trap
- v8/output/trap
- variables/output/trap
- vue/output/trap
- yaml
- input
- output/trap
- test/com/semmle/js/extractor/test
- ql
- lib
- change-notes
- released
- semmle/javascript
- frameworks
- data
- internal
- security
- dataflow
- upgrades/578367e82a25a3e286aaf1238613db3717b67476
- src
- change-notes/released
- test
- library-tests
- TypeScript/Shebangs
- frameworks
- ReactJS
- WebSocket
- vercel
- src
- variables
- query-tests
- Declarations
- SuspiciousMethodNameDeclaration
- UniquePropertyNames
- Expressions
- DuplicateProperty
- ExprHasNoEffect
- Quality/UnhandledErrorInStreamPipeline
- Security
- CWE-022/TaintedPath
- CWE-078/CommandInjection
- CWE-079/ReflectedXss
- CWE-089/untyped
- CWE-770/MissingRateLimit
- CWE-918
- Statements/LoopIterationSkippedDueToShifting
- java
- documentation/library-coverage
- downgrades/de4ded61c8ae83f829aedaf05be73307ba25ca40
- kotlin-extractor
- deps
- dev
- src/main/kotlin
- utils
- versions
- v_1_6_0
- v_1_6_20
- v_1_7_0
- v_1_7_20
- v_1_8_0
- v_1_9_0-Beta
- ql
- consistency-queries
- examples/snippets
- integration-tests/kotlin
- all-platforms
- annotation-id-consistency
- compiler_arguments/app
- diagnostics/kotlin-version-too-new
- gradle_groovy_app/app
- gradle_kotlinx_serialization
- app
- java_modifiers
- jvmoverloads-external-class
- kotlin_java_static_fields
- kotlin_kfunction/app
- nullability-annotations
- posix/module_mangled_names
- lib
- change-notes
- released
- config
- experimental/quantum
- ext
- generated/modelgenerator
- semmle/code/java
- arithmetic
- comparison
- controlflow
- unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- dispatch
- frameworks
- android
- javaee
- ejb
- jsf
- spring
- stapler
- metrics
- security
- internal
- regexp
- upgrades/9f6026c400996c13842974b24f076a486ad1f69c
- utils/test
- src
- Advisory/Declarations
- Language Abuse
- Likely Bugs
- Arithmetic
- Collections
- Comparison
- Concurrency
- Frameworks/Swing
- Serialization
- Statements
- Termination
- Security/CWE
- CWE-079
- CWE-1004
- CWE-117
- CWE-295
- CWE-319
- CWE-338
- CWE-367
- CWE-835
- Violations of Best Practice
- Boolean Logic
- Boxed Types
- Dead Code
- Declarations
- Implementation Hiding
- Naming Conventions
- legacy
- change-notes/released
- experimental
- Security/CWE
- CWE-094
- CWE-208
- CWE-295
- CWE-327
- CWE-400
- CWE-489
- CWE-625
- CWE-652
- CWE-665
- quantum/Examples
- semmle/code/java/frameworks
- utils/modelgenerator/internal
- test-kotlin1/library-tests
- controlflow
- basic
- dominance
- data-classes
- exprs
- java-kotlin-collection-type-generic-methods
- methods
- ministdlib
- test-kotlin2/library-tests
- annotation_classes
- annotations/jvmName
- classes
- comments
- companion_objects
- controlflow
- basic
- dominance
- data-classes
- exprs
- generic-instance-methods
- generic-selective-extraction
- inherited-default-value
- interface-delegate
- internal-constructor-called-from-java
- internal-public-alias
- java-kotlin-collection-type-generic-methods
- java_and_kotlin_internal
- java_and_kotlin
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmoverloads_generics
- jvmstatic-annotation
- lateinit
- methods-mixed-java-and-kotlin
- methods
- modifiers
- parameter-defaults
- private-anonymous-types
- properties
- reflection
- stmts
- vararg
- test
- experimental/query-tests/quantum/examples
- BadMacUse
- InsecureOrUnknownNonceSource
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- ext/TestModels
- library-tests
- compact-source-files
- controlflow
- basic
- dominance
- dataflow
- capture
- entrypoint-types
- fluent-methods
- kdf
- scoped-values
- taint-jackson
- taintsources
- errorexpr
- flexible-constructors
- frameworks
- android
- intent
- slice
- taint-database
- apache-commons-lang3
- apache-http
- guava/handwritten
- javax-json
- jms
- lastaflute
- netty/manual
- rabbitmq
- ratpack/resources
- spring
- cache
- context
- controller
- data
- http
- ui
- util
- validation
- webmultipart
- websocket
- webutil
- guards12
- guards
- java7/MultiCatch
- locations
- module-import-declarations
- optional
- pattern-instanceof
- pattern-switch/cfg
- ssa
- successors
- CloseReaderTest
- LoopVarReadTest
- SaveFileTest
- SchackTest
- TestBreak
- TestContinue
- TestDeclarations
- TestFinallyBreakContinue
- TestFinally
- TestLoopBranch
- TestThrow2
- TestThrow
- TestTryCatch
- TestTryWithResources
- switch-default-impossible-dispatch
- unreachableblocks
- unreachableblocks
- query-tests
- Escaping
- Nullness
- SafePublication
- StringComparison
- ThreadSafe/examples
- UselessComparisonTest
- lgtm-example-queries
- security
- CWE-022/semmle/tests
- CWE-023/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-1004
- CWE-117
- CWE-1204
- CWE-190/semmle/tests
- CWE-200/semmle/tests
- SensitiveNotification
- SensitiveTextView
- CWE-287
- InsecureKeys/Test1
- InsecureLocalAuth
- CWE-295
- AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- ImproperWebVeiwCertificateValidation
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-327/semmle/tests
- CWE-501
- CWE-524/res/layout
- CWE-532
- CWE-611
- CWE-676/semmle/tests
- CWE-749
- CWE-918
- CWE-927
- stubs
- hibernate-5.x/org/hibernate
- query
- javax-validation-constraints/javax/validation
- constraints
- woodstox-core-6.4.0
- com/ctc/wstx/stax
- org/codehaus/stax2
- misc
- bazel
- 3rdparty
- py_deps
- tree_sitter_extractors_deps
- cmake
- internal/zipmerge
- registry
- modules
- rules_dotnet/0.21.5-codeql.1
- rules_kotlin
- 2.1.3-codeql.1
- 2.2.2-codeql.1
- patches
- codegen
- templates
- scripts/models-as-data
- suite-helpers
- change-notes/released
- python
- downgrades/eb5fc917c79bb23ce2de4a022f3e566d57a91be9
- extractor
- semmle
- python
- parser
- tests/parser
- tsg-python
- tsp
- src
- tree_sitter
- ql
- consistency-queries
- integration-tests/query-suite
- lib
- analysis
- change-notes
- released
- semmle/python
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
14 | 16 | | |
15 | 17 | | |
16 | 18 | | |
| |||
34 | 36 | | |
35 | 37 | | |
36 | 38 | | |
37 | | - | |
| 39 | + | |
38 | 40 | | |
39 | 41 | | |
40 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| 48 | + | |
| 49 | + | |
This file was deleted.
This file was deleted.
0 commit comments