Commit 90c91fa
File tree
- .github
- workflows
- actions/ql
- examples
- snippets
- lib
- change-notes
- released
- codeql/actions
- ast/internal
- ext
- config
- manual
- src
- Security
- CWE-275
- CWE-829
- change-notes
- released
- test
- library-tests
- basic
- .github/workflows
- very-long-expression
- .github/workflows
- query-tests/Security
- CWE-275/.github/workflows
- CWE-829
- .github
- actions/unpinned-tag
- workflows
- config
- cpp
- downgrades
- 1402ab319d20cdc9289deb7bfc1c70f36be44d44
- 770002bb02322e04fa25345838ce6e82af285a0b
- 7e7c2f55670f8123d514cf542ccb1938118ac561
- 83100310bf73eefc37c1d8d0ac98b2ca3019c7b6
- 837c4e02326aee4582405d069263092e80a15d82
- 9439176c1d1312787926458dd54d65a849069118
- d2d611b3fdcc7c4fe370f0d115200a3aa6ad5837
- ef8d209a22e27413aaaeff4446f0ecb9fa2c227b
- ql
- integration-tests/query-suite
- lib
- change-notes
- released
- ext
- allocation
- generated/modelgenerator
- brotli
- curl
- glibc
- libidn2
- libssh2
- libuv
- nghttp2
- openssl
- sqlite
- zlib
- semmle/code/cpp
- commons
- controlflow
- dataflow
- internal
- exprs
- internal
- ir
- dataflow
- internal
- implementation
- aliased_ssa
- raw
- internal
- unaliased_ssa
- models
- implementations
- interfaces
- rangeanalysis
- security
- stmts
- upgrades
- 1402ab319d20cdc9289deb7bfc1c70f36be44d44
- 770002bb02322e04fa25345838ce6e82af285a0b
- 7e7c2f55670f8123d514cf542ccb1938118ac561
- 83100310bf73eefc37c1d8d0ac98b2ca3019c7b6
- 837c4e02326aee4582405d069263092e80a15d82
- 9439176c1d1312787926458dd54d65a849069118
- a42ce5fc943254097f85471b94ae2247e819104a
- d2d611b3fdcc7c4fe370f0d115200a3aa6ad5837
- src
- Diagnostics
- Likely Bugs
- Arithmetic
- Format
- Leap Year
- Memory Management
- OO
- Underspecified Functions
- Security/CWE
- CWE-020
- CWE-079
- CWE-089
- CWE-120
- CWE-134
- CWE-190
- CWE-311
- CWE-468
- Telemetry
- change-notes
- released
- jsf/lib/section_4_21_Operators
- utils/modelgenerator/internal
- test
- experimental/query-tests/Security/CWE/CWE-193/constant-size
- library-tests
- builtins
- complex
- type_traits
- types
- controlflow
- guards-ir
- guards
- ctorinits
- dataflow
- asDefinition
- certain
- dataflow-tests
- external-models
- fields
- ir-barrier-guards
- models-as-data
- source-sink-tests
- taint-tests
- friends/loop
- ir
- ir
- points_to
- range-analysis
- types
- literals/literals
- rangeanalysis/SimpleRangeAnalysis
- scanf
- subscript_operator
- syntax-zoo
- templates/type_instantiations
- type_sizes
- unspecified_type/types
- using-aliases
- variables/variables
- vector_types
- query-tests
- Critical/UnsafeUseOfThis
- Likely Bugs
- Arithmetic
- IntMultToLong
- PointlessComparison
- Format
- NonConstantFormat
- WrongTypeFormatArguments/Buildless
- Leap Year/UncheckedLeapYearAfterYearModification
- Likely Typos/ExprHasNoEffect
- autoconf
- meson-private/tmp_abc
- Memory Management/ReturnStackAllocatedMemory
- Underspecified Functions
- Security/CWE
- CWE-311/semmle/tests
- CWE-468/semmle/SuspiciousAddWithSizeof
- CWE-497/semmle/tests
- csharp
- .config
- .paket
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- downgrades
- 178a7e6cf335486d33d4e49543148e3f57f04a9a
- 19b8cc3e2dc768d4cbc03d6e3773b709bbebd036
- 3cabc77473cbbda95edebafea345c2e3fdfa12d9
- e73ca2c93df8aae162f1704edc4817a5cb330529
- ea7ad33252e550241975676f09fcc7b0a703deab
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- Semmle.Extraction.CSharp.Util
- Semmle.Extraction.CSharp
- CodeAnalysisExtensions
- Entities
- Base
- Compilations
- Expressions
- ObjectCreation
- Types
- Kinds
- Trap
- Semmle.Util
- ql
- campaigns/Solorigate
- lib
- change-notes/released
- src
- change-notes/released
- consistency-queries
- examples/snippets
- integration-tests
- all-platforms
- autobuild_slnx
- autobuild
- binlog_multiple
- binlog
- blazor_build_mode_none
- BlazorTest
- blazor
- BlazorTest
- conditional_compilation
- cshtml_standalone_disabled
- cshtml_standalone_flowsteps
- cshtml_standalone_net6
- cshtml_standalone
- cshtml
- diag_dotnet_incompatible
- diag_missing_project_files
- diag_missing_xamarin_sdk
- diag_recursive_generics
- dotnet_10
- dotnet_build
- dotnet_no_args_inject
- dotnet_pack
- dotnet_publish
- dotnet_run
- source_generator
- standalone_buildless_option
- standalone_dependencies_net48
- standalone_dependency_dir/proj
- standalone_failed
- standalone_resx
- standalone_slnx
- standalone_winforms
- standalone
- linux
- compiler_args
- diag_nuget_config_casing
- sub-project
- standalone_dependencies_non_utf8_filename
- posix
- dotnet_test_mstest
- dotnet_test
- inherit-env-vars
- query-suite
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_clear
- clear
- proj
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- standalone_dependencies_nuget_no_sources
- proj
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- warn_as_error
- windows/standalone_dependencies
- lib
- Linq
- change-notes
- released
- experimental/code/csharp/Cryptography
- ext
- generated/modelgenerator
- semmle/code/csharp
- commons
- controlflow
- internal
- dataflow
- internal
- rangeanalysis
- dispatch
- exprs
- internal
- frameworks
- system
- runtime
- internal
- metrics
- security
- auth
- dataflow
- flowsinks
- flowsources
- xml
- upgrades
- 178a7e6cf335486d33d4e49543148e3f57f04a9a
- 19b8cc3e2dc768d4cbc03d6e3773b709bbebd036
- 68b5aec54e50fe7e375df3777b756a746ca3a37c
- e73ca2c93df8aae162f1704edc4817a5cb330529
- ea7ad33252e550241975676f09fcc7b0a703deab
- utils/test
- src
- Bad Practices/Control-Flow
- CSI
- Complexity
- Concurrency
- Dead Code
- Language Abuse
- Likely Bugs
- Collections
- Dynamic
- Statements
- Linq
- Performance
- Security Features
- CWE-079
- CWE-1004
- CWE-117
- CWE-119
- CWE-327
- CWE-352
- CWE-384
- CWE-502
- CWE-614
- Telemetry
- Useless code
- change-notes
- released
- codeql-suites
- experimental
- CWE-918
- Security Features/CWE-759
- utils/modelgenerator/internal
- test
- library-tests
- arguments
- assignables
- assignments
- controlflow
- graph
- CONSISTENCY
- guards-large
- guards
- conversion
- pointer
- span
- csharp10
- csharp11
- csharp6
- csharp7
- csharp8
- dataflow
- call-sensitivity
- callablereturnsarg
- constructors
- defuse
- extensions
- external-models
- fields
- flowsources
- aspremote
- remote
- global
- library
- local
- methods
- modulusanalysis
- nullcoalescing
- nullness
- operators
- signanalysis
- ssa-large
- ssa
- structs
- dispatch
- dynamic
- enums
- expressions
- extension
- goto
- linq
- obinit
- operators
- parameters
- partial
- properties
- security/dataflow/flowsources
- standalone/controlflow
- structuralcomparison
- query-tests
- API Abuse
- ClassDoesNotImplementEquals
- IncorrectEqualsSignature
- Bad Practices/Control-Flow/ConstantCondition
- Concurrency/SynchSetUnsynchGet
- Dead Code/DeadStoreOfLocal
- Language Abuse/UselessNullCoalescingExpression
- Likely Bugs/ConstantComparison
- Linq/MissedSelectOpportunity
- Nullness
- Security Features
- CWE-1004/HttpOnlyCookie
- AspNetCore/NoPolicy
- SystemWeb/HttpOnlyCookiesFalse
- CWE-117
- CWE-352
- missing-aspnetcore
- missing
- CWE-614/InsecureCookie
- AspNetCore/NoPolicy
- SystemWeb/RequireSSLFalse
- CWE-639/MVCTests
- Useless Code/RedundantToStringCall
- WriteOnlyContainer
- standalone/Bad Practices/Control-Flow/ConstantCondition
- resources/stubs
- utils/modelgenerator/dataflow
- tools
- docs
- codeql
- _static
- codeql-language-guides
- codeql-overview/codeql-changelog
- ql-language-reference
- reusables
- ql-libraries/dataflow
- go
- actions/test
- codeql-tools
- documentation/library-coverage
- extractor
- autobuilder
- cli/go-autobuilder
- diagnostics
- registries
- toolchain
- util
- ql
- consistency-queries
- change-notes/released
- integration-tests
- diagnostics
- package-not-found-with-go-mod
- package-not-found-without-go-mod
- root-internal-tests
- src
- nested
- lib
- change-notes
- released
- ext
- semmle/go
- concepts
- controlflow
- dataflow
- barrierguardutil
- internal
- dependencies
- frameworks
- stdlib
- security
- utils/test/internal
- src
- RedundantCode
- Security
- CWE-020
- CWE-079
- CWE-117
- CWE-209
- CWE-327/examples
- CWE-352
- change-notes/released
- experimental
- CWE-203
- CWE-287
- CWE-918
- filters
- test
- library-tests/semmle/go
- PrintAst
- dataflow
- ExternalFlowInheritance
- ExternalTaintFlow
- ExternalValueFlow
- FlowSteps
- PromotedFields
- VarArgsWithFunctionModels
- flowsources/local
- file
- stdin
- frameworks
- Beego
- Encoding
- Macaron
- StdlibTaintFlow
- query-tests/Security/CWE-079
- javascript
- downgrades
- 26a123164be893893e2aa0374d820785decf55af
- 578367e82a25a3e286aaf1238613db3717b67476
- extractor
- src/com/semmle/js/extractor
- tests
- cfg/output/trap
- closure/output/trap
- comments/output/trap
- default-encoding/output/trap
- e4x/output/trap
- encoding/output/trap
- errors/output/trap
- es2015/output/trap
- es2016/output/trap
- es2017/output/trap
- es2018/output/trap
- es2019/output/trap
- es2021/output/trap
- es2024/output/trap
- esnext/output/trap
- exprs/output/trap
- extensions/output/trap
- externs/output/trap
- flow/output/trap
- functionbind/output/trap
- generatedcode/output/trap
- helloworld/output/trap
- html/output/trap
- jscript/output/trap
- jsx/output/trap
- keywords/output/trap
- moduleTypes1/output/trap
- moduleTypes2/output/trap
- moduleTypes3/output/trap
- mozilla/output/trap
- ng-templates/output/trap
- node/output/trap
- regexp/output/trap
- restprops/output/trap
- shebang/output/trap
- stmts/output/trap
- strictmode/output/trap
- ts/output/trap
- v8/output/trap
- variables/output/trap
- vue/output/trap
- yaml
- input
- output/trap
- test/com/semmle/js/extractor/test
- ql/lib
- change-notes
- released
- semmle/javascript
- dataflow
- internal
- frameworks
- java
- documentation/library-coverage
- downgrades/de4ded61c8ae83f829aedaf05be73307ba25ca40
- kotlin-extractor
- deps
- dev
- src/main/kotlin
- utils
- versions
- v_1_6_0
- v_1_6_20
- v_1_7_0
- v_1_7_20
- v_1_8_0
- v_1_9_0-Beta
- ql
- consistency-queries
- examples/snippets
- integration-tests
- java
- buildless-maven-existing-settings-xml
- buildless-maven-mirrorof
- buildless-maven-timeout
- buildless-maven
- kotlin
- all-platforms
- annotation-id-consistency
- compiler_arguments/app
- diagnostics/kotlin-version-too-new
- gradle_groovy_app/app
- gradle_kotlinx_serialization
- app
- java_modifiers
- jvmoverloads-external-class
- kotlin_java_static_fields
- kotlin_kfunction/app
- nullability-annotations
- posix/module_mangled_names
- lib
- change-notes
- released
- config
- experimental/quantum
- ext
- generated
- llmgenerator
- modelgenerator
- semmle/code/java
- arithmetic
- comparison
- controlflow
- unreachableblocks
- dataflow
- internal
- rangeanalysis
- deadcode
- dispatch
- frameworks
- android
- javaee
- ejb
- jsf
- spring
- stapler
- struts
- metrics
- security
- internal
- regexp
- upgrades/9f6026c400996c13842974b24f076a486ad1f69c
- utils/test
- src
- Advisory/Declarations
- Language Abuse
- Likely Bugs
- Arithmetic
- Collections
- Comparison
- Concurrency
- Frameworks/Swing
- Serialization
- Statements
- Termination
- Metrics/Summaries
- Security/CWE
- CWE-079
- CWE-1004
- CWE-117
- CWE-295
- CWE-319
- CWE-338
- CWE-367
- CWE-502
- CWE-835
- Violations of Best Practice
- Boolean Logic
- Boxed Types
- Dead Code
- Declarations
- Implementation Hiding
- Naming Conventions
- legacy
- change-notes
- released
- experimental
- Security/CWE
- CWE-094
- CWE-208
- CWE-295
- CWE-327
- CWE-400
- CWE-489
- CWE-625
- CWE-652
- CWE-665
- quantum/Examples
- semmle/code/java
- frameworks
- security
- semmle/code/xml
- utils/modelgenerator/internal
- test-kotlin1/library-tests
- controlflow
- basic
- dominance
- data-classes
- exprs
- java-kotlin-collection-type-generic-methods
- methods
- ministdlib
- test-kotlin2/library-tests
- annotation_classes
- annotations/jvmName
- classes
- comments
- companion_objects
- controlflow
- basic
- dominance
- data-classes
- exprs
- generic-instance-methods
- generic-selective-extraction
- inherited-default-value
- interface-delegate
- internal-constructor-called-from-java
- internal-public-alias
- java-kotlin-collection-type-generic-methods
- java_and_kotlin_internal
- java_and_kotlin
- jvmoverloads-annotation
- jvmoverloads_flow
- jvmoverloads_generics
- jvmstatic-annotation
- lateinit
- methods-mixed-java-and-kotlin
- methods
- modifiers
- parameter-defaults
- private-anonymous-types
- properties
- reflection
- stmts
- vararg
- test
- experimental/query-tests
- quantum/examples
- BadMacUse
- InsecureOrUnknownNonceSource
- WeakOrUnknownAsymmetricKeySize
- WeakOrUnknownBlockMode
- WeakOrUnknownHash
- WeakOrUnknownKDFIterationCount
- WeakOrUnknownKDFKeySize
- WeakOrUnknownSymmetricCipher
- security
- CWE-073
- CWE-601
- ext/TestModels
- library-tests
- compact-source-files
- controlflow
- basic
- dominance
- dataflow
- capture
- collections
- entrypoint-types
- fluent-methods
- kdf
- scoped-values
- taint-jackson
- taintsources
- errorexpr
- flexible-constructors
- frameworks
- android
- intent
- slice
- taint-database
- apache-collections
- apache-commons-fileupload-1.4
- apache-commons-lang3
- apache-http
- guava/handwritten
- javax-json
- jms
- json-java
- lastaflute
- netty
- generated
- manual
- rabbitmq
- ratpack/resources
- spring
- beans
- cache
- context
- controller
- data
- http
- ui
- util
- validation
- webmultipart
- websocket
- webutil
- guards12
- guards
- java7/MultiCatch
- locations
- module-import-declarations
- optional
- pattern-instanceof
- pattern-switch/cfg
- scanner
- ssa
- successors
- CloseReaderTest
- LoopVarReadTest
- SaveFileTest
- SchackTest
- TestBreak
- TestContinue
- TestDeclarations
- TestFinallyBreakContinue
- TestFinally
- TestLoopBranch
- TestThrow2
- TestThrow
- TestTryCatch
- TestTryWithResources
- switch-default-impossible-dispatch
- typeflow
- unreachableblocks
- unreachableblocks
- query-tests
- Escaping
- Nullness
- SafePublication
- StringComparison
- ThreadSafe
- examples
- UnreleasedLock
- UselessComparisonTest
- lgtm-example-queries
- security
- CWE-022/semmle/tests
- CWE-023/semmle/tests
- CWE-078
- CWE-089/semmle/examples
- CWE-1004
- CWE-117
- CWE-1204
- CWE-190/semmle/tests
- CWE-200/semmle/tests
- SensitiveNotification
- SensitiveTextView
- CWE-287
- InsecureKeys/Test1
- InsecureLocalAuth
- CWE-295
- AndroidMissingCertificatePinning
- Test1
- Test2
- Test3
- Test4
- ImproperWebVeiwCertificateValidation
- CWE-297
- CWE-312/android/CleartextStorage
- CWE-327/semmle/tests
- CWE-501
- CWE-524/res/layout
- CWE-532
- CWE-611
- CWE-676/semmle/tests
- CWE-749
- CWE-798/semmle/tests
- CWE-918
- CWE-927
- stubs
- apache-commons-fileupload-1.4/org/apache/commons/fileupload
- servlet
- util
- couchbaseClient/com/couchbase/client
- core/env
- java
- analytics
- kv
- query
- hibernate-5.x/org/hibernate
- query
- jakarta.servlet-api-6.0.0/jakarta/servlet
- annotation
- descriptor
- http
- javax-validation-constraints/javax/validation
- constraints
- springframework-5.8.x/org/springframework/web/socket
- handler
- woodstox-core-6.4.0
- com/ctc/wstx/stax
- org/codehaus/stax2
- utils/modelgenerator/dataflow/p
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
11 | 11 | | |
12 | 12 | | |
13 | 13 | | |
| 14 | + | |
| 15 | + | |
14 | 16 | | |
15 | 17 | | |
16 | 18 | | |
| |||
34 | 36 | | |
35 | 37 | | |
36 | 38 | | |
37 | | - | |
| 39 | + | |
38 | 40 | | |
39 | 41 | | |
40 | 42 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| 48 | + | |
| 49 | + | |
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
70 | 70 | | |
71 | 71 | | |
72 | 72 | | |
73 | | - | |
| 73 | + | |
74 | 74 | | |
75 | 75 | | |
76 | 76 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
8 | | - | |
| 8 | + | |
9 | 9 | | |
10 | 10 | | |
11 | 11 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
| 30 | + | |
30 | 31 | | |
31 | 32 | | |
32 | 33 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| 33 | + | |
33 | 34 | | |
34 | 35 | | |
35 | 36 | | |
| |||
75 | 76 | | |
76 | 77 | | |
77 | 78 | | |
| 79 | + | |
78 | 80 | | |
79 | 81 | | |
80 | 82 | | |
| |||
This file was deleted.
0 commit comments