Commit 3da6cee
File tree
- .github/workflows
- cpp
- downgrades/02a123a1a681f98cf502f189a2a79b0dfb398e59
- ql
- lib
- change-notes
- semmle/code/cpp
- dataflow/internal
- exprs
- ir/dataflow/internal
- models
- implementations
- interfaces
- upgrades/68930f3b81bbe3fdbb91c850deca1fec8072d62a
- src
- Security/CWE
- CWE-190
- CWE-570
- change-notes
- test
- library-tests
- builtins/type_traits
- dataflow
- fields
- taint-tests
- types
- datasizeof
- sizeof
- query-tests
- Critical/MemoryFreed
- Security/CWE
- CWE-190/semmle
- TaintedAllocationSize
- tainted
- CWE-570
- csharp
- autobuilder
- Semmle.Autobuild.CSharp.Tests
- Semmle.Autobuild.Cpp.Tests
- documentation/library-coverage
- extractor
- Semmle.Extraction.CSharp.DependencyFetching
- SourceGenerators
- DotnetSourceGeneratorWrapper
- Semmle.Extraction.CSharp
- Entities
- Compilations
- Extractor
- Semmle.Extraction
- Entities
- Semmle.Util
- ql
- integration-tests
- all-platforms
- cshtml_standalone_disabled
- cshtml_standalone_net6
- cshtml_standalone
- standalone_dependencies_net48
- standalone_resx
- standalone_winforms
- standalone
- posix-only
- standalone_dependencies_executing_runtime
- standalone_dependencies_multi_project
- standalone_dependencies_multi_target
- standalone_dependencies_no_framework
- standalone_dependencies_nuget with_space
- standalone_dependencies_nuget_config_error_timeout
- standalone_dependencies_nuget_config_error
- standalone_dependencies_nuget_config_fallback
- standalone_dependencies_nuget_no_sources
- standalone_dependencies_nuget_versions
- standalone_dependencies_nuget
- standalone_dependencies
- windows-only/standalone_dependencies
- lib
- change-notes
- ext
- semmle/code/csharp
- dataflow/internal
- frameworks
- microsoft
- security/dataflow/flowsources
- src
- Telemetry
- utils/modelgenerator
- debug
- internal
- test
- library-tests
- dataflow
- collections
- external-models
- flowsources/aspremote
- global
- library
- frameworks/microsoft
- partial
- query-tests/Security Features
- CWE-089
- CWE-134
- CWE-338
- utils/modelgenerator/dataflow
- docs/codeql
- codeql-language-guides
- reusables
- go
- codeql-tools
- documentation/library-coverage
- extractor
- cli/go-configure-baseline
- configurebaseline
- util
- ql
- integration-tests
- bazel-sample-1
- src
- bazel-sample-2
- src
- configure-baseline
- src
- a/vendor
- b/vendor
- c/vendor
- dep-sample
- work
- vendor/golang.org/x/time
- rate
- diagnostics
- build-constraints-exclude-all-go-files
- work
- go-files-found-not-processed
- work
- subdir
- invalid-toolchain-version
- src
- newer-go-version-needed
- work
- no-go-files-found
- work
- package-not-found-with-go-mod
- work
- package-not-found-without-go-mod
- work
- unsupported-relative-path
- work/main
- subpkg
- extract-vendor
- src
- vendor
- example.com/test
- glide-sample
- work
- vendor/golang.org/x/time
- rate
- go-get-without-modules-sample
- src
- go-mod-sample
- src
- go-mod-without-version
- src
- subdir
- go-version-bump
- src
- make-sample
- src
- mixed-layout
- src
- module
- stray-files
- workspace
- subdir
- ninja-sample
- src
- resolve-build-environment/newer-go-needed
- src
- single-go-mod-and-go-files-not-under-it
- src
- subdir
- subsubdir
- single-go-mod-in-root
- src
- subdir
- single-go-mod-not-in-root
- src/subdir
- subsubdir
- single-go-work-not-in-root
- src/modules
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-nested-none-in-root
- src/subdir0
- subdir1
- subsubdir1
- subdir2
- two-go-mods-nested-one-in-root
- src
- subdir1
- subsubdir1
- subdir2
- two-go-mods-not-nested
- src
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- two-go-mods-one-failure
- src
- subdir1
- subsubdir1
- subdir2
- subsubdir2
- lib
- change-notes
- ext
- semmle/go
- concepts
- dataflow
- internal
- frameworks
- stdlib
- security
- test
- experimental
- CWE-1004
- CWE-74
- library-tests/semmle/go
- dataflow
- DefaultTaintSanitizer
- flowsources/local
- environment
- vendor
- github.com
- caarlos0/env
- gobuffalo/envy
- hashicorp/go-envparse
- joho/godotenv
- kelseyhightower/envconfig
- file
- frameworks
- BeegoOrm
- Echo
- SQL
- Gorm
- Sqlx
- bun
- gogf
- gorqlite
- vendor
- github.com/rqlite/gorqlite
- Twirp
- XNetHtml
- query-tests
- InconsistentCode/UnhandledCloseWritableHandle
- Security
- CWE-078
- CWE-079
- CWE-089
- CWE-190
- javascript/ql
- integration-tests
- all-platforms/no-types
- diagnostics
- internal-error
- src
- syntax-error
- no-types
- lib/semmle/javascript
- frameworks/helmet
- security/dataflow
- src
- Security/CWE-693
- change-notes
- test/query-tests/Security
- CWE-022/TaintedPath
- CWE-079/DomBasedXss
- CWE-326
- CWE-730
- java
- integration-tests-lib
- kotlin-extractor
- dev
- src/main/kotlin/utils
- ql
- integration-tests
- all-platforms
- java
- android-8-sample
- gradle/wrapper
- android-sample-kotlin-build-script-no-wrapper
- android-sample-kotlin-build-script
- gradle/wrapper
- android-sample-no-wrapper
- android-sample-old-style-kotlin-build-script-no-wrapper
- android-sample-old-style-kotlin-build-script
- gradle/wrapper
- android-sample-old-style-no-wrapper
- android-sample-old-style
- gradle/wrapper
- android-sample
- gradle/wrapper
- ant-sample
- buildless-dependency-different-repository
- buildless-erroneous
- buildless-gradle-classifiers
- gradle/wrapper
- buildless-gradle-timeout
- buildless-gradle
- gradle/wrapper
- buildless-inherit-trust-store
- buildless-maven-executable-war
- buildless-maven-multimodule
- buildless-maven-timeout
- buildless-maven
- buildless-module-definition-not-in-module-info-file
- buildless-proxy-gradle
- gradle/wrapper
- buildless-proxy-maven
- buildless-sibling-projects
- buildless-snapshot-repository
- buildless
- diagnostics
- android-gradle-incompatibility
- gradle/wrapper
- compilation-error
- dependency-error
- java-version-too-old
- gradle
- wrapper
- maven-http-repository
- multiple-candidate-builds
- no-build-system
- no-gradle-test-classes
- no-gradle-wrapper
- ecj-sample-noexit
- ecj-sample
- ecj-tolerate-enum-annotations
- gradle-sample-kotlin-script
- gradle/wrapper
- gradle-sample
- gradle
- wrapper
- java-web-jsp
- maven-enforcer
- maven-sample-extract-properties
- maven-sample-large-xml-files
- maven-sample-small-xml-files
- maven-sample-xml-mode-all
- maven-sample-xml-mode-byname
- maven-sample-xml-mode-disabled
- maven-sample-xml-mode-smart
- maven-sample
- maven-wrapper-script-only
- maven-wrapper-source-only
- maven-wrapper
- multi-release-jar-java11
- multi-release-jar-java17
- partial-gradle-sample-without-gradle
- partial-gradle-sample
- spring-boot-sample
- gradle/wrapper
- kotlin
- annotation-id-consistency
- compiler_arguments
- gradle/wrapper
- default-parameter-mad-flow
- diagnostics/kotlin-version-too-new
- enabling
- enhanced-nullability
- external-property-overloads
- extractor_crash
- code
- extractor_information_kotlin1
- extractor_information_kotlin2
- file_classes
- gradle_groovy_app
- gradle/wrapper
- gradle_kotlinx_serialization
- gradle/wrapper
- java-interface-redeclares-tostring
- java_modifiers
- jvmoverloads-external-class
- kotlin-interface-inherited-default
- kotlin_compiler_java_source
- kotlin_file_import
- kotlin_java_lowering_wildcards
- kotlin_java_static_fields
- kotlin_kfunction
- gradle/wrapper
- kotlinc_multi
- logs
- nested_generic_types
- nullability-annotations
- path_transformer
- private_property_accessors
- raw_generic_types
- repeatable-annotations
- trap_compression
- linux-only/kotlin
- custom_plugin
- use_java_library
- posix-only/kotlin
- generic-extension-property
- java_kotlin_extraction_orders
- kotlin_double_interception
- code
- module_mangled_names
- needless-java-wildcards
- lib
- change-notes
- ext
- experimental
- semmle/code/java
- dataflow
- internal
- src
- experimental/Security/CWE
- CWE-078
- CWE-347
- utils/modelgenerator
- debug
- internal
- test-kotlin1/library-tests/dataflow/summaries
- test-kotlin2/library-tests/dataflow/summaries
- test
- experimental
- query-tests/security
- CWE-200
- CWE-347
- CWE-625
- stubs
- auth0-java-jwt-4.4.0/com
- auth0/jwt
- algorithms
- exceptions
- interfaces
- github/luben/zstd
- org-apache-shiro-authc-2.0.1/org/apache/shiro/authc
- ext/TestModels
- library-tests
- dataflow
- callctx
- capture
- collections
- external-models
- stubs
- fluent-methods
- implicit-read
- stream-collect
- stream-read
- subpaths
- synth-global
- taint-format
- taint-gson
- taint-jackson
- threat-models
- typeflow-dispatch
- frameworks
- android
- asynctask
- content-provider-summaries
- flow-steps
- intent
- notification
- uri
- widget
- apache-ant
- apache-collections
- apache-commons-compress
- apache-commons-lang3
- gson
- guava/generated
- cache
- collect
- hudson
- jackson
- javax-json
- jdk
- java.io
- java.net
- java.nio.file
- json-java
- netty/generated
- play
- spring
- beans
- cache
- componentscan
- WEB-INF
- com/semmle
- d
- e
- f
- g
- h
- context
- data
- http
- ui
- util
- validation
- webmultipart
- webutil
- stapler
- stream
- thymeleaf
- logging
- optional
- paths
- regex
- scanner
- query-tests
- DeadCode/camel
- com/semmle/camel
- javadsl
- security/CWE-927
- stubs
- apache-camel-4.0.6
- org/apache/camel
- builder
- impl
- model
- springframework-5.3.8/org/springframework
- beans
- factory
- config
- support
- context/annotation
- core
- type
- utils/modelgenerator/dataflow
- p
- misc
- bazel
- buildifier
- internal
- zipmerge
- ripunzip
- python/ql
- lib/semmle/python/dataflow/new/internal
- src/Security/CWE-020
- test/library-tests/frameworks/django-orm
- ruby/ql
- integration-tests/diagnostics
- syntax-error
- unknown-encoding
- lib/codeql/ruby/dataflow/internal
- test
- library-tests
- dataflow
- api-graphs
- array-flow
- flow-summaries
- params
- type-tracker
- frameworks/action_controller
- query-tests/security/cwe-094/CodeInjection
- swift/ql
- integration-tests
- autobuilder
- failure
- hello-failure.xcodeproj
- project.xcworkspace
- no-build-system
- no-swift-with-spm
- hello-objective.xcodeproj
- project.xcworkspace
- hello-objective
- no-swift
- hello-objective.xcodeproj
- project.xcworkspace
- hello-objective
- no-xcode-with-spm
- only-tests-with-spm
- hello-tests.xcodeproj
- project.xcworkspace
- only-tests
- hello-tests.xcodeproj
- project.xcworkspace
- xcode-fails-spm-works
- Sources/hello-world
- codeql-swift-autobuild-test.xcodeproj
- codeql-swift-autobuild-test
- linux/RegexLiteralExpr
- osx
- canonical-case
- hello-xcode
- codeql-swift-autobuild-test.xcodeproj
- codeql-swift-autobuild-test
- posix
- cross-references
- Sources/cross-references
- deduplication
- Sources/deduplication
- frontend-invocations
- dir
- hello-world
- Sources/hello-world
- linkage-awareness
- Foo1
- Sources/foo
- Foo2
- Sources/foo
- partial-modules
- A
- Sources/A
- B
- Sources/B
- Sources/partial-modules
- symlinks
- preserve
- Sources
- resolve
- Sources
- lib/codeql/swift
- dataflow/internal
- security
- src/change-notes
- test
- library-tests/dataflow/taint
- core
- libraries
- query-tests/Security
- CWE-078
- CWE-094
- CWE-311
- CWE-321
- CWE-757
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
| 27 | + | |
27 | 28 | | |
28 | 29 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
24 | 24 | | |
25 | 25 | | |
26 | 26 | | |
27 | | - | |
| 27 | + | |
28 | 28 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
37 | 37 | | |
38 | 38 | | |
39 | 39 | | |
40 | | - | |
| 40 | + | |
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| |||
48 | 48 | | |
49 | 49 | | |
50 | 50 | | |
51 | | - | |
| 51 | + | |
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
7 | 7 | | |
8 | 8 | | |
9 | 9 | | |
| 10 | + | |
10 | 11 | | |
11 | | - | |
12 | 12 | | |
13 | 13 | | |
14 | 14 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
29 | | - | |
| 29 | + | |
30 | 30 | | |
31 | 31 | | |
32 | 32 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
| 2 | + | |
3 | 3 | | |
| 4 | + | |
4 | 5 | | |
5 | 6 | | |
6 | 7 | | |
| |||
30 | 31 | | |
31 | 32 | | |
32 | 33 | | |
33 | | - | |
| 34 | + | |
| 35 | + | |
34 | 36 | | |
35 | 37 | | |
| 38 | + | |
36 | 39 | | |
37 | | - | |
| 40 | + | |
38 | 41 | | |
39 | 42 | | |
40 | 43 | | |
41 | 44 | | |
42 | 45 | | |
43 | 46 | | |
44 | 47 | | |
45 | | - | |
46 | | - | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
47 | 58 | | |
48 | 59 | | |
49 | 60 | | |
50 | 61 | | |
51 | 62 | | |
52 | 63 | | |
53 | | - | |
| 64 | + | |
54 | 65 | | |
55 | 66 | | |
56 | 67 | | |
| |||
Lines changed: 17 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
0 commit comments