Commit c7c1eca
File tree
- actions/ql
- lib
- change-notes
- released
- codeql/actions
- ast/internal
- security
- src
- Security/CWE-829
- change-notes
- released
- test/query-tests/Security
- CWE-284/.github/workflows
- CWE-829
- cpp
- downgrades/0853f43dc8c08deecb473c54a2b70da8597f1ab5
- ql
- lib
- semmle/code/cpp
- upgrades/ef8d209a22e27413aaaeff4446f0ecb9fa2c227b
- test/library-tests/name_qualifiers
- csharp
- downgrades/d13c4c187d7318fd2b8f35c7e8d7f4dc26be68b1
- extractor/Semmle.Extraction.CSharp/Entities/Expressions
- ql
- lib
- change-notes
- experimental/code/csharp/Cryptography
- semmle/code/csharp
- controlflow
- internal
- dispatch
- exprs
- security/dataflow/flowsources
- upgrades/3cabc77473cbbda95edebafea345c2e3fdfa12d9
- src/Telemetry
- test
- library-tests
- csharp11
- dataflow
- external-models
- flowsources/aspremote
- properties
- spans
- query-tests/Telemetry/DatabaseQuality
- go
- extractor
- ql
- lib
- change-notes
- semmle/go
- dataflow/internal
- src
- InconsistentCode
- change-notes
- experimental/CWE-525
- test
- experimental
- CWE-090
- CWE-203
- CWE-285
- CWE-287
- CWE-321-V2
- CWE-369
- CWE-400
- CWE-522-DecompressionBombs
- CWE-525
- CWE-74
- CWE-807
- CWE-840
- InconsistentCode
- Unsafe
- library-tests/semmle/go
- controlflow/ControlFlowGraph
- dataflow/Nodes
- frameworks
- BeegoOrm
- Chi
- Echo
- GoMicro
- Revel
- CONSISTENCY
- examples/booking/app
- Twirp
- client
- rpc/notes
- server
- XNetHtml
- query-tests
- InconsistentCode
- ConstantLengthComparison
- InconsistentLoopOrientation
- LengthComparisonOffByOne
- MissingErrorCheck
- MistypedExponentiation
- UnhandledCloseWritableHandle
- WhitespaceContradictsPrecedence
- WrappedErrorAlwaysNil
- RedundantCode
- CompareIdenticalValues
- DeadStoreOfField
- DeadStoreOfLocal
- DuplicateBranches
- DuplicateCondition
- DuplicateSwitchCase
- ExprHasNoEffect
- ImpossibleInterfaceNilCheck
- NegativeLengthCheck
- RedundantExpr
- RedundantRecover
- SelfAssignment
- ShiftOutOfRange
- UnreachableStatement
- Security
- CWE-020
- IncompleteHostnameRegexp
- IncompleteUrlSchemeCheck
- MissingRegexpAnchor
- SuspiciousCharacterInRegexp
- CWE-022
- GorillaMuxDefault
- GorillaMuxSkipClean
- CWE-078
- CWE-089
- CWE-190
- CWE-209
- CWE-295/DisabledCertificateCheck
- CWE-322
- CWE-326
- CWE-327
- CWE-338/InsecureRandomness
- CWE-347
- CWE-352
- CWE-601/BadRedirectCheck
- CWE-643
- CWE-798
- javascript
- downgrades/ce4a5f401c03a70b0595e71bdc20612d82fa4e67
- extractor/tests/yaml/output/trap
- ql
- integration-tests/query-suite
- lib
- change-notes
- ext
- semmle/javascript
- frameworks
- security/dataflow
- upgrades/26a123164be893893e2aa0374d820785decf55af
- src
- Security/CWE-1427
- examples
- change-notes
- test
- Security/CWE-1427
- SystemPromptInjection
- UserPromptInjection
- library-tests
- Comments
- Directives
- java/ql
- integration-tests
- java
- buildless-erroneous
- buildless-gradle-boms
- buildless-gradle-classifiers
- buildless-gradle-timeout
- buildless-gradle
- buildless-inherit-trust-store
- buildless-maven-executable-war
- buildless-maven-existing-settings-xml
- buildless-maven-mirrorof
- buildless-maven-multimodule
- buildless-maven-timeout
- buildless-maven
- buildless-proxy-gradle
- buildless-proxy-maven
- buildless-sibling-projects
- buildless
- kotlin/all-platforms/gradle_kotlinx_serialization
- lib/semmle/code/java
- dataflow
- security
- test-kotlin1/query-tests
- AbstractToConcreteCollection
- AutoBoxing
- CloseReader
- CloseWriter
- ConfusingOverloading
- ConstantLoopCondition
- DeadCode
- DeadRefTypes
- EmptyBlock
- ExposeRepresentation
- InnerClassCouldBeStatic
- MissingInstanceofInEquals
- MissingOverrideAnnotation
- MutualDependency
- NamingConventionsRefTypes
- NonSerializableField
- NonSerializableInnerClass
- NullMaybe
- OneStatementPerLine
- PartiallyMaskedCatch
- ReturnValueIgnored
- SimplifyBoolExpr
- UnderscoreIdentifier
- UnreadLocal
- UselessNullCheck
- UselessParameter
- WhitespaceContradictsPrecedence
- test-kotlin2/query-tests
- AbstractToConcreteCollection
- AutoBoxing
- CloseReader
- CloseWriter
- ConfusingOverloading
- ConstantLoopCondition
- DeadCode
- DeadRefTypes
- EmptyBlock
- ExposeRepresentation
- InnerClassCouldBeStatic
- MissingInstanceofInEquals
- MissingOverrideAnnotation
- MutualDependency
- NamingConventionsRefTypes
- NonSerializableField
- NonSerializableInnerClass
- NullMaybe
- OneStatementPerLine
- PartiallyMaskedCatch
- ReturnValueIgnored
- SimplifyBoolExpr
- UnderscoreIdentifier
- UnreadLocal
- UselessNullCheck
- UselessParameter
- WhitespaceContradictsPrecedence
- test
- experimental/query-tests
- quantum/examples/NonceReuse
- security
- CWE-020
- CWE-073
- CWE-078
- CWE-089/src/main
- CWE-094
- CWE-200
- CWE-208
- NotConstantTimeCheckOnSignature
- TimingAttackAgainstHeader
- TimingAttackAgainstSignagure
- CWE-295
- jxbrowser-6.23.1
- jxbrowser-6.24
- CWE-297
- CWE-299
- CWE-327
- CWE-346
- CWE-347
- CWE-348
- CWE-352
- CWE-400
- CWE-470
- CWE-489
- CWE-502
- CWE-548
- CWE-555
- CWE-598
- CWE-600
- CWE-601
- CWE-625
- CWE-652
- CWE-665
- CWE-755
- CWE-759
- library-tests/frameworks/JaxWs
- query-tests
- AmbiguousOuterSuper
- AutoBoxing
- AvoidDeprecatedCallableAccess
- BadAbsOfRandom
- BadCheckOdd
- BoxedVariable
- BusyWait
- CloseResource
- CloseReader
- CloseWriter
- CompareIdenticalValues
- ComplexCondition
- ConfusingOverloading
- ConstantExpAppearsNonConstant
- ConstantLoopCondition
- ContainerSizeCmpZero
- ContinueInFalseLoop
- ContradictoryTypeChecks
- DeadCode
- DeadRefTypes
- NonAssignedFields
- Declarations
- DefineEqualsWhenAddingFields
- DoubleCheckedLocking
- EqualsArray
- EqualsUsesInstanceOf
- ExposeRepresentation
- Finally
- HashedButNoHash
- IgnoreExceptionalReturn
- ImpossibleCast
- impossible_cast
- InconsistentEqualsHashCode
- InconsistentOperations
- InefficientOutputStream
- InnerClassCouldBeStatic
- Iterable
- IteratorRemoveMayFail
- Javadoc
- LShiftLargerThanTypeWidth
- LazyInitStaticField
- Likely Bugs/Statements/MissingEnumInSwitch
- MissedTernaryOpportunity
- MissingCallToSuperClone
- MissingInstanceofInEquals
- MissingOverrideAnnotation
- MissingSpaceTypo
- MissingVoidConstructorsOnSerializable
- MutualDependency
- onepackage
- Naming
- NonPrivateField
- NonSerializableField
- NonSerializableInnerClass
- NonSynchronizedOverride
- NotifyWithoutSynch
- Nullness
- NumberFormatException
- PartiallyMaskedCatch
- PointlessForwardingMethod
- pointlessforwardingmethod
- PrintLnArray
- RandomUsedOnce
- RangeAnalysis
- ReadOnlyContainer
- ReturnValueIgnored
- return_value_ignored
- SelfAssignment
- SimplifyBoolExpr
- StartInConstructor
- StaticArray
- StringComparison
- StringFormat
- SuspiciousDateFormat
- SynchSetUnsynchGet
- TypeMismatch
- incomparable_equals
- remove_type_mismatch
- UnreadLocal
- UnreadLocal
- UnreleasedLock
- UseBraces
- UselessComparisonTest
- UselessNullCheck
- UselessUpcast
- WhitespaceContradictsPrecedence
- WriteOnlyContainer
- WrongNanComparison
- dead-code
- DeadCallable
- DeadClass
- DeadEnumConstant
- DeadField
- DeadMethod
- UselessParameter
- maven-dependencies
- my-project
- security
- CWE-020
- CWE-022/semmle/tests
- CWE-078
- CWE-079/semmle/tests
- CWE-089/semmle/examples
- CWE-090
- CWE-094
- ApkInstallationTest
- GroovyInjection
- JexlInjection
- MvelInjection
- SpelInjection
- TemplateInjection
- CWE-1104/semmle/tests
- CWE-113/semmle/tests
- CWE-129/semmle/tests
- CWE-134/semmle/tests
- CWE-190/semmle/tests
- CWE-200/semmle/tests
- TempDirLocalInformationDisclosure
- WebViewAccess
- CWE-209/semmle/tests
- CWE-297
- CWE-311
- CWE-319
- CWE-614/semmle/tests
- CWE-312/android/backup
- TestExplicitlyEnabled
- TestMissing
- CWE-327/semmle/tests
- CWE-335/semmle/tests
- CWE-338/semmle/tests
- vulnerable
- CWE-421/semmle
- CWE-601/semmle/tests
- mad
- CWE-676/semmle/tests
- CWE-681/semmle/tests
- CWE-732/semmle/tests
- CWE-807/semmle/tests
- CWE-829/semmle/tests
- CWE-833/semmle/tests
- CWE-835/semmle/tests
- python
- downgrades/b7745eb2df865c97e50b7803956a82988716e29a
- extractor/semmle
- ql
- lib
- change-notes/released
- semmle/python
- upgrades/eb5fc917c79bb23ce2de4a022f3e566d57a91be9
- src/experimental/semmle/python
- frameworks
- security/dataflow
- ql/ql
- src
- codeql_ql/ast
- test/queries
- bugs
- OrderByConst
- SumWithoutDomain
- overlay/InlineOverlayCaller
- performance
- AbstractClassImport
- MissingNoInline
- VarUnusedInDisjunct
- style
- AcronymsShouldBeCamelCase
- CouldBeCast
- DataFlowConfigModuleNaming
- DeadCode
- FieldOnlyUsedInCharPred
- ImplicitThis
- MissingParameterInQlDoc
- MissingQualityMetadata
- testcases
- MissingSecurityMetadata
- testcases
- Misspelling
- NonDocBlock
- OmittableExists
- QlRefInlineExpectations
- RedundantCast
- RedundantImport
- RedundantOverride
- SwappedParameterNames
- UseInstanceofExtension
- UseSetLiteral
- ValidatePredicateGetReturns
- ruby
- downgrades/d6f4c73dc33d28aebcffd53ba080eeecc99470f5
- ql
- lib
- change-notes
- codeql/ruby
- ast
- internal
- controlflow/internal
- dataflow/internal
- upgrades/29b7b6fc1982422368cb0a4644fd0c81f993c618
- test
- library-tests
- ast
- control
- modules
- variables
- query-tests
- experimental
- CWE-522-DecompressionBombs
- ImproperLdapAuth
- InsecureRandomness
- LdapInjection
- TemplateInjection
- XPathInjection
- cwe-022-ZipSlip
- cwe-176
- cwe-347
- cwe-502
- manually-check-http-verb
- weak-params
- performance/UseDetect
- security
- cwe-020
- IncompleteHostnameRegExp
- IncompleteUrlSubstringSanitization
- MissingFullAnchor
- impl
- MissingRegExpAnchor
- SuspiciousRegexpRange
- cwe-078
- KernelOpen
- NonConstantKernelOpen
- UnsafeShellCommandConstruction
- impl
- sub
- cwe-089
- cwe-094/UnsafeCodeConstruction
- impl
- cwe-116
- BadTagFilter
- IncompleteSanitization
- cwe-117
- app/controllers
- cwe-1333-exponential-redos
- cwe-1333-polynomial-redos
- lib
- cwe-1333-regexp-injection
- cwe-134
- cwe-209
- cwe-295
- cwe-312
- app
- controllers
- models
- cwe-327
- cwe-352
- railsapp
- app/controllers
- config
- environments
- cwe-502
- oj-global-options
- ox-global-options
- unsafe-deserialization
- cwe-506
- cwe-598
- app/controllers
- cwe-601
- cwe-611
- libxml-backend
- xxe
- cwe-732
- app/config
- cwe-798
- cwe-807-user-controlled-bypass
- cwe-912
- cwe-915
- cwe-918
- decompression-api
- rust
- downgrades/e1bce498ef78280ebe0a32b1d9d6f26c96eaf41f
- ql/lib
- upgrades/77e9a70be4b0cf5ecb1d4c1d841b2d970715a912
- swift
- ql
- integration-tests/osx/hello-xcode
- lib/utils/test/internal
- test/query-tests/Security
- CWE-020
- CWE-022/UnsafeUnpack
- CWE-079
- CWE-089
- CWE-116
- CWE-1204
- CWE-1333
- CWE-134
- CWE-259
- CWE-311
- CWE-312
- CWE-327
- CWE-328
- CWE-730
- CWE-760
- CWE-916
- tools
- unified/ql
- lib
- codeql/unified
- test/library-tests/comments
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| |||
59 | 59 | | |
60 | 60 | | |
61 | 61 | | |
62 | | - | |
63 | | - | |
64 | | - | |
65 | | - | |
66 | 62 | | |
67 | 63 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| |||
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
| 5 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1920 | 1920 | | |
1921 | 1921 | | |
1922 | 1922 | | |
| 1923 | + | |
| 1924 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
52 | 52 | | |
53 | 53 | | |
54 | 54 | | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
55 | 61 | | |
56 | 62 | | |
57 | 63 | | |
Lines changed: 6 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
5 | | - | |
6 | | - | |
7 | | - | |
8 | | - | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
9 | 11 | | |
10 | 12 | | |
11 | 13 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
| 18 | + | |
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
| |||
Lines changed: 5 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | | - | |
3 | | - | |
4 | | - | |
5 | | - | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
6 | 6 | | |
7 | 7 | | |
8 | 8 | | |
| |||
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
23 | | - | |
| 23 | + | |
Lines changed: 4 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
0 commit comments