├── README.md ├── action.yml ├── go-debug-pack ├── dependencies.ql ├── generate.sh ├── noresults.ql ├── qlpack.yml ├── queries.xml ├── source-and-sink-counts.qls ├── source-and-sink-counts │ ├── go__allocation_size_overflow │ │ └── query.ql │ ├── go__bad_redirect_check │ │ └── query.ql │ ├── go__clear_text_logging │ │ └── query.ql │ ├── go__command_injection │ │ └── query.ql │ ├── go__constant_oauth2_state │ │ └── query.ql │ ├── go__email_injection │ │ ├── EmailInjection.qll │ │ ├── EmailInjectionCustomizations.qll │ │ └── query.ql │ ├── go__incomplete_hostname_regexp │ │ └── query.ql │ ├── go__incorrect_integer_conversion │ │ └── query.ql │ ├── go__insecure_hostkeycallback │ │ └── query.ql │ ├── go__insecure_randomness │ │ └── query.ql │ ├── go__insecure_tls │ │ └── query.ql │ ├── go__path_injection │ │ └── query.ql │ ├── go__reflected_xss │ │ └── query.ql │ ├── go__request_forgery │ │ └── query.ql │ ├── go__sql_injection │ │ └── query.ql │ ├── go__stack_trace_exposure │ │ └── query.ql │ ├── go__stored_command │ │ └── query.ql │ ├── go__stored_xss │ │ └── query.ql │ ├── go__suspicious_character_in_regex │ │ └── query.ql │ ├── go__unsafe_quoting │ │ └── query.ql │ ├── go__unsafe_unzip_symlink │ │ └── query.ql │ ├── go__untrusted_data_to_external_api │ │ └── query.ql │ ├── go__untrusted_data_to_unknown_external_api │ │ └── query.ql │ ├── go__unvalidated_url_redirection │ │ └── query.ql │ ├── go__xml__xpath_injection │ │ └── query.ql │ └── go__zipslip │ │ └── query.ql ├── sources-and-sinks.qls └── sources-and-sinks │ ├── go__allocation_size_overflow │ └── query.ql │ ├── go__bad_redirect_check │ └── query.ql │ ├── go__clear_text_logging │ └── query.ql │ ├── go__command_injection │ └── query.ql │ ├── go__constant_oauth2_state │ └── query.ql │ ├── go__email_injection │ ├── EmailInjection.qll │ ├── EmailInjectionCustomizations.qll │ └── query.ql │ ├── go__incomplete_hostname_regexp │ └── query.ql │ ├── go__incorrect_integer_conversion │ └── query.ql │ ├── go__insecure_hostkeycallback │ └── query.ql │ ├── go__insecure_randomness │ └── query.ql │ ├── go__insecure_tls │ └── query.ql │ ├── go__path_injection │ └── query.ql │ ├── go__reflected_xss │ └── query.ql │ ├── go__request_forgery │ └── query.ql │ ├── go__sql_injection │ └── query.ql │ ├── go__stack_trace_exposure │ └── query.ql │ ├── go__stored_command │ └── query.ql │ ├── go__stored_xss │ └── query.ql │ ├── go__suspicious_character_in_regex │ └── query.ql │ ├── go__unsafe_quoting │ └── query.ql │ ├── go__unsafe_unzip_symlink │ └── query.ql │ ├── go__untrusted_data_to_external_api │ └── query.ql │ ├── go__untrusted_data_to_unknown_external_api │ └── query.ql │ ├── go__unvalidated_url_redirection │ └── query.ql │ ├── go__xml__xpath_injection │ └── query.ql │ └── go__zipslip │ └── query.ql ├── java-debug-pack ├── dependencies.ql ├── generate.sh ├── noresults.ql ├── qlpack.yml ├── queries.xml ├── source-and-sink-counts.qls ├── source-and-sink-counts │ ├── java__command_line_injection_local │ │ ├── ExecCommon.qll │ │ └── query.ql │ ├── java__extreme_value_arithmetic │ │ ├── ArithmeticCommon.qll │ │ └── query.ql │ ├── java__hardcoded_credential_api_call │ │ ├── HardcodedCredentials.qll │ │ ├── SensitiveApi.qll │ │ └── query.ql │ ├── java__hardcoded_credential_sensitive_call │ │ ├── HardcodedCredentials.qll │ │ ├── SensitiveApi.qll │ │ └── query.ql │ ├── java__http_response_splitting │ │ └── query.ql │ ├── java__http_response_splitting_local │ │ └── query.ql │ ├── java__improper_validation_of_array_construction │ │ ├── ArraySizing.qll │ │ ├── BoundingChecks.qll │ │ └── query.ql │ ├── java__improper_validation_of_array_construction_code_specified │ │ ├── ArraySizing.qll │ │ ├── BoundingChecks.qll │ │ └── query.ql │ ├── java__improper_validation_of_array_construction_local │ │ ├── ArraySizing.qll │ │ ├── BoundingChecks.qll │ │ └── query.ql │ ├── java__improper_validation_of_array_index │ │ ├── ArraySizing.qll │ │ ├── BoundingChecks.qll │ │ └── query.ql │ ├── java__improper_validation_of_array_index_code_specified │ │ ├── ArraySizing.qll │ │ ├── BoundingChecks.qll │ │ └── query.ql │ ├── java__improper_validation_of_array_index_local │ │ ├── ArraySizing.qll │ │ ├── BoundingChecks.qll │ │ └── query.ql │ ├── java__insecure_bean_validation │ │ └── query.ql │ ├── java__ldap_injection │ │ ├── LdapInjectionLib.qll │ │ └── query.ql │ ├── java__non_https_url │ │ └── query.ql │ ├── java__path_injection │ │ ├── TaintedPathCommon.qll │ │ └── query.ql │ ├── java__path_injection_local │ │ ├── TaintedPathCommon.qll │ │ └── query.ql │ ├── java__potentially_weak_cryptographic_algorithm │ │ └── query.ql │ ├── java__sql_injection_local │ │ ├── SqlInjectionLib.qll │ │ └── query.ql │ ├── java__tainted_arithmetic │ │ ├── ArithmeticCommon.qll │ │ └── query.ql │ ├── java__tainted_arithmetic_local │ │ ├── ArithmeticCommon.qll │ │ └── query.ql │ ├── java__tainted_format_string │ │ └── query.ql │ ├── java__tainted_format_string_local │ │ └── query.ql │ ├── java__tainted_numeric_cast │ │ ├── NumericCastCommon.qll │ │ └── query.ql │ ├── java__tainted_numeric_cast_local │ │ ├── NumericCastCommon.qll │ │ └── query.ql │ ├── java__tainted_permissions_check │ │ └── query.ql │ ├── java__uncontrolled_arithmetic │ │ ├── ArithmeticCommon.qll │ │ └── query.ql │ ├── java__unsafe_deserialization │ │ └── query.ql │ ├── java__unsafe_hostname_verification │ │ └── query.ql │ ├── java__untrusted_data_to_external_api │ │ └── query.ql │ ├── java__unvalidated_url_redirection │ │ └── query.ql │ ├── java__unvalidated_url_redirection_local │ │ └── query.ql │ ├── java__user_controlled_bypass │ │ └── query.ql │ ├── java__weak_cryptographic_algorithm │ │ └── query.ql │ ├── java__xss │ │ └── query.ql │ ├── java__xss_local │ │ └── query.ql │ ├── java__xxe │ │ └── query.ql │ └── java__zipslip │ │ ├── TaintedPathCommon.qll │ │ └── query.ql ├── sources-and-sinks.qls └── sources-and-sinks │ ├── java__command_line_injection_local │ ├── ExecCommon.qll │ └── query.ql │ ├── java__extreme_value_arithmetic │ ├── ArithmeticCommon.qll │ └── query.ql │ ├── java__hardcoded_credential_api_call │ ├── HardcodedCredentials.qll │ ├── SensitiveApi.qll │ └── query.ql │ ├── java__hardcoded_credential_sensitive_call │ ├── HardcodedCredentials.qll │ ├── SensitiveApi.qll │ └── query.ql │ ├── java__http_response_splitting │ └── query.ql │ ├── java__http_response_splitting_local │ └── query.ql │ ├── java__improper_validation_of_array_construction │ ├── ArraySizing.qll │ ├── BoundingChecks.qll │ └── query.ql │ ├── java__improper_validation_of_array_construction_code_specified │ ├── ArraySizing.qll │ ├── BoundingChecks.qll │ └── query.ql │ ├── java__improper_validation_of_array_construction_local │ ├── ArraySizing.qll │ ├── BoundingChecks.qll │ └── query.ql │ ├── java__improper_validation_of_array_index │ ├── ArraySizing.qll │ ├── BoundingChecks.qll │ └── query.ql │ ├── java__improper_validation_of_array_index_code_specified │ ├── ArraySizing.qll │ ├── BoundingChecks.qll │ └── query.ql │ ├── java__improper_validation_of_array_index_local │ ├── ArraySizing.qll │ ├── BoundingChecks.qll │ └── query.ql │ ├── java__insecure_bean_validation │ └── query.ql │ ├── java__ldap_injection │ ├── LdapInjectionLib.qll │ └── query.ql │ ├── java__non_https_url │ └── query.ql │ ├── java__path_injection │ ├── TaintedPathCommon.qll │ └── query.ql │ ├── java__path_injection_local │ ├── TaintedPathCommon.qll │ └── query.ql │ ├── java__potentially_weak_cryptographic_algorithm │ └── query.ql │ ├── java__sql_injection_local │ ├── SqlInjectionLib.qll │ └── query.ql │ ├── java__tainted_arithmetic │ ├── ArithmeticCommon.qll │ └── query.ql │ ├── java__tainted_arithmetic_local │ ├── ArithmeticCommon.qll │ └── query.ql │ ├── java__tainted_format_string │ └── query.ql │ ├── java__tainted_format_string_local │ └── query.ql │ ├── java__tainted_numeric_cast │ ├── NumericCastCommon.qll │ └── query.ql │ ├── java__tainted_numeric_cast_local │ ├── NumericCastCommon.qll │ └── query.ql │ ├── java__tainted_permissions_check │ └── query.ql │ ├── java__uncontrolled_arithmetic │ ├── ArithmeticCommon.qll │ └── query.ql │ ├── java__unsafe_deserialization │ └── query.ql │ ├── java__unsafe_hostname_verification │ └── query.ql │ ├── java__untrusted_data_to_external_api │ └── query.ql │ ├── java__unvalidated_url_redirection │ └── query.ql │ ├── java__unvalidated_url_redirection_local │ └── query.ql │ ├── java__user_controlled_bypass │ └── query.ql │ ├── java__weak_cryptographic_algorithm │ └── query.ql │ ├── java__xss │ └── query.ql │ ├── java__xss_local │ └── query.ql │ ├── java__xxe │ └── query.ql │ └── java__zipslip │ ├── TaintedPathCommon.qll │ └── query.ql ├── javascript-debug-pack ├── dependencies.ql ├── generate.sh ├── noresults.ql ├── qlpack.yml ├── queries.xml ├── source-and-sink-counts.qls ├── source-and-sink-counts │ ├── js__bad_code_sanitization │ │ └── query.ql │ ├── js__build_artifact_leak │ │ └── query.ql │ ├── js__clear_text_logging │ │ └── query.ql │ ├── js__clear_text_storage_of_sensitive_data │ │ └── query.ql │ ├── js__client_side_unvalidated_url_redirection │ │ └── query.ql │ ├── js__code_injection │ │ └── query.ql │ ├── js__command_line_injection │ │ └── query.ql │ ├── js__cors_misconfiguration_for_credentials │ │ └── query.ql │ ├── js__cross_window_information_leak │ │ └── query.ql │ ├── js__file_access_to_http │ │ └── query.ql │ ├── js__hardcoded_credentials │ │ └── query.ql │ ├── js__hardcoded_data_interpreted_as_code │ │ └── query.ql │ ├── js__host_header_forgery_in_email_generation │ │ └── query.ql │ ├── js__http_to_file_access │ │ └── query.ql │ ├── js__incomplete_html_attribute_sanitization │ │ └── query.ql │ ├── js__indirect_command_line_injection │ │ └── query.ql │ ├── js__insecure_download │ │ └── query.ql │ ├── js__insecure_randomness │ │ └── query.ql │ ├── js__insufficient_password_hash │ │ └── query.ql │ ├── js__log_injection │ │ └── query.ql │ ├── js__loop_bound_injection │ │ └── query.ql │ ├── js__path_injection │ │ └── query.ql │ ├── js__prototype_polluting_assignment │ │ └── query.ql │ ├── js__prototype_pollution │ │ └── query.ql │ ├── js__prototype_pollution_utility │ │ └── query.ql │ ├── js__reflected_xss │ │ └── query.ql │ ├── js__regex_injection │ │ └── query.ql │ ├── js__remote_property_injection │ │ └── query.ql │ ├── js__request_forgery │ │ └── query.ql │ ├── js__server_side_unvalidated_url_redirection │ │ └── query.ql │ ├── js__shell_command_constructed_from_input │ │ └── query.ql │ ├── js__shell_command_injection_from_environment │ │ └── query.ql │ ├── js__sql_injection │ │ └── query.ql │ ├── js__stack_trace_exposure │ │ └── query.ql │ ├── js__stored_xss │ │ └── query.ql │ ├── js__tainted_format_string │ │ └── query.ql │ ├── js__type_confusion_through_parameter_tampering │ │ └── query.ql │ ├── js__unsafe_deserialization │ │ └── query.ql │ ├── js__unsafe_dynamic_method_access │ │ └── query.ql │ ├── js__unsafe_jquery_plugin │ │ └── query.ql │ ├── js__untrusted_data_to_external_api │ │ ├── HostnameRegexpShared.qll │ │ └── query.ql │ ├── js__unvalidated_dynamic_method_call │ │ └── query.ql │ ├── js__weak_cryptographic_algorithm │ │ └── query.ql │ ├── js__xml_bomb │ │ └── query.ql │ ├── js__xpath_injection │ │ └── query.ql │ ├── js__xss │ │ └── query.ql │ ├── js__xss_through_dom │ │ └── query.ql │ ├── js__xss_through_exception │ │ └── query.ql │ ├── js__xxe │ │ └── query.ql │ └── js__zipslip │ │ └── query.ql ├── sources-and-sinks.qls └── sources-and-sinks │ ├── js__bad_code_sanitization │ └── query.ql │ ├── js__build_artifact_leak │ └── query.ql │ ├── js__clear_text_logging │ └── query.ql │ ├── js__clear_text_storage_of_sensitive_data │ └── query.ql │ ├── js__client_side_unvalidated_url_redirection │ └── query.ql │ ├── js__code_injection │ └── query.ql │ ├── js__command_line_injection │ └── query.ql │ ├── js__cors_misconfiguration_for_credentials │ └── query.ql │ ├── js__cross_window_information_leak │ └── query.ql │ ├── js__file_access_to_http │ └── query.ql │ ├── js__hardcoded_credentials │ └── query.ql │ ├── js__hardcoded_data_interpreted_as_code │ └── query.ql │ ├── js__host_header_forgery_in_email_generation │ └── query.ql │ ├── js__http_to_file_access │ └── query.ql │ ├── js__incomplete_html_attribute_sanitization │ └── query.ql │ ├── js__indirect_command_line_injection │ └── query.ql │ ├── js__insecure_download │ └── query.ql │ ├── js__insecure_randomness │ └── query.ql │ ├── js__insufficient_password_hash │ └── query.ql │ ├── js__log_injection │ └── query.ql │ ├── js__loop_bound_injection │ └── query.ql │ ├── js__path_injection │ └── query.ql │ ├── js__prototype_polluting_assignment │ └── query.ql │ ├── js__prototype_pollution │ └── query.ql │ ├── js__prototype_pollution_utility │ └── query.ql │ ├── js__reflected_xss │ └── query.ql │ ├── js__regex_injection │ └── query.ql │ ├── js__remote_property_injection │ └── query.ql │ ├── js__request_forgery │ └── query.ql │ ├── js__server_side_unvalidated_url_redirection │ └── query.ql │ ├── js__shell_command_constructed_from_input │ └── query.ql │ ├── js__shell_command_injection_from_environment │ └── query.ql │ ├── js__sql_injection │ └── query.ql │ ├── js__stack_trace_exposure │ └── query.ql │ ├── js__stored_xss │ └── query.ql │ ├── js__tainted_format_string │ └── query.ql │ ├── js__type_confusion_through_parameter_tampering │ └── query.ql │ ├── js__unsafe_deserialization │ └── query.ql │ ├── js__unsafe_dynamic_method_access │ └── query.ql │ ├── js__unsafe_jquery_plugin │ └── query.ql │ ├── js__untrusted_data_to_external_api │ ├── HostnameRegexpShared.qll │ └── query.ql │ ├── js__unvalidated_dynamic_method_call │ └── query.ql │ ├── js__weak_cryptographic_algorithm │ └── query.ql │ ├── js__xml_bomb │ └── query.ql │ ├── js__xpath_injection │ └── query.ql │ ├── js__xss │ └── query.ql │ ├── js__xss_through_dom │ └── query.ql │ ├── js__xss_through_exception │ └── query.ql │ ├── js__xxe │ └── query.ql │ └── js__zipslip │ └── query.ql ├── process.py └── query-generator └── generate /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/README.md -------------------------------------------------------------------------------- /action.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/action.yml -------------------------------------------------------------------------------- /go-debug-pack/dependencies.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/dependencies.ql -------------------------------------------------------------------------------- /go-debug-pack/generate.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/generate.sh -------------------------------------------------------------------------------- /go-debug-pack/noresults.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/noresults.ql -------------------------------------------------------------------------------- /go-debug-pack/qlpack.yml: -------------------------------------------------------------------------------- 1 | name: go-debug-pack 2 | version: 1.0.0 3 | libraryPathDependencies: codeql-go 4 | -------------------------------------------------------------------------------- /go-debug-pack/queries.xml: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts.qls: -------------------------------------------------------------------------------- 1 | - queries: source-and-sink-counts 2 | -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__allocation_size_overflow/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__allocation_size_overflow/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__bad_redirect_check/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__bad_redirect_check/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__clear_text_logging/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__clear_text_logging/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__command_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__command_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__constant_oauth2_state/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__constant_oauth2_state/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__email_injection/EmailInjection.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__email_injection/EmailInjection.qll -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__email_injection/EmailInjectionCustomizations.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__email_injection/EmailInjectionCustomizations.qll -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__email_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__email_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__incomplete_hostname_regexp/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__incomplete_hostname_regexp/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__incorrect_integer_conversion/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__incorrect_integer_conversion/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__insecure_hostkeycallback/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__insecure_hostkeycallback/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__insecure_randomness/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__insecure_randomness/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__insecure_tls/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__insecure_tls/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__path_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__path_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__reflected_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__reflected_xss/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__request_forgery/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__request_forgery/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__sql_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__sql_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__stack_trace_exposure/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__stack_trace_exposure/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__stored_command/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__stored_command/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__stored_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__stored_xss/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__suspicious_character_in_regex/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__suspicious_character_in_regex/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__unsafe_quoting/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__unsafe_quoting/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__unsafe_unzip_symlink/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__unsafe_unzip_symlink/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__untrusted_data_to_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__untrusted_data_to_external_api/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__untrusted_data_to_unknown_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__untrusted_data_to_unknown_external_api/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__xml__xpath_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__xml__xpath_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/source-and-sink-counts/go__zipslip/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/source-and-sink-counts/go__zipslip/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks.qls: -------------------------------------------------------------------------------- 1 | - queries: sources-and-sinks 2 | -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__allocation_size_overflow/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__allocation_size_overflow/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__bad_redirect_check/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__bad_redirect_check/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__clear_text_logging/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__clear_text_logging/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__command_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__command_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__constant_oauth2_state/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__constant_oauth2_state/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__email_injection/EmailInjection.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__email_injection/EmailInjection.qll -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__email_injection/EmailInjectionCustomizations.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__email_injection/EmailInjectionCustomizations.qll -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__email_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__email_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__incomplete_hostname_regexp/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__incomplete_hostname_regexp/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__incorrect_integer_conversion/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__incorrect_integer_conversion/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__insecure_hostkeycallback/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__insecure_hostkeycallback/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__insecure_randomness/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__insecure_randomness/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__insecure_tls/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__insecure_tls/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__path_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__path_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__reflected_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__reflected_xss/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__request_forgery/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__request_forgery/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__sql_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__sql_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__stack_trace_exposure/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__stack_trace_exposure/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__stored_command/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__stored_command/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__stored_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__stored_xss/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__suspicious_character_in_regex/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__suspicious_character_in_regex/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__unsafe_quoting/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__unsafe_quoting/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__unsafe_unzip_symlink/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__unsafe_unzip_symlink/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__untrusted_data_to_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__untrusted_data_to_external_api/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__untrusted_data_to_unknown_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__untrusted_data_to_unknown_external_api/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__xml__xpath_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__xml__xpath_injection/query.ql -------------------------------------------------------------------------------- /go-debug-pack/sources-and-sinks/go__zipslip/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/go-debug-pack/sources-and-sinks/go__zipslip/query.ql -------------------------------------------------------------------------------- /java-debug-pack/dependencies.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/dependencies.ql -------------------------------------------------------------------------------- /java-debug-pack/generate.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/generate.sh -------------------------------------------------------------------------------- /java-debug-pack/noresults.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/noresults.ql -------------------------------------------------------------------------------- /java-debug-pack/qlpack.yml: -------------------------------------------------------------------------------- 1 | name: java-debug-pack 2 | version: 1.0.0 3 | libraryPathDependencies: codeql-java 4 | -------------------------------------------------------------------------------- /java-debug-pack/queries.xml: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts.qls: -------------------------------------------------------------------------------- 1 | - queries: source-and-sink-counts 2 | -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__command_line_injection_local/ExecCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__command_line_injection_local/ExecCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__command_line_injection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__command_line_injection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__extreme_value_arithmetic/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__extreme_value_arithmetic/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__extreme_value_arithmetic/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__extreme_value_arithmetic/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__hardcoded_credential_api_call/HardcodedCredentials.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__hardcoded_credential_api_call/HardcodedCredentials.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__hardcoded_credential_api_call/SensitiveApi.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__hardcoded_credential_api_call/SensitiveApi.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__hardcoded_credential_api_call/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__hardcoded_credential_api_call/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__hardcoded_credential_sensitive_call/HardcodedCredentials.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__hardcoded_credential_sensitive_call/HardcodedCredentials.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__hardcoded_credential_sensitive_call/SensitiveApi.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__hardcoded_credential_sensitive_call/SensitiveApi.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__hardcoded_credential_sensitive_call/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__hardcoded_credential_sensitive_call/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__http_response_splitting/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__http_response_splitting/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__http_response_splitting_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__http_response_splitting_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_code_specified/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_code_specified/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_code_specified/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_code_specified/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_code_specified/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_code_specified/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_local/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_local/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_local/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_local/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_construction_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_code_specified/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_code_specified/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_code_specified/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_code_specified/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_code_specified/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_code_specified/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_local/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_local/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_local/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_local/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__improper_validation_of_array_index_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__insecure_bean_validation/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__insecure_bean_validation/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__ldap_injection/LdapInjectionLib.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__ldap_injection/LdapInjectionLib.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__ldap_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__ldap_injection/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__non_https_url/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__non_https_url/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__path_injection/TaintedPathCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__path_injection/TaintedPathCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__path_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__path_injection/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__path_injection_local/TaintedPathCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__path_injection_local/TaintedPathCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__path_injection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__path_injection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__potentially_weak_cryptographic_algorithm/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__potentially_weak_cryptographic_algorithm/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__sql_injection_local/SqlInjectionLib.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__sql_injection_local/SqlInjectionLib.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__sql_injection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__sql_injection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_arithmetic/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_arithmetic/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_arithmetic/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_arithmetic/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_arithmetic_local/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_arithmetic_local/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_arithmetic_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_arithmetic_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_format_string/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_format_string/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_format_string_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_format_string_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast/NumericCastCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast/NumericCastCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast_local/NumericCastCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast_local/NumericCastCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_numeric_cast_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__tainted_permissions_check/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__tainted_permissions_check/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__uncontrolled_arithmetic/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__uncontrolled_arithmetic/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__uncontrolled_arithmetic/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__uncontrolled_arithmetic/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__unsafe_deserialization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__unsafe_deserialization/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__unsafe_hostname_verification/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__unsafe_hostname_verification/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__untrusted_data_to_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__untrusted_data_to_external_api/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__unvalidated_url_redirection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__unvalidated_url_redirection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__user_controlled_bypass/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__user_controlled_bypass/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__weak_cryptographic_algorithm/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__weak_cryptographic_algorithm/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__xss/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__xss_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__xss_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__xxe/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__xxe/query.ql -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__zipslip/TaintedPathCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__zipslip/TaintedPathCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/source-and-sink-counts/java__zipslip/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/source-and-sink-counts/java__zipslip/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks.qls: -------------------------------------------------------------------------------- 1 | - queries: sources-and-sinks 2 | -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__command_line_injection_local/ExecCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__command_line_injection_local/ExecCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__command_line_injection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__command_line_injection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__extreme_value_arithmetic/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__extreme_value_arithmetic/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__extreme_value_arithmetic/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__extreme_value_arithmetic/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__hardcoded_credential_api_call/HardcodedCredentials.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__hardcoded_credential_api_call/HardcodedCredentials.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__hardcoded_credential_api_call/SensitiveApi.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__hardcoded_credential_api_call/SensitiveApi.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__hardcoded_credential_api_call/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__hardcoded_credential_api_call/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__hardcoded_credential_sensitive_call/HardcodedCredentials.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__hardcoded_credential_sensitive_call/HardcodedCredentials.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__hardcoded_credential_sensitive_call/SensitiveApi.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__hardcoded_credential_sensitive_call/SensitiveApi.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__hardcoded_credential_sensitive_call/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__hardcoded_credential_sensitive_call/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__http_response_splitting/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__http_response_splitting/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__http_response_splitting_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__http_response_splitting_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_code_specified/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_code_specified/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_code_specified/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_code_specified/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_code_specified/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_code_specified/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_local/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_local/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_local/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_local/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_construction_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_code_specified/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_code_specified/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_code_specified/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_code_specified/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_code_specified/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_code_specified/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_local/ArraySizing.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_local/ArraySizing.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_local/BoundingChecks.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_local/BoundingChecks.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__improper_validation_of_array_index_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__insecure_bean_validation/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__insecure_bean_validation/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__ldap_injection/LdapInjectionLib.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__ldap_injection/LdapInjectionLib.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__ldap_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__ldap_injection/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__non_https_url/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__non_https_url/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__path_injection/TaintedPathCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__path_injection/TaintedPathCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__path_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__path_injection/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__path_injection_local/TaintedPathCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__path_injection_local/TaintedPathCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__path_injection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__path_injection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__potentially_weak_cryptographic_algorithm/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__potentially_weak_cryptographic_algorithm/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__sql_injection_local/SqlInjectionLib.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__sql_injection_local/SqlInjectionLib.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__sql_injection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__sql_injection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_arithmetic/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_arithmetic/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_arithmetic/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_arithmetic/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_arithmetic_local/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_arithmetic_local/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_arithmetic_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_arithmetic_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_format_string/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_format_string/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_format_string_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_format_string_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_numeric_cast/NumericCastCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_numeric_cast/NumericCastCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_numeric_cast/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_numeric_cast/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_numeric_cast_local/NumericCastCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_numeric_cast_local/NumericCastCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_numeric_cast_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_numeric_cast_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__tainted_permissions_check/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__tainted_permissions_check/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__uncontrolled_arithmetic/ArithmeticCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__uncontrolled_arithmetic/ArithmeticCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__uncontrolled_arithmetic/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__uncontrolled_arithmetic/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__unsafe_deserialization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__unsafe_deserialization/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__unsafe_hostname_verification/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__unsafe_hostname_verification/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__untrusted_data_to_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__untrusted_data_to_external_api/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__unvalidated_url_redirection_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__unvalidated_url_redirection_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__user_controlled_bypass/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__user_controlled_bypass/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__weak_cryptographic_algorithm/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__weak_cryptographic_algorithm/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__xss/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__xss_local/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__xss_local/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__xxe/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__xxe/query.ql -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__zipslip/TaintedPathCommon.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__zipslip/TaintedPathCommon.qll -------------------------------------------------------------------------------- /java-debug-pack/sources-and-sinks/java__zipslip/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/java-debug-pack/sources-and-sinks/java__zipslip/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/dependencies.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/dependencies.ql -------------------------------------------------------------------------------- /javascript-debug-pack/generate.sh: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/generate.sh -------------------------------------------------------------------------------- /javascript-debug-pack/noresults.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/noresults.ql -------------------------------------------------------------------------------- /javascript-debug-pack/qlpack.yml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/qlpack.yml -------------------------------------------------------------------------------- /javascript-debug-pack/queries.xml: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts.qls: -------------------------------------------------------------------------------- 1 | - queries: source-and-sink-counts 2 | -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__bad_code_sanitization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__bad_code_sanitization/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__build_artifact_leak/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__build_artifact_leak/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__clear_text_logging/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__clear_text_logging/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__clear_text_storage_of_sensitive_data/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__clear_text_storage_of_sensitive_data/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__client_side_unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__client_side_unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__code_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__code_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__command_line_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__command_line_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__cors_misconfiguration_for_credentials/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__cors_misconfiguration_for_credentials/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__cross_window_information_leak/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__cross_window_information_leak/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__file_access_to_http/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__file_access_to_http/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__hardcoded_credentials/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__hardcoded_credentials/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__hardcoded_data_interpreted_as_code/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__hardcoded_data_interpreted_as_code/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__host_header_forgery_in_email_generation/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__host_header_forgery_in_email_generation/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__http_to_file_access/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__http_to_file_access/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__incomplete_html_attribute_sanitization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__incomplete_html_attribute_sanitization/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__indirect_command_line_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__indirect_command_line_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__insecure_download/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__insecure_download/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__insecure_randomness/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__insecure_randomness/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__insufficient_password_hash/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__insufficient_password_hash/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__log_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__log_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__loop_bound_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__loop_bound_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__path_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__path_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__prototype_polluting_assignment/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__prototype_polluting_assignment/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__prototype_pollution/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__prototype_pollution/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__prototype_pollution_utility/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__prototype_pollution_utility/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__reflected_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__reflected_xss/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__regex_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__regex_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__remote_property_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__remote_property_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__request_forgery/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__request_forgery/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__server_side_unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__server_side_unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__shell_command_constructed_from_input/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__shell_command_constructed_from_input/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__shell_command_injection_from_environment/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__shell_command_injection_from_environment/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__sql_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__sql_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__stack_trace_exposure/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__stack_trace_exposure/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__stored_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__stored_xss/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__tainted_format_string/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__tainted_format_string/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__type_confusion_through_parameter_tampering/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__type_confusion_through_parameter_tampering/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__unsafe_deserialization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__unsafe_deserialization/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__unsafe_dynamic_method_access/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__unsafe_dynamic_method_access/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__unsafe_jquery_plugin/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__unsafe_jquery_plugin/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__untrusted_data_to_external_api/HostnameRegexpShared.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__untrusted_data_to_external_api/HostnameRegexpShared.qll -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__untrusted_data_to_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__untrusted_data_to_external_api/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__unvalidated_dynamic_method_call/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__unvalidated_dynamic_method_call/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__weak_cryptographic_algorithm/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__weak_cryptographic_algorithm/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__xml_bomb/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__xml_bomb/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__xpath_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__xpath_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__xss/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__xss_through_dom/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__xss_through_dom/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__xss_through_exception/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__xss_through_exception/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__xxe/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__xxe/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/source-and-sink-counts/js__zipslip/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/source-and-sink-counts/js__zipslip/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks.qls: -------------------------------------------------------------------------------- 1 | - queries: sources-and-sinks 2 | -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__bad_code_sanitization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__bad_code_sanitization/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__build_artifact_leak/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__build_artifact_leak/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__clear_text_logging/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__clear_text_logging/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__clear_text_storage_of_sensitive_data/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__clear_text_storage_of_sensitive_data/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__client_side_unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__client_side_unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__code_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__code_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__command_line_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__command_line_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__cors_misconfiguration_for_credentials/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__cors_misconfiguration_for_credentials/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__cross_window_information_leak/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__cross_window_information_leak/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__file_access_to_http/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__file_access_to_http/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__hardcoded_credentials/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__hardcoded_credentials/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__hardcoded_data_interpreted_as_code/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__hardcoded_data_interpreted_as_code/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__host_header_forgery_in_email_generation/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__host_header_forgery_in_email_generation/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__http_to_file_access/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__http_to_file_access/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__incomplete_html_attribute_sanitization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__incomplete_html_attribute_sanitization/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__indirect_command_line_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__indirect_command_line_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__insecure_download/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__insecure_download/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__insecure_randomness/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__insecure_randomness/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__insufficient_password_hash/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__insufficient_password_hash/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__log_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__log_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__loop_bound_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__loop_bound_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__path_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__path_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__prototype_polluting_assignment/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__prototype_polluting_assignment/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__prototype_pollution/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__prototype_pollution/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__prototype_pollution_utility/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__prototype_pollution_utility/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__reflected_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__reflected_xss/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__regex_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__regex_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__remote_property_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__remote_property_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__request_forgery/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__request_forgery/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__server_side_unvalidated_url_redirection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__server_side_unvalidated_url_redirection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__shell_command_constructed_from_input/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__shell_command_constructed_from_input/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__shell_command_injection_from_environment/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__shell_command_injection_from_environment/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__sql_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__sql_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__stack_trace_exposure/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__stack_trace_exposure/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__stored_xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__stored_xss/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__tainted_format_string/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__tainted_format_string/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__type_confusion_through_parameter_tampering/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__type_confusion_through_parameter_tampering/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__unsafe_deserialization/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__unsafe_deserialization/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__unsafe_dynamic_method_access/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__unsafe_dynamic_method_access/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__unsafe_jquery_plugin/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__unsafe_jquery_plugin/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__untrusted_data_to_external_api/HostnameRegexpShared.qll: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__untrusted_data_to_external_api/HostnameRegexpShared.qll -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__untrusted_data_to_external_api/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__untrusted_data_to_external_api/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__unvalidated_dynamic_method_call/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__unvalidated_dynamic_method_call/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__weak_cryptographic_algorithm/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__weak_cryptographic_algorithm/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__xml_bomb/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__xml_bomb/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__xpath_injection/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__xpath_injection/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__xss/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__xss/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__xss_through_dom/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__xss_through_dom/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__xss_through_exception/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__xss_through_exception/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__xxe/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__xxe/query.ql -------------------------------------------------------------------------------- /javascript-debug-pack/sources-and-sinks/js__zipslip/query.ql: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/javascript-debug-pack/sources-and-sinks/js__zipslip/query.ql -------------------------------------------------------------------------------- /process.py: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/process.py -------------------------------------------------------------------------------- /query-generator/generate: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/zbazztian/codeql-debug/HEAD/query-generator/generate --------------------------------------------------------------------------------