CodeQL

CodeQL

GitHub
CodeSonar

CodeSonar

CodeSecure
+
+

Related Products

  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Parasoft
    125 Ratings
    Visit Website
  • Aikido Security
    71 Ratings
    Visit Website
  • Twilio
    1,291 Ratings
    Visit Website
  • Cody
    87 Ratings
    Visit Website
  • Criminal IP
    11 Ratings
    Visit Website
  • Adobe PDF Library SDK
    35 Ratings
    Visit Website
  • Appsmith
    67 Ratings
    Visit Website
  • Windsurf Editor
    137 Ratings
    Visit Website
  • Wiz
    Visit Website

About

Discover vulnerabilities across a codebase with CodeQL, our industry-leading semantic code analysis engine. CodeQL lets you query code as though it were data. Write a query to find all variants of a vulnerability, eradicating it forever. Then share your query to help others do the same. CodeQL is free for research and open source. Run real queries on popular open source codebases using CodeQL for Visual Studio Code. See how powerful it is to discover a bad pattern and then find similar occurrences across the entire codebase. You can create CodeQL databases yourself for any project that's under an OSI-approved open source license. GitHub CodeQL can only be used on codebases that are released under an OSI-approved open source license, to perform academic research, or to generate CodeQL databases for or during automated analysis. Download and add the project’s CodeQL database to VS Code, or create a CodeQL database using the CodeQL CLI.

About

CodeSonar employs a unified dataflow and symbolic execution analysis that examines the computation of the complete application. By not relying on pattern matching or similar approximations, CodeSonar's static analysis engine is extraordinarily deep, finding 3-5 times more defects on average than other static analysis tools. Unlike many software development tools, such as testing tools, compilers, configuration management, etc., SAST tools can be integrated into a team's development process at any time with ease. SAST technologies like CodeSonar simply attach to your existing build environments to add analysis information to your verification process. Like a compiler, CodeSonar does a build of your code using your existing build environment, but instead of creating object code, CodeSonar creates an abstract model of your entire program. From the derived model, CodeSonar’s symbolic execution engine explores program paths, reasoning about program variables and how they relate.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Developers searching for a solution to find vulnerabilities across their codebase

Audience

Development teams interested in a Static Application Security Testing (SAST) solution

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

GitHub
Founded: 2008
United States
codeql.github.com

Company Information

CodeSecure
United States
www.grammatech.com/products/source-code-analysis

Alternatives

Dependabot

Dependabot

GitHub

Alternatives

Flawnter

Flawnter

CyberTest
SonarQube Server

SonarQube Server

SonarSource
Jtest

Jtest

Parasoft

Categories

Categories

Integrations

GitHub
Java
Visual Studio Code
AWS GovCloud
Android
C#
C++
CodeSentry
Docker
Eclipse IDE
Go
JavaScript
Jira
Kotlin
Python
Qlik Sense
Rust
Seeker
TypeScript
Visual Studio

Integrations

GitHub
Java
Visual Studio Code
AWS GovCloud
Android
C#
C++
CodeSentry
Docker
Eclipse IDE
Go
JavaScript
Jira
Kotlin
Python
Qlik Sense
Rust
Seeker
TypeScript
Visual Studio
Claim CodeQL and update features and information
Claim CodeQL and update features and information
Claim CodeSonar and update features and information
Claim CodeSonar and update features and information