CodeQL

CodeQL

GitHub
+
+

Related Products

  • ZeroPath
    2 Ratings
    Visit Website
  • Parasoft
    143 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • DbVisualizer
    565 Ratings
    Visit Website
  • Aikido Security
    231 Ratings
    Visit Website
  • Google Cloud BigQuery
    2,018 Ratings
    Visit Website
  • Windsurf Editor
    168 Ratings
    Visit Website
  • SoftCo AP Automation
    56 Ratings
    Visit Website
  • JetBrains Junie
    12 Ratings
    Visit Website
  • Source Defense
    7 Ratings
    Visit Website

About

Discover vulnerabilities across a codebase with CodeQL, our industry-leading semantic code analysis engine. CodeQL lets you query code as though it were data. Write a query to find all variants of a vulnerability, eradicating it forever. Then share your query to help others do the same. CodeQL is free for research and open source. Run real queries on popular open source codebases using CodeQL for Visual Studio Code. See how powerful it is to discover a bad pattern and then find similar occurrences across the entire codebase. You can create CodeQL databases yourself for any project that's under an OSI-approved open source license. GitHub CodeQL can only be used on codebases that are released under an OSI-approved open source license, to perform academic research, or to generate CodeQL databases for or during automated analysis. Download and add the project’s CodeQL database to VS Code, or create a CodeQL database using the CodeQL CLI.

About

Coverity Static Analysis is a comprehensive code scanning solution that enables developers and security teams to deliver high-quality software in compliance with security, functional safety, and industry standards. It effectively uncovers complex defects across extensive codebases, identifying and resolving code quality and security issues that span multiple files and libraries. Coverity supports compliance with a wide range of standards, including OWASP Top 10, CWE Top 25, MISRA, and CERT C/C++/Java, providing built-in reports to track and prioritize issues. With the Code Sight™ IDE plugin, developers receive real-time results, including CWE information and remediation guidance, directly within their development environment, facilitating the integration of security into the software development life cycle without compromising developer velocity.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Developers searching for a solution to find vulnerabilities across their codebase

Audience

Developers that need a powerful static analysis solution

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

GitHub
Founded: 2008
United States
codeql.github.com

Company Information

Black Duck
Founded: 2002
United States
www.blackduck.com/static-analysis-tools-sast/coverity.html

Alternatives

Alternatives

Dependabot

Dependabot

GitHub
Revenera SCA

Revenera SCA

Revenera
Klocwork

Klocwork

Perforce

Categories

Categories

Integrations

GitHub
Java
ASP.NET
C
C++
Docker
GitLab
Google Cloud Platform
Kondukto
Kubernetes
Microsoft Azure
Objective-C
Ruby
Salesforce
Swift
Travis CI
Tromzo
TypeScript
Visual Studio Code
XML

Integrations

GitHub
Java
ASP.NET
C
C++
Docker
GitLab
Google Cloud Platform
Kondukto
Kubernetes
Microsoft Azure
Objective-C
Ruby
Salesforce
Swift
Travis CI
Tromzo
TypeScript
Visual Studio Code
XML
Claim CodeQL and update features and information
Claim CodeQL and update features and information
Claim Coverity Static Analysis and update features and information
Claim Coverity Static Analysis and update features and information