CodeQL

CodeQL

GitHub
+
+

Related Products

  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Parasoft
    127 Ratings
    Visit Website
  • Aikido Security
    100 Ratings
    Visit Website
  • Twilio
    1,301 Ratings
    Visit Website
  • Criminal IP
    12 Ratings
    Visit Website
  • Windsurf Editor
    141 Ratings
    Visit Website
  • Wiz
    1,051 Ratings
    Visit Website
  • Adobe PDF Library SDK
    35 Ratings
    Visit Website
  • AnalyticsCreator
    46 Ratings
    Visit Website
  • Vertex AI
    726 Ratings
    Visit Website

About

Discover vulnerabilities across a codebase with CodeQL, our industry-leading semantic code analysis engine. CodeQL lets you query code as though it were data. Write a query to find all variants of a vulnerability, eradicating it forever. Then share your query to help others do the same. CodeQL is free for research and open source. Run real queries on popular open source codebases using CodeQL for Visual Studio Code. See how powerful it is to discover a bad pattern and then find similar occurrences across the entire codebase. You can create CodeQL databases yourself for any project that's under an OSI-approved open source license. GitHub CodeQL can only be used on codebases that are released under an OSI-approved open source license, to perform academic research, or to generate CodeQL databases for or during automated analysis. Download and add the project’s CodeQL database to VS Code, or create a CodeQL database using the CodeQL CLI.

About

Modern security teams are “paving the road” for developers — enforcing code guardrails on every commit. r2c’s Semgrep can eliminate vulnerability classes organization-wide. Scale your security team with lightweight static analysis. Semgrep is a fast, open-source, static analysis tool that excels at expressing code standards — without complicated queries — and surfacing bugs early in the development flow. Precise rules look like the code you’re searching; no more traversing abstract syntax trees or wrestling with regexes. Start right away with 900+ rules and SaaS infrastructure to get fast results in your editor, at commit-time, or in CI. When off-the-shelf rules aren’t enough, quickly and intuitively write custom rules to express your unique code standards. Rules look like the code you’re searching. For example, rules for Go look like Go. Find function calls, class or method definitions, and more without having to understand abstract syntax trees or wrestle with regexes.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Developers searching for a solution to find vulnerabilities across their codebase

Audience

Developer teams that want to ensure security on every code commit

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

$40 per month
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

GitHub
Founded: 2008
United States
codeql.github.com

Company Information

r2c
Founded: 2003
United Kingdom
r2c.dev/

Alternatives

Dependabot

Dependabot

GitHub

Alternatives

CodeQL

CodeQL

GitHub
Jsmon

Jsmon

Jsmon Inc.

Categories

Categories

Integrations

GitHub
Amazon S3
Archipelo
Betterscan.io
Cider
Cortex
DefectDojo
Enso
Hexway ASOC
Java
Jira
Jit
Kondukto
Logilica
Patched
Pixee
Seemplicity
Silk Security
Tromzo
Visual Studio Code

Integrations

GitHub
Amazon S3
Archipelo
Betterscan.io
Cider
Cortex
DefectDojo
Enso
Hexway ASOC
Java
Jira
Jit
Kondukto
Logilica
Patched
Pixee
Seemplicity
Silk Security
Tromzo
Visual Studio Code
Claim CodeQL and update features and information
Claim CodeQL and update features and information
Claim Semgrep and update features and information
Claim Semgrep and update features and information