CodeQL

CodeQL

GitHub
+
+

Related Products

  • Parasoft
    152 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • DbVisualizer
    585 Ratings
    Visit Website
  • Aikido Security
    239 Ratings
    Visit Website
  • Google Cloud BigQuery
    2,027 Ratings
    Visit Website
  • Rocket z/Assure VAP
    1 Rating
    Visit Website
  • Source Defense
    7 Ratings
    Visit Website
  • Retool
    593 Ratings
    Visit Website
  • Flagsmith
    43 Ratings
    Visit Website
  • JetBrains Junie
    12 Ratings
    Visit Website

About

Discover vulnerabilities across a codebase with CodeQL, our industry-leading semantic code analysis engine. CodeQL lets you query code as though it were data. Write a query to find all variants of a vulnerability, eradicating it forever. Then share your query to help others do the same. CodeQL is free for research and open source. Run real queries on popular open source codebases using CodeQL for Visual Studio Code. See how powerful it is to discover a bad pattern and then find similar occurrences across the entire codebase. You can create CodeQL databases yourself for any project that's under an OSI-approved open source license. GitHub CodeQL can only be used on codebases that are released under an OSI-approved open source license, to perform academic research, or to generate CodeQL databases for or during automated analysis. Download and add the project’s CodeQL database to VS Code, or create a CodeQL database using the CodeQL CLI.

About

Snyk is the leader in developer security. We empower the world’s developers to build secure applications and equip security teams to meet the demands of the digital world. Our developer-first approach ensures organizations can secure all of the critical components of their applications from code to cloud, leading to increased developer productivity, revenue growth, customer satisfaction, cost savings and an overall improved security posture. Snyk’s Developer Security Platform automatically integrates with a developer’s workflow and is purpose-built for security teams to collaborate with their development teams. Snyk is used by 1,200 customers worldwide today, including industry leaders such as Asurion, Google, Intuit, MongoDB, New Relic, Revolut and Salesforce. Snyk is recognized on the Forbes Cloud 100 2021, the 2021 CNBC Disruptor 50 and was named a Visionary in the 2021 Gartner Magic Quadrant for AST.

Platforms Supported

Windows Supported
Mac Supported
Linux Supported
Cloud Not Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Platforms Supported

Windows Supported
Mac Supported
Linux Not Supported
Cloud Supported
On-Premises Not Supported
iPhone Not Supported
iPad Not Supported
Android Not Supported
Chromebook Not Supported

Audience

Developers searching for a solution to find vulnerabilities across their codebase

Audience

Developers and security teams

Support

Phone Support Not Supported
24/7 Live Support Not Supported
Online Supported

Support

Phone Support Supported
24/7 Live Support Not Supported
Online Supported

API

Offers API Supported

API

Offers API Supported

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version Supported
Free Trial Not Supported

Pricing

$0
200 Open Source tests per month
100 Container tests per month
300 IaC tests per month
100 Snyk Code tests per month
Unlimited Developers
Free Version Not Supported
Free Trial Supported

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 5.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 5.0 / 5
support 5.0 / 5

Pros & Cons from Real Users

Pros

  • I've been using Snyk for a while now, and I have to say it’s one of the best security tools I’ve integrated into our CI/CD pipeline. As an IT Security administrator, I’m always on the lookout for vulnerabilities in open-source dependencies, and Snyk makes it ridiculously easy to catch them before they become a problem. The fact that it plugs right into our repositories and continuously scans for issues saves me a ton of time. The best thing about Snyk is how seamlessly it integrates with our existing workflows—GitHub, Jenkins, Kubernetes, you name it. The vulnerability database is top-notch, constantly updated, and the remediation suggestions are actually useful. It’s not just "here’s a problem" but "here’s how to fix it." The reporting and policy enforcement features also make compliance way less of a headache.

Cons

  • The free tier is great for small projects, but if you need enterprise-level features, the pricing can add up fast. Also, while it covers a lot of ecosystems, the scan times on larger codebases can sometimes be a bit slow. Not a dealbreaker, but something to be aware of.

Training

Documentation Supported
Webinars Not Supported
Live Online Not Supported
In Person Not Supported

Training

Documentation Supported
Webinars Supported
Live Online Supported
In Person Supported

Company Information

GitHub
Founded: 2008
United States
codeql.github.com

Company Information

Snyk
Founded: 2015
United Kingdom
snyk.io

Alternatives

Alternatives

Dependabot

Dependabot

GitHub
Astra Pentest

Astra Pentest

Astra Security
Xygeni

Xygeni

Xygeni Security

Categories

Categories

Static Code Analysis Features

Analytics / Reporting Supported
Code Standardization / Validation Not Supported
Multiple Programming Language Support Supported
Provides Recommendations Not Supported
Standard Security/Industry Libraries Not Supported
Vulnerability Management Supported

Cybersecurity Features

AI / Machine Learning Not Supported
Behavioral Analytics Not Supported
Endpoint Management Not Supported
Incident Management Not Supported
IOC Verification Not Supported
Tokenization Not Supported
Vulnerability Scanning Supported
Whitelisting / Blacklisting Not Supported

IT Security Features

Anti Spam Not Supported
Anti Virus Not Supported
Email Attachment Protection Not Supported
Event Tracking Not Supported
Internet Usage Monitoring Not Supported
Intrusion Detection System Not Supported
IP Protection Not Supported
Spyware Removal Not Supported
Two-Factor Authentication Not Supported
Vulnerability Scanning Supported
Web Threat Management Not Supported
Web Traffic Reporting Not Supported

Vulnerability Management Features

Asset Discovery Supported
Asset Tagging Supported
Network Scanning Not Supported
Patch Management Supported
Policy Management Supported
Prioritization Supported
Risk Management Supported
Vulnerability Assessment Supported
Web Scanning Not Supported

Integrations

Earthly Lunar Supported
GitHub Supported
Java Supported
Visual Studio Code Supported
Bitbucket Not Supported
Blink Not Supported
Claude Code Not Supported
Code Dx Not Supported
FossID Not Supported
GoLand Not Supported
HUMAN Sightline Cyberfraud Defense Not Supported
InsightCloudSec Not Supported
Jenkins Not Supported
Roadie Not Supported
SeeMetrics Not Supported
Sequence Not Supported
Silk Security Not Supported
ThreadFix Not Supported
Vulcan Cyber Not Supported
appNovi Not Supported

Integrations

Earthly Lunar Supported
GitHub Supported
Java Supported
Visual Studio Code Supported
Bitbucket Supported
Blink Supported
Claude Code Supported
Code Dx Supported
FossID Supported
GoLand Supported
HUMAN Sightline Cyberfraud Defense Supported
InsightCloudSec Supported
Jenkins Supported
Roadie Supported
SeeMetrics Supported
Sequence Supported
Silk Security Supported
ThreadFix Supported
Vulcan Cyber Supported
appNovi Supported
Claim CodeQL and update features and information
Claim CodeQL and update features and information
Claim Snyk and update features and information
Claim Snyk and update features and information