CodeQL

CodeQL

GitHub
SonarQube Server

SonarQube Server

SonarSource
+
+

Related Products

  • SonarQube Cloud
    190 Ratings
    Visit Website
  • ZeroPath
    2 Ratings
    Visit Website
  • TrustInSoft Analyzer
    6 Ratings
    Visit Website
  • Parasoft
    132 Ratings
    Visit Website
  • Aikido Security
    120 Ratings
    Visit Website
  • Vertex AI
    783 Ratings
    Visit Website
  • Google Cloud BigQuery
    1,867 Ratings
    Visit Website
  • Windsurf Editor
    148 Ratings
    Visit Website
  • Twilio
    1,336 Ratings
    Visit Website
  • JetBrains Junie
    2 Ratings
    Visit Website

About

Discover vulnerabilities across a codebase with CodeQL, our industry-leading semantic code analysis engine. CodeQL lets you query code as though it were data. Write a query to find all variants of a vulnerability, eradicating it forever. Then share your query to help others do the same. CodeQL is free for research and open source. Run real queries on popular open source codebases using CodeQL for Visual Studio Code. See how powerful it is to discover a bad pattern and then find similar occurrences across the entire codebase. You can create CodeQL databases yourself for any project that's under an OSI-approved open source license. GitHub CodeQL can only be used on codebases that are released under an OSI-approved open source license, to perform academic research, or to generate CodeQL databases for or during automated analysis. Download and add the project’s CodeQL database to VS Code, or create a CodeQL database using the CodeQL CLI.

About

SonarQube Server is a self-managed solution for continuous code quality inspection that helps development teams identify and fix bugs, vulnerabilities, and code smells in real-time. It provides automated static code analysis for a variety of programming languages, ensuring the highest quality and security standards are maintained throughout the development lifecycle. SonarQube Server integrates seamlessly with existing CI/CD pipelines, offering flexibility for on-premise or cloud-based deployment. With advanced reporting features, it helps teams manage technical debt, track improvements, and enforce coding standards. SonarQube Server is ideal for organizations seeking full control over their code quality and security without compromising on performance.

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Platforms Supported

Windows
Mac
Linux
Cloud
On-Premises
iPhone
iPad
Android
Chromebook

Audience

Developers searching for a solution to find vulnerabilities across their codebase

Audience

Companies searching for a solution to manage and empower their dev teams

Support

Phone Support
24/7 Live Support
Online

Support

Phone Support
24/7 Live Support
Online

API

Offers API

API

Offers API

Screenshots and Videos

Screenshots and Videos

Pricing

Free
Free Version
Free Trial

Pricing

No information available.
Free Version
Free Trial

Reviews/Ratings

Overall 0.0 / 5
ease 0.0 / 5
features 0.0 / 5
design 0.0 / 5
support 0.0 / 5

This software hasn't been reviewed yet. Be the first to provide a review:

Review this Software

Reviews/Ratings

Overall 5.0 / 5
ease 5.0 / 5
features 5.0 / 5
design 5.0 / 5
support 5.0 / 5

Training

Documentation
Webinars
Live Online
In Person

Training

Documentation
Webinars
Live Online
In Person

Company Information

GitHub
Founded: 2008
United States
codeql.github.com

Company Information

SonarSource
Founded: 2008
Switzerland
www.sonarsource.com/products/sonarqube/

Alternatives

Dependabot

Dependabot

GitHub

Alternatives

SonarQube Cloud

SonarQube Cloud

SonarSource
SonarQube for IDE

SonarQube for IDE

SonarSource

Categories

Categories

Static Code Analysis Features

Analytics / Reporting
Code Standardization / Validation
Multiple Programming Language Support
Provides Recommendations
Standard Security/Industry Libraries
Vulnerability Management

Application Security Features

Analytics / Reporting
Open Source Component Monitoring
Source Code Analysis
Third-Party Tools Integration
Training Resources
Vulnerability Detection
Vulnerability Remediation

Integrations

Java
Opsera
AWS Marketplace
BMC Compuware Hiperstation
C#
CodePeer
CodeScene
Cortex
Docker
Flosum
Jtest
Kaholo
Kubernetes
OpenText Static Application Security Testing
PHP
Parasoft
Polyspace Code Prover
Python
Terraform
configure8

Integrations

Java
Opsera
AWS Marketplace
BMC Compuware Hiperstation
C#
CodePeer
CodeScene
Cortex
Docker
Flosum
Jtest
Kaholo
Kubernetes
OpenText Static Application Security Testing
PHP
Parasoft
Polyspace Code Prover
Python
Terraform
configure8
Claim CodeQL and update features and information
Claim CodeQL and update features and information
Claim SonarQube Server and update features and information
Claim SonarQube Server and update features and information