Directory / CodeQL
CodeQL
Verified
GitHub semantic code analysis with query-based CI checks.
CodeQL is GitHub's semantic static-analysis engine. Queries find classes and variants of issues, and the engine runs through GitHub Advanced Security and Actions. It fits verification workflows already centered on GitHub.
- Model support
- Multi-model
- Deployment
- Cloud, Self-hosted
- Open source
- No
- License
- See GitHub CodeQL terms (not a casual OSS license)
- Pricing model
- Mixed
- Added / updated
- 19 Aug 2026 / 19 Aug 2026
Assessment
CodeQL queries security and correctness properties; it is not an AI review bot. Its licensing differs from permissive open-source linters. Use it for explicit security invariants and review agent-generated queries before adopting them.
Strengths
- Semantic query language.
- Native GitHub Actions integration.
- Variant analysis for bug classes.
Limitations
- More restrictive licensing than Semgrep's engine.
- Heavier operation than a linter.
- Commercial packaging centered on GitHub.