softwarefactory.build

Directory / CodeQL

CodeQL

Verified

GitHub semantic code analysis with query-based CI checks.

CodeQL is GitHub's semantic static-analysis engine. Queries find classes and variants of issues, and the engine runs through GitHub Advanced Security and Actions. It fits verification workflows already centered on GitHub.

Model support
Multi-model
Deployment
Cloud, Self-hosted
Open source
No
License
See GitHub CodeQL terms (not a casual OSS license)
Pricing model
Mixed
Added / updated
19 Aug 2026 / 19 Aug 2026

codeql.github.com · Docs

Assessment

CodeQL queries security and correctness properties; it is not an AI review bot. Its licensing differs from permissive open-source linters. Use it for explicit security invariants and review agent-generated queries before adopting them.

Strengths

  • Semantic query language.
  • Native GitHub Actions integration.
  • Variant analysis for bug classes.

Limitations

  • More restrictive licensing than Semgrep's engine.
  • Heavier operation than a linter.
  • Commercial packaging centered on GitHub.

Fields last checked against primary sources on . Pricing and plan names change; check the vendor URL.