Semgrep vs GitHub CodeQL
Pattern Rules or Semantic Queries
Semgrep matches code shapes without a build; CodeQL queries a semantic database of your program. How that choice plays out in ownership, noise and depth.
Read the comparison
236 tools 13 categories
Why this exists
Independent profiles for the people who have to choose these tools, and then live with them.
Limitations first. Structured the same way for every tool. Nothing on this site is for sale.
Read the editorial policyThe AppSec lifecycle
All 13 categories, placed at the stage of delivery where they catch what the others miss. Each one says what it finds, when it runs, and which tools lead it.
Editor, pre-commit and pull request
Catch the flaw while its author still has the context to fix it in minutes.
Injection, unsafe deserialization and risky API use in code your team wrote.
Runs: Every pull request, with a full scan nightly
Keys, tokens and passwords committed to source or buried in history.
Runs: Pre-commit hook, then every push
Public buckets, open security groups and privileged pods before they are applied.
Runs: Pull requests that touch infrastructure
Dependencies and artifacts
Most of what you ship, you did not write. Check it before it is packaged.
Open source packages with known vulnerabilities or license obligations.
Runs: Every build, plus alerts when a new advisory lands
Vulnerable OS packages and weak defaults baked into images.
Runs: Image build, then continuously in the registry
The running application
Some flaws only exist once the pieces are wired together and serving requests.
Injection, authentication and session flaws visible from outside, no source needed.
Runs: Against staging, per release or nightly
Vulnerabilities confirmed on real code paths while your tests drive the app.
Runs: During the integration tests you already run
Broken object level authorization, shadow endpoints and drift from the contract.
Runs: The OpenAPI spec in CI, live traffic in staging
Insecure local storage, weak transport security and secrets inside app binaries.
Runs: Each Android or iOS build
Posture, gating and ownership
Decide what blocks a release and who owns each finding, across every scanner.
Duplicate and low value findings, ranked by exposure and routed to an owner.
Runs: Continuously, over every scanner's output
Production
Assume something got through. Detect and block exploitation while it happens.
Exploit attempts stopped inside the application as the vulnerable code executes.
Runs: Always on, in the production runtime
Malicious requests filtered at the edge before they reach the application.
Runs: Always on, in front of the app
Across every stage
AI features bring a new input channel, and AI written code needs the same checks as any other.
Prompt injection, jailbreaks, data leakage and unsafe agent actions.
Runs: Red teaming before release, guardrails at runtime
Head to head
Two tools teams actually shortlist together, compared on the one difference that decides it, with the facts side by side.
Pattern Rules or Semantic Queries
Semgrep matches code shapes without a build; CodeQL queries a semantic database of your program. How that choice plays out in ownership, noise and depth.
Read the comparison
Lockfiles or Container Images
Read the comparison
History Sweeps or a Baseline You Hold
Read the comparison
Deep App Scanning or Fast Known-Issue Sweeps
Read the comparison
Graph Checks or Rego Queries
Read the comparison
Probe Scanner or Red Team Campaign Framework
Read the comparison
Start here
Start with the discipline, then go deep on a category. Each hub says what you will learn and what to read first.
The discipline
The whole picture before you pick tools: what each category catches, how they fit across delivery, and what to adopt first.
Start with the guideWhat you will learn
Hub 01 · Static Application Security Testing
What you will learn
Read first
Hub 02 · Software Composition Analysis
What you will learn
Read first
Hub 03 · Dynamic Application Security Testing
What you will learn
Read first
Hub 04 · AI and LLM Security
What you will learn
Read first
Fresh in the catalog
Zimperium
Automated scanner that analyzes compiled Android and iOS builds for security, privacy and compliance issues inside the release pipeline.
ZeroThreat
Hosted dynamic scanner for web applications and APIs, offered with a free entry tier and automation intended to reduce manual scan configuration.
ZAP project, Software Security Project
Open source intercepting proxy and scanner that passively analyzes proxied traffic and actively attacks discovered endpoints, scriptable end to end.
Xygeni
A software supply chain security platform covering malicious package detection, pipeline and source control hardening, secrets, dependencies and code analysis.
Xage Security
Distributed zero trust access platform for operational and industrial environments, extended to control what machine and AI agent identities may do.
Wiz
An agentless cloud-native application protection platform that builds a graph of cloud resources, identities and workloads to surface real attack paths.
Guides and roundups
Ten secret scanning tools compared by where they sit in the lifecycle, whether they verify credentials, and whether they carry a leak through to rotation.
12 min read
Ten software composition analysis tools picked for distinct jobs: reachability triage, license compliance, SBOM monitoring, malicious package detection and patching.
12 min read
A practitioner's guide to ten static analysis tools, chosen for distinct scenarios rather than ranked, with the trade-offs each one brings.
12 min read
Editorial policy
236 tools, 13 categories, one standard