What we still need to verify : 1 point in this profile is not yet confirmed against vendor documentation.
- Current language list and which are in beta: confirm with vendor docs
Treat these points as unconfirmed. They are open items in the catalog's verification queue, and this note stays until each is checked against the vendor's documentation.
What it does
CodeQL extracts a codebase into a relational database. For compiled languages the extractor observes the build; for interpreted languages it parses source directly. The database holds the abstract syntax tree, the type system, the control flow graph and the call graph as tables you can query. Analysis is then a matter of running queries written in QL, a declarative logic language with classes, predicates and recursion, against that database.
The security query packs build on shared libraries that define taint tracking configurations: a set of sources, a set of sinks, and the flow steps and sanitizers between them. Because those libraries are open and the query language is expressive, you can extend them rather than fight them. Declare your framework's custom request wrapper as a source and every injection query starts seeing flows through it. The same mechanism supports variant analysis: after an incident, write a query describing the exact mistake and run it across every repository to find the other places it occurs. Results are emitted as SARIF.
Where it fits
The common deployment is a GitHub Actions workflow running on pull requests and on a schedule, with results in the repository security tab. The CLI also runs standalone in other CI systems or locally, and databases can be built once and queried many times, which suits a research workflow. Developers consume alerts; a security engineer who learns QL gets disproportionate value, because the shipped queries are a starting point rather than the product. Compiled languages need a working build for extraction.
Strengths
- QL is genuinely expressive, and a well-written custom query can encode organization-specific security invariants that no off-the-shelf rule set covers.
- Standard libraries and queries are open source, so you can read exactly why a finding fired and adjust the model rather than suppress the result.
- Variant analysis across many repositories turns one incident into systematic cleanup.
- Path visualization shows the full source-to-sink trace, which makes triage concrete.
Limitations
- QL has a real learning curve. Teams that never invest in writing queries get a decent but unremarkable default scanner.
- Database build times for large compiled projects are long, and build extraction failures are a recurring operational annoyance.
- The smoothest experience is tied to GitHub's platform, and using it well elsewhere means running and maintaining the CLI yourself.
Who it suits
Excellent for security engineering teams willing to invest in query writing, and for organizations already on GitHub where the integration is free of friction. Less compelling for a team that wants results with zero tuning and has nobody who will ever open a QL file.
Used GitHub CodeQL? Recommend it under your own name and title.
Recommend this tool