Find vulnerabilities before they ship.
static analysis
Scans a codebase for security vulnerabilities with CodeQL's interprocedural data-flow and taint-tracking analysis.
When to use it
Use it for CodeQL scans, database builds, SAST, taint analysis, data-flow analysis, or vulnerability searches; use semgrep for fast single-file matching and sarif-parsing for existing SARIF.
Give it a codebase and scan request; it builds a CodeQL database, creates data extensions, runs analysis, and stores the generated artifacts in the output directory.
What you provide
No additional actions listed in the analysis.
The CodeQL CLI must be installed and available on PATH.
jq must be installed and available on PATH to parse CodeQL database metadata.
uv must be installed and available on PATH to run the guard scripts and suite generators.