| Apr | MAY | Jun |
| 12 | ||
| 2021 | 2022 | 2023 |
COLLECTED BY
Collection: github.com

Get set up in minutes using GitHub Actions, or run analysis in any CI provider.
Read

Integrate any static application security testing (SAST) engine. Use CodeQL, an open source engine, or any commercial third-party SAST tool.
Read
Audit changes to your code in response to a security scanning result.
Read

Monitor results across codebases in a centralized view, allowing you to prioritize the most important issues.
Read
Export results via our API and listen for new alerts via webhooks.
Read



Focus on real results, not false positives. CodeQL’s security queries have been refined to deliver industry-leading fix rates—60% of reported issues in 2020.
Leverage the CodeQL community. CodeQL comes with 2,000+ queries created and supported by GitHub and the community, all of which are open source.
Read

Create custom queries for bespoke problems. Find every instance of a bug across your codebases, then check every future git push for reversions automatically.
Secure your code
Read

Get notifications for 45+ secret providers including AWS, Azure, Google Cloud, npm, Stripe, and Twilio in the developer workflow.
Read

Mark notifications as fixed, false positive, or won’t fix.
Read
