CLI tool
github/codeql avatar
github/codeql

github/codeql: the query libraries behind GitHub code scanning, and how to install the CLI

CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security

10,138 stars2,100 forksCodeQLMIT

At a glance

What is it?
This repository holds the standard CodeQL libraries and queries, not the engine. Here is what it contains, how to install and run the CodeQL CLI against it, and where the MIT licence stops.
Who is it for?
Adopt this repository if you write or audit CodeQL queries, or if you need to read the standard checks before trusting them. Do not adopt it expecting a ready-to-run scanner: the engine lives in github/codeql-cli-binaries under a separate licence, and closed-source analysis needs a commercial licence from GitHub.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository received new commits within the last day.
What is it written in?
Mainly CodeQL, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.

DEEP OPEN-SOURCE ANALYSIS

What github/codeql actually contains, and who it is for

The repository is not a scanner. It is the standard CodeQL libraries and queries that power GitHub Advanced Security and the other application security products GitHub sells. The README states this directly in its first paragraph. If you clone it expecting a binary that prints findings, you will find QL source files instead.

The audience is narrow and specific. First, security researchers who write their own queries and want to build on the standard library rather than start from nothing. Second, engineers who want to read the standard checks and understand why a finding fired. Third, contributors: the README explicitly invites pull requests for new checks or improvements to existing ones, and points to CONTRIBUTING.md plus the style guides under docs/ for query metadata and query help documentation.

The top-level layout reflects that scope. There are per-language directories (cpp, csharp, go, java, javascript, python, ruby, rust, swift, actions, unified), a ql/ directory, shared/ for common code, docs/, change-notes/, and config/. The presence of separate directories per language is the first thing to check against your own stack: support is organised per language, not as one universal analyser.

How the libraries, extractors and CLI fit together

Two halves are visible in the repository. The first is QL: the libraries and queries that describe what a vulnerability pattern looks like. The second is extraction. The Cargo.toml workspace file lists members including shared/tree-sitter-extractor, ruby/extractor, unified/extractor, rust/extractor, rust/autobuild and unified/swift-syntax-rs. That tells you how source code becomes queryable data: an extractor parses a language and produces a database, and the queries then run against that database.

The tree-sitter reference in the workspace is the clearest signal of the parsing approach for the extractors listed there. A shared extractor crate is reused across languages rather than each language growing its own parser from scratch.

The engine that executes queries is not here. The README says the CodeQL CLI, including the CodeQL engine, is hosted in a different repository, github/codeql-cli-binaries, and is licensed separately. So the practical data flow for a user is: install the CLI from that other repository, obtain or build a database for your code, then point the CLI at queries from this repository.

Bazel appears in the tooling too, with BUILD.bazel, MODULE.bazel, .bazelrc and defs.bzl at the top level, alongside a Rust toolchain pin in rust-toolchain.toml and a Cargo workspace. That is a build system aimed at people working on the repository itself, not at people who just want to run a scan.

Installing the CodeQL CLI and running a first query

The README does not give install commands. It points to documentation instead: the CodeQL language docs at codeql.github.com/docs, the CodeQL extension for Visual Studio Code, and the CodeQL CLI docs under docs.github.com. The CLI itself is distributed from github/codeql-cli-binaries, a separate repository. Follow those pages for the download and setup steps; nothing in this repository's README substitutes for them.

Once the CLI is on your PATH, the workflow is a database followed by a query. The CLI documentation describes the CLI as the entry point for creating databases and running queries. Check the CLI docs for the exact flags your version accepts before relying on any of it.

For working with the queries themselves, the README recommends the CodeQL for Visual Studio Code extension, available from the Visual Studio Marketplace under the identifier GitHub.vscode-codeql. It provides syntax highlighting, IntelliSense, code navigation for QL, and unit test support for testing CodeQL libraries and queries. If you plan to edit queries rather than just run them, that extension is the intended path.

The repository also defines custom tasks in .vscode/tasks.json. The README says to invoke them through Terminal | Run Task... or the Tasks: Run Task command in the command palette. Those tasks are for working inside this repository, so they are relevant to contributors, not to downstream users.

The licence boundary is the real constraint

This is where most adoption decisions actually get made. The code in this repository is MIT licensed by GitHub. That covers the libraries and queries.

The CodeQL CLI, including the engine, is not covered by that grant. The README states it lives in github/codeql-cli-binaries and is licensed separately. It also states that using the CodeQL CLI to analyze closed-source code requires a separate commercial licence, with a contact link for further help.

Read those two sentences together and the practical split is clear. Open-source analysis and query development sit on the MIT side. Closed-source analysis does not. Teams that assume "MIT repository" means "free for our private monorepo" have misread the scope, and the README is unusually direct about it rather than burying it.

One more boundary: this repository has no releases listed. There is a change-notes/ directory, which suggests changes are tracked in-tree rather than through tagged releases, but the README does not document a release or upgrade procedure. If you pin to this repository, pin to a commit and read change-notes/ yourself.

CodeQL versus SonarQube and Semgrep: different centres of gravity

The comparison people search for most is CodeQL against SonarQube, and the second is CodeQL against Semgrep. The difference that matters here is where the product lives.

CodeQL's model is a database and a query language. Source is extracted into a relational database, and analysis is expressed as QL queries over that database. That is why this repository is full of QL libraries and per-language extractors rather than rule files in YAML. It is also why the learning curve is real: writing a query means learning a language, not filling in a pattern template. The upside is that a query can express data flow across functions and files, which a purely syntactic pattern cannot.

Semgrep's model starts from patterns that resemble the code you are searching for, which lowers the barrier to writing a first rule. SonarQube's model starts from a server product with its own rule catalogue and dashboards. Neither of those descriptions is a claim about detection quality; they are claims about the shape of the tool.

The honest framing for a team: if you want to run existing checks and read a report, this repository is not the shortest path, because you still need the separately licensed CLI and a database build step. If you want to express a custom analysis over a queryable representation of a codebase, and you are willing to learn QL, the model here is the one that fits.

Where github/codeql is the wrong tool

If you need a scanner running in CI by tomorrow, this repository will not get you there. There is no install command in the README, no default configuration to copy, and no bundled engine. The path runs through the CLI repository, its separate licence, and the CLI documentation.

If your code is closed source, the licence question comes before the technical one. The README's statement about a commercial licence for closed-source analysis means the MIT grant on this repository does not settle your situation.

If your language is not among the directories here (cpp, csharp, go, java, javascript, python, ruby, rust, swift, actions), there is nothing in this repository for you to build on, and the extractor workspace members listed in Cargo.toml cover a subset of those languages rather than all of them.

Finally, if you only want to consume findings, you are looking at the wrong layer. The queries here are the input to a pipeline, not the pipeline's output. Reading a query to understand a finding is a legitimate use. Treating the repository as a product with a user interface is not.

Maintenance, contribution and what to check before adopting

The repository is not archived, and the last push was on 2026-09-21. The presence of change-notes/ and CODEOWNERS suggests changes are recorded and reviewed in-tree.

The contribution path is documented: read CONTRIBUTING.md, then the style guides under docs/ for formatting, query metadata, and query help documentation. The README frames contributions as welcome for both new checks and improvements to existing queries. There is also a separate contributing guide for documentation at docs/codeql/CONTRIBUTING.md.

Upgrade cost is the weak spot in the documentation. The README does not document rollback, version pinning, or a release cadence. With no releases listed, the practical approach is to track commits and read change-notes/ before moving a pinned revision. For a team embedding these queries in a pipeline, that means owning the upgrade decision rather than waiting for a version number to appear.

On licence implications: the MIT grant covers this repository's code. It does not cover the CLI or the engine, and it does not resolve closed-source use. That is a statement about what the README says, not legal advice; if your use is commercial and closed source, the README points to GitHub's enterprise contact form.

Editorial conclusion

Adopt this repository if you write or audit CodeQL queries, or if you need to read the standard checks before trusting them. Do not adopt it expecting a ready-to-run scanner: the engine lives in github/codeql-cli-binaries under a separate licence, and closed-source analysis needs a commercial licence from GitHub. Before anything else, confirm which languages you actually need, since the repository ships separate directories per language, and check whether your use falls inside the MIT grant or requires the commercial path.

Frequently asked questions

What is CodeQL used for?

The README describes this repository as the standard CodeQL libraries and queries that power GitHub Advanced Security and GitHub's other application security products. In practice the queries are run against a database extracted from source code to find security issues.

Is CodeQL better than SonarQube?

The README makes no comparison with SonarQube. The structural difference visible here is that CodeQL analysis is expressed as QL queries over a database extracted from source, while SonarQube is a server product with its own rule catalogue; the README does not claim anything about detection quality.

Is CodeQL free?

The code in this repository is MIT licensed by GitHub. The CodeQL CLI, including the engine, is hosted in a different repository and licensed separately, and the README states that analyzing closed-source code with the CLI requires a separate commercial licence.

How do I install the CodeQL CLI?

The README does not give install steps. It points to the CodeQL CLI documentation under docs.github.com and notes that the CLI lives in the separate github/codeql-cli-binaries repository, where the download and setup instructions are.

How do I use CodeQL in Visual Studio Code?

The README recommends installing the CodeQL for Visual Studio Code extension, listed on the Visual Studio Marketplace as GitHub.vscode-codeql. It provides syntax highlighting, IntelliSense, code navigation for QL, and unit test support for CodeQL libraries and queries.

Is CodeQL hard to learn?

Analysis here is expressed in QL, a query language, rather than in pattern templates, and the README points to separate documentation for the CodeQL language and for writing queries with the VS Code extension. The repository also contains style guides for formatting, query metadata and query help documentation, which implies query authorship has its own conventions to learn.

Official sources

  1. github/codeql on GitHub
  2. Issues
  3. License: MIT
  4. Project website
  5. README
For maintainers

Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/github-codeql.svg)](https://hysenlabs.com/projects/github-codeql)
Community notes

Community notes