CodeQL, Semgrep and SARIF static-analysis toolkit from Trail of Bits: taint tracking, fast pattern scans and merged, deduplicated security findings for coding agents.
13 views
CodeQL static analysis: building databases, running taint-tracking and data-flow queries, modelling project-specific sources and sinks, and reading the SARIF that comes out.
2 skills tagged CodeQL.
CodeQL, Semgrep and SARIF static-analysis toolkit from Trail of Bits: taint tracking, fast pattern scans and merged, deduplicated security findings for coding agents.
by Trail of Bits
Trail of Bits' CodeQL skill: build databases, run taint-tracking and data-flow queries across eight languages, and model project-specific sources and sinks.
Tags that appear alongside this one, ranked by how often.