-
Notifications
You must be signed in to change notification settings - Fork 1.9k
Is it possible to use CodeQL to replace code quality tools like SonarQube or Codacy? #19371
-
CodeQL is specifically geared toward security analysis, but it seems that the tool should be able to do things like detecting "code smells" like SonarQube. Do any sufficient query packs like this exist? A corollary - where can one find published CodeQL query packs other than those provided by GitHub?
Beta Was this translation helpful? Give feedback.
All reactions
Replies: 1 comment 8 replies
-
👋 PM with the code scanning team at GitHub here. Are you using our GitHub Advanced Security suite of tools or CodeQL independently today? We're starting explorations into the area of code quality and would be interested in speaking with you more about your needs here. If you're interested, please feel free to grab a spot on my calendar here: https://calendar.app.google/1wcXpbxvSVYYzmCi8
Beta Was this translation helpful? Give feedback.
All reactions
-
@tvalenta absolutely, please feel free to book a spot on my calendar here: https://calendar.app.google/qBKmsgLHjDQfiQNx8
Beta Was this translation helpful? Give feedback.
All reactions
-
Hi Caro - appreciate this was posted some months ago. This topic has come up recently in my org - are you still looking for discussion/input on this?
Beta Was this translation helpful? Give feedback.
All reactions
-
@matt-buchanan yes! The link I posted above for my calendar is still active (next week I'm out at Black Hat so availability may be limited until the week of the 11th).
Beta Was this translation helpful? Give feedback.
All reactions
-
Hi Caro, glad to know Code quality is being considered and explored as part of CodeQL.
Has there been any updates since the original post, that you'll be able to share?
I am exploring tools for Code Quality/Security Scan for my org. and have been wondering if CodeQL is a good alternative for tools like Sonar, but haven't had much success so far.
Beta Was this translation helpful? Give feedback.
All reactions
-
@jjkcharles we are still working on this, currently in a private preview stage. I'd love to hear more about your code quality needs at your org, feel free to book some time with me: https://calendar.app.google/qBKmsgLHjDQfiQNx8
Or send me an email (my handle @github.com)
Beta Was this translation helpful? Give feedback.