CodeQL Query Customizations | Expert Services | GitHub · GitHub
https://github.com/services/codeql-query-customizations • 204 KB fetched Open original page
CodeQL Query Customizations | Expert Services | GitHub · GitHub
Skip to content
Navigation Menu
Sign in
* Platform
* AI CODE CREATION
* GitHub Copilot Write better code with AI
* GitHub Copilot app Direct agents from issue to merge
* MCP Registry Integrate external tools
* DEVELOPER WORKFLOWS
* Actions Automate any workflow
* Codespaces Instant dev environments
* Issues Plan and track work
* Code Review Manage code changes
* Code Quality Enforce quality at merge
* APPLICATION SECURITY
* GitHub Advanced Security Find and fix vulnerabilities
* Code security Secure your code as you build
* Secret protection Stop leaks before they start
* EXPLORE
* Why GitHub
* Documentation
* Blog
* Changelog
* Marketplace
View all features
* Solutions
* BY COMPANY SIZE
* Enterprises
* Small and medium teams
* Startups
* Nonprofits
* BY USE CASE
* App Modernization
* DevSecOps
* DevOps
* CI/CD
* View all use cases
* BY INDUSTRY
* Healthcare
* Financial services
* Manufacturing
* Government
* View all industries
View all solutions
* Resources
* EXPLORE BY TOPIC
* AI
* Software Development
* DevOps
* Security
* View all topics
* EXPLORE BY TYPE
* Customer stories
* Events & webinars
* Ebooks & reports
* Business insights
* GitHub Skills
* SUPPORT & SERVICES
* Documentation
* Customer support
* Community forum
* Trust center
* Partners
View all resources
* Open Source
* COMMUNITY
* GitHub Sponsors Fund open source developers
* PROGRAMS
* Security Lab
* Maintainer Community
* GitHub Stars
* Archive Program
* REPOSITORIES
* Topics
* Trending
* Collections
* Enterprise
* ENTERPRISE SOLUTIONS
* Enterprise platform AI-powered developer platform
* AVAILABLE ADD-ONS
* GitHub Advanced Security Enterprise-grade security features
* Copilot for Business Enterprise-grade AI features
* Premium Support Enterprise-grade 24/7 support
* Pricing
Search /
Sign in
Sign up
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
Expert Services
Introduction
Our Process
Services Catalog
Contact Experts
CodeQL Query Customizations
Overview
CodeQL ships with hundreds of queries out of the box for each language and includes comprehensive support for finding vulnerabilities in code using the most common and popular libraries and frameworks. However, if you use libraries that are internal to your organization, less popular libraries which are not covered by default, or use uncommon code patterns, you may find CodeQL misses results (false negatives) or produces incorrect results (false positives).
In this engagement we will collaborate with you to extend or modify the existing queries to reduce false positives or false negatives.
You will be able to specify some number of (potentially internal) extension items (sources/sinks/sanitizers), and have a CodeQL expert deliver models that will allow pre-existing CodeQL queries to return customized results. Options for extension items are grouped within different languages supported by CodeQL (Java, JavaScript/TypeScript, Go, C#, Python, C/C++, Ruby). For each requested customization, example code will be provided, or, for non-internal extensions, open source vulnerabilities or false positive examples that you wish to target.
Offering level
N/A
Target Audience
* Product/Application Security team
* Security architecture team
* Development/Engineering/QA testing team
* SecDevOps sponsor
* CTO or designated representative
* CISO or designated representative
Key features and benefits
* Main deliverable of custom models for extension items and custom CodeQL bundle containing custom models.
* Example CodeQL classes and predicates for future CodeQL learning efforts.
* Example custom CodeQL bundle mechanism.
Syllabus
* A pre-sales scoping session to define each customization to be implemented and determine an estimated time-to-implement for each customization based on its assigned difficulty. To do the estimate we require one or more of the following be supplied:
* A security vulnerability/code pattern/false positive result that they want to find/omit with CodeQL
* A list of sources/sinks/sanitizers to be modelled
* A test setup (code examples) to validate that the customization improves analysis as expected
* A post-sales kick-off session to clarify scope and remediate any missing dependencies, such as access to proprietary code
* Development of the customizations, using an iterative process:
* Write CodeQL sources/sinks/sanitizers
* Deliver the customizations with deployment instructions
* Review feedback on customization impact (reduced false positives/negatives) via issues and a project board
* Refine sources/sinks/sanitizers if impact is not as expected
* A final review and Q&A session
Learning outcomes/business outcomes
* sources/sinks/sanitizers that allow pre-existing queries to detect the example vulnerabilities or omit the example false positives
* Participants will be able to apply the delivered bundle to generate improved results
Prerequisites
* A list of sources/sinks/sanitizers has been gathered that you wish to have modelled. In the case where an entire API is requested there must be some set of scope - in terms of - sources/sinks/sanitizers that define sufficiently implemented
* Example code has been gathered where CodeQL analysis (either via CLI or in Actions) has run as a baseline for the results to be improved
* A CodeQL Analysis Engineer has evaluated the feasibility of the proposed technical scope of the customization to be developed as well as CodeQL support for the language(s) to be targeted. Customizations can only be developed to model problems of a clear and reasonably defined scope.
How can we help?
Let's build a customized solution that meets all of your needs.
Full name
This field is required.
Business email
Please enter a valid work email address.
Company
This field is required.
What can we help you with?
This field is required.
Contact our team
For support questions, head to
github.com/contact
Back to catalog listing
Subscribe to The GitHub Insider
A newsletter for developers covering techniques, technical guides, and the latest product innovations coming from GitHub.
Email Address *
Subscribe
Yes please, I’d like GitHub and affiliates to use my information for personalized communications, targeted advertising and campaign effectiveness. See the GitHub Privacy Statement for more details.
Subscribe
Site-wide Links
The developer newsletter
Get tips, technical guides, and best practices. Twice a month. Right in your inbox.
Subscribe
Platform
* Features
* Enterprise
* Copilot
* AI
* Security
* Pricing
* Team
* Resources
* Roadmap
* Compare GitHub
Ecosystem
* Developer API
* Partners
* Education
* GitHub CLI
* GitHub Desktop
* GitHub Mobile
* GitHub Marketplace
* MCP Registry
Support
* Docs
* Community Forum
* Professional Services
* Premium Support
* Skills
* Status
* Contact GitHub
* What is Git?
* Sitemap
Company
* About
* Why GitHub
* Customer Stories
* Blog
* The ReadME Project
* Careers
* Newsroom
* Inclusion
* Social Impact
* Shop
* © 2026 GitHub, Inc.
* Terms
* Privacy
* Manage cookies
* Do not share my personal information
* GitHub on LinkedIn
* GitHub on Instagram
* GitHub on YouTube
* GitHub on X
* GitHub on TikTok
* GitHub on Twitch
* GitHub’s organization on GitHub
English
You can’t perform that action at this time.
Links found on this page
- Skip to content [direct]
- Sign in [direct]
- GitHub Copilot Write better code with AI [direct]
- GitHub Copilot app Direct agents from issue to merge [direct]
- MCP Registry Integrate external tools [direct]
- Actions Automate any workflow [direct]
- Codespaces Instant dev environments [direct]
- Issues Plan and track work [direct]
- Code Review Manage code changes [direct]
- Code Quality Enforce quality at merge [direct]
- GitHub Advanced Security Find and fix vulnerabilities [direct]
- Code security Secure your code as you build [direct]
- Secret protection Stop leaks before they start [direct]
- Why GitHub [direct]
- Documentation [direct]
- Blog [direct]
- Changelog [direct]
- Marketplace [direct]
- View all features [direct]
- Enterprises [direct]
- Small and medium teams [direct]
- Startups [direct]
- Nonprofits [direct]
- App Modernization [direct]
- DevSecOps [direct]
- DevOps [direct]
- CI/CD [direct]
- View all use cases [direct]
- Healthcare [direct]
- Financial services [direct]
- Manufacturing [direct]
- Government [direct]
- View all industries [direct]
- View all solutions [direct]
- AI [direct]
- Software Development [direct]
- DevOps [direct]
- Security [direct]
- View all topics [direct]
- Customer stories [direct]
- Events & webinars [direct]
- Ebooks & reports [direct]
- Business insights [direct]
- GitHub Skills [direct]
- Customer support [direct]
- Community forum [direct]
- Trust center [direct]
- Partners [direct]
- View all resources [direct]
- GitHub Sponsors Fund open source developers [direct]
- Security Lab [direct]
- Maintainer Community [direct]
- GitHub Stars [direct]
- Archive Program [direct]
- Topics [direct]
- Trending [direct]
- Collections [direct]
- Copilot for Business Enterprise-grade AI features [direct]
- Premium Support Enterprise-grade 24/7 support [direct]
- Pricing [direct]
- Sign up [direct]
- Expert Services [direct]
- Introduction [direct]
- github.com/contact [direct]
- GitHub Privacy Statement [direct]
- Subscribe [direct]
- AI [direct]
- Security [direct]
- Roadmap [direct]
- Compare GitHub [direct]
- Developer API [direct]
- Education [direct]
- GitHub CLI [direct]
- GitHub Desktop [direct]
- GitHub Mobile [direct]
- Community Forum [direct]
- Status [direct]
- Contact GitHub [direct]
- What is Git? [direct]
- Sitemap [direct]
|
|