CodeQL Query Development | Expert Services | GitHub · GitHub
https://github.com/services/codeql-query-development • 204 KB fetched Open original page
CodeQL Query Development | Expert Services | GitHub · GitHub
Skip to content
Navigation Menu
Sign in
* Platform
* AI CODE CREATION
* GitHub Copilot Write better code with AI
* GitHub Copilot app Direct agents from issue to merge
* MCP Registry Integrate external tools
* DEVELOPER WORKFLOWS
* Actions Automate any workflow
* Codespaces Instant dev environments
* Issues Plan and track work
* Code Review Manage code changes
* Code Quality Enforce quality at merge
* APPLICATION SECURITY
* GitHub Advanced Security Find and fix vulnerabilities
* Code security Secure your code as you build
* Secret protection Stop leaks before they start
* EXPLORE
* Why GitHub
* Documentation
* Blog
* Changelog
* Marketplace
View all features
* Solutions
* BY COMPANY SIZE
* Enterprises
* Small and medium teams
* Startups
* Nonprofits
* BY USE CASE
* App Modernization
* DevSecOps
* DevOps
* CI/CD
* View all use cases
* BY INDUSTRY
* Healthcare
* Financial services
* Manufacturing
* Government
* View all industries
View all solutions
* Resources
* EXPLORE BY TOPIC
* AI
* Software Development
* DevOps
* Security
* View all topics
* EXPLORE BY TYPE
* Customer stories
* Events & webinars
* Ebooks & reports
* Business insights
* GitHub Skills
* SUPPORT & SERVICES
* Documentation
* Customer support
* Community forum
* Trust center
* Partners
View all resources
* Open Source
* COMMUNITY
* GitHub Sponsors Fund open source developers
* PROGRAMS
* Security Lab
* Maintainer Community
* GitHub Stars
* Archive Program
* REPOSITORIES
* Topics
* Trending
* Collections
* Enterprise
* ENTERPRISE SOLUTIONS
* Enterprise platform AI-powered developer platform
* AVAILABLE ADD-ONS
* GitHub Advanced Security Enterprise-grade security features
* Copilot for Business Enterprise-grade AI features
* Premium Support Enterprise-grade 24/7 support
* Pricing
Search /
Sign in
Sign up
You signed in with another tab or window. Reload to refresh your session.
You signed out in another tab or window. Reload to refresh your session.
You switched accounts on another tab or window. Reload to refresh your session.
Dismiss alert
Expert Services
Introduction
Our Process
Services Catalog
Contact Experts
CodeQL Query Development
Overview
CodeQL ships with hundreds of queries out of the box for each language that typically cover the most critical and important security vulnerability categories. In this engagement, we will write, deliver and assist with testing and deploying one or more new queries to find security vulnerabilities which are not covered out-of-the-box, or to identify correctness, performance or code smell issues.
For each requested query, detailed specifications for the queries to be developed must be provided. If determined to be necessary during the pre-sales scoping phase, test-cases and example code to assist development and verify the correctness of deliverable queries must also be provided.
This engagement also offers the option to additionally release the developed CodeQL queries as an open-source contribution to the CodeQL Standard Library, thus saving future query maintenance costs at the expense of a longer initial query development phase.
Target Audience
* Security Researchers
* Application Security Teams
* Software Engineering Technical Leads
Key Features and Benefits
After an initial scoping and feasibility assessment meeting, one or more CodeQL experts will be assigned to write custom queries and assist in deploying them in an organization. This engagement will provide CodeQL queries adding targeted code coverage of additional or organization-specific vulnerabilities, correctness, performance, or code smell issues.
Syllabus
* A pre-sales scoping and feasibility evaluation meeting to define each rule to be implemented as a query and determine an estimated time-to-implement for each rule based on its assigned difficulty.
* A post-sales kick-off call to clarify any remaining scope or architectural questions as well as to remediate any missing dependencies, such as access to proprietary code or query test cases.
* Internal project management and engineering tasks.
* Development of the queries, using an iterative process:
* CodeQL query development
* Incremental delivery of queries as CodeQL query packs or similar with deployment guidance
* Collaborative review of query feedback and issue reports
* Remediation of any false-positives, false-negatives, or other issues reported
* Optionally, based on the individual services agreement, open-sourcing of the queries
* A final review and Q&A session
Learning/Business Outcomes
* One or more custom queries ready to be deployed in your organization.
* A deeper understanding of how CodeQL can be used to model patterns in your code.
Prerequisites
* A clear technical scope for the CodeQL query or queries to be implemented can be provided; this prerequisite can be fulfilled through items including but not strictly limited to the following:
* Specifying an established coding standard which contains technical specifications for the behaviour to be enforced or prohibited as well as demonstrative examples of the behaviour in question
* An example of a security vulnerability, correctness issue, or otherwise undesired code pattern in a shareable codebase, proof-of-concept application, or code snippet
* To develop custom queries which specifically model proprietary or closed-source software, it must be possible to provide access to the source code to be targeted or self-contained examples modelling their proprietary code.
* In the pre-sales phase, a CodeQL Analysis Engineer has evaluated the feasibility of the proposed technical scope of the custom queries to be developed as well as CodeQL support for the language(s) to be targeted. Custom queries can only be developed to model problems of a clear and reasonably defined scope.
How can we help?
Let's build a customized solution that meets all of your needs.
Full name
This field is required.
Business email
Please enter a valid work email address.
Company
This field is required.
What can we help you with?
This field is required.
Contact our team
For support questions, head to
github.com/contact
Back to catalog listing
Subscribe to The GitHub Insider
A newsletter for developers covering techniques, technical guides, and the latest product innovations coming from GitHub.
Email Address *
Subscribe
Yes please, I’d like GitHub and affiliates to use my information for personalized communications, targeted advertising and campaign effectiveness. See the GitHub Privacy Statement for more details.
Subscribe
Site-wide Links
The developer newsletter
Get tips, technical guides, and best practices. Twice a month. Right in your inbox.
Subscribe
Platform
* Features
* Enterprise
* Copilot
* AI
* Security
* Pricing
* Team
* Resources
* Roadmap
* Compare GitHub
Ecosystem
* Developer API
* Partners
* Education
* GitHub CLI
* GitHub Desktop
* GitHub Mobile
* GitHub Marketplace
* MCP Registry
Support
* Docs
* Community Forum
* Professional Services
* Premium Support
* Skills
* Status
* Contact GitHub
* What is Git?
* Sitemap
Company
* About
* Why GitHub
* Customer Stories
* Blog
* The ReadME Project
* Careers
* Newsroom
* Inclusion
* Social Impact
* Shop
* © 2026 GitHub, Inc.
* Terms
* Privacy
* Manage cookies
* Do not share my personal information
* GitHub on LinkedIn
* GitHub on Instagram
* GitHub on YouTube
* GitHub on X
* GitHub on TikTok
* GitHub on Twitch
* GitHub’s organization on GitHub
English
You can’t perform that action at this time.
Links found on this page
- Skip to content [direct]
- Sign in [direct]
- GitHub Copilot Write better code with AI [direct]
- GitHub Copilot app Direct agents from issue to merge [direct]
- MCP Registry Integrate external tools [direct]
- Actions Automate any workflow [direct]
- Codespaces Instant dev environments [direct]
- Issues Plan and track work [direct]
- Code Review Manage code changes [direct]
- Code Quality Enforce quality at merge [direct]
- GitHub Advanced Security Find and fix vulnerabilities [direct]
- Code security Secure your code as you build [direct]
- Secret protection Stop leaks before they start [direct]
- Why GitHub [direct]
- Documentation [direct]
- Blog [direct]
- Changelog [direct]
- Marketplace [direct]
- View all features [direct]
- Enterprises [direct]
- Small and medium teams [direct]
- Startups [direct]
- Nonprofits [direct]
- App Modernization [direct]
- DevSecOps [direct]
- DevOps [direct]
- CI/CD [direct]
- View all use cases [direct]
- Healthcare [direct]
- Financial services [direct]
- Manufacturing [direct]
- Government [direct]
- View all industries [direct]
- View all solutions [direct]
- AI [direct]
- Software Development [direct]
- DevOps [direct]
- Security [direct]
- View all topics [direct]
- Customer stories [direct]
- Events & webinars [direct]
- Ebooks & reports [direct]
- Business insights [direct]
- GitHub Skills [direct]
- Customer support [direct]
- Community forum [direct]
- Trust center [direct]
- Partners [direct]
- View all resources [direct]
- GitHub Sponsors Fund open source developers [direct]
- Security Lab [direct]
- Maintainer Community [direct]
- GitHub Stars [direct]
- Archive Program [direct]
- Topics [direct]
- Trending [direct]
- Collections [direct]
- Copilot for Business Enterprise-grade AI features [direct]
- Premium Support Enterprise-grade 24/7 support [direct]
- Pricing [direct]
- Sign up [direct]
- Expert Services [direct]
- Introduction [direct]
- github.com/contact [direct]
- GitHub Privacy Statement [direct]
- Subscribe [direct]
- AI [direct]
- Security [direct]
- Roadmap [direct]
- Compare GitHub [direct]
- Developer API [direct]
- Education [direct]
- GitHub CLI [direct]
- GitHub Desktop [direct]
- GitHub Mobile [direct]
- Community Forum [direct]
- Status [direct]
- Contact GitHub [direct]
- What is Git? [direct]
- Sitemap [direct]
|
|