CodeQL
AssessTools
A code analysis engine used by GitHub code scanning to detect security issues in source code and workflows.
Why it's here
Placed in Assess: 2 article(s) of evidence from 2 source(s), led by security coverage, with 1 in the last 30 days. Confidence 41%.
Evidence (2)
- 6InfoQ·8/10/2026product_launchGitHub Launches AI-Assisted Code Quality Checks for Enterprise and Team
GitHub Code Quality is now generally available for GitHub Enterprise Cloud and GitHub Team. It combines CodeQL analysis with AI-assisted detection of maintainability and reliability issues, and can use Copilot Autofix to propose changes in pull requests.
- 7GitHub Blog·7/1/2026securityGitHub urges maintainers to enable key security settings
GitHub Security Lab highlights six free security settings that maintainers can enable in under 30 minutes to improve project security posture. The recommendations include adding a SECURITY.md file, enabling private vulnerability reporting, secret scanning with push protection, Dependabot and dependency review, and code scanning.