Categories

Methodologies

Semgrep: modern SAST in your pipeline

Semgrep has grown into one of the most pragmatic static analyzers in the ecosystem. A look at why it works where other SAST tools fail, and how to fit it into a pipeline without turning it into noise.

Technology

CodeQL in GitHub Advanced Security: what it actually covers

CodeQL is GitHub's semantic code analysis engine and the heart of the GitHub Advanced Security offering. It succeeded Semmle, which GitHub acquired on September 18, 2019, and its query libraries now cover almost every language a mid-sized company uses: Rust went generally available on October 14, 2025, and Kotlin moved to an official analyzer.