Automic VaultAutomic Vault

cask

codeql を Homebrew Cask でインストール

codeql のインストール経路、実行ファイル、メタデータ、AI エージェント向けセキュリティノートを確認します。

インストール

追加のインストールコマンド

macOS

Homebrew Cask確認済み · 100%
brew install --cask codeql

local Homebrew cask metadata

概要

パッケージ概要

Semantic code analysis engine

コマンドとエイリアス

  • codeql

履歴

プロジェクトの歴史と使われ方

CodeQL is GitHub's semantic code analysis engine and query language, packaged for command-line use through the CodeQL CLI. It is used for code scanning, security research, custom queries, and CI analysis.

プロジェクトの歴史

CodeQL originated at Semmle, whose semantic analysis technology was acquired by GitHub in 2019. GitHub subsequently made CodeQL central to GitHub Advanced Security and to code scanning workflows, with the CLI distributed from GitHub-controlled release repositories.

採用の歴史

Adoption moved from security research and Semmle users into GitHub's hosted code scanning product, GitHub Actions workflows, and enterprise security programs. The CLI remains important for users who need local analysis, custom queries, alternative CI systems, or prebuilt CodeQL databases.

使われ方

The CLI creates CodeQL databases, runs queries, analyzes code, produces SARIF results, manages CodeQL packs, and uploads results to GitHub code scanning. GitHub recommends the CodeQL bundle because it includes the CLI plus compatible queries and libraries.

パッケージ好きにとっての重要性

Package nerds care because the Homebrew cask wraps a large, versioned security-analysis toolchain that is otherwise commonly installed from GitHub release bundles. Its formula/cask packaging makes CodeQL feel like a normal terminal tool despite its bundled queries, extractors, and platform-specific binaries.

タイムライン

  • 2019: GitHub creates the codeql-cli-binaries repository for CLI binaries.
  • 2019: GitHub acquires Semmle, bringing CodeQL into GitHub.
  • 2020: CodeQL becomes a core part of GitHub code scanning and Advanced Security workflows.
  • 2026: Homebrew cask distributes CodeQL CLI 2.25.6.

Related projects

  • Related projects include github/codeql for queries and libraries, github/codeql-action for GitHub Actions integration, GitHub code scanning, SARIF tooling, and CodeQL for Visual Studio Code.

セキュリティ状態

保護ツール対応はまだ見つかっていません

codeql に一致するローカルシークレット処理マニフェストは見つかりませんでした。将来の対応で安定したパッケージ URL を使えるよう、Nucleus パッケージメタデータはここに公開されています。

インストール挙動

  • formula メタデータに Homebrew post-install フックは記録されていません。
  • Homebrew bottle メタデータは記録されていません。

推奨レビュー

エージェントに無人実行させる前に、このツールが平文の認証情報を読むか、リモート状態を書き込むか、成果物を公開するか、プラグインを起動するかを確認してください。

実行可能ファイル

インストールされる実行可能ファイル

コマンド種類公開範囲メモ
codeqlバイナリHomebrew cask バイナリcodeql

鮮度

バージョンと鮮度

これらの信号は、ページ生成時期、パッケージマネージャの活動、上流リリース比較を分けて示します。バージョン遅れは、証拠 URL と比較可能なバージョンがある場合だけ警告されます。

ページ生成日2026-07-25
マネージャ版2.26.1
マネージャ更新日2026-07-16
ローカルデータOK
上流not checked
検出された最新未検出

https://github.com/github/codeql-cli-binaries

インストールメタデータ

パッケージメタデータ

パッケージキーcask:codeql
バージョン2.26.1
パッケージマネージャHomebrew Cask
パッケージマネージャページhttps://formulae.brew.sh/cask/codeql
ホームページhttps://codeql.github.com/
リポジトリhttps://github.com/github/codeql-cli-binaries
上流ドキュメントhttps://codeql.github.com/
ソースアーカイブhttps://github.com/github/codeql-cli-binaries/releases/download/v2.26.1/codeql-osx64.zip
最終更新2026-07-16T10:20:31Z
Pulseupdated
SHA-25661c5d2b53e1cd8ee2bd57c31a55c57af53ffaafdf19c46d2341704c6cacf35d3
ダウンロード URLhttps://github.com/github/codeql-cli-binaries/releases/download/v2.26.1/codeql-osx64.zip
Bottle未記録
Homebrew post-install未定義
サービス宣言なし

レジストリ情報

ソースデータベース詳細

Source DatabaseHomebrew cask API
Taphomebrew/cask
Full Tokencodeql
Names
  • CodeQL
Artifacts
Deprecatedno
Disabledno

ソースデータベース一致

他のパッケージマネージャ記録

一致は外部パッケージマネージャインデックスから取得され、ローカルの Automic Vault パッケージリンクとは分けて表示されます。

Nix95%

codeql

nix profile install nixpkgs#codeql
  • normalized package name match
  • 一致条件: Codeql
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/co/codeql/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop95%

main/codeql

scoop install main/codeql
  • normalized package name match
  • 一致条件: Codeql
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/codeql.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

ソース経路

リポジトリデータから生成

このページは scripts/generate-pkg-sqlite.py が生成した非公開のパッケージ SQLite アーティファクトから av-web によって提供されます。

使用ソース

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment