Automic VaultAutomic Vault

cask

Install codeql with Homebrew Cask

Semantic code analysis engine. Version 2.26.1 via Homebrew Cask; verified 2026-07-16. Also installable with nix: nix profile install nixpkgs#codeql.

install

Additional install commands

macOS

Homebrew Caskverified · 100%
brew install --cask codeql

local Homebrew cask metadata

overview

Package summary

Semantic code analysis engine

Commands and aliases

  • codeql

history

Project history and usage

CodeQL is GitHub's semantic code analysis engine and query language, packaged for command-line use through the CodeQL CLI. It is used for code scanning, security research, custom queries, and CI analysis.

Project history

CodeQL originated at Semmle, whose semantic analysis technology was acquired by GitHub in 2019. GitHub subsequently made CodeQL central to GitHub Advanced Security and to code scanning workflows, with the CLI distributed from GitHub-controlled release repositories.

Adoption history

Adoption moved from security research and Semmle users into GitHub's hosted code scanning product, GitHub Actions workflows, and enterprise security programs. The CLI remains important for users who need local analysis, custom queries, alternative CI systems, or prebuilt CodeQL databases.

How it is used

The CLI creates CodeQL databases, runs queries, analyzes code, produces SARIF results, manages CodeQL packs, and uploads results to GitHub code scanning. GitHub recommends the CodeQL bundle because it includes the CLI plus compatible queries and libraries.

Why package nerds care

Package nerds care because the Homebrew cask wraps a large, versioned security-analysis toolchain that is otherwise commonly installed from GitHub release bundles. Its formula/cask packaging makes CodeQL feel like a normal terminal tool despite its bundled queries, extractors, and platform-specific binaries.

Timeline

  • 2019: GitHub creates the codeql-cli-binaries repository for CLI binaries.
  • 2019: GitHub acquires Semmle, bringing CodeQL into GitHub.
  • 2020: CodeQL becomes a core part of GitHub code scanning and Advanced Security workflows.
  • 2026: Homebrew cask distributes CodeQL CLI 2.25.6.

Related projects

  • Related projects include github/codeql for queries and libraries, github/codeql-action for GitHub Actions integration, GitHub code scanning, SARIF tooling, and CodeQL for Visual Studio Code.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for codeql. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • No Homebrew bottle metadata was recorded.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

executables

Installed executables

CommandKindExposureNote
codeqlbinaryHomebrew cask binarycodeql

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version2.26.1
manager updated2026-07-16
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/github/codeql-cli-binaries

install metadata

Package metadata

Package keycask:codeql
Version2.26.1
Package managerHomebrew Cask
Package manager pagehttps://formulae.brew.sh/cask/codeql
Homepagehttps://codeql.github.com/
Repositoryhttps://github.com/github/codeql-cli-binaries
Upstream docshttps://codeql.github.com/
Source archivehttps://github.com/github/codeql-cli-binaries/releases/download/v2.26.1/codeql-osx64.zip
Last updated2026-07-16T10:20:31Z
Pulseupdated
SHA-25661c5d2b53e1cd8ee2bd57c31a55c57af53ffaafdf19c46d2341704c6cacf35d3
Download URLhttps://github.com/github/codeql-cli-binaries/releases/download/v2.26.1/codeql-osx64.zip
Bottlenot recorded
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew cask API
Taphomebrew/cask
Full Tokencodeql
Names
  • CodeQL
Artifacts
Deprecatedno
Disabledno

source database matches

Other package-manager records

Matches are pulled from external package-manager indexes and kept separate from local Automic Vault package links.

Nix95%

codeql

nix profile install nixpkgs#codeql
  • normalized package name match
  • Matched by: Codeql
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/co/codeql/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop95%

main/codeql

scoop install main/codeql
  • normalized package name match
  • Matched by: Codeql
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/codeql.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment