Automic VaultAutomic Vault

cask

使用 Homebrew Cask 安装 codeql

查看 codeql 的安装路径、可执行文件、元数据以及面向 AI 代理工作流的安全说明。

安装

其他安装命令

macOS

Homebrew Cask已验证 · 100%
brew install --cask codeql

local Homebrew cask metadata

概览

软件包摘要

Semantic code analysis engine

命令和别名

  • codeql

历史

项目历史与用法

CodeQL is GitHub's semantic code analysis engine and query language, packaged for command-line use through the CodeQL CLI. It is used for code scanning, security research, custom queries, and CI analysis.

项目历史

CodeQL originated at Semmle, whose semantic analysis technology was acquired by GitHub in 2019. GitHub subsequently made CodeQL central to GitHub Advanced Security and to code scanning workflows, with the CLI distributed from GitHub-controlled release repositories.

采用历史

Adoption moved from security research and Semmle users into GitHub's hosted code scanning product, GitHub Actions workflows, and enterprise security programs. The CLI remains important for users who need local analysis, custom queries, alternative CI systems, or prebuilt CodeQL databases.

使用方式

The CLI creates CodeQL databases, runs queries, analyzes code, produces SARIF results, manages CodeQL packs, and uploads results to GitHub code scanning. GitHub recommends the CodeQL bundle because it includes the CLI plus compatible queries and libraries.

为什么软件包爱好者会关心

Package nerds care because the Homebrew cask wraps a large, versioned security-analysis toolchain that is otherwise commonly installed from GitHub release bundles. Its formula/cask packaging makes CodeQL feel like a normal terminal tool despite its bundled queries, extractors, and platform-specific binaries.

时间线

  • 2019: GitHub creates the codeql-cli-binaries repository for CLI binaries.
  • 2019: GitHub acquires Semmle, bringing CodeQL into GitHub.
  • 2020: CodeQL becomes a core part of GitHub code scanning and Advanced Security workflows.
  • 2026: Homebrew cask distributes CodeQL CLI 2.25.6.

Related projects

  • Related projects include github/codeql for queries and libraries, github/codeql-action for GitHub Actions integration, GitHub code scanning, SARIF tooling, and CodeQL for Visual Studio Code.

安全态势

尚未找到受保护工具覆盖

没有找到 codeql 的匹配本地密钥处理 manifest。Nucleus 软件包元数据仍在此发布,以便未来覆盖拥有稳定的软件包 URL。

安装行为

  • formula 元数据中未记录 Homebrew post-install 钩子。
  • 未记录 Homebrew bottle 元数据。

建议审查

在无人值守的代理使用前,请检查该工具是否读取明文凭据、写入远程状态、发布制品或调用插件。

可执行文件

已安装的可执行文件

命令类型暴露范围备注
codeql二进制Homebrew cask 二进制codeql

新鲜度

版本和新鲜度

这些信号区分页生成时间、软件包管理器活动和上游发布比较。只有存在证据 URL 和可比较版本时,才会提示版本落后。

页面生成时间2026-07-25
管理器版本2.26.1
管理器更新时间2026-07-16
本地数据OK
上游not checked
检测到的最新版本未检测到

https://github.com/github/codeql-cli-binaries

安装元数据

软件包元数据

软件包键cask:codeql
版本2.26.1
软件包管理器Homebrew Cask
软件包管理器页面https://formulae.brew.sh/cask/codeql
主页https://codeql.github.com/
仓库https://github.com/github/codeql-cli-binaries
上游文档https://codeql.github.com/
源码归档https://github.com/github/codeql-cli-binaries/releases/download/v2.26.1/codeql-osx64.zip
最后更新2026-07-16T10:20:31Z
Pulseupdated
SHA-25661c5d2b53e1cd8ee2bd57c31a55c57af53ffaafdf19c46d2341704c6cacf35d3
下载 URLhttps://github.com/github/codeql-cli-binaries/releases/download/v2.26.1/codeql-osx64.zip
Bottle未记录
Homebrew post-install未定义
服务未声明

注册表事实

源数据库详情

Source DatabaseHomebrew cask API
Taphomebrew/cask
Full Tokencodeql
Names
  • CodeQL
Artifacts
Deprecatedno
Disabledno

源数据库匹配

其他软件包管理器记录

匹配项来自外部软件包管理器索引,并与本地 Automic Vault 软件包链接分开显示。

Nix95%

codeql

nix profile install nixpkgs#codeql
  • normalized package name match
  • 匹配方式:Codeql
nixpkgs package indexes · api.github.com · nixpkgs package indexes: pkgs/by-name/co/codeql/package.nix from https://api.github.com/repos/NixOS/nixpkgs/git/trees/master?recursive=1
Scoop95%

main/codeql

scoop install main/codeql
  • normalized package name match
  • 匹配方式:Codeql
Scoop official bucket manifest trees · api.github.com · Scoop official bucket manifest trees: bucket/codeql.json from https://api.github.com/repos/ScoopInstaller/Main/git/trees/master?recursive=1

来源线索

由仓库数据生成

此页面由 av-webscripts/generate-pkg-sqlite.py 生成的私有软件包 SQLite 工件提供。

使用的来源

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated package history
  • external package-manager database matches
  • package relationship graph
  • package version freshness
  • package-page enrichment