Skip to main content

CodeQL Wrapper

Lint Build PyPI version Python versions Documentation License: MIT


A universal Python CLI wrapper for running CodeQL analysis seamlessly across any project architecture and CI/CD platform.

CodeQL Wrapper simplifies security analysis by providing a unified interface for CodeQL across monorepos, single repositories, and diverse CI/CD environments including Jenkins, GitHub Actions, Harness, Azure DevOps, and more.

Features

Universal Support
Works with both monorepos and single repositories

CI/CD Agnostic
Seamless integration across all major CI/CD platforms

Smart Language Detection
Automatically detects and analyzes multiple programming languages

SARIF Integration
Built-in support for SARIF upload to GitHub Advanced Security

Performance Optimized
Parallel processing and intelligent resource management

Auto-Installation
Automatically downloads and manages CodeQL CLI

Flexible Configuration
JSON-based configuration for complex project structures

Prerequisites

Requirement Version/Details
Python 3.9 or higher
Git For repository analysis
GitHub Token Required for SARIF upload functionality

Quick Start

Installation

Install CodeQL Wrapper from PyPI:

pip install codeql-wrapper

Basic Usage

Single Repository Analysis

Analyze a single repository with automatic language detection:

codeql-wrapper analyze /path/to/repository

Monorepo Analysis

Analyze all projects in a monorepo "using build-mode none" and upload results to GitHub Advanced Security:

codeql-wrapper analyze /path/to/monorepo --monorepo --upload-sarif

Targeted Analysis

Analyze only projects with changes (perfect for CI/CD):

codeql-wrapper analyze /path/to/repo --monorepo --only-changed-files --upload-sarif

Note: Ensure your GITHUB_TOKEN environment variable is set for SARIF upload functionality.


Advanced Configuration

For complex monorepo setups, create a .codeql.json configuration file in your repository root:

Click to view example configuration
{
  "projects": [
    {
      "path": "./monorepo/project-java-1",
      "build-mode": "manual",
      "build-script": "./build/project-java-1.sh",
      "queries": ["java-security-extended"],
      "language": "java"
    },
    {
      "path": "./monorepo/project-java-1", 
      "language": "javascript"
    },
    {
      "path": "./monorepo/project-python-1",
      "build-mode": "none"
    },
    {
      "path": "./monorepo/project-python-javascript-cpp",
      "build-mode": "none",
      "language": "javascript"
    }
  ]
}

Configuration Options

Option Description Values
path Relative path to the project Any valid path
build-mode How to build the project (default=none) none, manual, autobuild
build-script Custom build script path Path to executable script
queries CodeQL query suites to run Array of query suite names
language Target language (default=auto-detect) Any supported language

CI/CD Integration

Platform Status
GitHub Actions ✅ Supported
Harness ✅ Supported
Circle CI ✅ Supported
Azure Pipelines ✅ Supported
Jenkins ✅ Supported

Examples and implementation guides available at:
https://github.com/ModusCreate-fernandomatsuo-GHAS/poc-codeql-wrapper


Documentation

Complete documentation is available at:
https://moduscreate-perdigao-ghas-playground.github.io/codeql-wrapper


Contributing

We welcome contributions! Please see the contributing guidelines for more information.


License

This project is licensed under the MIT License - see the LICENSE file for details.


Made with ❤️ by the Modus Create team

Metadata

Release files for codeql-wrapper 0.1.13

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for codeql-wrapper 0.1.13
File Size Uploaded
codeql_wrapper-0.1.13.tar.gz 36.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for codeql-wrapper 0.1.13
File Interpreter ABI Platform
codeql_wrapper-0.1.13-py3-none-any.whl Python 3 none any Details

Total release size: 79.3 kB

Release files / codeql_wrapper-0.1.13.tar.gz

Download URL codeql_wrapper-0.1.13.tar.gz
Size 36.0 kB
Tags Source
SHA-256 checksum
How to use checksums
c3b50d4186a761d1f0ca5902d3de02d6fb980f82fe0549885e2e30de3fea107c
BLAKE2b-256 checksum
How to use checksums
fbe65e2b94214217d8632f27d5a5af3d8479c1e99a1fe87dfd41ff3719a3d248
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 28, 2025.

Transparency log

Release files / codeql_wrapper-0.1.13-py3-none-any.whl

Download URL codeql_wrapper-0.1.13-py3-none-any.whl
Size 43.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
e5cb10af33c0605495f1e748419e28e2369ba5e475b2597806d2d6748be9daad
BLAKE2b-256 checksum
How to use checksums
d3adbf7a86998b042c79ba1e4b1fbf632961f887ac77149439383a99ebf73f49
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.12.9

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Jul 28, 2025.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.13 This release

2 release files

0.1.12

2 release files

0.1.11

2 release files

0.1.9

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page