CodeQL Wrapper
A universal Python CLI wrapper for running CodeQL analysis seamlessly across any project architecture and CI/CD platform.
CodeQL Wrapper simplifies security analysis by providing a unified interface for CodeQL across monorepos, single repositories, and diverse CI/CD environments including Jenkins, GitHub Actions, Harness, Azure DevOps, and more.
Features
|
Universal Support CI/CD Agnostic Smart Language Detection SARIF Integration |
Performance Optimized Auto-Installation Flexible Configuration |
Prerequisites
| Requirement | Version/Details |
|---|---|
| Python | 3.9 or higher |
| Git | For repository analysis |
| GitHub Token | Required for SARIF upload functionality |
Quick Start
Installation
Install CodeQL Wrapper from PyPI:
pip install codeql-wrapper
Basic Usage
Single Repository Analysis
Analyze a single repository with automatic language detection:
codeql-wrapper analyze /path/to/repository
Monorepo Analysis
Analyze all projects in a monorepo "using build-mode none" and upload results to GitHub Advanced Security:
codeql-wrapper analyze /path/to/monorepo --monorepo --upload-sarif
Targeted Analysis
Analyze only projects with changes (perfect for CI/CD):
codeql-wrapper analyze /path/to/repo --monorepo --only-changed-files --upload-sarif
Note: Ensure your
GITHUB_TOKENenvironment variable is set for SARIF upload functionality.
Advanced Configuration
For complex monorepo setups, create a .codeql.json configuration file in your repository root:
Click to view example configuration
{
"projects": [
{
"path": "./monorepo/project-java-1",
"build-mode": "manual",
"build-script": "./build/project-java-1.sh",
"queries": ["java-security-extended"],
"language": "java"
},
{
"path": "./monorepo/project-java-1",
"language": "javascript"
},
{
"path": "./monorepo/project-python-1",
"build-mode": "none"
},
{
"path": "./monorepo/project-python-javascript-cpp",
"build-mode": "none",
"language": "javascript"
}
]
}
Configuration Options
| Option | Description | Values |
|---|---|---|
path |
Relative path to the project | Any valid path |
build-mode |
How to build the project (default=none) | none, manual, autobuild |
build-script |
Custom build script path | Path to executable script |
queries |
CodeQL query suites to run | Array of query suite names |
language |
Target language (default=auto-detect) | Any supported language |
CI/CD Integration
| Platform | Status |
|---|---|
| GitHub Actions | ✅ Supported |
| Harness | ✅ Supported |
| Circle CI | ✅ Supported |
| Azure Pipelines | ✅ Supported |
| Jenkins | ✅ Supported |
Examples and implementation guides available at:
https://github.com/ModusCreate-fernandomatsuo-GHAS/poc-codeql-wrapper
Documentation
Complete documentation is available at:
https://moduscreate-perdigao-ghas-playground.github.io/codeql-wrapper
Contributing
We welcome contributions! Please see the contributing guidelines for more information.
License
This project is licensed under the MIT License - see the LICENSE file for details.
Made with ❤️ by the Modus Create team
Metadata
Release files for codeql-wrapper 0.1.13
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| codeql_wrapper-0.1.13.tar.gz | 36.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| codeql_wrapper-0.1.13-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 79.3 kB
Release files / codeql_wrapper-0.1.13.tar.gz
| Download URL | codeql_wrapper-0.1.13.tar.gz |
|---|---|
| Size | 36.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
c3b50d4186a761d1f0ca5902d3de02d6fb980f82fe0549885e2e30de3fea107c
|
|
BLAKE2b-256 checksum How to use checksums |
fbe65e2b94214217d8632f27d5a5af3d8479c1e99a1fe87dfd41ff3719a3d248
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 28, 2025.
Transparency logRelease files / codeql_wrapper-0.1.13-py3-none-any.whl
| Download URL | codeql_wrapper-0.1.13-py3-none-any.whl |
|---|---|
| Size | 43.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e5cb10af33c0605495f1e748419e28e2369ba5e475b2597806d2d6748be9daad
|
|
BLAKE2b-256 checksum How to use checksums |
d3adbf7a86998b042c79ba1e4b1fbf632961f887ac77149439383a99ebf73f49
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.12.9
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 28, 2025.
Transparency log