Skip to content

Comparative evaluation of static analysis of program code using CodeQL, Semgrep and SonarQube

2026 · SOFT MEASUREMENTS AND COMPUTING · 0 citations

Abstract

This article provides a comparative evaluation of the static code analysis tools CodeQL, Semgrep, and SonarQube. The architectural principles, data flow analysis mechanisms, and propagation of potentially dangerous values, as well as the effectiveness of defect detection, are compared. Accuracy, recall, harmonic measure, false positive rate, and computational effort are used for quantitative evaluation. The advantages and limitations of each tool are identified, areas of rational application are defined, and the feasibility of combined analysis for ensuring software quality and security is substantiated.

View source

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.