Comparative evaluation of static analysis of program code using CodeQL, Semgrep and SonarQube
Abstract
This article provides a comparative evaluation of the static code analysis tools CodeQL, Semgrep, and SonarQube. The architectural principles, data flow analysis mechanisms, and propagation of potentially dangerous values, as well as the effectiveness of defect detection, are compared. Accuracy, recall, harmonic measure, false positive rate, and computational effort are used for quantitative evaluation. The advantages and limitations of each tool are identified, areas of rational application are defined, and the feasibility of combined analysis for ensuring software quality and security is substantiated.