Home / Companies / GitHub / Blog / Post Details
Content Deep Dive

CodeQL team uses AI to power vulnerability detection in code

Blog post from GitHub

Post Details
Company
Date Published
Author
Walker Chabbott, Florin Coada
Word Count
585
Company Posts That Month
20
Language
English
Hacker News Points
-
Post removed?
No
Summary

Artificial Intelligence (AI) is transforming technology and security, and GitHub is utilizing AI to enhance both software development speed and security. GitHub Copilot includes a security filter to prevent common coding vulnerabilities, while the CodeQL team uses AI to optimize their modeling process for detecting vulnerabilities. By employing Large Language Models (LLMs), they've automated API modeling, significantly reducing false negatives and enhancing CodeQL's detection capabilities. This approach recently led to the discovery of a new CVE in Gradle. GitHub continues to integrate AI into security testing, aiming to improve security offerings and enable scalable variant analysis with tools like Multi-Repository Variant Analysis (MRVA), which allows for extensive code scanning across repositories.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Coding Assistant 1 195 27 18 -39%
LLM 1 2,134 271 94 -26%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.