From Wikipedia, the free encyclopedia
Jump to navigation Jump to search
Semmle logo.png
Type of businessSubsidiary
FoundedDecember 2006 (2006-12) in Oxford, England
HeadquartersSan Francisco, California, U.S.
Founder(s)Oege de Moor
Key peopleOege de Moor, Pavel Augustinov, Julian Tibble
IndustrySoftware analysis
ProductsCode analysis software and services
ParentGitHub[1] (2019–present)

Semmle Inc is a code-analysis platform provider, with offices in San Francisco, Seattle, New York, Oxford, Valencia and Copenhagen.[2] Semmle was acquired by GitHub (itself owned by Microsoft) on 18 September 2019 for an undisclosed amount.[3] Semmle's LGTM technology automates code review, tracks developer contributions, and flags software security issues.[3] The LGTM platform leverages the CodeQL query engine (formerly QL)[4] to perform semantic analysis on software code bases. GitHub aims to integrate Semmle technology to provide continuous vulnerability detection services.[5] In November 2019, use of CodeQL was made free for research and open source.[6] CodeQL either shares a direct pedigree with .QL (dot-que-ell), which derives from the Datalog family tree, or is an evolution of similar technology.[clarification needed]

SemmleCode is an object-oriented query language for deductive databases developed by Semmle. It is distinguished within this class by its support for recursive query.

Corporate background[edit]

Built on research in compilers and data analysis, developed by a team from the University of Oxford, Semmle's patented technology creates a knowledge base using all available data about the software development process (source code, issue tickets, development costs, team location, etc.), and allows its users to accurately and efficiently query that knowledge base. Results are presented in user interfaces designed for the different needs of developers, managers, and executives. Semmle purports that insights derived from application of the Semmle technology helps teams staff projects more intelligently, retain and develop talent better, control software costs, and deliver new functionality sooner.[citation needed]

The company is headquartered in San Francisco, with its development operations based in Blue Boar Court, Alfred Street, central Oxford, England. Semmle's customers include Credit Suisse, NASA and Dell.[7]

SemmleCode background[edit]


SemmleCode builds on academic research on querying the source of software programs. The first such system was Linton's Omega system,[8] where queries were phrased in QUEL. QUEL did not allow for recursion in queries, making it difficult to inspect hierarchical program structures such as the call graph. The next significant development was therefore the use of logic programming, which does allow such recursive queries, in the XL C++ Browser.[9] The disadvantage of using a full logic programming language is however that it is very difficult to attain acceptable efficiency. The CodeQuest system,[10] developed at the University of Oxford, was the first to exploit the observation that Datalog, a very restrictive version of logic programming, is in the sweet spot between expressive power and efficiency. The QL query language is an object-oriented version of Datalog.


The early research works on querying the source of software programs spun off a number of industrial applications. In particular it became the cornerstone of systems for application intelligence (data mining on the source of software systems) and software renovation. In 2007, Paris-based CAST[11] is one of the market leaders in that area, and other significant players include BluePhoenix in Herzliya, Israel. SemmleCode differs from these systems in its use of an object-oriented query language, which allows programmers to easily formulate new queries that are particular to their own project.

A full account of the academic and industrial developments leading up to the creation of SemmleCode can be found in a paper by Hajiyev et al.[12]

Sample query in QL[edit]

To illustrate the use of QL, consider the well-known rule in object-oriented programming that public fields should be declared final. To find violations of that rule, we should search for fields that are public but not final. In QL, that requirement is expressed as follows:

 from Field f
 where f.hasModifier("public")
 select f.getDeclaringType().getPackage(),

Here not only is the offending field f selected, but also the package and type in which its declaration occurs.

SemmleCode integration with development environments[edit]

SemmleCode provides a user interface via the Eclipse IDE to query Java code (both source code and bytecode) as well as XML files, and to edit QL queries. This is however but one application of the technology that underlies it: QL can be used to query any other type of complex data.

As part of the fold into the Microsoft/GitHub corporate house, the original Eclipse-based workflow has been supplanted with a workflow based around Microsoft's Visual Studio Code.[4]

See also[edit]


  1. ^ "GitHub acquires Semmle to help developers spot code exploits". Retrieved 20 September 2019.
  2. ^ "Contact Us". Semmle.
  3. ^ a b Lardinois, Frederic (18 September 2019). "GitHub acquires code analysis tool Semmle". TechCrunch. Retrieved 13 March 2021.
  4. ^ a b "Introducing CodeQL". Semmle. September 2019. Retrieved 13 March 2021. the 'QL' product and tooling has been renamed to CodeQL ... what was previously called a 'QL snapshot' is now a CodeQL database.
  5. ^ De Simone, Sergio (19 September 2019). "GitHub to Integrate Semmle Code Analysis for Continuous Vulnerability Detection". infoq. InfoQ. Retrieved 13 March 2021.
  6. ^ Krill, Paul (15 November 2019). "GitHub makes CodeQL free for research and open source". InfoWorld. Retrieved 13 March 2021.
  7. ^ "Spin-out company Semmle secures $8M from Accel Partners" (Press release). University of Oxford. September 16, 2014. Retrieved September 18, 2015.
  8. ^ "Linton's Omega system". USA: University of California, Berkeley. 1983.
  9. ^ Shahram Javey, Kin’ichi Mitsui, Hiroaki Nakamura, Tsuyoshi Ohira, Kazu Yasuda, Kazushi Kuse, Tsutomu Kamimura, and Richard Helm. Architecture of the XL C++ browser. In CASCON ’92: Proceedings of the 1992 conference of the Centre for Advanced Studies on Collaborative research, pages 369–379. IBM Press, 1992.
  10. ^ "CodeQuest system". UK: Oxford University Computing Laboratory. Archived from the original on October 9, 2006.
  11. ^ "CAST Software".
  12. ^ Elnar Hajiyev, Mathieu Verbaere, and Oege de Moor, CodeQuest: Scalable Source Code Queries with Datalog. In ECOOP 2006: Proceedings of the 2006 European Conference on Object-Oriented Programming, pages 2–27. Springer, 2006.

Further reading[edit]

  • Mark A. Linton. Implementing relational views of programs. In Peter B. Henderson, editor, Software Development Environments (SDE), pages 132–140, 1984.

External links[edit]