# ASTTeam/CodeQL

《深入理解CodeQL》Finding vulnerabilities with CodeQL.

Repository: https://github.com/ASTTeam/CodeQL
Canonical: https://ross.abutalabs.com/products/astteam-codeql
License Family: other
Topics: 0e0w, codeql, hackjava, hackaspx, hackgolang, javasec, ql, learning-codeql, codeql-queries, semmle-ql, devsecops, sast
Last push: 2023-11-21T04:58:48+00:00

## Health v2 (maintenance only)
Score: 32/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 35, longevity 100
- inputs: {"age_days": 1724, "days_push": 1016, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases, no_license
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1789, forks 181 (observed 2026-08-28T04:05:36.425635+00:00)

## What it is
A curated Chinese-language knowledge base titled 'Deep Understanding of CodeQL' collecting resources, fundamentals, and case studies for finding vulnerabilities with CodeQL. It aggregates official docs, community notes, videos, and academic publications about semantic code analysis and SAST.

## Use cases
- learn codeql from scratch
- find vulnerabilities with codeql
- write codeql queries for java security
- study static application security testing
- find similar vulnerabilities using known CVE patterns
- learn semantic code analysis for code audit

## When to choose
- you want a curated index of CodeQL tutorials, notes, and case studies
- you prefer Chinese-language learning material for CodeQL
- you are researching vulnerability discovery via semantic code queries

## When to avoid
- you need the CodeQL tool itself or official documentation
- you need actively maintained content (last updated November 2023)
- you need a runnable software artifact rather than a resource collection

## Facets
- artifact type: learning-resource
- maturity: maintenance
- function: security, developer-tools, documentation
- domain: security, developer-tools, tutorials
- platform: cross-platform
- tags: codeql, static-analysis, sast, vulnerability-research, code-audit, ql, semmle, devsecops, awesome-list

## Member repositories
- ASTTeam/CodeQL (main) score 32

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:36.425635+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:23:18.040315+00:00, confidence not recorded.
  - readme: https://github.com/ASTTeam/CodeQL (fetched 2026-08-28T04:05:36.425635+00:00, sha 214942adacfe)
- Data as of 2026-08-30T08:39:29.467469+00:00.
