Semgrep vs CodeQL for local developer review.
Compare Semgrep and CodeQL when the practical need is local feedback, agent repair context, SARIF evidence, and a fast PR security gate.
radar scan . --quickWhere Radar fits
Semgrep and CodeQL solve important AppSec problems, but many developers still need a local merge-readiness scanner before the PR exists.
- Local CLI review
- MCP agent handoff
- Git hooks
- GitHub Actions SARIF
Evidence to inspect
Use “Semgrep vs CodeQL for local developer review.” as the scope for this decision: verify the input, finding detail, workflow handoff, and product boundary before you install or buy.
Run Code Radar locally
Use Radar around deeper tools
Use deeper semantic analysis where it belongs, then use Radar for daily local checks, generated-code review, and concise pull-request enforcement.
radar scan . --quick
radar scan . --format sarif --fail-on highPrimary sources
- GitHubCodeQL documentation
- OASIS OpenSARIF 2.1.0 standard
Validate the workflow on your own code.
Apply this page’s evidence to one real repository. For “Semgrep vs CodeQL for local developer review.”, confirm which finding is produced, whether the proposed next step is reproducible, and where local scanning, reports, agents, or CI should stop or expand.