github / github/codeql

Clarification on CodeQL CLI Licensing for On-Premise Azure DevOps Usage

Open
#21,487 1 comment 0 reactions 0 assignees View on GitHub
question
Dominant language
CodeQL
Stars
10.1k
Forks
2.1k
Avg merge
2d 15h
Merged PRs (30d)
141

Description

Hello,

I've reviewed the CodeQL CLI LICENSE.md (https://github.com/github/codeql-cli-binaries/blob/main/LICENSE.md), which states that local analysis of non-open-source codebases requires a paid GitHub Advanced Security (GHAS) license.

My questions:

1. Can the CodeQL CLI be used legally for local analysis (database creation/analysis) on private enterprise code hosted in on-premise Azure DevOps Server (not Azure DevOps Services/GitHub)? Or I must host my code in the cloud?

2. Does a standard GHAS license (via GitHub Enterprise Cloud/Server) cover this scenario, or is additional licensing required for Azure DevOps on-prem integration?

Contributor guide

Open the contributing guide

Research direction

Start with LICENSE.md and the CodeQL CLI licensing terms referenced in the issue. Verify whether local analysis of private code on on-premise Azure DevOps Server is covered and whether GHAS licensing addresses it. Done means providing an authoritative clarification or updating the relevant licensing documentation.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.