CodeQL is best-in-class for code security scanning.
Free for open source, reasonable for private repos.
Free
Open source
$30/month per committer
Private repos
$19/month per committer
Add-on
Per-committer pricing can scale quickly
Requires GitHub Enterprise for some features
Security-conscious teams
Code quality
Vulnerability detection
Compliance needs
startup
Free for public repos. Budget $30-49/committer for private.
enterprise
Bundle with GitHub Enterprise for discounts.
SonarQube cheaper for code quality. Snyk similar for security. CodeQL best integration with GitHub.