GitHub buys code analysis tool Semmle, which helps identify security vulnerabilities and has Microsoft, Google among clients; Semmle raised $31M in VC funding
Microsoft's GitHub today announced that it has acquired Semmle, a code analysis tool that helps developers and security researchers …
TechCrunchFrederic Lardinois
Context & Ripple Effects
A year after Microsoft moved to buy GitHub, its new subsidiary is buying the technology that will anchor GitHub's security push: Semmle, whose code-analysis engine already counts Microsoft and Google among clients and had raised $31M in VC funding. The deal puts a proven static-analysis platform in-house rather than leaving GitHub dependent on third-party scanners.
That in-housing set up everything that followed: GitHub's code-scanning rollout in 2020 ran on the acquired tech (CodeQL), and by 2024 the same engine powered Copilot-driven autofix for GitHub Advanced Security customers — turning detection into automated remediation inside the platform where developers already work.
First-order effects
Google, previously a Semmle client, now relies on a tool owned by a direct competitor's parent — a likely catalyst to seek neutral alternatives.
GitHub gains CodeQL outright, giving its paid Advanced Security tier a differentiated scanner it no longer has to license or partner for.
Second-order effects
Independent rivals become the beneficiaries of neutrality concerns: Semgrep went on to raise a $53M Series C in 2023 and then a $100M Series D in 2025, building an autonomous code-security platform positioned against GitHub's bundled stack.
Bundling shifts pricing pressure onto standalone SAST vendors, who must now compete against a scanner given away inside the developer platform itself.
Third-order effects
If the pattern holds, application security consolidates into dev-platform suites — detect-and-fix loops like GitHub's Copilot autofix make scanning a feature rather than a product category, forcing independents toward multi-platform neutrality or deeper automation.
The trend: Code security is collapsing into developer platforms, as acquisitions like Semmle let GitHub own the scan-to-fix loop while funded independents like Semgrep compete on neutrality and automation.
Apart from the news about acquisition of @Semmle which is a market leader in Variant Analysis, GitHub clearly sees the big picture of Application Security. Slow clap 👏 https://github.blog/...
Holy shit, GitHub is becoming a CVE authority which will allow filing for CVE numbers directly from the web UI. Also the new security advisory workflow is looking *sweet*!!
A warm welcome to Oege and the rest of @Semmle! This really confirms the value of treating code as data, and on behalf of the Semantic Code team, I can't wait to see what we can build together! (And I'm also excited to have more Oxonians on the team 😁) https://twitter.com/...
What a gr8 move. I hear from ppl all the time that tell me how hard it is to get a CVE. Having @github as a CNA is critically important. https://twitter.com/...
Our mission is to build a global platform for developer collaboration. But that platform needs to be one that all of us can use to secure the world's software, together. Learn more on how you can help. https://github.blog/...
Incredible, industry-shifting work at @github & @Semmle in helping the entire software supply chain detect, eradicate, and prevent entire classes of security vulnerabilities. Honestly this has me hopeful that finally, we may see certain classes of bugs eradicated in my lifetime. …
10 years ago I discovered the amazing @semmle technology and team, I knew they would make a difference in the industry. 1 year ago I was excited to join them, and today I am even more excited by the huge step we are taking by joining @github https://blog.semmle.com/... #securecod…
badass acquisition.. congrats to all Semmle hackers there for joining GitHub :) https://techcrunch.com/... @fjserna @nicowaisman @agustingianni @mmolgtm @Nosoynadiemas @kevin_backhouse et al.
@github would not issue CVE's for Microsoft applications as @Microsoft is already a CNA that issues their own. GitHub is allowed to issue CVE's for reported vulnerabilities assuming the vendor in question is not already a CNA (as far as I understand).
As for volume... just do a search for “fix buffer overflows” or “fix XSS” in issues and imagine them all having a nicely labelled CVE. It's an exciting time to be alive.
Big news! Semmle is joining the @Github team to bring community-powered security analysis to millions of developers. Learn more from Semmle CEO @oegerikus here: https://blog.semmle.com/...
> GitHub ... is now a CVE Numbering Authority. ..Maintainers will be able to report vulnerabilities...GitHub will assign IDs & add [them] to the National Vulnerability Database. Sounds like there'll be an influx of CVEs now. What “CVE” means is probably going to change a bit 😅