/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

GitHub buys code analysis tool Semmle, which helps identify security vulnerabilities and has Microsoft, Google among clients; Semmle raised $31M in VC funding

Microsoft's GitHub today announced that it has acquired Semmle, a code analysis tool that helps developers and security researchers …

TechCrunch Frederic Lardinois

Context & Ripple Effects

A year after Microsoft moved to buy GitHub, its new subsidiary is buying the technology that will anchor GitHub's security push: Semmle, whose code-analysis engine already counts Microsoft and Google among clients and had raised $31M in VC funding. The deal puts a proven static-analysis platform in-house rather than leaving GitHub dependent on third-party scanners.

That in-housing set up everything that followed: GitHub's code-scanning rollout in 2020 ran on the acquired tech (CodeQL), and by 2024 the same engine powered Copilot-driven autofix for GitHub Advanced Security customers — turning detection into automated remediation inside the platform where developers already work.

First-order effects

  • Google, previously a Semmle client, now relies on a tool owned by a direct competitor's parent — a likely catalyst to seek neutral alternatives.
  • GitHub gains CodeQL outright, giving its paid Advanced Security tier a differentiated scanner it no longer has to license or partner for.

Second-order effects

  • Independent rivals become the beneficiaries of neutrality concerns: Semgrep went on to raise a $53M Series C in 2023 and then a $100M Series D in 2025, building an autonomous code-security platform positioned against GitHub's bundled stack.
  • Bundling shifts pricing pressure onto standalone SAST vendors, who must now compete against a scanner given away inside the developer platform itself.

Third-order effects

  • If the pattern holds, application security consolidates into dev-platform suites — detect-and-fix loops like GitHub's Copilot autofix make scanning a feature rather than a product category, forcing independents toward multi-platform neutrality or deeper automation.

The trend: Code security is collapsing into developer platforms, as acquisitions like Semmle let GitHub own the scan-to-fix loop while funded independents like Semgrep compete on neutrality and automation.

Discussion

  • @andrzejdyjak Andrzej Dyjak on x
    Apart from the news about acquisition of @Semmle which is a market leader in Variant Analysis, GitHub clearly sees the big picture of Application Security. Slow clap 👏 https://github.blog/...
  • @nicowaisman Nico Waisman on x
    We are @github now! \o/ https://twitter.com/...
  • @yoshuawuyts Yosh on x
    Holy shit, GitHub is becoming a CVE authority which will allow filing for CVE numbers directly from the web UI. Also the new security advisory workflow is looking *sweet*!!
  • @dcreager Douglas Creager on x
    A warm welcome to Oege and the rest of @Semmle! This really confirms the value of treating code as data, and on behalf of the Semantic Code team, I can't wait to see what we can build together! (And I'm also excited to have more Oxonians on the team 😁) https://twitter.com/...
  • @techjournalist Sean Kerner on x
    What a gr8 move. I hear from ppl all the time that tell me how hard it is to get a CVE. Having @github as a CNA is critically important. https://twitter.com/...
  • @danhatesnumbers Dan Murphy on x
    So GitHub are becoming a CVE Numbering Authority. Nice!
  • @github @github on x
    Our mission is to build a global platform for developer collaboration. But that platform needs to be one that all of us can use to secure the world's software, together. Learn more on how you can help. https://github.blog/...
  • @oegerikus Oege de Moor on x
    1/7 I'm overjoyed to share that @semmle is joining @github! https://blog.semmle.com/...
  • @k8em0 Katie Moussouris on x
    Incredible, industry-shifting work at @github & @Semmle in helping the entire software supply chain detect, eradicate, and prevent entire classes of security vulnerabilities. Honestly this has me hopeful that finally, we may see certain classes of bugs eradicated in my lifetime. …
  • @xcorail Xavier Ren-Corail on x
    10 years ago I discovered the amazing @semmle technology and team, I knew they would make a difference in the industry. 1 year ago I was excited to join them, and today I am even more excited by the huge step we are taking by joining @github https://blog.semmle.com/... #securecod…
  • @shiftreduce @shiftreduce on x
    badass acquisition.. congrats to all Semmle hackers there for joining GitHub :) https://techcrunch.com/... @fjserna @nicowaisman @agustingianni @mmolgtm @Nosoynadiemas @kevin_backhouse et al.
  • @nathanmcnulty Nathan McNulty on x
    @github would not issue CVE's for Microsoft applications as @Microsoft is already a CNA that issues their own. GitHub is allowed to issue CVE's for reported vulnerabilities assuming the vendor in question is not already a CNA (as far as I understand).
  • @kurtseifried Kurt Seifried on x
    As for volume... just do a search for “fix buffer overflows” or “fix XSS” in issues and imagine them all having a nicely labelled CVE. It's an exciting time to be alive.
  • @quinnypig Corey Quinn on x
    It says a lot about Github and by extension Microsoft that the overwhelming response to this announcement is positive. https://twitter.com/...
  • @semmle @semmle on x
    Big news! Semmle is joining the @Github team to bring community-powered security analysis to millions of developers. Learn more from Semmle CEO @oegerikus here: https://blog.semmle.com/...
  • @rvtond Rijnard van Tonder on x
    > GitHub ... is now a CVE Numbering Authority. ..Maintainers will be able to report vulnerabilities...GitHub will assign IDs & add [them] to the National Vulnerability Database. Sounds like there'll be an influx of CVEs now. What “CVE” means is probably going to change a bit 😅
  • @nicebrogg @nicebrogg on x
    GitHub acquires code analysis tool Semmle | Microsoft's GitHub today announced that it has acquired Semmle, a code anal ... https://nicebrogg.com/...