Movatterモバイル変換


[0]ホーム

URL:


Skip to contentSkip to sidebar
/Blog
Use Copilot for freeContact sales

The next step for LGTM.com: GitHub code scanning!

Today, GitHub code scanning has all of LGTM.com’s key features—and more! The time has therefore come to announce the plan for the gradual deprecation of LGTM.com.

Screenshot of the legacy view of LGTM.com
|3 minutes
  • Share:

Three years ago,the team that built LGTM.com joined GitHub. From that moment on, we have worked tirelessly to natively integrate its underlying CodeQL analysis technology into GitHub. In 2020, GitHub code scanning waslaunched in public beta, and later that year it becamegenerally available for everyone. GitHub code scanning is powered by the very same analysis engine: CodeQL.

We’ve since continued to invest in CodeQL and GitHub code scanning. Today, GitHub code scanning has all of LGTM.com’s key features—andmore! The time has therefore come to announce the plan for the gradual deprecation of LGTM.com.

End of August 2022: no more user sign-ups and new repositories

Starting at the end of August, LGTM.com will no longer accept new user sign-ups. It will also no longer be possible to add new repositories for analysis to LGTM.com. Existing users will continue to be able to log in and use LGTM.com, and the analysis of existing repositories will continue to work. However,historical analysis will no longer be performed–only new commits will be analyzed.

October: help migrate repositories to GitHub code scanning

We will do our best to help migrate repositories that actively use LGTM.com to flag potential security issues in their pull requests. For those repositories, we will create pull requests that add aGitHub Actions workflow that runs code scanning. Once that configuration file is merged, the repository’s source code (and future pull requests) will be scanned by GitHub code scanning. GitHub code scanning will flag any potential security issuesin pull requests and on the repository’ssecurity tab. Once that’s all working as it should, you can disable the LGTM.com integration.

Some repositories make use of advanced LGTM.com build and analysis configurations. In such cases, we might not be able to automatically propose a GitHub Actions workflow to set up code scanning. We will notify such repositories directly.

End of November: new commits and pull requests are no longer analyzed

At the end of November, LGTM.com will stop fetching new commits for the repositories that it analyzes. It will also stop analyzing pull requests on GitHub.com. Repositories that still use LGTM.com’s pull request analysis in the week(s) leading up to this deprecation phase will be reminded through a message in the pull request comments that are posted by LGTM.com.

16th of December: LGTM.com will be shut down

From the 16th of December, LGTM.com will no longer be available. This includes but is not limited to:

So long and thanks for all the fish!

On behalf of the entire LGTM.com team, we’d like to thank you all for joining us on this wonderful journey. From launching LGTM.com back in 2017, all the way throughGitHub’s acquisition of Semmle in 2019, the subsequentlaunch of GitHub code scanning, and all theimprovements we’ve since shipped: it’s been an absolutely amazing journey. Thank you!


FAQ

How do I get started with GitHub code scanning?

GitHub is committed to helping build safer and more secure software without compromising on the developer experience. To learn more or enable GitHub’s security features in repositories, like code scanning or Dependabot, check out thegetting started guide.

I love the LGTM.com query console—can I continue to use it?

If you are an active user of the LGTM.com query console and are not yet part of our beta program to test this functionality on GitHub, please leave us a notehere.

Where can I ask questions or leave feedback?

Please join our GitHub Discussion on this topichere!

How can I download data from LGTM.com before it goes offline?

Please take a look at thelarge number of APIs that are available on LGTM.com.

Written by

Related posts

News & insights

GitHub Copilot: Meet the new coding agent

Implementing features has never been easier: Just assign a task or issue to Copilot. It runs in the background with GitHub Actions and submits its work as a pull request.

Three people in very active poses are featured in front of a multi-colored background. They are all wearing brightly colored GitHub branded gear.
Company news

Code. Create. Commit. Welcome to dev/core

The new GitHub Shop collection is here. We’re celebrating you.

Company news

GitHub Availability Report: April 2025

In April, we experienced three incidents that resulted in degraded performance across GitHub services.

Explore more from GitHub

Docs

Docs

Everything you need to master GitHub, all in one place.

Go to Docs
The ReadME Project

The ReadME Project

Stories and voices from the developer community.

Learn more
GitHub Actions

GitHub Actions

Native CI/CD alongside code hosted in GitHub.

Learn more
Enterprise content

Enterprise content

Executive insights, curated just for you

Get started

We do newsletters, too

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.


[8]ページ先頭

©2009-2025 Movatter.jp