# Sharing security expertise through CodeQL packs (Part I)

DevFeed: [Sharing security expertise through CodeQL packs (Part I)](<https://devfeed.tech/articles/sharing-security-expertise-through-codeql-packs-part-i-68356.md>)

Original publisher: [Read original article](<https://github.blog/security/vulnerability-research/sharing-security-expertise-through-codeql-packs-part-i/>)

Author: Andrew Eisenberg

Published: 2022-04-19T17:00:02Z

Content type: tutorial

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [software composition analysis](<https://devfeed.tech/topics/software-composition-analysis.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [code-scanning](<https://devfeed.tech/tags/code-scanning.md>), [codeql](<https://devfeed.tech/tags/codeql.md>), [github-advanced-security](<https://devfeed.tech/tags/github-advanced-security.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

## AI overview

The article explains how to create, publish, and use CodeQL query packs to share vulnerability detection queries. It covers pack configuration, dependency installation, publishing to GitHub's registry, and running packs through the CodeQL CLI or GitHub code scanning workflows.

## Source excerpt

Introducing CodeQL packs to help you codify and share your knowledge of vulnerabilities.