Towards Scalable and Cost-Efficient Vulnerability Detection: A Study on Automatic Query Generation
Static analysis remains a cornerstone of software security, yet the effectiveness of tools such as CodeQL is often limited by the substantial manual effort required to develop high-coverage query suites. While large language models (LLMs) have emerged as a potential solution for automated code reasoning, their practica...