CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis
CodeQL 2.27.2 is now available, adding a C++ regular-expression parser and analysis improvements across several languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues in your code. The Default suite runs 498 security queries covering 170 CWEs. The Extended suite adds 131 queries covering 32 more CWEs.
C/C++
- CodeQL now parses regular expressions that use the ECMAScript grammar in
std::regex. - We’ve added SQL-injection sink models for the Comdb2 C API as well as flow summaries for Bloomberg BDE codecs and byte-stream deserializers.
Go
- CodeQL now models the
github.com/coder/websocketimport path, in addition tonhooyr.io/websocket.
Rust
- The Rust extractor now supports the
AnyAttrandDocCommentclasses. - We’ve improved data flow for async blocks used with
awaitas well as added flow summaries fornative-tls,async-native-tls, andtokio-native-tls.
JavaScript/TypeScript
- CodeQL now recognizes the Workflow SDK’s
"use workflow"and"use step"directives. - We’ve improved Hapi route-handler and request-input tracking through custom route-registration helpers and higher-order functions.
- With the release of macOS 27 and Xcode 27, Apple stopped shipping multi-architecture x86-64/arm64 binaries. These binaries are required by CodeQL to perform traced analysis. For this reason, CodeQL’s
autobuildandmanualbuild modes will not be supported for compiled languages on macOS 27 with any Xcode version, and on macOS 26 when Xcode 27 is selected. When using these build modes, please use at most macOS 26 and Xcode 26. We are also working on improving support for build modenoneon macOS to help mitigate this limitation.
C#
- The
cs/web/missing-x-frame-optionsquery now recognizes ASP.NET Core response headers and Content Security Policyframe-ancestorsdirectives as clickjacking protections. - The
cs/web/xssquery no longer treats Razor tag-helper attribute values written withWriteLiteralas XSS sinks.
GitHub Actions
- You can now remove owners from the trusted set used by the
actions/unpinned-tagquery by adding an entry prefixed with!, such as!github. This lets you report unpinned tags for first-party owners.
- The CLI now reports invalid
qlpack:andfrom:values in query suites as clear errors instead of crashing. - CodeQL now rejects YAML data-extension integers outside the signed 32-bit range instead of silently truncating some values.
- Error and warning messages on standard error now include
ERROR:andWARNING:prefixes. Structured output, including logs and SARIF, remains unchanged. codeql query compilenow accepts--dil-constantswith--dump-dilto include optimized constant tuple sets in emitted DIL.- Commands that load data extensions now only warn when none of the patterns in a pack’s
dataExtensionslist match any files.
The Go control-flow graph (CFG) now uses the shared CFG library. It includes additional nodes for constructs such as assignments, parameters and results, range statements, and deferred calls, and excludes nodes that aren’t reachable from the entry point. This changes CFG nodes, edges, locations, textual representations, and basic-block boundaries, so you may need to update queries that rely on the previous representation.
The update:
- Removes
BasicBlocks::Cfg. - Adds
ControlFlow::EntryNode,ControlFlow::ExitNode, andSwitchStmt.getExpr. - Deprecates
IfStmt.getCondin favor ofIfStmt.getCondition. - Changes the return types of
IfStmt.getThenandLoopStmt.getBodytoStmt. - Consolidates several IR instruction classes.
For full details, see the CodeQL 2.27.2 changelog. GitHub automatically deploys every new CodeQL version to users of GitHub code scanning on github.com. A future GitHub Enterprise Server (GHES) release will also include the new functionality in CodeQL 2.27.2. If you use an older version of GHES, you can manually upgrade your CodeQL version.