CodeQL 2.27.2 improves C++, Go, Rust and JavaScript analysis in GitHub's scanner
Version released on October 9, 2026 adds a regex parser for C++, new flow models for Go and Rust, and support for the Workflow SDK in JavaScript, but also brings a silent breaking change for those who maintain custom queries.
GitHub released CodeQL 2.27.2 on October 9, 2026, the static analysis engine behind the platform's code scanning. It's the tool that scans repositories for SQL injection, XSS, path traversal, and other classes of flaws before code reaches production. According to GitHub's official changelog, the standard suite (Default) runs 498 security queries covering 170 CWEs, and the extended suite (Extended) adds another 131 queries for 32 more CWEs.
For those who already use code scanning on GitHub.com, the update is automatic: nothing to install. Those who run CodeQL on GitHub Enterprise Server or via their own CLI (in CI/CD pipelines outside github.com) need to update manually, and that's where it's worth paying attention to the details below, because at least one change breaks compatibility.
C++ gets a regular expression parser
The most concrete news for those maintaining C++ code in production is the new regex parser: CodeQL now understands expressions written in ECMAScript grammar inside std::regex. This matters because poorly written regex is a classic source of ReDoS (denial of service via catastrophic regular expressions) and input validation bypass. Previously, this type of pattern slipped past static analysis; now the scanner can inspect what's inside the regex, not just the fact that it exists.

The release also adds SQL injection sink models for the Comdb2 C API and flow summaries for Bloomberg BDE codecs and for byte-stream deserializers. In practice, these are libraries used more in corporate/financial settings, so teams working with trading stacks or legacy C++ systems gain coverage that previously required a custom query.
Go: new WebSocket library and a breaking change that demands attention
CodeQL now models the github.com/coder/websocket import, in addition to the already supported nhooyr.io/websocket. It's a small adjustment, but it resolves a real point of friction: teams that migrated from one library to the other were losing taint tracking coverage on WebSocket connections without realizing it.
The change that calls for more caution is structural. Go's control flow graph (CFG) now uses the shared CFG library, the same base shared with other languages. This changes nodes, edges, locations, textual representation, and the basic block boundaries of the graph. Anyone who maintains custom CodeQL queries for Go needs to review their code, because:
BasicBlocks::Cfgwas removed;ControlFlow::EntryNode,ControlFlow::ExitNode, andSwitchStmt.getExprwere added;IfStmt.getCondis deprecated in favor ofIfStmt.getCondition;- the return types of
IfStmt.getThenandLoopStmt.getBodychanged toStmt; - several IR instruction classes were consolidated.
If the team only uses GitHub's standard queries, nothing changes in practice. If there's a custom query written against the old CFG API, it may simply stop compiling or, worse, compile and produce a different result than expected.
Rust: better async analysis and new classes in the extractor
The Rust extractor gained support for the AnyAttr and DocComment classes, which improves CodeQL's ability to understand attributes and documentation when parsing code. More relevant for security is the improvement in data flow for async blocks used with await: asynchronous code has historically been a blind spot for static analyzers, because data flow doesn't follow the textual order of the code.
The release also adds flow summaries for native-tls, async-native-tls, and tokio-native-tls. These are TLS crates widely used in Rust services that make network calls; with the flow summaries, CodeQL can track sensitive data (such as tokens or credentials) that passes through these libraries, something that previously required manual modeling.
JavaScript/TypeScript: Workflow SDK and Hapi routes
CodeQL now recognizes the "use workflow" and "use step" directives from the Workflow SDK, a pattern that has been gaining traction in code that orchestrates long-running asynchronous tasks. Without this recognition, the analyzer treated these blocks as regular code and could lose track of data entering and leaving the workflow's steps.
Route and request input tracking in Hapi also improved, covering custom route registration helpers and higher-order functions used to compose handlers. This is the kind of fix that resolves a silent false negative: Hapi APIs using their own abstractions on top of the framework went unnoticed by XSS and injection queries before this improvement.
macOS 27 breaks automatic build for compiled languages
This is the change that most catches off guard those running CI on macOS runners. With the release of macOS 27 and Xcode 27, Apple stopped distributing multi-architecture x86-64/arm64 binaries, which CodeQL needs to perform traced analysis (when it observes the project's actual build). The result: CodeQL's autobuild and manual build modes stop working for compiled languages on macOS 27, with any version of Xcode, and also on macOS 26 when Xcode 27 is selected.
For now, GitHub recommends locking in to macOS 26 with Xcode 26 for those who depend on these build modes. Teams with macOS runners doing code scanning for C, C++, Go, or other compiled languages should check the OS and Xcode combination before updating the toolchain, at the risk of the scan simply stopping without a clear error. GitHub says it's working to improve support for build mode none on macOS as a mitigation.
Other adjustments: C#, GitHub Actions, and CLI
C#'s cs/web/missing-x-frame-options query now recognizes ASP.NET Core response headers and Content Security Policy frame-ancestors directives as valid protection against clickjacking, reducing false positives in APIs that already use modern CSP instead of the legacy X-Frame-Options header. Meanwhile, cs/web/xss stopped treating Razor tag helper attribute values written via WriteLiteral as an XSS sink.
For GitHub Actions, the actions/unpinned-tag query now allows removing owners from the trusted set by prefixing the entry with !, as in !github, which makes it possible to report unpinned tags even from first-party organizations when security policy requires it.
In the CLI, suite configuration errors (invalid qlpack: and from:) now appear as clear messages instead of crashing the process, and integers outside the signed 32-bit range in YAML data extensions are now rejected instead of silently truncated, which avoids a subtle bug in custom dataExtensions configurations.
Is it worth updating now?
For those using code scanning directly on github.com, there's no decision to make: the update is already active. For those running CodeQL via GHES or their own CLI in a CI/CD pipeline, the recommended path is: first, check whether there's a custom Go query referencing the old BasicBlocks::Cfg API, IfStmt.getCond, or the changed return types; second, if CI runs on macOS, confirm the OS and Xcode version combination before updating tools. Beyond that, the improvements in C++, Rust, and JavaScript/TypeScript arrive without requiring any configuration change, just extra coverage on the next scan.
Translated from the Brazilian Portuguese original · Read the original
JDK 25 brings the fifth preview of Structured Concurrency, not the stable version
Understand what changes in the fifth preview of the StructuredTaskScope API and why it's still not time to use `--enable-preview` in production.