Trending:

CodeQL 2.27.2 Adds C++ Regex Parsing and Broader Language Improvements

CodeQL 2.27.2 release banner
TechStaged-owned

Summary

  • CodeQL 2.27.2 is now available and adds a C++ regular-expression parser and analysis improvements across multiple languages.
  • The Default suite runs 498 security queries covering 170 CWEs; the Extended suite adds 131 queries covering 32 more CWEs.
  • CodeQL now parses regular expressions that use the ECMAScript grammar in std::regex.

CodeQL 2.27.2 is now available and includes a dedicated C++ regular-expression parser, alongside analysis improvements across several languages. The release positions CodeQL as the static analysis engine behind GitHub code scanning, helping teams find and remediate security issues in their code.

The Default query suite continues to run a broad set of security checks, while the Extended suite expands coverage with additional queries.

  • C++ regular-expression parsing
  • Regular-expression analysis improvements across multiple languages

WHAT CHANGED IN THE CODEQL LANGUAGE TOOLING

Key updates in this release include the ability to parse regular expressions that use the ECMAScript grammar within std::regex, and several language-specific enhancements that broaden CodeQL’s analysis capabilities. TechStaged has also covered GitHub completes staged rollout of stateless App installation tokens, with longer token format and unchanged permissions.

  • ECMAScript-regex parsing in std::regex
  • Cross-language analysis improvements

NEW MODELS AND DATA-FLOW ENHANCEMENTS

The release introduces SQL-injection sink models for the Comdb2 C API, as well as flow summaries for certain codecs and byte-stream deserializers.

Data-flow enhancements cover async blocks used with await, plus flow summaries for TLS-related libraries and async-tls variants.

  • SQL-injection sink models for Comdb2 C API
  • Flow summaries for Bloomberg BDE codecs and byte-stream deserializers
  • Improved data flow for async blocks (await)
  • Flow summaries for native-tls, async-native-tls, and tokio-native-tls

EXPANDED IMPORT PATHS AND RUST IMPROVEMENTS

CodeQL now models the github.com/coder/websocket import path in addition to the previously supported nhooyr.io/websocket, broadening dependency understanding in code bases using WebSocket libraries.

The Rust extractor gains support for the AnyAttr and DocComment classes, enabling richer extraction of Rust attributes and documentation comments.

  • New import-path modeling for websocket libraries
  • Rust extractor: AnyAttr and DocComment support

GO, JAVASCRIPT, AND WORKFLOW-AWARE ENHANCEMENTS

The Go control-flow graph (CFG) has been modernized to a shared CFG library and now includes more constructs such as assignments, parameters, results, and range statements, which can influence CFG-based queries.

CodeQL also recognizes Workflow SDK directives like use workflow and use step, improving alignment with repository automation patterns.

  • Go CFG refactor with broader node set
  • Workflow SDK directive recognition

OTHER DEVELOPER-FACING IMPROVEMENTS

Hapi route-handler and request-input tracking receive enhancements through custom route-registration helpers and higher-order functions.

The CLI and diagnostic output see quality improvements, including more explicit error handling and output structure for status messages.

  • Hapi route-handler and request-input tracking improvements
  • CLI error handling and structured output enhancements

MACOS, XCODE, AND BUILD-MODE NOTES

Apple’s macOS 27 and Xcode 27 release bring changes that affect CodeQL’s build modes. Specifically, multi-architecture x86-64/arm64 binaries are no longer shipped for those environments, which impacts traced analysis. As a result, autobuild and manual build modes will not be supported for compiled languages on macOS 27 with any Xcode version, and on macOS 26 when Xcode 27 is in use. The recommendation is to operate with at most macOS 26 and Xcode 26 while these limitations remain, with ongoing work to improve “build mode none” support.

  • macOS 27/Xcode 27: no multi-arch binaries
  • Autobuild/manual build modes not supported for compiled languages on affected macOS versions
  • Recommendation: macOS 26/Xcode 26 until further notice

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.