CodeQL 2.27.2 is now available and includes a dedicated C++ regular-expression parser, alongside analysis improvements across several languages. The release positions CodeQL as the static analysis engine behind GitHub code scanning, helping teams find and remediate security issues in their code.
The Default query suite continues to run a broad set of security checks, while the Extended suite expands coverage with additional queries.
- C++ regular-expression parsing
- Regular-expression analysis improvements across multiple languages
WHAT CHANGED IN THE CODEQL LANGUAGE TOOLING
Key updates in this release include the ability to parse regular expressions that use the ECMAScript grammar within std::regex, and several language-specific enhancements that broaden CodeQL’s analysis capabilities. TechStaged has also covered GitHub completes staged rollout of stateless App installation tokens, with longer token format and unchanged permissions.
- ECMAScript-regex parsing in std::regex
- Cross-language analysis improvements
NEW MODELS AND DATA-FLOW ENHANCEMENTS
The release introduces SQL-injection sink models for the Comdb2 C API, as well as flow summaries for certain codecs and byte-stream deserializers.
Data-flow enhancements cover async blocks used with await, plus flow summaries for TLS-related libraries and async-tls variants.
- SQL-injection sink models for Comdb2 C API
- Flow summaries for Bloomberg BDE codecs and byte-stream deserializers
- Improved data flow for async blocks (await)
- Flow summaries for native-tls, async-native-tls, and tokio-native-tls
EXPANDED IMPORT PATHS AND RUST IMPROVEMENTS
CodeQL now models the github.com/coder/websocket import path in addition to the previously supported nhooyr.io/websocket, broadening dependency understanding in code bases using WebSocket libraries.
The Rust extractor gains support for the AnyAttr and DocComment classes, enabling richer extraction of Rust attributes and documentation comments.
- New import-path modeling for websocket libraries
- Rust extractor: AnyAttr and DocComment support
GO, JAVASCRIPT, AND WORKFLOW-AWARE ENHANCEMENTS
The Go control-flow graph (CFG) has been modernized to a shared CFG library and now includes more constructs such as assignments, parameters, results, and range statements, which can influence CFG-based queries.
CodeQL also recognizes Workflow SDK directives like use workflow and use step, improving alignment with repository automation patterns.
- Go CFG refactor with broader node set
- Workflow SDK directive recognition
OTHER DEVELOPER-FACING IMPROVEMENTS
Hapi route-handler and request-input tracking receive enhancements through custom route-registration helpers and higher-order functions.
The CLI and diagnostic output see quality improvements, including more explicit error handling and output structure for status messages.
- Hapi route-handler and request-input tracking improvements
- CLI error handling and structured output enhancements
MACOS, XCODE, AND BUILD-MODE NOTES
Apple’s macOS 27 and Xcode 27 release bring changes that affect CodeQL’s build modes. Specifically, multi-architecture x86-64/arm64 binaries are no longer shipped for those environments, which impacts traced analysis. As a result, autobuild and manual build modes will not be supported for compiled languages on macOS 27 with any Xcode version, and on macOS 26 when Xcode 27 is in use. The recommendation is to operate with at most macOS 26 and Xcode 26 while these limitations remain, with ongoing work to improve “build mode none” support.
- macOS 27/Xcode 27: no multi-arch binaries
- Autobuild/manual build modes not supported for compiled languages on affected macOS versions
- Recommendation: macOS 26/Xcode 26 until further notice
RELATED COVERAGE
- GitHub completes staged rollout of stateless App installation tokens, with longer token format and unchanged permissions
- GitHub Copilot adds general availability for local sandboxing across CLI, app, and VS Code
- Code Scanning Rollout Plan for Teams Starting With GitHub CodeQL
- GitHub adds confidential comments to repository security advisories
- Developer Tools articles
SOURCES
- Archive: 2026 - GitHub Changelog: CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis Published · Primary source






