CodeQL 2.27.2 (2026-10-07)¶
This is an overview of changes in the CodeQL CLI and relevant CodeQL query and library packs. For additional updates on changes to the CodeQL code scanning experience, check out the code scanning section on the GitHub blog, relevant GitHub Changelog updates, changes in the CodeQL extension for Visual Studio Code, and the CodeQL Action changelog.
Security Coverage¶
CodeQL 2.27.2 runs a total of 498 security queries when configured with the Default suite (covering 170 CWE). The Extended suite enables an additional 131 queries (covering 32 more CWE).
CodeQL CLI¶
Bug Fixes¶
Fixed a crash in
codeql resolve queries(and other commands that resolve query suites) that reported a fatal internal error when a suite entry’sqlpack:orfrom:value was not a valid QL pack name. Such input now produces a clear, user-facing error instead.Fixed a bug in the handling of YAML data extensions that would quietly accept integers outside of the signed 64-bit range, truncating them to smaller values. (Values outside of the signed 32-bit range, but inside the signed 64-bit range, were correctly rejected.) Now, all integers outside of the signed 32-bit range are rejected and will cause evaluation to fail.
Improvements¶
Error and warning messages printed to standard error are now labelled with an
ERROR:orWARNING:prefix. Previously only diagnostics carried such a label, so the severity of other messages was not apparent in plain-text output. Structured output is unaffected: log files, SARIF, and stored diagnostics continue to record severity without the prefix.The
codeql query compilecommand now accepts the--dil-constantsflag. When specified along with--dump-dil, the emitted DIL will include the values of predicates that have been optimized into constant tuple sets. Otherwise, these constants are omitted. This flag also enables pretty-printing of constant tuple sets for higher-level commands that involve query compilation.
Miscellaneous¶
CLI commands that load data extensions, such as
codeql database run-queries, previously emitted a warning for each file-pattern from thedataExtensionslist of aqlpack.ymlmanifest that failed to match any extension files. This check has been relaxed, and will now only emit a warning if none of the patterns match any files (i.e. when there is at least one pattern but no extensions are found).
Query Packs¶
Minor Analysis Improvements¶
C#¶
The
cs/web/missing-x-frame-optionsquery now recognizes clickjacking protection configured through ASP.NET Core response headers and enforced Content Security Policyframe-ancestorsdirectives.
Language Libraries¶
Bug Fixes¶
C#¶
Fixed an issue where types for pattern expressions were not extracted correctly.
JavaScript/TypeScript¶
Improved Hapi route handler and request input tracking through custom route registration helpers and higher-order function wrappers.
Breaking Changes¶
Golang¶
The Go control flow graph (CFG) implementation has been completely rewritten to use the shared CFG library. The CFG now includes additional nodes to more accurately represent certain constructs, including assignments, function parameters and results, range statements, and deferred calls. The CFG now only includes nodes that are reachable from the entry point. Basic blocks are also now constructed directly from the shared CFG. Existing code that relies on specific CFG nodes, edges, locations, textual representations, or basic block boundaries may need to be updated. Additionally, the following API changes have been made:
BasicBlocks::Cfghas been removed.BasicBlocknow directly uses the basic-block implementation provided by the shared CFG library.ControlFlow::EntryNodeandControlFlow::ExitNodehave been added, andControlFlow::entryNodeandControlFlow::exitNodenow return these more specific types.IfStmt.getCondhas been deprecated. Please use the newIfStmt.getConditioninstead.The result types of
IfStmt.getThenandLoopStmt.getBodyhave been widened fromBlockStmttoStmt.SwitchStmt.getExprhas been added, providing a common accessor for the expression examined by expression and type switches.Several IR instruction classes have been removed or consolidated, including
ReadArgumentInstruction,InitResultInstruction,IncDecInstruction,EvalIncDecRhsInstruction,EvalImplicitOneInstruction,SelectInstruction, andSendInstruction.EvalCompoundAssignRhsInstructionnow also represents increment and decrement operations, and it andEvalImplicitInitInstructiondirectly represent their associated writes.
Major Analysis Improvements¶
C#¶
Fixed a false positive in
cs/web/xssfor ASP.NET Core Razor Pages/MVC views:WriteLiteralcalls generated for tag helper attribute values (for example,asp-for) capture the value into an internal buffer instead of writing it directly to the response, so they are no longer treated as XSS sinks.
Minor Analysis Improvements¶
C/C++¶
Added SQL-injection sink models for the Comdb2 C API functions
cdb2_run_statementandcdb2_run_statement_typed.Added flow summaries for the BDE codecs
BloombergLP::balber::BerDecoder/BerEncoder,BloombergLP::baljsn::Decoder/EncoderandBloombergLP::balxml::Decoder/Encoder.Added taint flow summaries for the BDE
bslxbyte-stream deserializersBloombergLP::bslx::ByteInStream,BloombergLP::bslx::GenericInStream, andBloombergLP::bslx::InStreamFunctions::bdexStreamIn.
Golang¶
Models for the
nhooyr.io/websocketpackage have been updated to also support its new import pathgithub.com/coder/websocket.
JavaScript/TypeScript¶
The Workflow SDK directives
"use workflow"and"use step"are now recognized as known directives, so thejs/unknown-directivequery no longer flags them.
GitHub Actions¶
The
trustedActionsOwnerDataModelextensible predicate, used by theactions/unpinned-tagquery, now supports removing an owner from the trusted set by adding an entry prefixed with!(for example,!github). This makes it possible to distrust first-party owners (actions,github,advanced-security) so that unpinned tags for their Actions are reported.
Rust¶
The Rust extractor has been upgraded to use
rust-analyzerversion 0.0.352. As a result, the AST exposed by the Rust libraries now includes theAnyAttrandDocCommentclasses.Improve data flow for async blocks when used with
await.Added new flow summary models for the
native-tls,async-native-tls, andtokio-native-tlscrates.
New Features¶
C/C++¶
Added a C++ regular-expression parser for the ECMAScript grammar used by
std::regex.