CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis
By Steven Van ·
The release also updates C# and GitHub Actions queries, while macOS 27 cannot support traced analysis for compiled languages.
CodeQL 2.27.2 adds a C++ regular-expression parser and updates language analysis in GitHub code scanning. The Default suite runs 498 security queries covering 170 CWEs, while the Extended suite adds 131 queries covering 32 more CWEs.
Language and framework analysis
- C/C++ analysis now parses the ECMAScript regular-expression grammar used by std::regex. It also adds SQL-injection sink models for Comdb2 C API functions and flow summaries for Bloomberg BDE codecs and byte-stream deserializers.
- Go models now support github.com/coder/websocket alongside nhooyr.io/websocket. The rewritten control flow graph uses the shared CFG library and includes only reachable nodes. Code that depends on specific nodes, edges or basic block boundaries may need updating.
- Rust extraction now exposes AnyAttr and DocComment classes. Data flow improves for async blocks used with await, with new flow summaries for native-tls, async-native-tls and tokio-native-tls.
- JavaScript/TypeScript analysis recognizes the Workflow SDK’s "use workflow" and "use step" directives, so js/unknown-directive no longer flags them. Hapi route-handler and request-input tracking also improves through custom registration helpers and higher-order function wrappers.
Security query changes
The C# clickjacking query now recognizes ASP.NET Core response headers and enforced Content Security Policy frame-ancestors directives. The XSS query no longer treats Razor tag-helper attribute values captured by generated WriteLiteral calls as XSS sinks.
For GitHub Actions, an entry prefixed with ! removes an owner from the trusted set used by actions/unpinned-tag. Adding !github, for example, lets the query report unpinned tags for that first-party owner.
CLI fixes and diagnostics
Invalid qlpack: or from: values in query suites now produce clear errors instead of crashes. YAML data extensions reject all integers outside the signed 32-bit range. Plain-text messages on standard error now carry ERROR: or WARNING: prefixes; structured output is unchanged.
macOS build compatibility
Autobuild and manual build modes for compiled languages are unsupported on macOS 27 with any Xcode version, and on macOS 26 with Xcode 27 selected. Apple stopped shipping the multi-architecture binaries CodeQL needs for traced analysis. These build modes require at most macOS 26 and Xcode 26.
The CodeQL 2.27.2 changelog provides the detailed analysis and CLI changes.
