A desktop monitor displays a glowing software workflow dashboard with code, flowcharts, status indicators, and security alerts.
CodeQL 2.27.2 is a point release, but it has two things worth reading before your next scan. One is a breaking change for anyone who maintains custom Go queries. The other is a macOS build-mode limitation that affects teams adopting Apple's newest toolchain. The rest is a long list of analysis refinements across C++, Go, Rust, JavaScript/TypeScript, C#, GitHub Actions and the CLI.

A desktop monitor displays a glowing software workflow dashboard with code, flowcharts, status indicators, and security alerts. Release basics​

GitHub's CodeQL documentation dates the CLI release to October 7, 2026. The GitHub Changelog announcement followed on October 9. The upstream release repository lists v2.27.2 as the new CLI. It also deprecates the generic codeql.zip for all x86-64 platforms, which will be removed in a future release. GitHub asks users to download the per-platform codeql-PLATFORM.zip instead.

The release notes give the current suite coverage. The Default suite runs 498 security queries covering 170 CWEs, and the Extended suite adds 131 queries covering 32 more CWEs. These are the version's totals, not the number of queries added in this release.

GitHub says new CodeQL versions are deployed automatically for code scanning on github.com. A future GitHub Enterprise Server release will include 2.27.2, and users on older GHES versions can upgrade CodeQL manually.

The macOS limitation​

The GitHub announcement carries a compatibility warning that is not in the CLI changelog page.

  • Apple stopped shipping multi-architecture x86-64/arm64 binaries with macOS 27 and Xcode 27.
  • CodeQL needs those binaries for traced analysis.
  • Autobuild and manual build modes for compiled languages are therefore unsupported on macOS 27 with any Xcode version. They are also unsupported on macOS 26 when Xcode 27 is selected.
  • GitHub's guidance is to use at most macOS 26 and Xcode 26 with those build modes.
  • GitHub says it is working on better macOS support for build mode none to ease the problem. That work is described as in progress, so none is not presented as a finished fix.

If you run macOS runners for compiled-language scanning, check which Xcode version is selected on them. A runner image that quietly moves to Xcode 27 could break your scans. The limitation applies to compiled-language traced builds, not to CodeQL on macOS in general.

Go: a breaking change for query authors​

The Go control-flow graph has been rewritten on top of the shared CFG library. The new graph has these properties:

  • It includes extra nodes for assignments, function parameters and results, range statements and deferred calls.
  • It keeps only nodes that are reachable from the entry point.
  • It builds basic blocks directly from the shared CFG.

GitHub warns that queries relying on specific CFG nodes, edges, locations, text representations or basic-block boundaries may need updating. The documented API changes are:

  • BasicBlocks::Cfg is removed.
  • ControlFlow::EntryNode and ControlFlow::ExitNode are added, and entryNode and exitNode now return these types.
  • IfStmt.getCond is deprecated in favor of IfStmt.getCondition.
  • IfStmt.getThen and LoopStmt.getBody now return Stmt instead of BlockStmt.
  • SwitchStmt.getExpr is added.
  • Several IR instruction classes are removed or consolidated. These include ReadArgumentInstruction, InitResultInstruction, IncDecInstruction, EvalIncDecRhsInstruction, EvalImplicitOneInstruction, SelectInstruction and SendInstruction.
  • EvalCompoundAssignRhsInstruction now also covers increment and decrement operations.

Teams using only the standard query suites shouldn't need to do anything. Teams with custom Go queries should recompile them against 2.27.2 and compare results on a known codebase. A query that depends on the old graph shape could change its results without any other sign.

Go also gets a smaller change. The nhooyr.io/websocket models now also cover its new import path, github.com/coder/websocket.

C and C++​

  • Regular expressions: CodeQL adds a parser for the ECMAScript grammar used by std::regex.
  • Comdb2: There are new SQL-injection sink models for cdb2_run_statement and cdb2_run_statement_typed.
  • Bloomberg BDE codecs: There are new flow summaries for the BER, JSON and XML encoders and decoders.
  • BDE bslx deserializers: There are new taint-flow summaries for ByteInStream, GenericInStream and bdexStreamIn.

These are modeling improvements. They help CodeQL see data moving through these APIs, but the release notes give no figures for how many more alerts to expect. They do not fix anything in your code.

Rust​

  • The extractor now uses rust-analyzer 0.0.352, so the AST exposed to queries includes AnyAttr and DocComment classes.
  • Data flow is improved for async blocks used with await.
  • There are new flow-summary models for native-tls, async-native-tls and tokio-native-tls.

JavaScript and TypeScript​

The Workflow SDK directives "use workflow" and "use step" are now treated as known directives, so js/unknown-directive stops flagging them. Hapi route-handler and request-input tracking is also better through custom route-registration helpers and higher-order function wrappers.

C# query changes​

  • cs/web/missing-x-frame-options now accepts ASP.NET Core response headers and enforced Content Security Policy frame-ancestors directives as clickjacking protection. Fewer well-protected apps should be flagged.
  • cs/web/xss no longer treats WriteLiteral calls generated for Razor tag-helper attribute values, such as asp-for, as sinks. The changelog describes this as a false-positive fix. Those calls capture the value in an internal buffer instead of writing it directly to the response.

GitHub Actions: distrusting first-party owners​

The actions/unpinned-tag query uses the trustedActionsOwnerDataModel extensible predicate to decide which owners to trust. You can now remove an owner by adding an entry prefixed with !, such as !github. The changelog says this lets you distrust first-party owners (actions, github and advanced-security). Unpinned tags for their Actions are then reported.

Organizations that require commit-SHA pinning for every action can now apply that rule to first-party actions too. Expect more findings if you turn it on.

CLI changes​

  • Invalid qlpack: or from: values in query suites now produce a clear error. Previously they caused a fatal internal crash.
  • YAML data-extension integers outside the signed 32-bit range are now rejected and cause evaluation to fail. Previously, some values outside the signed 64-bit range were silently truncated.
  • Plain-text errors and warnings on standard error now carry ERROR: and WARNING: prefixes. Logs, SARIF and stored diagnostics are unchanged. If you scrape console output in CI, check that your parsing still works.
  • codeql query compile accepts --dil-constants. Combined with --dump-dil, it includes predicates optimized into constant tuple sets in the emitted DIL.
  • Commands that load data extensions now warn only when none of the patterns in a pack's dataExtensions list match any files. Before, they warned for each unmatched pattern.

What to do​

  1. If you scan compiled languages on macOS, confirm your OS and Xcode versions against the limits above.
  2. If you have custom Go queries, test them against 2.27.2 before relying on their results.
  3. If you parse CodeQL console output, check for the new ERROR: and WARNING: prefixes.
  4. If you want strict pinning for first-party Actions, add !actions, !github or !advanced-security to the trusted-owner model, and be ready for new alerts.
  5. On GHES, plan a manual CodeQL upgrade if you want these changes before your next GHES release.

On github.com, the default scanning experience updates itself. The only places where this release asks for action are the Go query rewrite, the macOS toolchain boundary and the optional Actions pinning change.

 

References

  1. CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis GitHub Changelog 2026-10-09T21:32:54+00:00
  2. CodeQL 2.27.2 (2026-10-07) — CodeQL codeql.github.com