Release basics
GitHub's CodeQL documentation dates the CLI release to October 7, 2026. The GitHub Changelog announcement followed on October 9. The upstream release repository lists v2.27.2 as the new CLI. It also deprecates the generic codeql.zip for all x86-64 platforms, which will be removed in a future release. GitHub asks users to download the per-platform codeql-PLATFORM.zip instead.
The release notes give the current suite coverage. The Default suite runs 498 security queries covering 170 CWEs, and the Extended suite adds 131 queries covering 32 more CWEs. These are the version's totals, not the number of queries added in this release.
GitHub says new CodeQL versions are deployed automatically for code scanning on github.com. A future GitHub Enterprise Server release will include 2.27.2, and users on older GHES versions can upgrade CodeQL manually.
The macOS limitation
The GitHub announcement carries a compatibility warning that is not in the CLI changelog page.
- Apple stopped shipping multi-architecture x86-64/arm64 binaries with macOS 27 and Xcode 27.
- CodeQL needs those binaries for traced analysis.
- Autobuild and manual build modes for compiled languages are therefore unsupported on macOS 27 with any Xcode version. They are also unsupported on macOS 26 when Xcode 27 is selected.
- GitHub's guidance is to use at most macOS 26 and Xcode 26 with those build modes.
- GitHub says it is working on better macOS support for build mode
noneto ease the problem. That work is described as in progress, sononeis not presented as a finished fix.
If you run macOS runners for compiled-language scanning, check which Xcode version is selected on them. A runner image that quietly moves to Xcode 27 could break your scans. The limitation applies to compiled-language traced builds, not to CodeQL on macOS in general.
Go: a breaking change for query authors
The Go control-flow graph has been rewritten on top of the shared CFG library. The new graph has these properties:
- It includes extra nodes for assignments, function parameters and results, range statements and deferred calls.
- It keeps only nodes that are reachable from the entry point.
- It builds basic blocks directly from the shared CFG.
GitHub warns that queries relying on specific CFG nodes, edges, locations, text representations or basic-block boundaries may need updating. The documented API changes are:
BasicBlocks::Cfgis removed.ControlFlow::EntryNodeandControlFlow::ExitNodeare added, andentryNodeandexitNodenow return these types.IfStmt.getCondis deprecated in favor ofIfStmt.getCondition.IfStmt.getThenandLoopStmt.getBodynow returnStmtinstead ofBlockStmt.SwitchStmt.getExpris added.- Several IR instruction classes are removed or consolidated. These include
ReadArgumentInstruction,InitResultInstruction,IncDecInstruction,EvalIncDecRhsInstruction,EvalImplicitOneInstruction,SelectInstructionandSendInstruction. EvalCompoundAssignRhsInstructionnow also covers increment and decrement operations.
Teams using only the standard query suites shouldn't need to do anything. Teams with custom Go queries should recompile them against 2.27.2 and compare results on a known codebase. A query that depends on the old graph shape could change its results without any other sign.
Go also gets a smaller change. The nhooyr.io/websocket models now also cover its new import path, github.com/coder/websocket.
C and C++
- Regular expressions: CodeQL adds a parser for the ECMAScript grammar used by
std::regex. - Comdb2: There are new SQL-injection sink models for
cdb2_run_statementandcdb2_run_statement_typed. - Bloomberg BDE codecs: There are new flow summaries for the BER, JSON and XML encoders and decoders.
- BDE
bslxdeserializers: There are new taint-flow summaries forByteInStream,GenericInStreamandbdexStreamIn.
These are modeling improvements. They help CodeQL see data moving through these APIs, but the release notes give no figures for how many more alerts to expect. They do not fix anything in your code.
Rust
- The extractor now uses rust-analyzer 0.0.352, so the AST exposed to queries includes
AnyAttrandDocCommentclasses. - Data flow is improved for async blocks used with
await. - There are new flow-summary models for
native-tls,async-native-tlsandtokio-native-tls.
JavaScript and TypeScript
The Workflow SDK directives "use workflow" and "use step" are now treated as known directives, so js/unknown-directive stops flagging them. Hapi route-handler and request-input tracking is also better through custom route-registration helpers and higher-order function wrappers.
C# query changes
cs/web/missing-x-frame-optionsnow accepts ASP.NET Core response headers and enforced Content Security Policyframe-ancestorsdirectives as clickjacking protection. Fewer well-protected apps should be flagged.cs/web/xssno longer treatsWriteLiteralcalls generated for Razor tag-helper attribute values, such asasp-for, as sinks. The changelog describes this as a false-positive fix. Those calls capture the value in an internal buffer instead of writing it directly to the response.
GitHub Actions: distrusting first-party owners
The actions/unpinned-tag query uses the trustedActionsOwnerDataModel extensible predicate to decide which owners to trust. You can now remove an owner by adding an entry prefixed with !, such as !github. The changelog says this lets you distrust first-party owners (actions, github and advanced-security). Unpinned tags for their Actions are then reported.
Organizations that require commit-SHA pinning for every action can now apply that rule to first-party actions too. Expect more findings if you turn it on.
CLI changes
- Invalid
qlpack:orfrom:values in query suites now produce a clear error. Previously they caused a fatal internal crash. - YAML data-extension integers outside the signed 32-bit range are now rejected and cause evaluation to fail. Previously, some values outside the signed 64-bit range were silently truncated.
- Plain-text errors and warnings on standard error now carry
ERROR:andWARNING:prefixes. Logs, SARIF and stored diagnostics are unchanged. If you scrape console output in CI, check that your parsing still works. codeql query compileaccepts--dil-constants. Combined with--dump-dil, it includes predicates optimized into constant tuple sets in the emitted DIL.- Commands that load data extensions now warn only when none of the patterns in a pack's
dataExtensionslist match any files. Before, they warned for each unmatched pattern.
What to do
- If you scan compiled languages on macOS, confirm your OS and Xcode versions against the limits above.
- If you have custom Go queries, test them against 2.27.2 before relying on their results.
- If you parse CodeQL console output, check for the new
ERROR:andWARNING:prefixes. - If you want strict pinning for first-party Actions, add
!actions,!githubor!advanced-securityto the trusted-owner model, and be ready for new alerts. - On GHES, plan a manual CodeQL upgrade if you want these changes before your next GHES release.
On github.com, the default scanning experience updates itself. The only places where this release asks for action are the Go query rewrite, the macOS toolchain boundary and the optional Actions pinning change.
References
- CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis GitHub Changelog · 2026-10-09T21:32:54+00:00
- CodeQL 2.27.2 (2026-10-07) — CodeQL codeql.github.com