GitHub released CodeQL 2.27.2 on October 9, 2026. The update improves security analysis for C++, Go, Rust and JavaScript/TypeScript, changes several query behaviors, and introduces a breaking change to the Go control-flow graph library. Teams using custom CodeQL queries should review the Go changes before updating, and teams building compiled languages on macOS should check the new Xcode compatibility limits.
What CodeQL 2.27.2 adds
CodeQL is the static analysis engine behind GitHub code scanning. It analyzes code and data flow to find patterns that may indicate security problems. Version 2.27.2 adds language models and analysis improvements rather than introducing a new AI coding assistant.
| Area | Changes described by GitHub | Who should review it |
|---|---|---|
| C/C++ | Parses ECMAScript-style regular expressions used by std::regex; adds SQL-injection sink models for the Comdb2 C API and flow summaries for Bloomberg BDE codecs and byte-stream deserializers. | Teams scanning C++ services, database code or custom data-processing libraries. |
| Go | Adds modeling for github.com/coder/websocket, alongside the existing nhooyr.io/websocket path. | Go teams using the newer WebSocket package path. |
| Rust | Adds extractor support for AnyAttr and DocComment, improves data flow around async blocks and await, and adds summaries for TLS libraries. | Rust teams with async code or TLS dependencies. |
| JavaScript/TypeScript | Recognizes Workflow SDK directives use workflow and use step, and improves Hapi route-handler and request-input tracking. | Teams using workflow frameworks or custom Hapi route registration. |
These changes can improve what CodeQL understands about a codebase, but they do not guarantee that every vulnerability will be found. Keep code review, tests and other security controls in place.
Important macOS and Xcode compatibility limit
GitHub notes that macOS 27 and Xcode 27 no longer ship the multi-architecture x86-64/arm64 binaries that CodeQL needs for traced analysis. As a result, CodeQL's autobuild and manual build modes for compiled languages are not supported on macOS 27 with any Xcode version, or on macOS 26 when Xcode 27 is selected.
For those build modes, GitHub says to use at most macOS 26 with Xcode 26. The team is working to improve support for the none build mode on macOS, but the changelog does not give a date for that work. If your CI image updates automatically, pin or review the operating-system and Xcode versions before the next CodeQL run.
The Go control-flow graph change may affect custom queries
The Go control-flow graph (CFG) now uses a shared CFG library. It includes additional nodes for assignments, parameters, results, range statements and deferred calls, while excluding nodes that are not reachable from the entry point. This changes node and edge structure, source locations, textual representations and basic-block boundaries.
GitHub lists several query API changes: BasicBlocks::Cfg is removed; ControlFlow::EntryNode, ControlFlow::ExitNode and SwitchStmt.getExpr are added; IfStmt.getCond is deprecated in favor of IfStmt.getCondition; and the return types of IfStmt.getThen and LoopStmt.getBody change to Stmt. If you maintain custom Go queries that depend on the old CFG shape, test and update them before treating the new results as equivalent.
Other query and CLI changes
The release also adjusts C# clickjacking and XSS query behavior, adds a way to flag first-party owners in the GitHub Actions unpinned-tag query, and improves CodeQL CLI error handling. Invalid qlpack: and from: values now produce clearer errors instead of a crash, and YAML data-extension integers outside the signed 32-bit range are rejected rather than silently truncated.
Structured output such as logs and SARIF remains unchanged for the CLI message-prefix update. Still, teams that parse plain-text stderr should check scripts that expect the previous error wording.
Availability and upgrade planning
GitHub says each new CodeQL version is deployed automatically to users of GitHub code scanning on github.com. A future GitHub Enterprise Server release will include CodeQL 2.27.2; customers on older GHES versions can manually upgrade the CodeQL version. Do not assume the same rollout date applies to every self-hosted installation.
- Check whether your scans use compiled-language autobuild or manual build modes on macOS.
- Review Xcode and macOS image changes in CI.
- Run your custom Go queries against representative repositories and inspect changed results.
- Check scripts that parse CodeQL CLI stderr.
- Compare the new alerts with code owners and security reviewers before changing production policy.
For another layer of pull-request review, see our guide to the GitHub Copilot Code Review API. The API-based review workflow and CodeQL static analysis solve different problems, so one should not replace the other.
Frequently asked questions
Does CodeQL 2.27.2 automatically reach GitHub code scanning?
GitHub says it automatically deploys new CodeQL versions to users of code scanning on github.com. GitHub Enterprise Server follows its own release schedule.
Should all Go query authors update their code?
Review custom queries that depend on CFG nodes, edges, basic blocks or the listed APIs. Queries that do not use those areas may need no change, but should still be tested.
Can I use Xcode 27 for compiled-language analysis on macOS 26?
GitHub says autobuild and manual build modes for compiled languages are not supported on macOS 26 when Xcode 27 is selected. Use macOS 26 with Xcode 26 or review the supported alternatives.
Sources
- GitHub Changelog: CodeQL 2.27.2 improves C++, Go, Rust and JavaScript analysis (October 9, 2026).
- GitHub Docs: Code scanning.