github GitHub Changelog · · 2.27.1

CodeQL 2.27.1 adds C/C++ query and Kotlin 2.4.20 support

securitygaengineer
feature patch

CodeQL 2.27.1 introduces new queries for C/C++ and C#, expands language and framework support for Go, Rust, and JavaScript/TypeScript, and adds support for Kotlin 2.4.20. These updates enhance the static analysis engine's ability to identify security issues and reduce false positives in code scanning. The release includes improvements to data flow models, query accuracy, and dependency resolution. CodeQL 2.27.1 is automatically deployed to GitHub code scanning users and will be included in GitHub Enterprise Server (GHES) 3.24, with manual upgrade options for older GHES versions.

  • →Enhanced C/C++ support and new query
  • →Kotlin 2.4.20 support and K2 compiler fix
  • →C# query and NuGet registry handling updates
  • →Improved Go data flow models
  • →JavaScript/TypeScript and Rust analysis improvements
Features (3) ›
  • Enhanced C/C++ support and new query

    CodeQL 2.27.1 adds new taint flow models for `boost::asio` and flow summaries for Bloomberg Development Environment's `Blob` segmented buffer, and Protocol Buffers `google::protobuf::MessageLite` C++ API. It also introduces the `cpp/ambiguous-assignment-of-comparison` query to detect potentially ambiguous assignment expressions.

  • Kotlin 2.4.20 support and K2 compiler fix

    CodeQL now supports Kotlin 2.4.20, enabling analysis of newer Kotlin projects. A fix for extraction of `Foo::class.java` arguments when using the Kotlin K2 compiler reduces false positives in relevant queries.

  • C# query and NuGet registry handling updates

    A new `cs/linq/missed-firstordefault` query identifies `foreach` loops that can be expressed more clearly with LINQ's `FirstOrDefault` method. The `cs/web/missing-token-validation` query now recognizes ASP.NET Core's `AutoValidateAntiforgeryTokenAttribute`, reducing false positives. CodeQL also improves C# dependency resolution by ensuring private NuGet registries with the `Replaces` option correctly override default feeds.

Enhancements (3) ›
  • Improved Go data flow models

    Data flow models for Go 1.27 standard-library APIs have been added or improved, including `bytes.CutLast`, `database/sql` conversions, and `net/url.URL.Clone`. Models for the `strings` package, covering `Clone`, `Cut`, and `Join` APIs, have also been expanded for better analysis.

  • JavaScript/TypeScript and Rust analysis improvements

    CodeQL now recognizes Fastify servers configured through chainable methods in JavaScript/TypeScript, improving route attribution and query results. For Rust, path resolution for `m::{self}` paths is fixed, and new data flow models for `core::fmt::Write` improve vulnerability detection. The Rust extractor also updates to `rust-analyzer` version 0.0.347.

  • GitHub Actions query accuracy improvements

    The `actions/unpinned-tag` query no longer reports actions pinned by a structurally valid `.github/workflows/actions.lock` entry. It also correctly ignores self-repository references like `uses: $/path/to/action` which are inherently pinned at the running commit.

Read the original announcement →

https://github.blog/changelog/2026-09-25-codeql-2-27-1-adds-c-and-c-query-and-kotlin-2-4-20-support

Related releases