
CodeQL 2.27.1 adds a C++ query, reads Actions lock files
CodeQL 2.27.1 ships 498 default security queries across 170 CWEs, a new C/C++ check, Kotlin 2.4.20 support and awareness of Actions lock files.
Tag archive

CodeQL 2.27.1 ships 498 default security queries across 170 CWEs, a new C/C++ check, Kotlin 2.4.20 support and awareness of Actions lock files.

On Monday morning I switched code scanning on in my blog repository. When the first scan finished,...
GitHub's static analysis engine now ships a native linux-arm64 CLI and bundle in 2.27.0, alongside a new Rust security query and expanded Java, Kotlin and C# framework coverage. Teams that already moved their runners to ARM stop paying an emulation tax on code scans.
GitHub Code Quality CodeQL workflows now run on a dedicated Actions path, per an August 20 changelog. Their runs no longer count against a repo's regular Actions usage, and no longer sit in the same workflow-run history as the rest of its CI.
CodeQL 2.26.3 reworks how the engine reasons about GitHub Actions workflows, tightening output-clobbering, cache-poisoning and env-var injection queries and removing the self-hosted runner module. Hosted code scanning is already on the new pack, so the next full run may move alert counts in both directions.
GitHub's static analysis engine adds Swift 6.3.3 and Kotlin 2.4.10 support in CodeQL 2.26.2, and quietly removes a batch of sanitizers that used to make path injection and URL redirection findings disappear.
GitHub code scanning across 500 repos: a 2026 rollout that avoids alert overload Summary....
"A security gate for head-branch instructions before customized AI review can influence a pull request."
GitHub Code Quality moved to general availability on GitHub Enterprise Cloud and GitHub Team on July 20, pairing CodeQL's analysis with AI-assisted detection and Copilot Autofix inside pull requests. The pricing landed the same day: $10 per active committer per month plus usage charges for AI work and CodeQL compute.
CodeQL 2.26.0 flags AI prompt injection: the 2026 code scanning setup guide Summary. On 10...
Turn CodeQL's new AI prompt-injection detection into a stable repository security contract with positive, negative, and SARIF assertions.
A practical walkthrough for adding static application security testing to a GitHub repository with CodeQL.