GitHub CodeQL 2.27.2 expands security analysis and flags macOS 27 scan limits

GitHub CodeQL 2.27.2 expands security analysis and flags macOS 27 scan limits

GitHub CodeQL 2.27.2 expands security queries and warns teams about macOS 27 limits for compiled-language scans.

Format News Brief
Read Time 3 min
Category Cyber Security
Updated Oct 11, 2026

GitHub has released CodeQL 2.27.2 with new language analysis coverage, query fixes, and a compatibility warning that matters for teams running code scanning in modern macOS build environments. The update is available now, and GitHub says new CodeQL versions are automatically deployed to users of GitHub code scanning on github.com.

What changed

The headline improvement is broader static analysis coverage across C++, Go, Rust, JavaScript, TypeScript, C#, and GitHub Actions workflows. GitHub says the default CodeQL suite now runs 498 security queries covering 170 CWEs, while the extended suite adds 131 queries covering 32 additional CWEs. For security teams, that means the release is not just a language support update. It changes how many classes of bugs can be searched for during normal code scanning.

For C and C++ projects, CodeQL can now parse regular expressions that use the ECMAScript grammar in std::regex. GitHub also added SQL injection sink models for the Comdb2 C API, plus new flow summaries for Bloomberg BDE codecs and byte stream deserializers. Rust analysis gains better data flow for async blocks used with await, along with summaries for native TLS libraries. JavaScript and TypeScript analysis now recognizes Workflow SDK directives such as "use workflow" and "use step", and GitHub says Hapi request tracking has improved.

Why it matters

The practical value is in fewer blind spots inside large, mixed language repositories. CodeQL is most useful when it understands framework behavior, common libraries, and data movement well enough to reduce manual security review. Better modeling for web frameworks, serializers, WebSocket packages, TLS libraries, and workflow code can turn into more actionable findings for teams that already rely on code scanning before merge.

There is also an operations catch. GitHub says Apple stopped shipping the multi architecture x86 64 and arm64 binaries that CodeQL needs for traced analysis in macOS 27 and Xcode 27. As a result, CodeQL autobuild and manual build modes will not be supported for compiled languages on macOS 27 with any Xcode version, or on macOS 26 when Xcode 27 is selected. Teams using those paths should pin scanning jobs to macOS 26 and Xcode 26 for now, or test whether build mode none is enough for their repositories.

What to watch next

The update is strongest for organizations that already have code scanning in regular pull request checks. CyberOGZ would treat this as a maintenance release with security impact, not a reason to rewrite pipelines overnight. The useful move is to review scan results after rollout, check custom queries that depend on Go control flow graph internals, and confirm macOS runner choices before Xcode 27 becomes a surprise source of failed scans.

Sources

Cover photo by Antoni Shkraba on Pexels, used under the Pexels License.

Comments (0)

Leave a Comment

Loading comments...