Live
OpenTelemetry tracing expands across Cloudflare’s proxy stack in betaDynamic Model Triage: Engineering Implications of Grok Bot’s Multi‑Model BackendAccess Cloudflare Skills Directly Through the API MCP ServerCodeQL 2.27.2 expands language models and tightens macOS build support – what engineers need to knowTangible Certification: Turning a Kubernetes Badge into a Gold NecklaceGoogle Data Cloud GA updates: agent‑centric tooling, hybrid Spanner, and expanded Lakehouse catalogCloudflare folds Deno runtime into Workers: practical impact on serverless deploymentsManaging Copilot Code Review Costs and License Scope with New Org‑Level ControlsOpenTelemetry tracing expands across Cloudflare’s proxy stack in betaDynamic Model Triage: Engineering Implications of Grok Bot’s Multi‑Model BackendAccess Cloudflare Skills Directly Through the API MCP ServerCodeQL 2.27.2 expands language models and tightens macOS build support – what engineers need to knowTangible Certification: Turning a Kubernetes Badge into a Gold NecklaceGoogle Data Cloud GA updates: agent‑centric tooling, hybrid Spanner, and expanded Lakehouse catalogCloudflare folds Deno runtime into Workers: practical impact on serverless deploymentsManaging Copilot Code Review Costs and License Scope with New Org‑Level Controls
GitHub

CodeQL 2.27.2 expands language models and tightens macOS build support – what engineers need to know

AI SummaryPowered by AI

CodeQL 2.27.2 introduces a C++ ECMAScript‑style regex parser, new models for Go, Rust and JavaScript, and several query and CLI refinements. These updates affect static‑analysis coverage, CI pipelines on macOS, and the reliability of security queries for AI, cloud, DevOps and security engineers.

Version 2.27.2 of CodeQL adds a C++ regular‑expression parser, new data‑flow models for Go, Rust and JavaScript, and a set of CLI and query‑suite improvements. For teams that embed CodeQL in CI/CD, code‑scanning policies, or custom security tooling, the changes broaden detection capability while imposing new constraints on macOS build environments.

CodeQL language analysis extensions

The release adds support for ECMAScript‑grammar regexes used in std::regex, enabling the Default suite to flag patterns that were previously invisible to the analyzer. In Go, the extractor now recognises the github.com/coder/websocket import path alongside nhooyr.io/websocket, improving coverage of WebSocket‑related sinks. Rust sees two class additions—AnyAttr and DocComment—and enhanced async‑block data‑flow handling, plus flow summaries for native-tls, async-native-tls and tokio-native-tls. JavaScript/TypeScript analysis now understands the Workflow SDK directives “use workflow” and “use step”, and it tracks Hapi route‑handler registration through higher‑order helpers.

macOS build‑mode restrictions

Apple’s shift to macOS 27 and Xcode 27 removes the multi‑architecture binaries that CodeQL relies on for traced analysis. Consequently, both the autobuild and manual build modes are unsupported for compiled languages on macOS 27 (any Xcode) and on macOS 26 when Xcode 27 is selected. Practitioners must stay on macOS 26 with Xcode 26 for those modes, or experiment with the “build mode none” workaround that the team is improving.

Query suite and CLI behavior changes

The C# web queries have been refined: the missing‑x‑frame‑options query now recognises ASP.NET Core CSP frame‑ancestors, and the XSS query no longer treats Razor WriteLiteral output as a sink. GitHub Actions’ actions/unpinned-tag query can now exclude owners by prefixing an entry with !, allowing first‑party tag‑pinning exceptions. The CLI now emits clear error messages for malformed qlpack: and from: values, and it rejects YAML integer extensions outside the signed 32‑bit range instead of truncating them. Standard‑error output now prefixes messages with ERROR: or WARNING:, aiding log parsing.

Go control‑flow graph breaking change

The Go extractor’s CFG now uses a shared library that adds nodes for assignments, parameters, range statements and deferred calls, while dropping unreachable nodes. This redesign changes node types, edge definitions and textual representations, meaning any custom queries that inspected the previous CFG structure will need review. The change also deprecates IfStmt.getCond in favour of IfStmt.getCondition and adjusts return types for IfStmt.getThen and LoopStmt.getBody to Stmt.

Related CloudNinjas coverage: security.

What This Means For Practitioners

Teams should update their CodeQL configuration to enable the new language models, especially if they rely on C++ regex detection or Go/WebSocket libraries. CI pipelines targeting macOS must pin the OS and Xcode versions to the supported matrix or switch to a non‑traced build mode to avoid broken scans. Review any custom Go CFG queries for compatibility with the new node schema, and adjust CI error‑handling to accommodate the stricter CLI validation. Finally, monitor the upcoming macOS 27 support work to plan a migration path before the current binaries become obsolete.

Originally published atGitHub Changelog