Version 2.27.2 of CodeQL adds a C++ regular‑expression parser, new data‑flow models for Go, Rust and JavaScript, and a set of CLI and query‑suite improvements. For teams that embed CodeQL in CI/CD, code‑scanning policies, or custom security tooling, the changes broaden detection capability while imposing new constraints on macOS build environments.
CodeQL language analysis extensions
The release adds support for ECMAScript‑grammar regexes used in std::regex, enabling the Default suite to flag patterns that were previously invisible to the analyzer. In Go, the extractor now recognises the github.com/coder/websocket import path alongside nhooyr.io/websocket, improving coverage of WebSocket‑related sinks. Rust sees two class additions—AnyAttr and DocComment—and enhanced async‑block data‑flow handling, plus flow summaries for native-tls, async-native-tls and tokio-native-tls. JavaScript/TypeScript analysis now understands the Workflow SDK directives “use workflow” and “use step”, and it tracks Hapi route‑handler registration through higher‑order helpers.
macOS build‑mode restrictions
Apple’s shift to macOS 27 and Xcode 27 removes the multi‑architecture binaries that CodeQL relies on for traced analysis. Consequently, both the autobuild and manual build modes are unsupported for compiled languages on macOS 27 (any Xcode) and on macOS 26 when Xcode 27 is selected. Practitioners must stay on macOS 26 with Xcode 26 for those modes, or experiment with the “build mode none” workaround that the team is improving.
Query suite and CLI behavior changes
The C# web queries have been refined: the missing‑x‑frame‑options query now recognises ASP.NET Core CSP frame‑ancestors, and the XSS query no longer treats Razor WriteLiteral output as a sink. GitHub Actions’ actions/unpinned-tag query can now exclude owners by prefixing an entry with !, allowing first‑party tag‑pinning exceptions. The CLI now emits clear error messages for malformed qlpack: and from: values, and it rejects YAML integer extensions outside the signed 32‑bit range instead of truncating them. Standard‑error output now prefixes messages with ERROR: or WARNING:, aiding log parsing.
Go control‑flow graph breaking change
The Go extractor’s CFG now uses a shared library that adds nodes for assignments, parameters, range statements and deferred calls, while dropping unreachable nodes. This redesign changes node types, edge definitions and textual representations, meaning any custom queries that inspected the previous CFG structure will need review. The change also deprecates IfStmt.getCond in favour of IfStmt.getCondition and adjusts return types for IfStmt.getThen and LoopStmt.getBody to Stmt.
Related CloudNinjas coverage: security.
What This Means For Practitioners
Teams should update their CodeQL configuration to enable the new language models, especially if they rely on C++ regex detection or Go/WebSocket libraries. CI pipelines targeting macOS must pin the OS and Xcode versions to the supported matrix or switch to a non‑traced build mode to avoid broken scans. Review any custom Go CFG queries for compatibility with the new node schema, and adjust CI error‑handling to accommodate the stricter CLI validation. Finally, monitor the upcoming macOS 27 support work to plan a migration path before the current binaries become obsolete.
