CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis
Summary
CodeQL 2.27.2 is now available, adding a C++ regular-expression parser and analysis improvements across several languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find… The post CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis appeared first on The GitHub Blog .
Original Text
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www.w3.org/TR/REC-html40/loose.dtd"> CodeQL 2.27.2 is now available, adding a C++ regular-expression parser and analysis improvements across several languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues in your code. The Default suite runs 498 security queries covering 170 CWEs. The Extended suite adds 131 queries covering 32 more CWEs.
Language and framework support
C/C++
CodeQL now parses regular expressions that use the ECMAScript grammar in std::regex.
We’ve added SQL-injection sink models for the Comdb2 C API as well as flow summaries for Bloomberg BDE codecs and byte-stream deserializers.
Go
CodeQL now models the github.com/coder/websocket import path, in addition to nhooyr.io/websocket.
Rust
The Rust extractor now supports the AnyAttr and DocComment classes.
We’ve improved data flow for async blocks used with await as well as added flow summaries for native-tls, async-native-tls, and tokio-native-tls.
JavaScript/TypeScript
CodeQL now recognizes the Workflow SDK’s "use workflow" and "use step" directives.
We’ve improved Hapi route-handler and request-input tracking through custom route-registration helpers and higher-order functions.
macOS 27 compatibility
With the release of macOS 27 and Xcode 27, Apple stopped shipping multi-architecture x86-64/arm64 binaries. These binaries are required by CodeQL to perform traced analysis. For this reason, CodeQL’s autobuild and manual build modes will not be supported for compiled languages on macOS 27 with any Xcode version, and on macOS 26 when Xcode 27 is selected. When using these build modes, please use at most macOS 26 and Xcode 26. We are also working on improving support for build mode none on macOS to help mitigate this limitation.
Query changes
C#
The cs/web/missing-x-frame-options query now recognizes ASP.NET Core response headers and Content Security Policy frame-ancestors directives as clickjacking protections.
The cs/web/xss query no longer treats Razor tag-helper attribute values written with WriteLiteral as XSS sinks.
GitHub Actions
You can now remove owners from the trusted set used by the actions/unpinned-tag query by adding an entry prefixed with !, such as !github. This lets you report unpinned tags for first-party owners.
CodeQL CLI
The CLI now reports invalid qlpack: and from: values in query suites as clear errors instead of crashing.
CodeQL now rejects YAML data-extension integers outside the signed 32-bit range instead of silently truncating some values.
Error and warning messages on standard error now include ERROR: and WARNING: prefixes. Structured output, including logs and SARIF, remains unchanged.
codeql query compile now accepts --dil-constants with --dump-dil to include optimized constant tuple sets in emitted DIL.
Commands that load data extensions now only warn when none of the patterns in a pack’s dataExtensions list match any files.
Go library breaking change
The Go control-flow graph (CFG) now uses the shared CFG library. It includes additional nodes for constructs such as assignments, parameters and results, range statements, and deferred calls, and excludes nodes that aren’t reachable from the entry point. This changes CFG nodes, edges, locations, textual representations, and basic-block boundaries, so you may need to update queries that rely on the previous representation.
The update:
Removes BasicBlocks::Cfg.
Adds ControlFlow::EntryNode, ControlFlow::ExitNode, and SwitchStmt.getExpr.
Deprecates IfStmt.getCond in favor of IfStmt.getCondition.
Changes the return types of IfStmt.getThen and LoopStmt.getBody to Stmt.
Consolidates several IR instruction classes.
For full details, see the CodeQL 2.27.2 changelog. GitHub automatically deploys every new CodeQL version to users of GitHub code scanning on github.com. A future GitHub Enterprise Server (GHES) release will also include the new functionality in CodeQL 2.27.2. If you use an older version of GHES, you can manually upgrade your CodeQL version.
The post CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis appeared first on The GitHub Blog.
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.