CodeQL 2.26.4 Adds Go 1.27 Support and Sharper Rust Data Flow Alerts

What shipped

CodeQL 2.26.4 is out — the static analysis engine behind GitHub code scanning for finding and remediating security issues in code.

What changed

Per-language highlights:

Why a builder cares

Coverage just landed where injection bugs hide: Go 1.27 codebases, Spring R2DBC reactive SQL, and Python list-mutation flows. The Rust alert-location change makes triage more actionable — expect a one-time churn of old alerts being closed and re-raised at the true sink.

Related posts