megachangelog
Improvement2.26.1

CodeQL 2.26.1 improves analysis accuracy and framework coverage

CodeQL 2.26.1 enhances static analysis accuracy and expands framework coverage for Go and other languages, improving GitHub's code scanning capabilities for security vulnerability detection.

CodeQL is the static analysis engine behind GitHub code scanning, which finds and remediates security issues in your code. We’ve recently released CodeQL 2.26.1, which improves framework coverage for Go, Java/Kotlin, and JavaScript/TypeScript, and reduces false positives in Rust analysis.

Language and framework support

C/C++

  • Models-as-data flow summaries now use fully qualified field names, such as MyNamespace::MyStruct::myField. Unqualified field names remain supported but will be removed in 12 months.

Go

  • We’ve improved modeling for the log/slog package, including slog.Logger methods, With, WithGroup, Attr, and Value. This expands coverage for applications using structured logging.

Java/Kotlin

  • We’ve added source, sink, and flow summary models for org.apache.poi.

JavaScript/TypeScript

  • We’ve added support for Angular’s @HostListener('window:message', ...) and @HostListener('document:message', ...) decorators. CodeQL now recognizes the decorated method’s event parameter as a client-side remote flow source.

Query changes

Go

  • The improved log/slog modeling expands coverage for the go/log-injection and go/clear-text-logging queries.

Java/Kotlin

  • The java/path-injection query now recognizes input validated with @javax.validation.constraints.Pattern as sanitized, reducing false positives.
  • The java/ssrf query now treats the first argument of Spring WebFlux’s WebClient.UriSpec.uri method as a request forgery sink, which may produce additional valid alerts.

JavaScript/TypeScript

  • The js/missing-origin-check query now analyzes Angular message event handlers declared with @HostListener.

Rust

  • The rust/hard-coded-cryptographic-value query now treats arithmetic, bitwise, and string append operations as barriers. This reduces false positives when code combines hard-coded constants with nonconstant data, such as when incrementing a nonce or appending variable data to a constant prefix.

For a full list of changes, please refer to the complete changelog for version 2.26.1. Every new version of CodeQL is automatically deployed to users of GitHub code scanning on github.com. The new functionality in CodeQL 2.26.1 will also be included in a future GitHub Enterprise Server (GHES) release. If you use an older version of GHES, you can manually upgrade your CodeQL version.

The post CodeQL 2.26.1 improves analysis accuracy and framework coverage appeared first on The GitHub Blog.

codeqlsecuritycode-scanninganalysisgo

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →