GitHub ships CodeQL 2.27.2: deeper Rust, Go and JS data-flow scans

Auto-deployed to github.com scanning, no upgrade step — but a breaking Go control-flow change hits query authors. Also: a Copilot CLI auth-and-context refresh.

Nowline OCT 10 9:00 PM banner

Top AI stories from the last hour

Top AI stories from the last hour

Copy markdown

  • Flows now reach Rust async, Go websockets and JS workflows

    CodeQL 2.27.2 is live on github.com code scanning with no action on your part. It now tracks data flow through Rust async/await and native-tls, Go's coder/websocket import, and JavaScript's Workflow SDK "use workflow"/"use step" directives plus Hapi route handlers; C/C++ gains std::regex parsing and Comdb2 SQL-injection sinks. The Default suite holds at 498 security queries across 170 CWEs, with 131 more in Extended.

  • Go query authors: the CFG just changed under you

    The same release moves Go's control-flow graph onto CodeQL's shared CFG library — a breaking change. BasicBlocks::Cfg is removed, EntryNode and ExitNode are added, and IfStmt.getCond is deprecated in favor of getCondition, so any custom query built on the old representation needs a fix before it compiles.

  • Copilot CLI steadies macOS logins

    Copilot CLI v1.0.95 (Oct 9) improves staying authenticated on macOS and adds control over what context each session loads; v1.0.94 the day before shipped faster model options and fixed config-setup and session-switching reliability. Update if the CLI keeps dropping your session mid-task.