GitHub released CodeQL 2.27.1 on September 25, 2026, with new C/C++ and C# queries, Kotlin 2.4.20 support, and analysis improvements across several supported languages. The release is relevant to teams using GitHub code scanning, CodeQL Action, or the standalone CodeQL CLI because it can change both language coverage and the findings produced by scans.
The update is already being deployed to GitHub code scanning users on GitHub.com. CodeQL Action 4.38.2, dated September 24, 2026, also sets CodeQL 2.27.1 as its default bundle. Teams running older GitHub Enterprise Server versions can manually upgrade CodeQL, although the supplied documentation does not provide a complete procedure for every older release.
What changed in CodeQL 2.27.1
The most visible additions are two new queries. For C and C++, cpp/ambiguous-assignment-of-comparison detects potentially ambiguous code where the result of an assignment involving a comparison is used as a truth value. The official query-help documentation gives the query warning severity, high precision, and CWE-783 references. It is listed in both cpp-code-quality.qls and cpp-security-and-quality.qls.
For C#, cs/linq/missed-firstordefault identifies loops that can be expressed using LINQ FirstOrDefault. The query is documented as a high-precision maintainability and readability recommendation rather than a vulnerability detector, and it is listed in csharp-code-quality.qls.
Suite-file membership does not establish that either query is enabled in every default setup. The available documentation also does not identify a query pack for these additions, so administrators should check their configured suites rather than assuming that every scan will run both queries.
CodeQL 2.27.1 also supports Kotlin 2.4.20. The release fixes a Kotlin K2 extraction issue involving Foo::class.java arguments that could contribute to false positives in affected queries. This may reduce compatibility friction for Kotlin projects, but the supplied release information does not define additional compiler, build-system, or project prerequisites specific to Kotlin 2.4.20.
Beyond the new queries and Kotlin support, the release includes analysis or data-flow changes for C/C++, C#, Go, Java and Kotlin, JavaScript and TypeScript, and Rust. The updated models include APIs introduced or updated in Go 1.27. For Rust, the extractor now uses rust-analyzer 0.0.347 and changes the exposed abstract syntax tree, making Rust projects an area that deserves particular attention during validation.
What the update means for scan results
CodeQL changes can affect results in more than one direction. New queries and improved data-flow models may produce additional findings, while extraction fixes may reduce false positives in affected code. Teams should therefore compare results before and after the upgrade rather than assume that a changed finding count represents either a regression or an improvement by itself.
The CodeQL Default suite contains 498 security queries covering 170 CWE categories. The Extended suite adds 131 queries covering 32 additional CWE categories. Those suite totals provide useful context when reviewing configuration, but they do not mean that every query described in the 2.27.1 release is enabled by every project’s configuration.
The C/C++ addition has a direct security-and-quality suite listing, while the C# addition is documented in the C# code-quality suite. Administrators should review the actual suite configuration used by each repository and confirm which results are expected before changing alert-management or triage rules.
Availability through CodeQL Action and the CLI
GitHub says new CodeQL versions are automatically deployed to code scanning users on GitHub.com. For users managing scans through CodeQL Action, version 4.38.2 updates the default CodeQL bundle to 2.27.1. This means the effective CodeQL version can depend on the Action version and configuration used by a workflow.
GitHub Enterprise Server 3.24 is expected to include the new functionality. The supplied sources do not specify the release date or detailed upgrade prerequisites for that version. Users of older GHES releases may manually upgrade CodeQL, but should consult the procedures applicable to their installation rather than treating the general announcement as a complete GHES migration guide.
For standalone CLI deployments, GitHub’s setup guidance recommends the CodeQL bundle instead of combining a standalone CLI with a separate query checkout. The bundle includes the CLI, compatible queries and libraries, and precompiled queries.
The documented platform-specific bundles are Linux x64, Linux ARM64, macOS, and Windows. All-platform distributions are being phased out, and CodeQL CLI 2.27.0 and later warns when run from an all-platforms distribution. The CLI is not currently compatible with non-glibc Linux distributions such as Alpine Linux. On Apple Silicon macOS, the setup documentation calls for Xcode command-line developer tools and Rosetta 2.
What developers and administrators should do
- Identify the CodeQL version in use. Check whether workflows use CodeQL Action 4.38.2 or another configuration that supplies CodeQL 2.27.1. GitHub.com code scanning users may receive the update automatically, while managed or standalone environments may require an explicit change.
- Review language-specific results. Compare C/C++, C#, Kotlin, JavaScript and TypeScript, Go, and Rust findings before and after the update. Pay particular attention to new C/C++ and C# recommendations and to Kotlin projects using the K2 compiler.
- Validate Rust pipelines. Because the Rust extractor uses rust-analyzer 0.0.347 and changes the exposed AST, review any Rust queries, custom analysis, or result-processing logic that depends on AST behavior.
- Confirm suite configuration. Check whether the relevant code-quality or security-and-quality suite files are enabled in each repository. Do not assume that documented suite membership means universal default enablement.
- Use the appropriate CLI bundle. Choose the platform-specific distribution for Linux x64, Linux ARM64, macOS, or Windows, and verify that the host is not using an unsupported non-glibc Linux distribution. Apple Silicon users should account for the documented developer-tools and Rosetta 2 requirements.
- Review environment-specific Java settings. The CLI runtime build of Eclipse Temurin OpenJDK was updated to 25.0.4.1. If that change causes an environment-specific issue, the supporting changelog documents
CODEQL_JAVA_HOMEas a mechanism for selecting an alternative JDK. - Check private NuGet configuration. If an organization uses a private NuGet registry, verify the organization-level
Replacesbase option and how it affects default feeds.
Important upgrade limits
CodeQL 2.27.1 should not be treated as a vulnerability fix, exploit mitigation, or critical security patch based on the available release information. Its security value comes from expanded and improved analysis, including security-relevant data-flow and framework modeling.
The supplied sources do not provide a complete 2.27.1 migration guide covering every possible breaking change. They also do not provide performance measurements, scan-duration changes, or resource-usage comparisons. Teams with custom queries, Rust analysis, private package feeds, or tightly controlled enterprise runners should stage the update and validate their own repositories before broad deployment.


