CodeQL 2.26.0 adds Kotlin 2.4.0 support and AI prompt injection detection
UpdateVerifiedAdded Sep 22, 2026
CodeQL is the static analysis engine behind GitHub code scanning , which finds and remediates security issues in your code. We’ve recently released CodeQL 2.26.0 , which adds support for Kotlin 2.4.0, introduces a JavaScript and TypeScript query for system prompt injection, and improves analysis accuracy across multiple languages.
Topics: SQL, Streaming, Security, Observability, Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jul 10 | Clearer names for secret scanning detector types Update | Update |
| Jul 9 | Organization-level targeting for GitHub Code Quality Preview | Preview |
| Jul 8 | Innersource security advisories are generally available GA | GA |
| Jul 8 | npm install-time security and GAT bypass2fa deprecation Deprecation | Deprecation |
| Jul 13 | Manage secret scanning custom patterns via REST API GA | GA |
| Jul 13 | GitHub Code Quality license estimate in public preview Preview | Preview |
| Jul 7 | Secret scanning extended metadata and multipart validation GA | GA |
| Jul 14 | Code scanning shows AI security detections on pull requests Update | Update |