CodeQL 2.26.1 improves analysis accuracy and framework coverage
UpdateVerifiedAdded Sep 22, 2026
CodeQL is the static analysis engine behind GitHub code scanning , which finds and remediates security issues in your code. We’ve recently released CodeQL 2.26.1 , which improves framework coverage for Go, Java/Kotlin, and JavaScript/TypeScript, and reduces false positives in Rust analysis.
Topics: SQL, Security, Observability, Developer tools
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Jul 28 | npm publish-time malware scanning and dual-use metadata Update | Update |
| Jul 28 | Dependabot alerts on malicious packages across more ecosystems Update | Update |
| Jul 31 | Restricting npm bypass-2FA granular access tokens Update | Update |
| Aug 4 | Customize code scanning default setup at scale Update | Update |
| Aug 4 | Customize Dependabot pull request branch names Update | Update |
| Aug 4 | Code coverage automatic enablement in Code Quality settings Preview | Preview |
| Aug 4 | CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support Update | Update |
| Aug 7 | Secret scanning coverage updates Update | Update |